Selective Disclosure
Prove a supported fact about your account without sharing its private history.
Choose a question#
The holder imports an FPL question about their notes or spend records. The audit compiler turns it into a plan, then the holder's device generates a proof. Private account data stays on that device.
The current backend proves positive upward claims, such as holding at least an amount or participating in matching transactions. The compiler rejects questions it cannot prove. A local preview can help the holder review a question, but it is not a verified answer.
Ask the holder to review#
Before proving, show the question itself, its subject and snapshot, asset, filters, threshold and expiry. The holder decides whether to answer. Importing a question does not give its author continuing access to the account.
The current holder-run flow has no server auditor session or viewing-key service. FPL can describe standing grants, but that language feature is separate from this per-program consent flow.
Verify the answer independently#
The auditor uses their own trusted deployment data and verification keys. They rebuild notes, spent nullifiers and spend records from complete finalized history, compile the same program and check the holder's proof chain.
Start reconstruction at the deployment block and continue through the selected finalized snapshot. A wallet scan checkpoint may omit history and cannot serve as the auditor's source of truth.
| Claim | What the proof says |
|---|---|
| Holdings at least a threshold | Owned unspent notes meet the amount and filters at the snapshot |
| Received or deposited amount at least a threshold | Matching notes meet a supported positive bound |
| Trade or withdrawal participation | The account owned an input to matching transactions; amounts are their public totals |
| Complete ancestry or exhaustive history | The current audit compiler rejects these questions |
Read what the proof says#
Questions in one program share an account tag, which tells the verifier that their answers concern the same subject. A different program uses a different nonce-bound tag. Within its supported capacity, the proof hides the selected note commitments and nullifiers.
A spend-record proof shows that the account participated in the transaction. It does not attribute the transaction's entire public amount to that account. Keep that qualification in results and exported reports.