Akamaister
Akamaister
andrewgstanton@primal.net
Nov 15, 2025

Npubs + Signed Messages: Replacing Logins

How npubs and cryptographic signatures can replace email/password logins.

Andrew G. Stanton - Aug. 25, 2025

1. The Login Problem

Every online service today starts with the same tired ritual: pick a username, invent a password, give us your email, and hope our database never gets hacked.

This model is broken. Passwords are reused and stolen. Emails are harvested. Centralized databases leak and leak again.

Logins are not just inconvenient. They are insecure by design.

2. Enter npubs

An npub (Nostr public key) is a sovereign identifier. Unlike usernames, it isn’t rented from a platform. Unlike emails, it doesn’t route through Gmail or Outlook.

Your npub is yours, forever. It’s portable and cryptographic. That makes it the perfect login credential.

3. Signed Messages as Authentication

How would it work? Simple:

  1. A service prompts you to “sign in with npub.”
  2. You sign a short message with your private key.
  3. The service verifies the signature against your npub.

That’s it. No passwords, no emails, no databases to hack. Just math.

4. Prototype in Practice: Continuum Pro

This isn’t just theoretical. I’m already using npubs + signed messages as the login system for Continuum Pro, my hosted dashboard ->

dashboard.mycontinum.xyx/nostr/dashboard/pro/default_npub...

  • The local Continuum app generates a signed message proving control of my npub(s).
  • Continuum Pro verifies the signature, then syncs those npubs into the hosted dashboard.
  • No passwords. No emails. No centralized database to leak.

The exact same flow that secures identity in Continuum Pro could secure identity anywhere on the web. If it works for sovereign publishing, it can work for banks, social platforms, and everyday apps.

5. Why This Beats Email/Password

  • Unphishable. There’s no password to trick out of you.
  • Unleakable. Services don’t need to store secrets.
  • Portable. You bring the same npub anywhere.
  • Permissionless. No one can revoke your login.

This isn’t just better security — it’s sovereignty applied to authentication.

6. Beyond Login: Identity Layers

Once services adopt npub login, they can add layers:

  • Display profile data directly from your kind:0 event.
  • Verify multiple npubs you own (personal, business, pseudonymous).
  • Use zaps or proofs (like credit receipts) as optional trust layers.

Suddenly, logins aren’t just credentials. They’re sovereign identities.

7. The Future Without Passwords

Imagine a web where:

  • No one ever asks for your email.
  • Password reset links don’t exist.
  • Your npub is your passport.

Services verify you without storing any secret that could leak.

That future is not fantasy. It’s already how Nostr works. We just need to extend it to every service that still clings to email and passwords.

8. Closing Thought

Passwords are the relic of a pre-sovereign internet.

Npubs and signed messages are the next step: authentication rooted in math, not bureaucracy.

Bitcoin gave us sovereign money. Nostr gives us sovereign identity. Together, they can give us sovereign access.


Acknowledgement

This article was drafted with the help of Dr. C - ChatGPT (GPT-5), which I use as a co-writer and collaborator in developing ideas around sovereignty, Bitcoin, decentralization, and theology


Zaps Appreciated

If this resonates, consider sending a zap. Every zap is an act of sovereign support — no middlemen, no gatekeepers, just direct proof that this work matters. It helps me keep building Continuum and writing about sovereign technology, freely and without VC overhead. Thank you.

You can send zaps to my lightning address here : andrewgstanton​​​@primal.net