LinuxmacOSWindows

Where Does nak Keep Keys?

nak keeps no config file: keys pass per command via flags or env vars. Signing flows and bunker persistence.

Last updated

nak has no config file and no key store. Every signing decision happens per invocation: pass the secret with a flag, export it for the session, or delegate to a bunker signer. Nothing on disk remembers the key afterwards.

That surprises people hunting for ~/.nak. The documented variable is NOSTR_SECRET_KEY for event keys, with a separate client key for bunker flows. The only thing nak persists is bunker session metadata on explicit request. Treat shell history as the leak vector instead of config files.

Where nak stores this, by platform

Linux
No config file (keys via --sec flag or NOSTR_SECRET_KEY)

Example: nak event --sec <hex|nsec> for one-shots, or export NOSTR_SECRET_KEY then sign. Bunker flows use bunker URLs with a client key. Only nak bunker --persist writes metadata. Same flag and env model on Mac and Windows builds.

macOS
No config file (keys via --sec flag or NOSTR_SECRET_KEY)

Same model as Linux. Keep keys out of shared shell history with leading-space or HISTCONTROL settings. The docs example key is illustrative only and must never sign real events.

Windows
No config file (keys via --sec flag or NOSTR_SECRET_KEY)

Same model on Windows builds. Prefer env vars set per session over flags that land in console history. Bunker persist files, when used, are the only artifacts to back up.

Frequently asked questions

Where is the nak config file?

Nowhere: none exists by design. Keys travel per command through the sec flag or the NOSTR_SECRET_KEY variable. Only explicit bunker persist writes anything to disk, and that holds session metadata rather than a keyring.

How do I avoid leaking my nsec with nak?

Prefer env vars over flags, keep history control tight, and clear the variable when done. Flags land in shell history verbatim. Bunker signing keeps the secret on the signer side entirely.

What does nak bunker persist actually save?

Bunker session metadata for reconnecting to the signer, optionally under a named profile. It does not become a general key store. Delete the persisted profile when retiring a signer relationship.

Notice an outdated path? Let us know.