Restricted operator surface
BitUnlock operations.
Platform-wide activity, onboarding, and incident attention for the configured super-admin identity. Every request requires a fresh NIP-98 signature.
Operator sign in
The API verifies that the signer is the configured BitUnlock super admin. This page does not create a privileged browser session.
Other sign-in options
Advanced: use the operator private key (nsec)
Higher risk: use only on a trusted device. The decoded key stays in memory, is never stored or sent, and its bytes are overwritten on sign-out.
Choose a sign-in method to continue.
Loading operator overview…
Platform overview
Service-wide commercial and operational totals. Tenant reporting remains isolated in the Seller portal.
Needs attention
Tenants
Operational tenant summaries. Credentials and generic secret values are never returned.
Orders
Sanitized platform-wide order state for support and incident response.
Seller onboarding allowlist
Add or remove Nostr identities permitted to create a seller tenant.
Approve a seller
The signed-in super admin is recorded as the approving identity.
Security & operations
Trust boundaries and current service posture for incident response.
Provider credentials
Tenant provider API keys live encrypted under that tenant’s Connections. This console does not display or recover them.
Generic secrets
Tenant Secrets are a separate write-only generic vault. Saving a value there does not configure an execution provider.
Wallet custody
Receiving-wallet credentials remain encrypted. BitUnlock’s wallet RPC allowlist is invoice/status only; this console has no wallet action.
Operator authorization
No cookie or bearer session exists. Each admin read and mutation is signed independently with NIP-98 and checked by the API.