Viewing Keys

A full viewing key enables one to identify incoming and outgoing notes only. It consists of three components:

• , the authorization key, a point on the decaf377 curve, derived as described in the proof authorization keys section,
• , the nullifier deriving key, used for deriving nullifiers for notes, derived from multiplying by a fixed generator point on decaf377,
• , the outgoing viewing key, derived as described in the expanded spending keys section,

The nullifier deriving key is generating by multiplying the scalar (from the spending key) by a fixed generator point on the decaf377 curve:

The incoming viewing key is derived from hashing together and .