Orkestia
Blog
Settings

Signing Keys

Create or import secp256k1 signing keys, copy nsec once, and bind them to a hosted site. Separate from org members.

Signing Keys are secp256k1 identities for relays (Buzz) and other consumers you bind. They are not organization members and not API tokens.

Navigate to Settings → Signing Keys or /settings/keys.

Create

  1. Enter a label.
  2. Create the key (identity.key.create).
  3. Copy nsec from the dialog. Buzz Desktop uses nsec, not hex. This is a one-time reveal.

Import

Paste nsec1… or 64-character private hex (identity.key.import). Copy nsec from the following dialog if you pasted hex.

Bind

Bind a key to a consumer (identity.key.bind): for Buzz, the consumer is the hosted site with role owner. Then re-apply Buzz on App Host.

Unbind with identity.key.unbind. Revoke with identity.key.revoke when the key must never authenticate again.

What this is not

  • Members stay under Settings → Members.
  • API tokens stay under Security / API tokens — those are org Bearer tokens for MCP, not nsec.
  • The relay private key never appears here. It stays on the App Host cluster.

Full customer path, including Desktop: App Host → Signing keys.