20 / 691BIP341

Taproot

key-path or script-path spending

SegWit version 1 rules combining Schnorr signatures and an optional script tree.

Taproot allows a P2TR output to be spent by signing for its output key or proving and satisfying a script branch. BIP 340 defines Schnorr signatures, BIP 341 Taproot and BIP 342 Tapscript.

Key path normally presents one Schnorr signature without revealing whether other script options existed. Script path reveals the executed script, its inputs and a control block proving membership in the committed tree. Other scripts need not be disclosed, but the revealed branch and proof structure still carry information. [BIP 341: Taproot]

Several participants can cooperate on one key and signature through a suitable signing protocol. Taproot itself neither merges all transaction inputs nor turns arbitrary multisig into one signature. Coordination, nonce handling and correct protocol implementation remain essential. [BIP 340: Schnorr signatures]

P2TR is native witness version 1 with a 32-byte program, commonly encoded on mainnet as a bc1p Bech32m address. Amounts and links between spent outputs remain public. Savings depend on the path and proof size; the address alone guarantees neither anonymity nor the lowest fee. [BIP 350: Bech32m]

For the clearest picture, read this entry together with SegWit, Private Key, Transaction, Lightning Network. The reverse links also lead from SegWit, Lightning Network, Cryptographic hash, SHA-256.

DOC · 001BIP 341: TaprootPrimaryDOC · 002BIP 340: Schnorr signaturesPrimaryDOC · 003BIP 342: TapscriptPrimaryDOC · 004BIP 350: Bech32mPrimary
Reviewed 1 August 2026Source-first · No investment advice