Skip to content
LogoLogo

Main circuits

CircuitPublicsProves
shieldcommitment, asset, amountwell-formed note for a public deposit
initiatenote_root, nullifiers[2], change_commitment, payment_root, recipient_fi_index, deadline_bucket, time_bucket, fee, relayer2 inputs in tree under a recent root, owned by the prover, nullifiers correct; Σ inputs = amount + change + fee; payment_root recomputed from all four regions' plaintext; refund_commitment welded to its preimage in sender_private; range checks
resolvepayment_root, output_commitment, time_bucketenvelope plaintext recomputes payment_root with sender_private_root opaque; witness bit selects: accept → output_commitment is the recipient note from shared fields and a Schnorr signature under the recipient's ak over payment_root verifies; reject → output_commitment == shared.refund_commitment
reclaimpayment_root, output_commitment, time_bucketsame recomputation; output_commitment == shared.refund_commitment; Schnorr under the sender's ak; time_bucket > deadline_bucket
unshieldnote_root, nullifiers[2], change_commitment, asset, amount, recipientstandard exit

The resolve circuit instantiates each shared gadget once (root recomputation, note commitment, signature verify) and lets the branch bit multiplex the values fed into them, so the disjunction costs little more than the larger branch.

Unshield has no FI policy slot in v1. This is deliberate and listed as a non-goal; a fourth Ctx phase and VK slot is the reserved extension.

These are the protocol team's circuits; FI developers never touch them.