Prover integration
Configure the SDK's authenticated Node.js ProductionProver and learn what it verifies before exposing witness inputs.
The SDK exports ProductionProver, which implements Prover.provePrivateSwap(input) and Prover.proveUnshield(input). ShieldedWallet.privateSwap and unshield invoke these methods internally after reconstructing the note witness and preparing the public statement.
const prover = new ProductionProver({
executablePath: process.env.PRODUCTION_PROVER_PATH!,
privateSwapPkPath: process.env.PRIVATE_SWAP_PK_PATH!,
unshieldPkPath: process.env.UNSHIELD_PK_PATH!,
});Before each proof, the SDK validates the executable's resolved file, expected SHA-256 and exact version (production-prover 0.2.0 ipc-v1), then validates the selected proving key's exact size and hash. The prover receives a bounded private stdin IPC frame with the witness tokens; it does not inherit the parent environment, wallet seed or RPC credentials. Request buffers are cleared after invocation.
The SDK package does not ship the executable or proving keys. Obtain them from the frozen release artifacts and verify their identities. On unsupported platform/architecture combinations, the authenticated executable digest is absent and the SDK fails closed.
The formal Prover interface is exported for integration, but a custom implementation is responsible for protecting witness material and must return the exact encoded public inputs. The SDK compares returned public inputs against its own encoding before transaction construction.