Every time Bitcoin changes hands, the transaction doesn't just record an amount and a recipient address. It contains a small program, called an output script, that sets the conditions for spending those funds. Understanding what a Bitcoin output script does helps explain why Bitcoin transactions are more expressive than a simple bank transfer, and why the network can enforce spending rules without any central authority.
What an output script actually is
A Bitcoin output script is a short program written in Bitcoin Script, the network's built-in scripting language. Every transaction output carries one. The script defines a puzzle: to spend the output, the next person must provide a solution that satisfies it.
Think of it as a padlock on a box of funds. The sender puts the money in the box and snaps the padlock shut. The padlock is the output script. The recipient must produce the right key to open it. That key is called the input script, or scriptSig, and it gets attached when the recipient creates a new transaction to spend the funds.
The Bitcoin network runs both scripts together and checks whether they produce a valid result. No trusted third party is involved. The math settles it.
The most common output script types
Most Bitcoin transactions use one of three standard output script formats. Each one locks funds in a slightly different way.
- P2PKH (Pay to Public Key Hash): The original and still widely used format. It locks funds to the hash of a public key. To spend, the recipient provides their public key and a digital signature. This is what most early Bitcoin addresses used.
- P2SH (Pay to Script Hash): Introduced to support more complex conditions, such as multisig setups. The output script contains only a hash. The full spending conditions are revealed only when the output is spent. This keeps the locking script compact.
- P2WPKH and P2WSH (SegWit formats): These are the SegWit address variants, which move signature data outside the main transaction body to reduce fees and improve throughput.
Taproot introduced P2TR in 2021, which packages complex conditions more efficiently using Schnorr signatures and a technique called MAST (Merklised Alternative Script Trees). P2TR outputs look identical on-chain regardless of how complex the spending conditions actually are.
How the locking and unlocking process works
When you receive Bitcoin, the sender's wallet builds a transaction with one or more outputs. Each output has a value in satoshis and an output script. That output then sits in the UTXO set, which is the collection of all unspent transaction outputs tracked by every node on the network.
When you want to spend that Bitcoin, your wallet constructs a new transaction. It references the UTXO it wants to spend and provides an input script that satisfies the output script's conditions. The network runs both together. If the result is valid, the transaction is accepted. If not, it's rejected outright.
This is why understanding UTxOs matters: each UTXO carries its own output script, so spending even a modest wallet balance might involve satisfying several different locking conditions across multiple UTXOs.
Why output scripts matter for security
The output script is the enforcement layer. It is what makes Bitcoin trustless. No one can move funds from an output without satisfying the script. That includes the miners who process transactions. They can choose whether to include a transaction in a block, but they cannot alter the spending conditions or redirect funds.
This property is why multisig setups work. A 2-of-3 multisig output script requires any two of three designated private keys to sign. No single party, not even someone who controls one of the keys, can move the funds alone. The script enforces the rule at the protocol level.
It is also why output scripts underpin more advanced features like timelocks. A script can include a condition that funds cannot be spent until a certain block height is reached. The network enforces this automatically, without any legal contract or custodian required.
What beginners should take away
You don't need to write Bitcoin Script to use Bitcoin safely. But knowing that every output carries a locking program changes how you think about the network. Bitcoin isn't just a ledger of balances. It's a system of programmable conditions enforced by cryptographic math across thousands of independent nodes.
When you send Bitcoin to someone's address, you're creating an output script tailored to that address. When they spend it, they prove they control the corresponding key. The whole process runs without any intermediary, which is exactly what makes Bitcoin different from every payment system that came before it.
Output scripts are one of the reasons Bitcoin can serve as a foundation for complex financial arrangements, from simple payments between two people to multi-party custody setups used by institutions. The locking mechanism scales with the complexity of the situation.

