English
← All news

LNURL-auth: inicia sesión con tu wallet, sin email ni contraseña

Qué es LNURL-auth y por qué reemplaza al email y la contraseña,Entrar con tu wallet Lightning: así funciona LNURL-auth

LNURL-auth is a login method where your Lightning wallet acts as a key. You scan a QR code, confirm in your wallet, and you're in. The site never receives an email, a password, or your name.

The problem with email and password

Every account you open with an email leaves three things on a third-party server: your address, a password (hopefully properly encrypted), and a link between the two and your activity on that site. If the database leaks, all of that is exposed. Furthermore, an email identifies you across different sites. Two unrelated services can cross-reference data simply because you used the same address. LNURL-auth eliminates both issues: there is no password to steal and no data to cross-reference.

What happens when you scan the QR code

  1. The site generates a challenge. It is a single-use random number included in the QR code along with the site's domain address.
  2. Your wallet creates a key for that site. Based on your seed and the domain, it derives a key pair exclusive to that domain.
  3. Your wallet signs the challenge with that pair's private key.
  4. The site verifies the signature using the public key sent by the wallet.
  5. That public key is your account. The next time you sign with it, the site knows you are the same person.

Everything happens in a couple of seconds. No satoshis move: logging in is not a payment and grants no spending permissions.

What the site sees and what it doesn't

What the site receivesWhat the site does not receive
A public key exclusive to that domainNeither your seed phrase nor your private keys
A valid signature of the challengeYour balance
Your payment history
Your name, email, or phone number
The key you use on other sites

Why each site sees a different key

The key is derived using the domain as an ingredient. The result is that on site-a.com you are one key and on site-b.com you are another, with no visible relationship between the two. Two sites cannot compare notes to know that you are the same person. It is a level of privacy that email cannot offer.

What you should know before using it

Your wallet is your account. There is no 'forgot password'. If you lose your wallet and don't have its backup, no one can restore your access, because the site doesn't store anything to identify you with. Save your backup words. If you restore the wallet using its 12 or 24 words, you recover the exact same key and, with it, your account. Restore in the same application. Not all wallets derive the login key the same way. Using the exact same seed words, a different application might generate a different key, and the site would see it as a brand-new account. In a custodial wallet, the provider holds the key. If that company shuts down or freezes your account, you also lose access to the sites you logged into with it. For anything you want to keep, use a wallet where you control the backup words. Check the domain before confirming. Your wallet shows which site you are logging into. If it is not the one you expected, cancel.

← All news