Replies (23)

cool! the event is passed clear to the target? No encryption? You must make sure your NWT does not ends in the wrong hands. Handy for client to manage their login once and for all, I see it being particularly useful for paid relays if they implement it.
I was thinking nip44 if the target has a pubkey, may be overkill, some will want the option, I don’t know
I like this, its a lot more structured and thought out than my initial attempt to build authorization tokens for blossom. I haven't thought through this completely yet, but I think this might be a good standard to move blossom to, and hopefully deprecate NIP-98. Unfortunately that would mean a breaking change, and no longer using the kind 24242 which I liked :(
Fwiw the zapstore publishing tool only pushes to one Blossom server because it's a pain to prompt the user for many (in browser signing for example) I think nwt would solve that problem
Thanks mate, I appreciate. I think changing kind is the best way to deprecate the old auth, otherwise there will be confusion and people will try to support both the old and the new spec.
↑