On this page

History and reconciliation

Read account activity, check pending operations and understand what a history export contains.

Read your activity#

Activity combines the account's authenticated private scan with public Pool events. It lists deposits, received notes, sends, in-account combines, Swap and Earn actions, and public withdrawals. The app rebuilds the timeline from recovered records, so it need not trust a list of transactions saved in one browser.

A send and Combine look the same onchain. Recovered sender and recipient records tell the app which happened. Change belongs to the operation that created it, so the timeline does not show it again as income. An external action's settlement output appears in its action row rather than a second Receive row.

Check status before counting funds#

A deposit can appear before it finishes the minimum-age and source-policy checks. An excluded deposit cannot be spent normally. An external action can be confirmed while its settlement output is still waiting to be appended. A saved authorization can still execute after you close its editor.

Reconcile with atomic token amounts, not USD estimates. Prices can change even when no note moves. Match the first nullifier or transaction identity to the reserved inputs, public event and recovered outputs. Keep submitted, confirmed and available as separate states in your application.

StateWhat happenedNext check
Deposit checkingFunding landed; eligibility is still being checkedRefresh deposit age and policy coverage
Action executed, unfinalizedThe route ran; outputs have not been appendedRead the receipt and finalize the reserved outputs
Sender recovery needs attentionThe spend is known; its private sender record is missingRecover keys and history before producing a full-ledger report
Outcome unknownThe original operation may still executeRead its saved authorization and chain state
SpentThe note's nullifier was consumedCount its replacement output or payout, not the old input

Use the public-history cache#

The queue runtime returns history status and logs for bounded block ranges. It requests every event in a range; it needs no owner, viewing key or list of private notes. Before replaying cached logs, the browser compares them with its canonical RPC response. It falls back to RPC if the cache fails or disagrees.

Include spends that create no outputs. A matching note root or block hash cannot tell you whether one of those spends was omitted. Choosing an independent browser RPC bypasses the default same-origin history service. After a reorg, return to a matching canonical anchor and replay the changed suffix.

http
GET /api/queue/public-history/v1/status
GET /api/queue/public-history/v1/logs?fromBlock=100&toBlock=199

# Use ranges appropriate to the selected Pool deployment.
# Authenticate every returned range against your canonical RPC.

Know how much history was restored#

A compact checkpoint saves a canonical tree frontier and absolute counters. The restored public arrays may contain only events after that checkpoint. Check historyCoverage before reading them. A checkpoint-tail array is a suffix, so its length is not the account's lifetime transaction count.

The app can display an authenticated private-history projection after refreshing the chain. A consumer that needs complete history, including audit compilation, must request full replay or refuse incomplete coverage. If an earlier key generation is missing, recover it rather than counting its unknown balance as zero. Keep the checkpoint scope, digest, block anchor and key lineage together.

Export a backup or an audit answer#

Export encrypted backup file saves scan state and included pending-operation journals so you can continue on another device. The file is encrypted; it is not a public account statement. Audit answer JSON is a separate export for the questions and snapshot you approved. Give the verifier the matching request.

The app has no general CSV accounting export, and an arbitrary row list does not prove a complete ledger. If you build a report, say which history it covers and use verified records. Keep token address, atomic amount, transaction hash, block and status in each row. Share private output openings only when the holder approves that disclosure; keep account secrets out of reports.

If activity and balance disagree#

Check the account, chain, Pool and key generation first. Refresh canonical history and inspect pending journals. For an executed action, read its measured output and finalization status rather than the old quote. For an uncertain send, check its original first nullifier before preparing another spend.

Keep browser storage and export an encrypted recovery file before clearing caches or changing devices. A failed RPC read, unreadable sender capsule or missing earlier key leaves history incomplete. Show the problem and continue recovery. Do not drop the missing rows or mark the account reconciled.