Skip to main content

Privacy Guarantees

Each party in a private transaction sees only what it needs to. In this example, Alice pays Bob, then Bob pays Charlie. Both are private transfers.
The Default Ring is the permissionless confidential Ring. Sender and recipient addresses are public onchain. Asset and amount are encrypted. Only the sender and the recipient can decrypt the transaction, each with their own viewing key. Each can decrypt only their own balance.Alice pays Bob, then Bob pays Charlie in a Confidential Ring. Each party's view shows the amounts it can decrypt; the addresses are public to everyone.
This example models private transfers. Deposits and withdrawals reveal more onchain:
  • A deposit from a public balance reveals the source, asset, and amount.
  • A withdrawal reveals the destination, asset, and amount.
See what stays private in each flow.

Encryption

A private wallet consists of a Solana keypair for signing, a nullifier key, and a viewing key for encryption. Together these keys form the shielded keypair. A shielded keypair signs, encrypts and decrypts transactions.
  • Signing key: The wallet’s Ed25519 Solana keypair to sign transactions. In Anonymous Custom Rings, the private wallet’s P-256 key signs instead.
  • Viewing key: A P-256 keypair, used to encrypt and decrypt transactions.
  • Nullifier key: A key used to derive nullifiers, which prevent a private balance from being spent twice.
The Shielded Address is the shielded keypair’s public keys. Transfers encrypt to it.
To learn how transactions are encrypted, see ViewingKey and AES Key derivation in the spec.

Integrating a Shielded Keypair

A wallet can hold the shielded keypair itself via the native Wallet Integration. With the Embedded Privacy Wallet, a Wallet Provider holds the shielded keypair and runs its key operations instead.

Decryption Modes

The owner decrypts their private balance with the viewing key. Confidential rings (the Default Ring and confidential Custom Rings) support local and delegated decryption. Anonymous rings (Custom Rings only) support only delegated decryption.

Local Decryption

In local decryption mode, the wallet decrypts and syncs balances and history locally. Local decryption keeps the viewing key on the device.

Delegated Decryption

In delegated decryption mode, the wallet and selected provider share a viewing key. This lets the provider decrypt balances and history, but it does not grant spending authority. A wallet may also share prior viewing keys when it authorizes the provider to sync historical activity. Auditor access is separate from delegated decryption. An auditor receives policy-defined Ring visibility, while a delegated provider receives wallet-scoped sync access.

Selective Disclosure

The owner can share the viewing key to grant read access, for example with an auditor for compliance or with a delegated decryption provider.
  • To disclose a single transaction, the sender shares the transaction viewing key, which decrypts only that transaction.
  • Custom Rings can also set a separate auditor key. It decrypts the Ring activity the policy defines. Learn more in Custom Enterprise Rings.

Learn More

Overview

Rings, privacy guarantees, and transaction flow.

Architecture

How wallets, RPC services, and Solana programs interact.

Private State and UTXOs

How private balances are stored and spent.

Custom Enterprise Rings

Learn how to configure a custom Ring.

Didn’t find what you were looking for?

Reach out! Telegram | E-Mail | Contact