NIP-26 documents a way for one Nostr key to authorize another key to sign a limited set of events. Its current specification is marked draft and unrecommended, so it records an earlier design rather than advice for a new integration.

How it works

The account key signs a delegation token naming the delegate key and conditions. The conditions can restrict event kinds and created_at times. The delegate signs the event with its own key and attaches the token in a delegation tag. A reader must verify both the event signature and the delegation token against those conditions. Relays that support the scheme can also search by delegator.

The model lets an application publish without holding the account’s primary signing key. Its extra validation and relay-search requirements explain why implementations cannot treat an ordinary event signature as sufficient proof of a delegated identity. The current specification explicitly marks the approach unrecommended.


Primary sources:

Mentioned in: