Privacy Guarantees
Each party in a private transaction sees only what it needs to. In this example, Alice pays Bob, then Bob pays Charlie. Both are private transfers.- Default Ring
- Custom Rings
The Default Ring is the permissionless confidential Ring.
Sender and recipient addresses are public onchain. Asset and amount are encrypted.
Only the sender and the recipient can decrypt the transaction, each with their own viewing key. Each can decrypt only their own balance.
This example models private transfers. Deposits and withdrawals reveal more onchain:
- A deposit from a public balance reveals the source, asset, and amount.
- A withdrawal reveals the destination, asset, and amount.
Encryption
A private wallet consists of a Solana keypair for signing, a nullifier key, and a viewing key for encryption. Together these keys form the shielded keypair. A shielded keypair signs, encrypts and decrypts transactions.- Signing key: The wallet’s Ed25519 Solana keypair to sign transactions. In Anonymous Custom Rings, the private wallet’s P-256 key signs instead.
- Viewing key: A P-256 keypair, used to encrypt and decrypt transactions.
- Nullifier key: A key used to derive nullifiers, which prevent a private balance from being spent twice.
Integrating a Shielded Keypair
A wallet can hold the shielded keypair itself via the native Wallet Integration. With the Embedded Privacy Wallet, a Wallet Provider holds the shielded keypair and runs its key operations instead.Decryption Modes
The owner decrypts their private balance with the viewing key. Confidential rings (the Default Ring and confidential Custom Rings) support local and delegated decryption. Anonymous rings (Custom Rings only) support only delegated decryption.Local Decryption
In local decryption mode, the wallet decrypts and syncs balances and history locally. Local decryption keeps the viewing key on the device.Delegated Decryption
In delegated decryption mode, the wallet and selected provider share a viewing key. This lets the provider decrypt balances and history, but it does not grant spending authority. A wallet may also share prior viewing keys when it authorizes the provider to sync historical activity. Auditor access is separate from delegated decryption. An auditor receives policy-defined Ring visibility, while a delegated provider receives wallet-scoped sync access.Selective Disclosure
The owner can share the viewing key to grant read access, for example with an auditor for compliance or with a delegated decryption provider.- To disclose a single transaction, the sender shares the transaction viewing key, which decrypts only that transaction.
- Custom Rings can also set a separate auditor key. It decrypts the Ring activity the policy defines. Learn more in Custom Enterprise Rings.
Learn More
Overview
Rings, privacy guarantees, and transaction flow.
Architecture
How wallets, RPC services, and Solana programs interact.
Private State and UTXOs
How private balances are stored and spent.
Custom Enterprise Rings
Learn how to configure a custom Ring.