Orkestia
Blog
App Host

Signing keys

Customer-managed secp256k1 keys (nsec) for Buzz — create or import, copy once, bind the site owner. Not org members, not a Chat Relay invite.

Buzz authenticates with Nostr (NIP-42). The key that proves you are the site owner is a signing key you manage. Orkestia does not generate a "Buzz invite" and does not put the relay private key in the console.

Where keys live

Settings → Signing Keys (/settings/keys).

That page is not Members. Members operate the org. Signing keys are secp256k1 identities for relays (and other consumers you bind).

Create or import

Create

On Signing Keys, create a key and give it a label. The console shows nsec once. Buzz Desktop wants nsec…, not hex. Copy it now. It will not be shown again.

Or import

Paste an nsec… (or 64-character hex) you already generated. The public key is derived. If you pasted hex, copy nsec from the next dialog so Desktop and the console agree.

Bind the site as owner

On the site Buzz tab (or from Signing Keys), bind that key as owner of the hosted site (identity.key.bind with consumer_kind=apphost_site). Then Re-apply Buzz so the relay knows the owner public key.

Open Desktop with that nsec

In Buzz Desktop choose Use a different key and paste the same nsec. A new Desktop key will not match the owner you bound.

Create uses identity.key.create. Import is identity.key.import. You do not need identity.key.reveal (that path is admin-only and is not how the console issues nsec).

Treat nsec like a password. The docs and the console will not print yours. If you lost it, import a key you still hold or create a new one, bind it, and re-apply Buzz.

What the platform keeps

The relay key stays on the cluster. The console shows how to connect (wss://, readiness, media), not BUZZ_RELAY_PRIVATE_KEY.

Owner keys you create are your material. Bind them; do not ask the platform to email them.

Members stay in Members

You wantWhere
Invite a teammate to the orgSettings → Members
Let someone AUTH to this Buzz as ownerSigning key + bind + their nsec in Desktop
Sign in an end-user to your appSign in with Orkestia

Do not create org people from the Buzz tab.