Getting Started

Getting Started

Set up your account and learn the basics of Colabonate.

Guide

Create your account

How Lightning and Nostr authentication works and what you need to get started.

Colabonate uses Lightning Network and Nostr protocol for authentication. No email or password required. Simply connect with a Lightning-compatible wallet (like Alby) or a Nostr extension (like nos2x). Your identity is tied to your public key — secure, decentralized, and portable.

How it works

1

Install Alby

Get a Lightning wallet browser extension

Guided setup with Alby

Free Nostr signer and Lightning wallet for Chrome, Firefox, Edge, Safari and Opera.

2

Connect

Click "Login" and approve the connection

3

Set up profile

Add your name and optional avatar

4

Choose Identity Level

Start at L0 or upgrade to L1 for more trust

Your pubkey is your identity — keep your NIP-07 extension secure.

Guide

Get started with Nostr

New to Nostr? Generate your keys, install a signer, fund Lightning, and connect to Colabonate — your complete first-time guide.

Welcome! Nostr is the decentralized protocol behind your Colabonate identity. There is no email and no password: a cryptographic keypair IS your account. This guide walks a complete newcomer from "what is a key?" all the way to logging in to Colabonate and making your first move.

How it works

1

Get your Nostr identity

Your keypair is your account. npub is the public address others follow; nsec is the secret — never share it

Create your identity with nosta.me

Generates your Nostr keypair and profile in one simple flow — perfect for your first identity.

2

Back up your nsec

Write it on paper or in a password manager immediately. There is no password reset — lose it, lose the account forever

3

Install a signer (recommended)

A signer like Alby, nos2x, or Amber holds your key and signs for every app, so your nsec never leaves it. Prefer a guided setup? Tools like nosta.me walk you through creating a profile and connecting a signer in one flow.

Guided setup with Alby

Free Nostr signer and Lightning wallet for Chrome, Firefox, Edge, Safari and Opera.

4

Fund a Lightning wallet

Colabonate runs on Bitcoin Lightning. Add sats to pay for offers, fund escrow, and receive payments

Top up your Alby wallet

Receive sats to your Alby Lightning address, or buy Bitcoin inside the extension.

5

Connect to Colabonate

On the login screen choose "via Signer" and approve the prompt — your signer signs without exposing your key

6

Build your network

Set a profile name, avatar, and optional NIP-05 so your Colabonate reputation travels across all Nostr apps

CRITICAL: never share your nsec or paste it into a website. If someone gets it they can impersonate you completely; if you lose it, your account and reputation are gone forever — there is no password reset. A signer app keeps it out of harm's way.

Your npub is portable: the same identity works in Damus, Amethyst, Iris, Primal, and every Nostr app — not just Colabonate.

No Nostr key yet? Email login gives you an instant L0 account; attach a real signer later from Account → Identity & Security.

Learn more

What is Nostr (and why Colabonate runs on it)?

Nostr ("Notes and Other Stuff Transmitted by Relays") is a simple, censorship-resistant protocol for publishing signed events. Instead of one company holding your account, you hold a keypair and everything you publish is cryptographically signed by it. Colabonate builds on Nostr so your identity, offers, tickets, and reviews stay portable, verifiable, and impossible to silently revoke — the same key works across the whole ecosystem, so you are never locked in.

Two ways to get your keys

Option 1 — generate keys inside a Nostr client app (e.g. Damus on iOS, Primal, Amethyst on Android): the app creates the keypair for you, but you must back up the nsec it shows immediately. Option 2 — use a signer first (recommended for security): install a dedicated signer such as Alby (browser extension), Amber (Android), nsec.app, or Nostore, generate your keys within it, back up the nsec, then connect to clients including Colabonate by choosing "Login with signer / extension". The signer signs on your behalf and your private key never leaves it — the safest way to use many apps. Colabonate login uses the NIP-07 signer path (Option 2).

NIP-07 vs NIP-46 — which signer?

NIP-07 keeps your private key inside a browser extension (Alby, nos2x, Nostr Signer, Flint) and signs locally — easiest for desktop. NIP-46 (Nostr Connect) keeps the key on a remote "bunker" such as Alby Hub, Amber, or nsecBunker; your browser asks the bunker to sign over a Nostr message, so the key never enters the browser. Pick NIP-07 for a quick desktop setup; pick NIP-46 for the strongest day-to-day security and mobile support. Both are first-class on Colabonate.

Relays and Zaps — the basics

Relays are the servers that store and distribute Nostr messages. Your client connects to several relays to send and receive notes and events — you can add or remove them anytime, which gives you control over where your data lives. Zaps are Bitcoin Lightning payments sent directly through Nostr, an easy way to support creators and show appreciation. Colabonate's escrow and peer-to-peer payments are built on the same Lightning layer, so the wallet you fund in Step 4 is what powers every payment on the platform.

Colabonate uses a four-tier identity system to balance privacy, trust, and access. L0 (Anonymous) is where every account starts, no matter which login provider you use. L1 (Nostr Profile) links your account to a Nostr public key so you can trade. L2 (Peer Verified) adds in-person community verification and unlocks governance. L3 (HID Verified) is the highest tier: a zero-knowledge biometric proof via Humanode Biomapper that guarantees one person, one account.

1

L0 Anonymous

Default after login — browse only, no trading

2

L1 Nostr Profile

Link a Nostr key via NIP-07 (Alby, nos2x, etc.) to create offers and tickets

3

L2 Peer Verified

Two independent verifiers confirm your identity — unlocks DAO governance and higher limits

4

L3 HID Verified

Humanode Biomapper ZK biometric proof — 1-person-1-vote and arbitrator eligibility

Login providers (Nostr, Lightning, Alby, MetaMask, Email, Nostr Connect) all create an L0 account. Upgrade to L1 to unlock trading.

L2 currently has a mock upgrade path in the UI; the full protocol requires two in-person verifiers and a proximity proof.

L3 is not yet implemented; the Humanode HID flow is planned for a later phase.

L0 Anonymous — browse before you trust

When you log in with any provider — Nostr (NIP-07), Lightning/LNURL-auth, Alby OAuth, MetaMask, Email magic link, or Nostr Connect (NIP-46) — your account starts at L0. This level lets you browse the marketplace, view offers and vendors, and create a basic profile, but you cannot create offers, start or accept tickets, or participate in governance. L0 is designed for exploration with minimal commitment.

L1 Nostr Profile — how to unlock trading

To reach L1 you link a Nostr profile to your Colabonate account. Go to Account → Identity & Security → Identity Levels and choose "Connect Nostr Profile → Level 1". You need a NIP-07 browser extension such as Alby or nos2x. The flow has three steps: (1) publish a Nostr Kind-0 profile with your display name and Lightning address (lud16), (2) publish a Kind-30021 identity credential that binds your Nostr pubkey to your Colabonate LNURL-auth pubkey, and (3) sign a NIP-98 auth event and call POST /api/identity/upgrade-l1. Once verified, you can create offers, open and accept tickets, and build public reputation.

L2 Peer Verified — governance and higher limits

Level 2 is reached when two independent community verifiers confirm your identity through an in-person proximity proof. The protocol requires you to post a security deposit, meet both verifiers in person, and have each verifier publish a Kind-30026 Proximity Proof event. When the protocol confirms both proofs, a Kind-30021 identity_level_2 credential is issued and your account is upgraded. In the current implementation this is exposed as a mock button ("Start Peer Verification (Mock)"); completing it also awards 50 COL-Points. L2 unlocks DAO governance votes, higher trade limits, priority matching, and reduced dispute risk.

L3 HID Verified — one person, one account

L3 is the highest trust tier. It uses Humanode Biomapper to generate a zero-knowledge biometric proof that you are a unique human, without revealing your identity or storing biometric data on Colabonate servers. The planned flow requires an L2 account, the Colabonate app with the Humanode Biomapper SDK, an on-device fingerprint scan, submission of an anonymous ZK commitment, and publication of a Kind-30023 HID attestation event. L3 unlocks 1-person-1-vote governance weight, arbitrator eligibility, maximum ticket limits, and the full trust multiplier. This level is currently shown as "Phase 4 – Coming soon" and is not yet available.

How login providers relate to your identity level

Your login method determines how you authenticate, not your identity level. Nostr (NIP-07) and Nostr Connect (NIP-46) sign challenges with your Nostr private key. Lightning/LNURL-auth and Alby OAuth prove control of a Lightning wallet. MetaMask derives a Nostr identity from your Ethereum address after two signatures. Email sends a magic link. All of these create or access an L0 account. To trade, you still need to upgrade to L1 by linking a Nostr profile, because offers, tickets, reviews, and reputation on Colabonate are Nostr events signed by your pubkey.

Why identity levels matter

Identity levels are Colabonate's sybil-resistance and trust layer. Higher levels make it harder for one person to operate many fake accounts, which protects reviews, votes, and escrow. They also signal trust to other users: buyers prefer L2/L3 sellers for high-value orders, and the platform requires L3 for sensitive roles such as arbitration. Each level is additive — L1 proves key ownership, L2 adds social verification, and L3 adds biometric uniqueness — so you only share as much information as needed for the features you want to use.

After login you will land on the Home screen. Use the bottom navigation to browse Buy, Sell, and Cooperate sections. Tap your profile to add a photo and description. Explore categories in the Buy tab to discover what is available nearby.

Use the search bar on Home to find specific products or services.

Set up your profile before creating your first offer to build trust faster.

The onboarding flow guides new users through profile setup, identity verification, and key features. You can skip individual screens and return later. Completed screens are marked with a checkmark. Finish onboarding to unlock full platform features.

You can restart the onboarding from Settings at any time.

If you already have MetaMask installed, you can use it to log in to Colabonate. The app asks you to sign two messages: one to derive your Nostr identity, and one to authenticate the session. Neither message spends gas or sends a transaction. Once signed, Colabonate creates an account linked to your Ethereum address and the derived Nostr public key.

1

Install MetaMask

Add the MetaMask extension to your browser

2

Choose MetaMask tab

On the login screen, select the MetaMask tab

3

Sign derivation

Approve the "derive identity" signature (one-time per address)

4

Sign authentication

Approve the session signature to log in

Your Nostr identity is reproducible from your MetaMask seed — keep your recovery phrase safe.

MetaMask is not a Lightning wallet. You still need a Lightning wallet for payments.