Developer · Decoder

BOLT11 Lightning invoice decoder.

Paste a Lightning invoice and read what is inside it: network, amount, created and expiry time, hashes, description, route hints and feature bits. Format decode only. Runs in your browser; nothing is sent anywhere.

Advertisement

Input

Starts with lnbc, lntb, lntbs or lnbcrt. A leading lightning: is fine.

Result

Paste an invoice and press Decode.

What a BOLT #11 invoice contains

Encoding: the invoice is one bech32 string (BIP-173 alphabet and 6-character checksum). BOLT #11 lifts the 90-character limit, so invoices run to several hundred characters. Upper case is allowed, mixed case is not.

Human-readable part: ln plus a currency prefix: lnbc Bitcoin mainnet, lntb testnet, lntbs signet, lnbcrt regtest. An optional amount follows, in bitcoin (not satoshis), with one optional multiplier: m (x 0.001), u (x 0.000001), n (x 0.000000001) or p (x 0.000000000001). A p amount must end in 0 so it is a whole number of millisatoshis. No amount means the payer chooses.

Data part: a 35-bit timestamp (seconds since 1 January 1970 UTC), then tagged fields, then a 520-bit signature (64-byte R and S plus a 1-byte recovery id).

Tagged fields: each is a 5-bit type, a 10-bit length and the data. p payment hash, s payment secret, d description (UTF-8), h description hash, x expiry seconds (default 3600), c minimum final CLTV expiry delta (default 18), f on-chain fallback address, r route hints (51-byte entries), n payee public key, m payment metadata and 9 feature bits. Unknown field types are skipped.

Feature bits: even bits mean required and odd bits mean optional. A reader must fail the payment on an unknown even bit and ignore an unknown odd one. Names come from the BOLT #9 table.

What this tool does not do

It does not verify the signature. That needs secp256k1 public-key recovery, which runs outside this page, so the R, S and recovery id are shown as data only. It does not compute the payee node ID when the invoice has no n field, and it does not turn a fallback payload into a Base58 or Bech32 address; it shows the version and hex. It cannot tell you whether an invoice was paid, is still payable, or was issued by a real node.

Sources (BOLT text checked 2026-09-30): BOLT #11, payment encoding; BIP-173, bech32; BOLT #9, feature bits.

Frequently asked questions

How do I decode a Lightning invoice?

Paste the full invoice string, starting with lnbc or another prefix, and press Decode. The tool checks the bech32 checksum, then reads the prefix, amount, timestamp and each tagged field.

Is it safe to paste an invoice here?

The decoding runs in your browser and the invoice is not uploaded. Even so, an invoice is a payment request that carries a payment hash and secret, so share real ones only with people you mean to pay you.

Does a valid result mean the invoice can be paid?

No. It means the string is well formed and its checksum matches. The tool cannot check the signature, whether the payee is reachable, or whether it has been paid already.

How is the amount calculated?

The number in the prefix is in bitcoin, scaled by the multiplier. 2500u is 2500 x 0.000001 = 0.0025 BTC, which is 250,000 sats or 250,000,000 millisatoshis (1 BTC is 1011 millisatoshis).

When does an invoice expire?

At the timestamp plus the x field in seconds, or 3600 seconds when there is no x field. The expired flag uses your device clock.

Format decode only

This tool decodes the BOLT #11 format. It does not verify the signature and cannot confirm payment status, channel liquidity or that the invoice was issued by a real node.

Advertisement
Advertisement
Listening…