Private Swap with the SDK
A real ShieldedWallet.privateSwap example with exact input/output mint semantics, bigint amounts and slippage bound.
privateSwap selects an available note for the input mint, reconstructs a finalized Merkle witness, quotes against current public reserves, invokes Prover.provePrivateSwap, then builds and submits the v0 instruction. It returns the finalized signature.
const amountIn = 1_000_000n;
const quote = await sdk.quote(pool, "AToB", amountIn);
const minAmountOut = (quote * 9_950n) / 10_000n; // 0.5% slippage allowance
const signature = await shielded.privateSwap({
pool,
inputMint: tokenAMint,
outputMint: tokenBMint,
amountIn,
minAmountOut,
});
console.log("Finalized Private Swap signature:", signature);The SDK produces a change note for input note amount − amountIn when nonzero and an output note for the public CPMM output. Those note preimages are stored locally. On-chain, the statement exposes the pool, direction, reserves, fee, input/output amounts, nullifier, commitments and other proof inputs.
Private Swap requires an authenticated production prover, persistent NoteStore, v0 signing and a validated lookup table. The SDK preflights the LUT and packet size before proving, then rechecks output-tree capacity after proof generation to handle a concurrent rollover safely.
Read Private Swap public inputs, transaction size and SDK errors.