Skip to content
Docs / Key derivation

Protocol

Key derivation

How note keys are derived and what each one allows.


On this page

One signature, every key

Your wallet signs one Sign-In-with-Ethereum message for oarkel.xyz. That signature, together with an optional passphrase you choose, is hashed into a seed, and the seed derives your note keys. The keys live only in the memory of the open tab. Because the same wallet always produces the same signature for the same message, you can restore your notes on a new device with nothing to back up beyond the wallet itself and, if you set one, the passphrase.

What each key can do

KeyCanCannot
Spending keySpend notes, build proofsNothing beyond your own notes
Viewing keyRead your notes and historySpend anything
Shielded addressReceive private paymentsRead or spend

Sharing a viewing key

Handing a viewing key to an accountant or tax adviser lets them read your history without being able to move funds. Scoped keys that reveal only a date range are on the roadmap.