Introduction
Weld is two things designed together.
The protocol is a shielded payment pool with a hold state machine, initiate then resolve or reclaim, in which every regulated party (a financial institution, "FI") proves that its private, registered policy permits each transition. A hold is a pending note: initiate spends the sender's inputs and parks the value, and every resolution, whether the recipient FI accepts or rejects, publishes the same record shape. The chain never learns the outcome.
The framework is a Noir library, a set of comptime attributes, and a CLI. You write judgments over typed, already-anchored values and return a verdict. The framework owns the lifecycle, the anchoring, the witness plumbing, packaging, registration, and testing. There is no API that returns an unwelded value, so a policy cannot be vacuous by accident, and the build fails on a policy that would brick its own institution.
The workflow layer generalizes the hold into programmable multi-party workflows in the shape of Canton and Daml: records with signatories and observers, choices with controllers, and transactions made of per-party fragments joined by one proof. Everything in the policy layer is reused unchanged.
Where to start?
Write, build, and test the corridor policy: an amount cap on initiate and a country deny-list on accept.
Goals, non-goals, and the one design move that makes the framework safe to hand to an engineer with no ZK background.
Two provers, two proof families, one shared object with one root that both sides can recompute.
Notes, the context tree, the registry, the policy ABI, the wrapper, the pool's welds, and the leakage profile.
Rule, Verdict, Ctx, params, state, attestations, combinators, and the CLI.
Records, authorization, fragments, flows, the join, and the reference workflows: hold, escrow, invoice, DvP.
How to read the specification
The protocol pages are normative. Where a page says a check "has a test", the security invariants list it. The leakage profile is also normative: a change to what any observer learns is a protocol change.
Section references such as §4.5 in the text point to the numbered sections of the source specification. On this site they are links.