Official MASTR logo MASTR
Menu

Bitcoin: recovery and Lightning

Bitcoin output descriptors: the wallet backup beyond a seed

Keys, derivation paths and spending rules answer different recovery questions.

Updated 30 September 2026 · MASTR Labs

Article text and technical graphics are in English. Navigation is available in seven languages.

Reference guides
  1. What a descriptor describes
  2. Watching and spending are different powers
  3. A checksum is not a backup test
  4. What to record
  5. Worked example
  6. Sources and originals

What a descriptor describes

A seed can recreate keys without telling the restoring wallet which scripts it should search for. Output descriptors make that missing context explicit: the script template, keys and derivation information belong to one readable expression. BIP-380 defines the common syntax; separate BIPs define particular expressions. A descriptor describes outputs a wallet can recognise or create. It is not a promise that the wallet can spend them. 1

Watching and spending are different powers

A public descriptor may let a service derive receiving addresses and watch balances without authorising a spend. That is useful for separating an online monitor from signing devices. It also exposes a much wider financial history than sharing one address. A descriptor containing private key material is a different object entirely and must be treated as secret. The words ‘descriptor export’ do not tell you which of these you received. 2

A checksum is not a backup test

The optional descriptor checksum detects transcription errors. It does not certify that the keys exist, the wallet supports the expression, or the policy matches the intended custody arrangement. Multisignature recovery also needs the complete policy and the other participants’ public keys. Retain the relevant recovery information offline and document what software can interpret it. Never put a real descriptor into an online tutorial, public issue or support chat.

What to record

A useful recovery inventory identifies the network, script type, key origins, receive and change branches, and whether the export is public-only. Check that a separate recovery environment derives known receiving addresses before relying on it. This is a compatibility check, not an instruction to expose a seed. Versioned wallet documentation matters because an export format can be broader than a particular application’s import support.

Recovery has 3 separate ingredients
Educational diagram. Open the full-size graphic. Credits ↗ A public descriptor supports observation. It is not spending authority.

Worked example

A watch-only laptop displays a deposit using public derivation information. A disconnected signer still holds the spending key. Losing the laptop need not lose the coins; publishing its public descriptor can nevertheless reveal the wallet’s future receiving addresses. These are different failure modes.

Sources and originals

  1. BIP-380: output script descriptors
  2. Bitcoin Core: descriptor documentation

Continue reading

Bitcoin: recovery and Lightning →

MASTR

Support independent research

The investigations, original evidence and guides here are free to read. Voluntary donations help fund the research and keep MASTR’s tools available.

Open wallet