[{"data":1,"prerenderedAt":483},["ShallowReactive",2],{"navigation_docs":3,"-math-secp256k1":44,"-math-secp256k1-surround":480},[4,24],{"title":5,"path":6,"stem":7,"children":8,"icon":23},"Guide","\u002Fguide","1.guide\u002F01.index",[9,11,15,19],{"title":10,"path":6,"stem":7},"Getting started",{"title":12,"path":13,"stem":14},"CLI","\u002Fguide\u002Fcli","1.guide\u002F02.cli",{"title":16,"path":17,"stem":18},"Agents","\u002Fguide\u002Fagents","1.guide\u002F03.agents",{"title":20,"path":21,"stem":22},"Playground","\u002Fguide\u002Fplayground","1.guide\u002F04.playground","i-lucide-book-open",{"title":25,"path":26,"stem":27,"children":28,"icon":43},"Math","\u002Fmath","2.math\u002F00.index",[29,31,35,39],{"title":30,"path":26,"stem":27},"Overview",{"title":32,"path":33,"stem":34},"Curves and points","\u002Fmath\u002Fcurves","2.math\u002F01.curves",{"title":36,"path":37,"stem":38},"Orders and logs","\u002Fmath\u002Fgroups","2.math\u002F02.groups",{"title":40,"path":41,"stem":42},"secp256k1","\u002Fmath\u002Fsecp256k1","2.math\u002F03.secp256k1","i-lucide-sigma",{"id":45,"title":40,"body":46,"description":473,"extension":474,"links":475,"meta":476,"navigation":92,"path":41,"seo":478,"stem":42,"__hash__":479},"docs\u002F2.math\u002F03.secp256k1.md",{"type":47,"value":48,"toc":465},"minimark",[49,54,162,178,278,282,285,339,342,346,362,386,389,393,401,412,416,423,426,430,455,461],[50,51,53],"h2",{"id":52},"points-in-points-out","Points in, points out",[55,56,61],"pre",{"className":57,"code":58,"language":59,"meta":60,"style":60},"language-ts shiki shiki-themes compressions compressions compressions","import { addPoints, liftX, multiplyGenerator, multiplyPoint } from \"@agntn\u002Fcurves\u002Fsecp256k1\";\n\nconst G = multiplyGenerator(\"1\"); \u002F\u002F \"0279be667ef9dcbb…1798\"\nmultiplyGenerator(3n); \u002F\u002F \"02f9308a019258c3…36f9\"\naddPoints(G, multiplyGenerator(2n)); \u002F\u002F \"02f9308a019258c3…36f9\", 3G again\n","ts","",[62,63,64,87,94,123,140],"code",{"__ignoreMap":60},[65,66,69,73,77,80,84],"span",{"class":67,"line":68},"line",1,[65,70,72],{"class":71},"skH_V","import",[65,74,76],{"class":75},"s38Sx"," { addPoints, liftX, multiplyGenerator, multiplyPoint } ",[65,78,79],{"class":71},"from",[65,81,83],{"class":82},"shU9J"," \"@agntn\u002Fcurves\u002Fsecp256k1\"",[65,85,86],{"class":75},";\n",[65,88,90],{"class":67,"line":89},2,[65,91,93],{"emptyLinePlaceholder":92},true,"\n",[65,95,97,100,103,106,110,113,116,119],{"class":67,"line":96},3,[65,98,99],{"class":71},"const",[65,101,102],{"class":75}," G ",[65,104,105],{"class":71},"=",[65,107,109],{"class":108},"sK71F"," multiplyGenerator",[65,111,112],{"class":75},"(",[65,114,115],{"class":82},"\"1\"",[65,117,118],{"class":75},"); ",[65,120,122],{"class":121},"scIB-","\u002F\u002F \"0279be667ef9dcbb…1798\"\n",[65,124,126,129,132,135,137],{"class":67,"line":125},4,[65,127,128],{"class":108},"multiplyGenerator",[65,130,131],{"class":75},"(3",[65,133,134],{"class":71},"n",[65,136,118],{"class":75},[65,138,139],{"class":121},"\u002F\u002F \"02f9308a019258c3…36f9\"\n",[65,141,143,146,149,151,154,156,159],{"class":67,"line":142},5,[65,144,145],{"class":108},"addPoints",[65,147,148],{"class":75},"(G, ",[65,150,128],{"class":108},[65,152,153],{"class":75},"(2",[65,155,134],{"class":71},[65,157,158],{"class":75},")); ",[65,160,161],{"class":121},"\u002F\u002F \"02f9308a019258c3…36f9\", 3G again\n",[163,164,165,166,169,170,173,174,177],"p",{},"Points are SEC1 hex without ",[62,167,168],{},"0x",", 33 bytes compressed or 65 uncompressed. Output is compressed unless you pass ",[62,171,172],{},"{ compressed: false }",". A scalar is hex up to 64 digits or a ",[62,175,176],{},"bigint",", from 1 to n - 1.",[179,180,181,194],"table",{},[182,183,184],"thead",{},[185,186,187,191],"tr",{},[188,189,190],"th",{},"Function",[188,192,193],{},"Does",[195,196,197,208,218,228,238,248,258,268],"tbody",{},[185,198,199,205],{},[200,201,202],"td",{},[62,203,204],{},"addPoints(a, b)",[200,206,207],{},"a + b, as in a split key vanity address",[185,209,210,215],{},[200,211,212],{},[62,213,214],{},"subtractPoints(a, b)",[200,216,217],{},"a - b, the offset between two known keys",[185,219,220,225],{},[200,221,222],{},[62,223,224],{},"negatePoint(p)",[200,226,227],{},"same x, the other y",[185,229,230,235],{},[200,231,232],{},[62,233,234],{},"multiplyPoint(p, k)",[200,236,237],{},"k times p",[185,239,240,245],{},[200,241,242],{},[62,243,244],{},"multiplyGenerator(k)",[200,246,247],{},"k times G, the public key of k",[185,249,250,255],{},[200,251,252],{},[62,253,254],{},"liftX(x)",[200,256,257],{},"both points above x, even first",[185,259,260,265],{},[200,261,262],{},[62,263,264],{},"isOnCurve(p)",[200,266,267],{},"true or false",[185,269,270,275],{},[200,271,272],{},[62,273,274],{},"convertPoint(p)",[200,276,277],{},"between 33 and 65 bytes",[50,279,281],{"id":280},"half-of-g","Half of G",[163,283,284],{},"What's G times the inverse of 2?",[55,286,288],{"className":57,"code":287,"language":59,"meta":60,"style":60},"import { invertScalar, multiplyPoint } from \"@agntn\u002Fcurves\u002Fsecp256k1\";\n\ninvertScalar(2n); \u002F\u002F \"7fffffffffffffffffffffffffffffff5d576e7357a4501ddfe92f46681b20a1\"\nmultiplyPoint(G, invertScalar(2n)); \u002F\u002F \"0200000000000000000000003b78ce563f89a0ed9414f5aa28ad0d96d6795f9c63\"\n",[62,289,290,303,307,321],{"__ignoreMap":60},[65,291,292,294,297,299,301],{"class":67,"line":68},[65,293,72],{"class":71},[65,295,296],{"class":75}," { invertScalar, multiplyPoint } ",[65,298,79],{"class":71},[65,300,83],{"class":82},[65,302,86],{"class":75},[65,304,305],{"class":67,"line":89},[65,306,93],{"emptyLinePlaceholder":92},[65,308,309,312,314,316,318],{"class":67,"line":96},[65,310,311],{"class":108},"invertScalar",[65,313,153],{"class":75},[65,315,134],{"class":71},[65,317,118],{"class":75},[65,319,320],{"class":121},"\u002F\u002F \"7fffffffffffffffffffffffffffffff5d576e7357a4501ddfe92f46681b20a1\"\n",[65,322,323,326,328,330,332,334,336],{"class":67,"line":125},[65,324,325],{"class":108},"multiplyPoint",[65,327,148],{"class":75},[65,329,311],{"class":108},[65,331,153],{"class":75},[65,333,134],{"class":71},[65,335,158],{"class":75},[65,337,338],{"class":121},"\u002F\u002F \"0200000000000000000000003b78ce563f89a0ed9414f5aa28ad0d96d6795f9c63\"\n",[163,340,341],{},"Eleven zero bytes at the start of x. Out of 2^256 possible values. Make of that what you will.",[50,343,345],{"id":344},"scalars-mod-n","Scalars mod n",[163,347,348,351,352,351,355,358,359,361],{},[62,349,350],{},"addScalars",", ",[62,353,354],{},"subtractScalars",[62,356,357],{},"multiplyScalars"," and ",[62,360,311],{}," work mod the group order and give 64 hex digits back:",[55,363,365],{"className":57,"code":364,"language":59,"meta":60,"style":60},"addScalars(\"fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364140\", \"2\"); \u002F\u002F \"000…001\"\n",[62,366,367],{"__ignoreMap":60},[65,368,369,371,373,376,378,381,383],{"class":67,"line":68},[65,370,350],{"class":108},[65,372,112],{"class":75},[65,374,375],{"class":82},"\"fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364140\"",[65,377,351],{"class":75},[65,379,380],{"class":82},"\"2\"",[65,382,118],{"class":75},[65,384,385],{"class":121},"\u002F\u002F \"000…001\"\n",[163,387,388],{},"That first number is n - 1, so adding 2 wraps to 1.",[50,390,392],{"id":391},"what-it-refuses","What it refuses",[55,394,399],{"className":395,"code":397,"language":398,"meta":60},[396],"language-text","subtractPoints(G, G)        \u002F\u002F The result is the point at infinity, which is no public key, as with P minus P\nmultiplyPoint(G, \"0\")       \u002F\u002F Scalar must be hex without 0x or a bigint, from 1 to the curve order minus 1\nnegatePoint(\"02000…0005\")   \u002F\u002F Invalid SEC1 secp256k1 public key\n","text",[62,400,397],{"__ignoreMap":60},[163,402,403,404,407,408,411],{},"No point of secp256k1 has x = 5, so the compressed form above is no point at all. ",[62,405,406],{},"isOnCurve"," says ",[62,409,410],{},"false"," for it instead of throwing. A coordinate at or above p is refused too, as SEC 1 asks.",[50,413,415],{"id":414},"written-from-the-specs","Written from the specs",[163,417,418,419,422],{},"The domain parameters come from SEC 2, section 2.4.1. The encodings follow SEC 1, sections 2.3.3 and 2.3.4. Points multiply in Jacobian coordinates, one inversion per result. No ",[62,420,421],{},"@noble\u002Fcurves"," underneath, though the tests hold every result to it.",[163,424,425],{},"Is it as fast? No. About 0.9 ms for a multiply of G, against 0.36 ms in noble, which has precomputed tables. Plenty for a puzzle. And it doesn't run in constant time, so keep real keys away from it.",[50,427,429],{"id":428},"over-mcp","Over MCP",[163,431,432,435,436,351,439,351,442,351,445,351,448,358,451,454],{},[62,433,434],{},"curves_secp256k1_compute"," does the point side: ",[62,437,438],{},"add",[62,440,441],{},"subtract",[62,443,444],{},"negate",[62,446,447],{},"multiply",[62,449,450],{},"lift",[62,452,453],{},"check",". Scalar math stays in the library.",[55,456,459],{"className":457,"code":458,"language":398,"meta":60},[396],"{\"operation\":\"lift\",\"even\":\"0279be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798\",\"odd\":\"0379be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f81798\"}\n",[62,460,458],{"__ignoreMap":60},[462,463,464],"style",{},"html pre.shiki code .skH_V, html code.shiki .skH_V{--shiki-light:var(--shiki-token-keyword);--shiki-default:var(--shiki-token-keyword);--shiki-dark:var(--shiki-token-keyword)}html pre.shiki code .s38Sx, html code.shiki .s38Sx{--shiki-light:var(--ui-text-highlighted);--shiki-default:var(--ui-text-highlighted);--shiki-dark:var(--ui-text-highlighted)}html pre.shiki code .shU9J, html code.shiki .shU9J{--shiki-light:var(--shiki-token-string);--shiki-default:var(--shiki-token-string);--shiki-dark:var(--shiki-token-string)}html pre.shiki code .sK71F, html code.shiki .sK71F{--shiki-light:var(--shiki-token-function);--shiki-default:var(--shiki-token-function);--shiki-dark:var(--shiki-token-function)}html pre.shiki code .scIB-, html code.shiki .scIB-{--shiki-light:var(--shiki-token-comment);--shiki-default:var(--shiki-token-comment);--shiki-dark:var(--shiki-token-comment)}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":60,"searchDepth":89,"depth":89,"links":466},[467,468,469,470,471,472],{"id":52,"depth":89,"text":53},{"id":280,"depth":89,"text":281},{"id":344,"depth":89,"text":345},{"id":391,"depth":89,"text":392},{"id":414,"depth":89,"text":415},{"id":428,"depth":89,"text":429},"Points of secp256k1 as SEC1 hex and scalars mod n. Add and subtract and multiply and lift an x coordinate","md",null,{"icon":477},"i-lucide-key-round",{"title":40,"description":473},"_wimEyS3WHtb8LfpluVxCRvspRU2o8prdz1OlhliC-4",[481,475],{"title":36,"path":37,"stem":38,"description":482,"children":-1},"Count and list the points of a curve and find the order of a point and a discrete log by baby step giant step",1791293523357]