View-only books · cannot spend
ZecBooks
Shield the coins. Keep the books.
Cannot spend · Your server or your Mac · No account
For a person, an exchange, or a custodian who holds shielded Zcash and still has to show the books. A viewing key can see the activity. It cannot spend. You classify the rows, then hand over an expiring proof pack. The reader never gets a key.
Not a wallet. This app cannot spend ZEC. Never paste recovery words (a seed phrase).
For exchanges and custodians
The public chain should not be your balance sheet
ZEC held in the transparent pool is a published book. The balance, the deposits, and the withdrawals sit where anyone can read them. Shielding that ZEC moves the stock into the shielded pool. The chain no longer shows the size of the position or the movement inside the house. Customers can still receive ZEC. The desk can still face an audit.
The audit is the hard part. A shielded balance is invisible to a bank, a regulator, or an outside accountant unless someone with a viewing key reads it. Giving them the spending key is how funds leave. Giving them a viewing key with no end date is how the history stays readable forever.
ZecBooks is the disclosure layer, not the custody system. The spending key stays on the machine that can sign. A detection host holds an incoming viewing key: it can see shielded activity, and it cannot spend. That host runs zecbooks against a lightwalletd you operate. You name the server. There is no hidden one. You classify income, expense, change, and fees. You seal a proof pack for a date range. The pack expires. It does not contain the viewing key. The reviewer opens it with zecbooks open or with the Mac app. They cannot move funds.
- Spend stays in custody. This program refuses recovery words and spending keys. It cannot build a transaction.
- Prefer an incoming viewing key on the detection host when the auditor does not need the spend side. A unified full viewing key also works, and it shows more. Treat either key like a bank-feed password.
- The pack is scoped and expiring. A full viewing key marks notes on the change address as change, and those rows stay out of the income total. An incoming-only key cannot see that address. A partial scan will not seal unless you acknowledge it. A start after shielded activation is partial unless you pass
--birthdayfor the account. The pack records the server host and the height it trusted, because a lightwalletd can omit blocks. - This does not custody coins. It does not sign, and it is not a claim that any named exchange already holds shielded ZEC this way. It is the books those desks need once they do.
On the detection host
zecbooks check --key-file viewing.key
zecbooks sync --key-file viewing.key \
--endpoint https://lwd.example:9067 \
--out ledger.json
zecbooks classify --ledger ledger.json \
--id ROW --as change
zecbooks pack --ledger ledger.json \
--from 2025-01-01 --to 2025-12-31 \
--expire 2027-04-15 \
--passphrase-file pass.txt \
--out year.sanebooks
zecbooks open --pack year.sanebooks \
--passphrase-file pass.txt
Windows, Linux, or macOS. One binary. The ledger and the key stay on that machine. Nothing phones home. Scan covers Sapling, Orchard, and Ironwood.
Build it from the MIT source, directory rust/. cargo test --manifest-path rust/Cargo.toml --locked. A container build is docker build -f Containerfile . from that directory. Mount the key and the ledger. Do not copy them into the image.
The problem
Privacy is not a tax dodge. Most people who use shielded Zcash are trying to live and do business without putting everything on a public ledger — and they still need clean books for tax season. Handing your accountant your wallet is the wrong answer.
The solution
View-only bookkeeping on your Mac. A view-only key can see your shielded activity but cannot spend. You classify income and expenses like any other books.
What your accountant gets
A locked tax package of the rows you choose (we call that a proof pack). It expires. It does not include your keys or the rest of your books.
Watch
From “I need books” to “here’s your package”
See the path: private books on your Mac, then a locked file for your accountant — without giving up spend control.
About 48 seconds. Problem → books on your Mac → locked tax package for your accountant.
How it works
Three steps to hand over the books
ZecBooks is bookkeeping for shielded Zcash — not a wallet. It never holds a spend key.
Import a view-only key
From Zashi or Zodl, export a key that can see your shielded transactions but cannot spend them. Paste it into ZecBooks. Recovery words are refused.
Keep the books
Your activity syncs into a private ledger on this Mac. Mark income, change, expense, and fees. Add tags and notes the way you would in any bookkeeping app.
Send a tax package
Pick the rows for the tax year (or engagement), set an expiry, and export a locked file. Your accountant opens that file in ZecBooks — they never get your keys or your full books.
Product
What you keep vs what you send
You keep the books and the view-only key on your Mac. Your accountant gets a locked file of selected rows — enough to review, not enough to move funds.
Guides
Safe setup for tax season
Short walkthroughs: what a view-only key is, how to export one, and how to build a file your accountant can open.
Basics
What is a view-only key?
It can see shielded activity. It cannot spend. That is the only kind of key ZecBooks accepts.
Setup
Export a view-only key from Zashi
Get a view-only key out of Zashi without exposing the ability to spend.
Workflow
Build a tax package
Pick rows, set an expiry, and export a locked file for your accountant.
Keep the books. Keep the keys.
A person downloads the Mac app. An exchange runs zecbooks on the detection host. Either way the reader gets a locked file, not a key, and nobody using ZecBooks can spend.