t-of-n BIP340 threshold signer · no group key ever exists

Member identity

This is your personal Nostr key. It is never the group key, never a FROST share, and never leaves this browser. It authenticates your DKG and signing coordination messages.

Identity verification

Create a group (DKG)

Every member runs DKG together. The group public key is the sum of each member's constant-term commitment. No dealer, no reconstructed secret. Membership is fixed at DKG time.

Coordination is ephemeral. All members need at least one common relay; 3–4 is typical.

Your groups

DKG transcript

Full cryptographic audit of group formation — commitments, proofs of knowledge, per-member verifying shares, and the derived group key.

No group selected.

Group chat

No group selected
Ctrl/⌘ + Enter to sign · coordination is ephemeral, other members must be online

Session inspector

Every value in the signing round — nonce commitments, binding factors, Lagrange coefficients, shares, and independent BIP340 verification.

No session yet.

Roster

Active relay pool

FROSTNostr never opens more than 4 relays at once. The active set is chosen by heuristics: trusted-relay reputation + measured latency + reliability history.

Relay catalog

Event log

RFC 9591 self-tests

In-browser checks against the noble-curves FROST implementation: DKG consistency, Lagrange interpolation, binding factors, nonce-reuse rejection, tamper detection, and BIP340 verification.