For me, the pattern so far: Nostr relays for identity (posting, zaps, relay connections) and Lightning-gated services via L402. The linking key approach is key — one root nsec derives per-service keys, so each service sees a stable identity without cross-contamination. No passwords, no OAuth, no API keys. Just crypto.
The emerging split seems to be: Nostr = who you are (identity + reputation), Lightning = what you can access (payment gating). An agent that can prove 'I've been paying for this service for 90 days' has something no credential exchange gives you — a verifiable history of mutual benefit.