Every bitcoin payment you send is recorded on the blockchain as a bitcoin transaction — a structured piece of data that moves value from one set of addresses to another. Most wallets hide this machinery behind a friendly interface, showing you only the amount and the recipient. But beneath the surface, each payment is a raw transaction: a compact, machine-readable record of inputs, outputs, scripts, and signatures.
Learning to decode a bitcoin transaction is one of the most empowering skills in the space. It lets you verify that a payment actually did what you expected, debug a stuck or unexpected transfer, audit a wallet’s behavior, and understand exactly how Bitcoin enforces its rules without any central authority. This guide walks you through raw transaction data field by field, in plain language.
What Is Raw Transaction Data?
When a wallet broadcasts a payment, it serializes the transaction into a long string of hexadecimal characters — the “raw transaction.” This hex string is the canonical form of the transaction: it is what miners include in blocks, what nodes relay across the network, and what block explorers parse to show you the friendly, human-readable view.
You do not need to read hex by hand. Decoders translate the raw bytes into labeled fields, but understanding what each field means turns the decoded view from a wall of jargon into a story you can follow: where the coins came from, where they went, and what conditions had to be satisfied to spend them.
The Anatomy of a Bitcoin Transaction
Every bitcoin transaction, from the simplest wallet payment to a complex multisignature operation, is built from the same core components. Here is what each one does.
1. Version
The first field is a version number, typically 1 or 2. It tells nodes which set of consensus rules to apply when validating the transaction. Version 2, for example, enables relative timelocks through the sequence field. For most readers, the version is background detail — but it matters when a transaction uses advanced features.
2. Inputs (vin)
Inputs are the heart of the bitcoin transaction model. Bitcoin does not use account balances; it uses unspent transaction outputs (UTXOs). Each input points to a specific previous output being spent, identified by the previous transaction’s ID (txid) and the output index (vout). The input also carries the unlocking data — a signature and public key, or witness data — that proves the spender is authorized.
3. Outputs (vout)
Outputs define where the bitcoin goes. Each output has a value, denominated in satoshis (one bitcoin equals 100,000,000 satoshis), and a locking script (scriptPubKey) that sets the conditions for spending it in the future — usually “only the holder of this address’s private key can spend this.” A transaction commonly has two outputs: the payment to the recipient and the change returned to the sender.
4. Locktime
Locktime specifies the earliest block height or timestamp at which the transaction becomes valid. A locktime of zero means the transaction is valid immediately. Higher values are used in protocols like payment channels and inheritance schemes to create time-delayed payments.
5. Witness Data (SegWit)
For SegWit transactions, signatures are moved into a separate “witness” section rather than the traditional scriptSig field. This was a major efficiency upgrade: it fixes transaction malleability and lets more transactions fit in each block. When you decode a modern bitcoin transaction, expect to see witness stacks containing signatures and public keys.
How to Decode a Raw Transaction Step by Step
You can decode any confirmed transaction yourself in a few minutes:
- Find the raw hex. On a block explorer such as mempool.space, open any transaction and look for a “view raw” or “copy raw hex” option. Paste it somewhere safe.
- Run it through a decoder. If you run a Bitcoin node, the command
bitcoin-cli decoderawtransactionwill parse it. Otherwise, most explorers decode it automatically on the transaction page. - Read the inputs. Each input’s txid and vout tell you exactly which previous coins were spent. Follow those links to trace the coin’s history backward.
- Read the outputs. Check each output’s value and address. The sum of inputs minus the sum of outputs is the miner fee — this is how you verify what you actually paid in fees.
- Inspect the scripts. The address type (legacy, SegWit, or Taproot) is revealed by the script structure, which tells you which wallet technology was used.
Reading Scripts Without Fear
Scripts look intimidating but follow simple patterns. The locking script (scriptPubKey) on an output and the unlocking script (scriptSig or witness) on the spending input must fit together like a key in a lock. Common script types you will encounter include P2PKH (pay to public key hash, the classic address starting with 1), P2SH (pay to script hash, addresses starting with 3, often multisig), P2WPKH (native SegWit, bc1q addresses), and P2TR (Taproot, bc1p addresses).
You rarely need to parse opcodes manually. What matters is recognizing which script type you are looking at, because it tells you the security model of the funds: single key, multisignature, or a Taproot construction that may hide more complex spending conditions.
Common Mistakes When Reading Raw Data
- Reversed txids: transaction IDs are displayed in reverse byte order compared to how they appear in the raw hex. Do not be confused when the internal reference looks “backwards.”
- Satoshis versus bitcoin: values in raw data are integers in satoshis. A value of 50000 is 0.0005 BTC, not 50,000 BTC.
- Assuming input order matters: inputs are processed as a set, not a sequence. The order in the raw data carries no meaning about which input “paid” which output.
- Misreading locktime: values below 500,000,000 are block heights; values above are Unix timestamps. Mixing them up changes the meaning entirely.
Why Decoding Matters
Being able to decode a bitcoin transaction transforms you from a passive wallet user into an informed participant. You can independently verify that an exchange actually sent your withdrawal, confirm the fee you paid, investigate a suspicious payment, and understand precisely how innovations like multisig and timelocks are expressed on-chain.
Bitcoin’s transparency is one of its defining features — every rule is enforced by data anyone can read. Raw transaction data is that data in its purest form, and now you know how to read it.
Frequently Asked Questions
What is the difference between a transaction ID and a raw transaction?
The raw transaction is the full serialized data in hexadecimal. The transaction ID (txid) is a double SHA-256 hash of that data, displayed in reverse byte order, used to reference the transaction.
What is SegWit witness data?
Since the SegWit upgrade, signatures are stored in a separate witness section. This fixed transaction malleability and lowered fees for many transactions, and it is why SegWit transactions have both a txid and a wtxid.
Which tools can decode a raw transaction?
Bitcoin Core’s decoderawtransaction command, and several block explorers, will turn hex into readable inputs, outputs, scripts and amounts. Decoding is read-only and safe; never paste private keys into any tool.



