Collapsed-by-default 'paste an nsec (unsafe)' option on the login screen, signs the NIP-98 login event client-side with nostr-tools and never persists the key (used once in memory, discarded) — for testing/kiosk use without a NIP-07 extension. Clearly labeled as unsafe in the UI.