A vibe coded project
Vault46 is an iOS NIP-46 remote signer (bunker) for Nostr. It securely stores your private keys and allows other Nostr applications to request signatures without exposing your keys.
NIP-46 defines a protocol for remote signing. Instead of giving your private key to every Nostr client, you can use Vault46 as a signing service. Clients send signing requests to Vault46 via relay, and you approve or deny each request on your device.
- Secure key storage using iOS Keychain (via Vault)
- Face ID / Touch ID lock with passcode fallback, for the app and for approvals
- Generate new Nostr keys or import existing ones (nsec or seed phrase)
- Review and approve signing requests from connected clients, or always-allow a request type per client
- Link clients two ways: show a
bunker://QR code, or open/paste anostrconnect://link - Manage connected client applications and the relays the signer listens on
- Replies to legacy NIP-04 clients in NIP-04, everyone else in NIP-44
- Xcode 26 or later
- iOS 26.2+ deployment target
- An Apple Developer account (for signing)
-
Clone the repository
-
Copy the xcconfig template and configure your personal settings:
cp User.xcconfig.template User.xcconfig -
Update
User.xcconfigwith your personal information:DEVELOPMENT_TEAM = YOUR_TEAM_ID BUNDLE_ID_PREFIX = com.yourcompanyReplace
YOUR_TEAM_IDwith your Apple Developer Team ID andcom.yourcompanywith your bundle identifier prefix. -
Open
Vault46.xcodeprojin Xcode -
Build and run
Model and service tests live in Vault46Tests (Swift Testing). Run them with Cmd-U or:
xcodebuild -project Vault46.xcodeproj -scheme Vault46 -destination 'platform=iOS Simulator,name=iPhone 17 Pro' test
- NostrKit - Nostr protocol implementation for iOS, including the
BunkerSignerNIP-46 engine this app is built on - Vault - Secure storage wrapper for iOS Keychain
The app follows a presenter-state pattern with SwiftUI:
- Models - Signing requests, client session display helpers, and the SwiftData mirror of connected clients
- Services - Key management (
KeyService), theBunkerSignerlifecycle (BunkerService), session persistence (SessionStore), and device authentication (BiometricService) - Modules - Feature-based organization (Auth, Main, Splash) with presenter/state/view separation
- Libs / Extensions - The
TaskTriggerpattern used for async work from views, and URL routing
Vault46 is licensed under the PolyForm Noncommercial License 1.0.0. You may use, modify, and share the code and the app for any noncommercial purpose. Commercial use requires permission from SparrowTek LLC. See LICENSE for the full terms.