ArchitectureCore release 0.1.0

System overview

How the wallet, SDK, prover, optional relayer, Solana program, public LP vaults and shielded state fit together.

The client controls note material and proof generation. Solana owns the authoritative pool, custody, tree and spent-nullifier accounts. An optional hosted relayer pays for a tightly constrained private operation.

Responsibilities

  • Wallet / app: supplies the signing adapter, seed-derived shielded keys, recipient intent and persistent NoteStore configuration.
  • SDK: reads finalized state, quotes, creates note data, reconstructs a Merkle witness, invokes the prover, builds instructions and reconciles transaction outcomes.
  • Production prover: receives a bounded private IPC request and returns a proof plus encoded public inputs. The SDK verifies the prover binary and exact PK artifacts before use.
  • Relayer (optional): validates a prepared v0 transaction, signs only as fee payer, simulates the exact signed transaction, submits it and exposes status polling.
  • Lethenymous program: recomputes the statement, verifies Groth16, enforces canonical state/PDA checks and performs token settlement.
  • Solana: publishes transaction logs, token-account changes, commitments, roots and spent markers.

The standard SDK convenience send flow uses its configured wallet as payer. To sponsor a private transaction, construct the supported instruction with the relayer public key as instruction payer and v0 message payer, then submit the unsigned payer slot to the relay endpoint. The relayer API docs detail that integration.

See public liquidity vs shielded custody, program accounts & PDAs and transaction flows.

PreviousThreat modelNext Public liquidity & custody
Source baseline: frozen Core v0.1.0 / SDK v0.1.1.