# Nostr

> 通过 NIP-04 加密消息实现的 Nostr 私信渠道

- 网址：https://funcoding.ai/agents/openclaw/channels/nostr/
- 来源：OpenClaw 官方文档原文（中文），MIT 许可，同步于 2026-10-11
- 官方原文：https://docs.openclaw.ai/zh-CN/channels/nostr

---
Nostr 是一个可下载的渠道插件（`@openclaw/nostr`），可让 OpenClaw 通过 Nostr 中继接收和回复使用 NIP-04 加密的私信。每个 Gateway 网关仅支持一个帐户；仅支持私信。

## 安装

```bash
openclaw plugins install @openclaw/nostr
```

使用不带版本的包规范可跟随当前官方发布标签。仅在需要可复现安装时固定确切版本。

从本地检出安装（开发工作流）：

```bash
openclaw plugins install --link <path-to-local-nostr-plugin>
```

安装或启用插件后，重启 Gateway 网关。安装插件后，新手引导（`openclaw onboard`）和 `openclaw channels add` 会从共享渠道目录中显示 Nostr。

### 非交互式设置

```bash
openclaw channels add --channel nostr --private-key "$NOSTR_PRIVATE_KEY"
openclaw channels add --channel nostr --private-key "$NOSTR_PRIVATE_KEY" --relay-urls "wss://relay.damus.io,wss://relay.primal.net"
```

使用 `--use-env` 可将 `NOSTR_PRIVATE_KEY` 保留在环境变量中，而不是将密钥存储在配置中（仅适用于默认帐户）。

## 快速设置

1. 生成 Nostr 密钥对（如需要）：

```bash
# 使用 nak
nak key generate
```

2. 添加到配置：

```json5
{
  channels: {
    nostr: {
      privateKey: "${NOSTR_PRIVATE_KEY}",
    },
  },
}
```

3. 导出密钥：

```bash
export NOSTR_PRIVATE_KEY="nsec1..."
```

4. 重启 Gateway 网关。

## 配置参考

| 键          | 类型     | 默认值                                     | 描述                                              |
| ------------ | -------- | ------------------------------------------- | -------------------------------------------------------- |
| `privateKey` | string   | 必填                                    | `nsec` 或十六进制格式的私钥；允许使用密钥引用 |
| `relays`     | string[] | `['wss://relay.damus.io', 'wss://nos.lol']` | 中继 URL（WebSocket）                                   |
| `dmPolicy`   | string   | `pairing`                                   | 私信访问策略                                         |
| `allowFrom`  | string[] | `[]`                                        | 允许的发送者公钥                                   |
| `enabled`    | boolean  | `true`                                      | 启用/禁用渠道                                   |
| `name`       | string   | -                                           | 显示名称                                             |
| `profile`    | object   | -                                           | NIP-01 个人资料元数据                                  |

## 个人资料元数据

个人资料数据会作为 NIP-01 `kind:0` 事件发布。你可以在 Control UI（Channels -> Nostr -> Profile）中管理，也可以直接在配置中设置。

示例：

```json5
{
  channels: {
    nostr: {
      privateKey: "${NOSTR_PRIVATE_KEY}",
      profile: {
        name: "openclaw",
        displayName: "OpenClaw",
        about: "个人助理私信机器人",
        picture: "https://example.com/avatar.png",
        banner: "https://example.com/banner.png",
        website: "https://example.com",
        nip05: "openclaw@example.com",
        lud16: "openclaw@example.com",
      },
    },
  },
}
```

注意：

- 个人资料 URL 必须使用 `https://`。
- 从中继导入时会合并字段，并保留本地覆盖值。

## 访问控制

### 私信策略

- **配对**（默认）：未知发送者会收到配对码。
- **允许列表**：只有 `allowFrom` 中的公钥才能发送私信。
- **开放**：公开接收入站私信（需要 `allowFrom: ["*"]`）。
- **禁用**：忽略入站私信。

执行说明：

- 在应用发送者策略和执行 NIP-04 解密前，会先验证入站事件签名，因此伪造事件会被提前拒绝。
- 发送配对回复时，不会解密或处理原始私信正文。
- 入站私信会受到速率限制（全局和按发送者），过大的负载会在解密前被丢弃。

### 允许列表示例

```json5
{
  channels: {
    nostr: {
      privateKey: "${NOSTR_PRIVATE_KEY}",
      dmPolicy: "allowlist",
      allowFrom: ["npub1abc...", "npub1xyz..."],
    },
  },
}
```

## 密钥格式

接受的格式：

- **私钥：**`nsec...` 或 64 字符十六进制格式
- **公钥（`allowFrom`）：**`npub...` 或十六进制格式

## 中继

默认值：`relay.damus.io` 和 `nos.lol`。

```json5
{
  channels: {
    nostr: {
      privateKey: "${NOSTR_PRIVATE_KEY}",
      relays: ["wss://relay.damus.io", "wss://relay.primal.net", "wss://nostr.wine"],
    },
  },
}
```

提示：

- 使用 2-3 个中继以实现冗余。
- 避免使用过多中继（会增加延迟和重复消息）。
- 付费中继可以提高可靠性。
- 本地中继适合用于测试（`ws://localhost:7777`）。

## 协议支持

| NIP    | 状态    | 描述                           |
| ------ | --------- | ------------------------------------- |
| NIP-01 | 支持 | 基本事件格式 + 个人资料元数据 |
| NIP-04 | 支持 | 加密私信（`kind:4`）              |
| NIP-17 | 计划支持   | 礼物包装式私信                      |
| NIP-44 | 计划支持   | 带版本的加密                  |

## 测试

### 本地中继

```bash
# 启动 strfry
docker run -p 7777:7777 ghcr.io/hoytech/strfry
```

```json5
{
  channels: {
    nostr: {
      privateKey: "${NOSTR_PRIVATE_KEY}",
      relays: ["ws://localhost:7777"],
    },
  },
}
```

### 手动测试

1. 从 Gateway 网关日志或 `openclaw channels status` 中记下机器人公钥（十六进制格式；如需要，请在客户端中转换为 npub）。
2. 打开 Nostr 客户端（Amethyst、Damus 等）。
3. 向机器人公钥发送私信。
4. 验证回复。

## 故障排查

### 未收到消息

- 验证私钥是否有效。
- 确保中继 URL 可访问并使用 `wss://`（本地使用 `ws://`）。
- 确认 `enabled` 不是 `false`。
- 检查 Gateway 网关日志中是否存在中继连接错误。

### 未发送回复

- 检查中继是否接受写入。
- 验证出站连接。
- 留意中继速率限制。

### 重复回复

- 使用多个中继时，这是预期行为。
- 消息会按事件 ID 去重；只有首次送达会触发回复。

## 安全

- 切勿提交私钥。
- 使用环境变量存储密钥。
- 对于生产环境机器人，请考虑使用 `allowlist`。
- 先验证签名，再应用发送者策略，并在解密前执行发送者策略，因此伪造事件会被提前拒绝，未知发送者也无法强制执行完整的加密运算。

## 限制（MVP）

- 仅支持私信（不支持群聊）。
- 不支持媒体附件。
- 仅支持 NIP-04（计划支持 NIP-17 礼物包装）。

## 相关内容

- [渠道概览](https://funcoding.ai/agents/openclaw/channels/) — 所有支持的渠道
- [配对](https://funcoding.ai/agents/openclaw/channels/pairing/) — 私信身份验证和配对流程
- [群组](https://funcoding.ai/agents/openclaw/channels/groups/) — 群聊行为和提及门控
- [频道路由](https://funcoding.ai/agents/openclaw/channels/channel-routing/) — 消息的会话路由
- [安全](https://funcoding.ai/agents/openclaw/gateway/security/) — 访问模型和安全加固
