# ZK Proofs 🤝 JavaScript

**URL:** <https://community.agoric.com/t/zk-proofs-javascript/520>\
**Category:** Platform & BLDers\
**Created:** [October 26, 2023, 8:31pm UTC](https://community.agoric.com/t/zk-proofs-javascript/520 "2023-10-26T20:31:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![0xpatrick](https://sea1.discourse-cdn.com/flex019/user_avatar/community.agoric.com/0xpatrick/32/64_2.png) [@0xpatrick](https://community.agoric.com/u/0xpatrick)\
**Post date:** [October 26, 2023, 8:31pm UTC](https://community.agoric.com/t/zk-proofs-javascript/520/1 "2023-10-26T20:31:08Z")

</div>

### Intro

Zero knowledge proofs are a rabbit hole I’ve peeked into but haven’t really gone down yet.

For those not familiar, [Wikipedia](https://en.wikipedia.org/wiki/Zero-knowledge_proof) provides a broad definition:

> In cryptography, a zero-knowledge proof or zero-knowledge protocol is a method by which one party can prove to another party that a given statement is true, while avoiding conveying to the verifier any information beyond the mere fact of the statement’s truth.

Put another way, they can allow us to have privacy in an environment that hasn’t typically been that private (a public blockchain). This can be the entire chain state, or specific protocols/contracts on a chain that implement circuits.

### Goal

Given @dtribble’s (exciting!) comment here, I’d like to elicit some technical discussion and gather resources, ideas, and other information.

> [@Agoric Privacy Aspirations: How do we get there?](https://community.agoric.com/t/agoric-privacy-aspirations-how-do-we-get-there/244/9):
>
> I have been thinking about zkOffers and zkZoe. They fit wonderfully with our general security model: contracts/servers don’t know who clients are (`message.sender` considered evil), they just know that any operation that can be invoked is authorized. So Zoe just needs strong assurance that the underlying assets are escrowed and can be reallocated. It doesn’t have to know anything about who or what client contracts provided them or gets to claim the payouts.

I don’t envision us discussing topics like “how do we build this into the Agoric VM”, although discussion on that is certainly welcome. Rather, I see us more talking about higher level abstractions, like writing proofs and frameworks in JavaScript that enable this.

---

<div class="post-metadata">

**Author:** ![0xpatrick](https://sea1.discourse-cdn.com/flex019/user_avatar/community.agoric.com/0xpatrick/32/64_2.png) [@0xpatrick](https://community.agoric.com/u/0xpatrick)\
**Post date:** [October 26, 2023, 8:38pm UTC](https://community.agoric.com/t/zk-proofs-javascript/520/2 "2023-10-26T20:38:29Z")

</div>

And to kick us off, here are some cool things I’ve found:

# Proof Systems

It seems the two most popular systems are:

- zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Argument of Knowledge)

- zk-STARKs (Zero-Knowledge Scalable Transparent Arguments of Knowledge)

Most of the implementation I’ve seen revolve around zk-SNARKs, such as Halo 2, Plonk, and Groth16.

# Libraries / Tools

It seems most folks working on this need to develop a JS sdk at some point, in order for participants to build their own proofs client-side in a web browser (generating a proof on a server kind of defeats the whole point iuuc).

I have not tried any of these out myself yet, but:

## 1. **halo2-repl,** by Axiom

Written in rust, but (seemingly) has JS bindings for writing circuits. Announced 2 days ago!

> <https://x.com/axiom_xyz/status/1717210722269016509>

> **[GitHub - axiom-crypto/halo2-browser: Monorepo of tools for using the halo2 proving...](https://github.com/axiom-crypto/halo2-browser)**
>
> Monorepo of tools for using the halo2 proving system in-browser using WASM.

**Repl Demo!**

[https://www.halo2repl.dev/](https://www.halo2repl.dev/)

## 2. **SnarkyJS / o1js** , written by Mina Protocol

- [SnarkyJS GitHub Source](https://github.com/o1-labs/snarky) (may be deprecated)
- [SnarkyJS GitHub Examples](https://github.com/o1-labs/snarkyjs-examples) (may be deprecated)

> **[GitHub - o1-labs/o1js: TypeScript framework for zk-SNARKs and zkApps](https://github.com/o1-labs/o1js)**
>
> TypeScript framework for zk-SNARKs and zkApps

> <https://twitter.com/jtriley_eth/status/1563188784836972545>

> <https://x.com/mitschabaude/status/1542116828427812865>

> **[o1js Basic Concepts | Mina Documentation](https://docs.minaprotocol.com/zkapps/o1js/basic-concepts)**
>
> Field elements are the basic unit of data in zero knowledge proof programming. Learn about built-in data types, functions, and common methods.

## 3. **Noir** , by Aztec

> <https://twitter.com/aztecnetwork/status/1717189113823236530>

[https://aztec.network/aztec-nr/](https://aztec.network/aztec-nr/)

It is unclear to me if there are JS bindings for writing circuits, or how tightly coupled the circuits are to the smart contracting framework.

# Use Cases / Implementations

The [ZK Email](https://github.com/zkemail) project is pretty cool! I spent some time digging into a few weeks ago.

They use the DKIM signature present in email messages to validate the receipt of emails. In their [demo](https://zkemail.xyz/), a user can verify ownership of a Twitter address by generating a proof from a password reset email.

The public key for the DKM signatures may change over time, or could be corrupted by a rogue sysadmin along the way, but the idea and implementation are cool nonetheless!

This [blog post](https://blog.aayushg.com/zkemail/) from one of the authors is nice as well.

> **[ZK Email](https://github.com/zkemail)**
>
> ZK Email tooling and application home. ZK Email has 96 repositories available. Follow their code on GitHub.

> **[ZK Email](https://zk.email/)**
>
> ZK Email lets you make privacy-preserving proofs of your existing emails. You can prove you own an email at some domain, prove attendance at a real-world event, or confirm transactions on chain.

> **[ZK Email](https://blog.aayushg.com/zkemail/)**
>
> How to verify data provenance via zk proofs of redacted emails, and what that unlocks
