Docs / Key derivation
Protocol
Key derivation
How note keys are derived and what each one allows.
One signature, every key
Your wallet signs one Sign-In-with-Ethereum message for oarkel.xyz. That signature, together with an optional passphrase you choose, is hashed into a seed, and the seed derives your note keys. The keys live only in the memory of the open tab. Because the same wallet always produces the same signature for the same message, you can restore your notes on a new device with nothing to back up beyond the wallet itself and, if you set one, the passphrase.
What each key can do
| Key | Can | Cannot |
|---|---|---|
| Spending key | Spend notes, build proofs | Nothing beyond your own notes |
| Viewing key | Read your notes and history | Spend anything |
| Shielded address | Receive private payments | Read or spend |
Sharing a viewing key
Handing a viewing key to an accountant or tax adviser lets them read your history without being able to move funds. Scoped keys that reveal only a date range are on the roadmap.