Returns the compressed public key for this identity.
Implementors wrapping a remote: throw only for a refusal that will repeat. provisionClaimSecret reads a transient throw — a network hiccup, an extension timeout — as "this signer cannot derive", and falls back to a stored random preimage for the artifact's whole life. That is claimable, but it persists a secret the seed would otherwise have replaced, and nothing surfaces the downgrade to the caller.
Returns the x-only public key used by Taproot scripts.
An identity that signs with
aux_rand = 0, which is what makes the derivation reproducible.DescriptorIdentitysatisfies it, and throws rather than degrading to a random-aux signer.