> For the complete documentation index, see [llms.txt](https://railhood.gitbook.io/railhood-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://railhood.gitbook.io/railhood-docs/viewing-keys.md).

# Viewing keys

### Books and records, on your terms

Off-market doesn't mean off the books. Every regulated desk keeps records its auditor can inspect — the street never confused confidentiality with lawlessness. Viewing keys are that discipline, rebuilt in cryptography.

### Two keys, two powers

Your spending key moves money. Your **viewing key** only reveals. Hand a viewing key to your accountant: they read your full off-market history — every entry, every exit, every amount — and they cannot move a wei. Grant it to exactly who needs it: an auditor, a tax authority, a fund's compliance officer, a co-founder. The public never enters the equation; they never had access to revoke.

### Who sees what

| Data                             | You | Your auditor | The public |
| -------------------------------- | --- | ------------ | ---------- |
| Your off-market balance          | ✓   | ✓            | ✕          |
| Amounts you move                 | ✓   | ✓            | ✕          |
| Who you transact with            | ✓   | ✓            | ✕          |
| Your full history                | ✓   | ✓            | ✕          |
| Proof funds are clean            | ✓   | ✓            | ✓          |
| That the pool exists & its depth | ✓   | ✓            | ✓          |

*(✓ = visible to that party · ✕ = hidden. Your auditor = a read-only viewing key you granted: reads everything, moves nothing. The public gets one thing — the proofs check out.)*

### Scope is the feature

Disclosure that can't be scoped isn't disclosure, it's surrender. The design principle: reveal to a chosen party, for a chosen purpose, and nothing propagates to anyone else. Your auditor seeing your books doesn't put your books on the tape — that's the entire difference between reporting and broadcasting, and it's the difference public chains forgot.

### Per-agent keys and the fleet

The fleet pattern from [Agents on glass](/railhood-docs/agents-on-glass.md) completes here: one off-market treasury, a viewing key per agent. You watch every agent's activity in full. Agents can't see each other. The world sees none of it. Full observability for the owner, zero for everyone else — which is what "supervised autonomy" should have meant all along. Viewing keys and per-agent scoping ship per the [Roadmap](/railhood-docs/roadmap.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://railhood.gitbook.io/railhood-docs/viewing-keys.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
