Relayer overview
A policy-constrained Devnet fee payer that submits supported prepared private transactions without receiving note secrets.
The Lethenymous relayer sponsors eligible private transactions. The client builds the proof and a v0 transaction; the relayer validates the exact message, pays Solana fees and any approved rent exposure, signs as the only required signer, simulates and submits it.
Client wallet + SDK + local prover
│ public prepared v0 transaction
▼
Relayer policy → relayer fee-payer signature → Solana
│
└─ status polling is separate from submissionSupported operations
The Devnet service accepts exactly one supported protocol operation:
private_swapunshield, including the SDK-level Private Send recipient flow
Optional canonical Compute Budget limit/price instructions may precede it. Private Send is not a separate program instruction. The relayer is not a generic transaction signer and will not relay arbitrary System, SPL Token, administrative or unknown program instructions.
What the relayer receives
The request contains a serialized public v0 transaction and proof. It does not contain a wallet seed, spend secret, view key, NoteStore master key, Merkle witness, proving key or private balance. A Groth16 proof can be relayed without exposing its witness under the circuit's cryptographic assumptions.
The relayer can observe request origin/timing, operation kind and public transaction fields. It is not a network anonymity layer.
Use the hosted Devnet relayer, then poll transaction status. A relay response of submitted is not finality.