{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "bitcoin-payjoin",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/bitcoin-payjoin/",
  "collection": "bitcoin",
  "title": "Bitcoin Payjoin: a payment built with inputs from both sides",
  "description": "Understand Payjoin, where the receiver adds inputs to a Bitcoin payment and why that weakens the common-input ownership assumption.",
  "aliases": [
    "bitcoin payjoin explained",
    "bitcoin payjoin explained explained"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T19:29:20.637Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "Payjoin lets a sender and receiver collaborate on one Bitcoin payment transaction, typically by adding receiver-controlled inputs alongside the sender’s inputs. That makes the usual assumption that every input belongs to one owner unreliable. In BIP-78, the parties exchange transaction proposals and the sender validates the result before signing and broadcasting. It improves a particular privacy property; it does not make the payment invisible or guarantee anonymity.",
    "claimId": "bitcoin-payjoin-quick-answer",
    "sourceIds": [
      "x425-btc-bip78"
    ]
  },
  "keyFacts": [
    {
      "label": "Collaboration",
      "value": "Both parties can contribute inputs",
      "sourceIds": [
        "x425-btc-bip78"
      ],
      "id": "collaboration",
      "claimId": "bitcoin-payjoin-fact-collaboration"
    },
    {
      "label": "Privacy goal",
      "value": "Weaken common-input ownership inference",
      "sourceIds": [
        "x425-btc-bip78"
      ],
      "id": "privacy-goal",
      "claimId": "bitcoin-payjoin-fact-privacy-goal"
    },
    {
      "label": "Validation",
      "value": "Check the proposal before final signing",
      "sourceIds": [
        "x425-btc-bip78"
      ],
      "id": "validation",
      "claimId": "bitcoin-payjoin-fact-validation"
    }
  ],
  "prerequisites": [
    "is-bitcoin-anonymous",
    "partially-signed-bitcoin-transactions"
  ],
  "sections": [
    {
      "id": "negotiation",
      "heading": "The receiver contributes to an ordinary on-chain payment",
      "sourceIds": [
        "x425-btc-bip78",
        "x425-btc-bip174"
      ],
      "paragraphs": [
        "The BIP-78 flow begins with a payment request advertising a Payjoin endpoint. The sender provides an original payment in the partially signed transaction format, PSBT. The receiver returns a proposal with its own inputs and permitted output changes.",
        "The sender must validate that proposal against the protocol’s checks before re-signing. A privacy label is not permission to accept arbitrary destinations or an uncontrolled fee increase."
      ]
    },
    {
      "id": "example",
      "heading": "A receiver can add value without changing the payment amount",
      "sourceIds": [
        "x425-btc-bip78"
      ],
      "paragraphs": [
        "Imagine the sender contributes 100,000 satoshis for a 50,000-satoshi purchase. The receiver adds its own 30,000-satoshi input. A simplified final transaction returns 49,000 to the sender, sends 80,000 to the receiver and pays a 1,000-satoshi fee. Total inputs and outputs plus fee both equal 130,000.",
        "The receiver’s net gain is 80,000 minus its own 30,000 input: 50,000. Seeing both inputs in one transaction therefore does not prove they had one owner. The example illustrates accounting, not a complete protocol test vector."
      ]
    },
    {
      "id": "limits",
      "heading": "Other information can still reveal the relationship",
      "sourceIds": [
        "x425-btc-bip78",
        "x425-btc-know"
      ],
      "paragraphs": [
        "The transaction remains public. The parties know they transacted, and network observations, reused addresses or later spending can reveal additional links. Payjoin addresses particular transaction-analysis assumptions rather than erasing all evidence.",
        "Both wallets need compatible support. BIP-78 describes one deployed proposal; later Payjoin protocols and wallet interfaces can have different negotiation and availability details."
      ]
    }
  ],
  "faq": [
    {
      "question": "Does the receiver need to give the sender its private key?",
      "answer": "No. Each participant signs for the inputs it controls. The collaboration exchanges transaction information and signatures, not a requirement to disclose private signing keys.",
      "sourceIds": [
        "x425-btc-bip78"
      ]
    },
    {
      "question": "Is a Payjoin transaction a separate blockchain asset?",
      "answer": "No. It is a Bitcoin transaction constructed collaboratively. The resulting inputs and outputs still follow Bitcoin’s normal validation rules.",
      "sourceIds": [
        "x425-btc-bip78",
        "x425-btc-dev-transactions"
      ]
    }
  ],
  "claims": [
    {
      "id": "bitcoin-payjoin-quick-answer",
      "articleSlug": "bitcoin-payjoin",
      "statement": "Payjoin lets a sender and receiver collaborate on one Bitcoin payment transaction, typically by adding receiver-controlled inputs alongside the sender’s inputs. That makes the usual assumption that every input belongs to one owner unreliable. In BIP-78, the parties exchange transaction proposals and the sender validates the result before signing and broadcasting. It improves a particular privacy property; it does not make the payment invisible or guarantee anonymity.",
      "sourceIds": [
        "source-bdc6c661a933e71b"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-bdc6c661a933e71b",
          "locator": "Motivation; Protocol; Receiver's original PSBT checklist; Sender's payjoin proposal checklist"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read BIP78 protocol and sender/receiver checklists plus BIP174.130,000sat input balance,49,000change,80,000receiver and1,000fee are consistent; net receiver gain50,000. The example is not claimed as a complete protocol vector and no private-key sharing is required."
        ]
      }
    },
    {
      "id": "bitcoin-payjoin-fact-collaboration",
      "articleSlug": "bitcoin-payjoin",
      "statement": "Collaboration: Both parties can contribute inputs",
      "sourceIds": [
        "source-bdc6c661a933e71b"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-bdc6c661a933e71b",
          "locator": "Motivation; Protocol; Receiver's original PSBT checklist; Sender's payjoin proposal checklist"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read BIP78 protocol and sender/receiver checklists plus BIP174.130,000sat input balance,49,000change,80,000receiver and1,000fee are consistent; net receiver gain50,000. The example is not claimed as a complete protocol vector and no private-key sharing is required."
        ]
      }
    },
    {
      "id": "bitcoin-payjoin-fact-privacy-goal",
      "articleSlug": "bitcoin-payjoin",
      "statement": "Privacy goal: Weaken common-input ownership inference",
      "sourceIds": [
        "source-bdc6c661a933e71b"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-bdc6c661a933e71b",
          "locator": "Motivation; Protocol; Receiver's original PSBT checklist; Sender's payjoin proposal checklist"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read BIP78 protocol and sender/receiver checklists plus BIP174.130,000sat input balance,49,000change,80,000receiver and1,000fee are consistent; net receiver gain50,000. The example is not claimed as a complete protocol vector and no private-key sharing is required."
        ]
      }
    },
    {
      "id": "bitcoin-payjoin-fact-validation",
      "articleSlug": "bitcoin-payjoin",
      "statement": "Validation: Check the proposal before final signing",
      "sourceIds": [
        "source-bdc6c661a933e71b"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-bdc6c661a933e71b",
          "locator": "Motivation; Protocol; Receiver's original PSBT checklist; Sender's payjoin proposal checklist"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read BIP78 protocol and sender/receiver checklists plus BIP174.130,000sat input balance,49,000change,80,000receiver and1,000fee are consistent; net receiver gain50,000. The example is not claimed as a complete protocol vector and no private-key sharing is required."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "x425-btc-bip78",
      "label": "A Simple Payjoin Proposal",
      "publisher": "Bitcoin Improvement Proposals",
      "url": "https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0078.mediawiki",
      "locator": "Motivation; Protocol; Receiver's original PSBT checklist; Sender's payjoin proposal checklist",
      "note": "Receiver-input payment proposal and required output/fee validation in BIP-78.",
      "version": "Pinned BIPs revision",
      "checkedAt": "2026-10-02T18:53:54.152Z",
      "contentSha256": "1888ea3529a77477820045358e4ff4ce1085020ecc3e1d7e47b39bfd3f0eada2",
      "recordId": "source-bdc6c661a933e71b"
    },
    {
      "id": "x425-btc-bip174",
      "label": "Partially Signed Bitcoin Transaction Format",
      "publisher": "Bitcoin Improvement Proposals",
      "url": "https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0174.mediawiki",
      "locator": "Roles; Creator; Signer; Transaction Extractor",
      "note": "Offline signing workflow, UTXO information and separate signing/finalization/broadcast steps.",
      "version": "Pinned BIPs revision",
      "checkedAt": "2026-10-02T18:53:54.151Z",
      "contentSha256": "f2a8e1a9c9e31cc7f607b3c7e2419c63eeccc4bd5b725968cde54ab8cfa1d410",
      "recordId": "source-5790dff0294c8035"
    },
    {
      "id": "x425-btc-know",
      "label": "Some things you need to know",
      "publisher": "Bitcoin.org",
      "url": "https://bitcoin.org/en/you-need-to-know",
      "locator": "Bitcoin payments are irreversible; Unconfirmed transactions aren't secure; You are your own bank; Bitcoin is not anonymous",
      "note": "Payment reversibility, confirmation risk and visible transaction records.",
      "checkedAt": "2026-10-02T18:53:53.609Z",
      "contentSha256": "929c698d3e96a7886d6e701b8d55470e6a3586d7eb525325e8993f9c56feb6c0",
      "recordId": "source-ba4dc8db91e16d53",
      "version": null
    },
    {
      "id": "x425-btc-dev-transactions",
      "label": "Transactions",
      "publisher": "Bitcoin developer documentation",
      "url": "https://developer.bitcoin.org/devguide/transactions.html",
      "locator": "Introduction; Spending An Output; P2PKH Script Validation; Multisig; Transaction Fees And Change; Avoiding Key Reuse",
      "note": "Inputs, outputs, authorization, change, coinbase exceptions and fee accounting.",
      "version": "Developer guide; historical implementation details require qualification",
      "checkedAt": "2026-10-02T18:53:53.759Z",
      "contentSha256": "2f3fc474d51880e6c7fd4c25f747f8d8d8da49a493ab82af8ff4916fa490d6b8",
      "recordId": "source-b282fdecc069b74d"
    }
  ],
  "related": {
    "articles": [
      "is-bitcoin-anonymous",
      "partially-signed-bitcoin-transactions",
      "bitcoin-address-reuse",
      "bitcoin-transaction-id-vs-address",
      "bitcoin-coinjoin"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and separate automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Bitcoin Payjoin: a payment built with inputs from both sides.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-payjoin/"
}
