Silent Payments

One static address you can post anywhere, and every payment to it lands on a fresh, unlinkable Taproot output. No notification transaction, no third-party server: your own node does the scanning.

🧪 Experimental. Silent payments (BIP352) are new in Fully Noded and FN-Server. Test with small amounts first.

What you need

  • Fully Noded with a signer (your seed) and a wallet made from it.
  • FN-Server on a Mac, running Bitcoin Core 25 or newer.
  • An unpruned node from the block you start scanning at. A pruned node can’t scan.
  • An app lock password set in Fully Noded (Settings → Security Center). Exporting the scan key requires it.

1. Get your silent payment address

In Fully Noded open the Signers tab, tap your signer and scroll to Silent Payment Address. That sp1… address (tsp1… on test networks) is yours to share: on a website, a donation page, an invoice or your Nostr profile. Tap the QR button to show it as a QR code.

Fully Noded signer: silent payment address and hidden SP scan private key
The silent payment address (blurred here) and the scan private key, which stays hidden until you export it.

2. Export the scan key

On the same screen, tap the QR button next to SP Scan Private Key. Fully Noded asks for confirmation and Face ID / Touch ID or your app password, then shows the key as a QR code only.

The scan key can’t spend, but anyone who has it can see every silent payment you receive. Only give it to a scanner you control, like your own FN-Server. Your spend key never leaves Fully Noded.

3. Start scanning in FN-Server

In FN-Server, on the Bitcoin Core tab, click the utilities (wrench) button, then Silent Payments.

FN-Server Utilities window with the Silent Payments button
FN-Server Silent Payments window: wallet picker and scan private key
FN-Server Silent Payments window: address, start height and scanner
  1. Wallet: pick the Fully Noded wallet you’ll spend from. It must be a watch-only descriptor wallet, which Fully Noded wallets are.
  2. Scan private key: import the key from step 2 with Scan QR (if your Mac has a camera), QR image… or Paste. If you saved the QR as an image, delete it afterwards and make sure it didn’t sync to a cloud photo library. FN-Server stores the key encrypted in your Mac’s Keychain.
  3. Silent payment address: add your sp1… address the same way. FN-Server checks that it matches the scan key and your node’s network, so a wrong key is caught before scanning starts.
  4. Start height: the first block that could contain a payment to you. For a brand-new address, use Use current height. Scanning from an old height on mainnet is slow.
  5. Click Start scanning.

FN-Server then follows the chain block by block with your own node. The Silent Payments row on the Bitcoin Core tab shows the scanner’s status. Scanning only runs while FN-Server is open, and it catches up when you relaunch it.

4. Receive

Anyone with a BIP352 wallet can pay your sp1… address. When FN-Server finds a payment it imports it into your wallet as a watch-only Taproot output and rescans once it’s caught up, so the balance shows up in Fully Noded like any other coin.

5. Spend

Spend from that wallet in Fully Noded as usual. The transaction verifier recognises silent payment inputs and signs them with your spend key on the device. When you spend silent payment outputs, Fully Noded asks where change should go: back to your own silent payment address, or the wallet’s normal change address.

To pay someone else’s silent payment address, just paste their sp1… address in the send view.

How it works, briefly

  • Your address is two public keys, a scan key and a spend key, both derived from your seed.
  • A sender combines the private keys of the coins they’re spending with your scan key to make a shared secret, which turns your spend key into a one-time Taproot output only you can link to you.
  • Your node recomputes that secret for each new transaction using your scan private key and checks whether any output is yours.
  • Spending uses your spend key plus that output’s tweak, so only the device with your seed can sign.

Current limits: one silent payment recipient per transaction, only the change label is supported, and scanning needs FN-Server (Fully Noded doesn’t scan by itself). Full technical details: SilentPayments.md.

search previous next tag category expand menu location phone mail time cart zoom edit close