*Security model
Server only sees your public key
All signing happens in your signer app
Communication is NIP-44 encrypted (ChaCha20 + HMAC-SHA256)
Server uses a disposable keypair for each session
Sessions stored server-side with HTTP-only cookies*
View quoted note β
