Fast ZK-SNARK proof generator for Orbinum privacy protocol. Witness calculation (TypeScript/snarkjs) + Proof generation (WASM/arkworks)
Generate 128-byte Groth16 ZK-SNARK proofs in ~400ms (small circuits, post-warmup). Same TypeScript code runs identically in Node.js, browsers, Electron, and Tauri.
New in v2.0: Circuit artifacts and WASM modules are now installed automatically as npm dependencies (@orbinum/circuits and @orbinum/groth16-proofs). No more manual downloads!
npm install @orbinum/proof-generatorDependencies are installed automatically:
@orbinum/circuits- Circuit artifacts (WASM, proving keys)@orbinum/groth16-proofs- Arkworks WASM proof generator
import { generateProof, CircuitType } from '@orbinum/proof-generator';
const result = await generateProof(CircuitType.Unshield, {
merkle_root: '0x...',
nullifier: '0x...',
amount: '100',
// ... more inputs
});
console.log('Proof:', result.proof); // 0x... (128 bytes)
console.log('Signals:', result.publicSignals); // ['0x...', ...]- API Reference - Complete API, error handling, and usage examples
- Development Guide - Setup, testing, architecture, and contribution guide
- ✅ Fast: ~80ms per proof (small circuits, snarkjs backend); ~253ms with arkworks backend
- ✅ Optimized: Direct decimal format pipeline (no conversion overhead)
- ✅ Compact: 128-byte proofs (50% smaller than snarkjs)
- ✅ Universal: Node.js, browsers, Electron, Tauri - same code
- ✅ Simple: No build tools, no Rust, no setup
- ✅ Type-Safe: Full TypeScript types
Benchmarked on Apple M-series (Node.js, 3 runs post-warmup):
| Circuit | snarkjs backend | arkworks backend | First call overhead |
|---|---|---|---|
| Unshield | ~407ms | ~2.1s | +1.5–2s (WASM init) |
| Transfer | ~1.1s | ~7.2s | +1.5–2s (WASM init) |
snarkjs backend (default): uses snarkjs
fullProvewith.zkeyproving keys — fastest option post-warmup.arkworks backend: uses snarkjs witness-only + arkworks WASM with
.arkproving keys — ~5× slower (Unshield, Transfer)..arkartifacts are 2–3× smaller than.zkey.
The first proof call in a process incurs the WASM initialization overhead (~1.5–2s). All subsequent proofs skip this.
Phase breakdown — where each backend spends its time (1 run):
| Circuit | Backend | Load | Witness | Serialize | Prove | Compress | Total |
|---|---|---|---|---|---|---|---|
| Unshield | snarkjs | 21ms | — | — | 367ms | — | 388ms |
| Unshield | arkworks | 8ms | 28ms | 26ms | 1965ms | — | 2027ms |
| Transfer | snarkjs | 54ms | — | — | 1094ms | — | 1148ms |
| Transfer | arkworks | 24ms | 94ms | 101ms | 6901ms | — | 7120ms |
Proverepresents 97% of total time for large circuits (Unshield, Transfer). Load, witness calculation, and serialization are negligible. For arkworks,Proveincludes PK deserialization +Groth16::proveinside WASM.
| Circuit | Versions | Use Case |
|---|---|---|
| Unshield | 1, 2 | Withdraw from pool to public address |
| Transfer | 1, 2 | Private-to-private transfer |
| Shield | 1+ | Deposit bound to its value and asset |
v2 (active since @orbinum/circuits 0.15.0) binds the encrypted memos to the
proof through an extra memo_hash public input. Shield (since 0.16.0) has one
layout at every version, so a rotated shield key proves without an update. The providers serve the
manifest's active version unless a circuit is pinned, and verify every artifact
against the manifest's sha256; see docs/usage.md.
- @orbinum/circuits - Circuit artifacts (installed automatically)
- @orbinum/groth16-proofs - WASM proof generator (installed automatically)
- orbinum/node - Substrate blockchain node
GNU General Public License v3.0 or later (LICENSE).
Not dual-licensed: @orbinum/circuits and @orbinum/groth16-proofs are both
GPL-3.0, and this package cannot be used without them.