Pravelle guided private wallet
← home Quickstart
loading zk engine…

Proof workspace

The tabs here illustrate; the ⛓ controls act. Guided mode is the wallet — it is where a normal deposit, order and settlement happen. This workspace instead lets you hold the notes, outputs and fees yourself and watch the circuit accept or reject them: the constraints are real and run in your browser, but a sample proof produces no Venus proof and touches no chain. Anything marked ⛓, and the real-notes views, are the exceptions — they do reach the chain and need a signed-in guided account plus the local prover.

Sample tabs, live controls. The transfer, swap, match and batch tabs build sample proofs to show what each circuit checks; they do not reach the chain. Live DarkPool readiness, notes, and on-chain order placement are called out explicitly below.

Sample transfer proof using generated notes.

A private joinsplit: spend Alice's notes, create new ones — proving Σ inputs = Σ outputs + fee in zero knowledge.

From · Alice spends notes
To · Bob gets a note

Alice's input notes

A note is private money Alice already holds — its amount and owner stay hidden on-chain. + note spends another of her notes in this transfer.

Outputs

Outputs are the new private notes this transfer creates — sent to Bob, or back to Alice as change. + output adds one.

Σ inputs0
=
Σ outputs0
+
fee0
zk proof

Sample swap proof using generated liquidity.

One proof trades Alice's asset A for Bob's asset B atomically, with value conserved per asset — the assets stay hidden in the commitments.

Alice brings A
Bob brings B

Build a sample order proof, or place a live DarkPool order.

A committed, owner-authorized order in the book. Place proves it's well-formed & yours; cancel retires it via an owner-derived nullifier — neither reveals which entry it is.

Live place and cancel actions generate real Venus proofs on the local prover and submit them to DarkPool. The reusable spending key stays in the browser.

Owner

Sample match proof plus live-settlement readiness.

Cross a sell and a buy, retire both, and settle as a swap. Payouts go to the owners' own keys — a matcher cannot misroute proceeds.

Seller
Buyer

Sample batch-auction proof.

A frequent batch auction clears every order at one uniform price p* — no per-order price, no ordering, so there's nothing to front-run.

Your real shielded notes — loaded read-only from the on-chain pool.

Unlike the sample builder above, these are your actual notes: decrypted in your browser from the DarkPool's NoteCipher events with your viewing key, via the client-side indexer. Read-only — nothing here is edited, proved, or sent on-chain.

Sign in via Guided mode first, then load your real notes here.