Viewing Keys

A full viewing key enables one to identify incoming and outgoing notes only. It consists of three components:

  • , the authorization key, a point on the decaf377 curve, derived as described in the proof authorization keys section,
  • , the nullifier deriving key, used for deriving nullifiers for notes, derived from multiplying by a fixed generator point on decaf377,
  • , the outgoing viewing key, derived as described in the expanded spending keys section,

The nullifier deriving key is generating by multiplying the scalar (from the spending key) by a fixed generator point on the decaf377 curve:

The incoming viewing key is derived from hashing together and .