https://sandbox-api.nuvante.ioExplainers
Zero-knowledge reserve proofs
How Nuvanté produces a claim, checkable by a machine, that an issuer's reserves meet the backing policy while keeping the actual holdings private.
The problem this solves
Say you're a central bank observer or a counterparty, and you want to know whether an issuer holds enough reserves. You have two options:
- Reported figures. The platform publishes the reserve amount, and you trust the pipeline that reported it. You can get these from List reserves.
- Proof-based verification. A proof states that the reserves satisfy a policy rule, and you check the arithmetic yourself. That way you rely on maths you can check yourself. The rest of this page covers this option.
The proof only tells you pass or fail. If it fails, it also tells you which rule was broken. The individual reserve line items stay private.
What the sandbox proof checks today
In sandbox, proofs are checked by a simulated verifier (SimulatedProofVerifier) using a fixed policy key, reserve-policy-v1-sandbox. The policy checks two things:
- Backing ratio:
reservesGbp / supplyIssued ≥ 1.0 - Central-bank deposit ratio:
centralBankDepositRatio ≥ 0.40
The artifact also includes a snapshot field with the three underlying figures. We only include these in sandbox, so you can audit how the check works.
Cryptographic circuit status
To be upfront about it: the sandbox mechanism re-runs the policy check against the snapshot figures in the artifact. It doesn't produce a cryptographic zero-knowledge proof in the SNARK or STARK sense. The current codebase has no circuit, proving key or verifying key.
There's also no GET /api/v1/circuits/{id}/verifying-key endpoint. The verify endpoint (POST /api/v1/reserves/proof/verify) simply runs the policy check again against the snapshot you submit.
Verifying-key endpoint status: Live
Endpoints
| Method | Path | Purpose |
|---|---|---|
POST | /api/v1/reserves/{issuerId}/proof/generate | Generates a fresh proof from the current sandbox reserve state. Needs the generateReserveProof capability (issuer tenant admin, own participant only). |
GET | /api/v1/reserves/{issuerId}/proof | Fetches the latest proof and its result. Needs viewReserves. |
POST | /api/v1/reserves/proof/verify | Re-runs the policy check against an artifact you submit. Any valid portal session works. |
Worked example
POST https://sandbox-api.nuvante.io/api/v1/reserves/323e4567-e89b-42d3-a456-426614174002/proof/generate{
"data": {
"issuerId": "323e4567-e89b-42d3-a456-426614174002",
"result": {
"pass": true,
"keyId": "reserve-policy-v1-sandbox"
},
"artifact": {
"issuerId": "323e4567-e89b-42d3-a456-426614174002",
"keyId": "reserve-policy-v1-sandbox",
"generatedAt": "2026-08-19T11:04:33.000Z",
"pass": true,
"snapshot": {
"reservesGbp": "1200000.0000000",
"supplyIssued": "1000000.0000000",
"centralBankDepositRatio": 0.42
}
}
}
}To try the failing path, deliberately under-fund the sandbox reserve and generate the proof again:
{
"data": {
"issuerId": "323e4567-e89b-42d3-a456-426614174002",
"result": {
"pass": false,
"keyId": "reserve-policy-v1-sandbox",
"failedRule": "backing_ratio_below_threshold: 0.3500 < 1.0"
},
"artifact": { "pass": false, "..." : "..." }
}
}You can send any artifact to the verify endpoint to get a fresh pass or fail result. This uses the figures in the artifact, so nothing is regenerated from live data:
POST https://sandbox-api.nuvante.io/api/v1/reserves/proof/verify
Content-Type: application/json
{ "artifact": { ...artifact from generate or GET... } }If the artifact has a keyId the verifier doesn't recognise, you'll get a 400. That makes the line between sandbox and production easy to see.
For administrators
If you're a central bank observer checking an issuer's backing, proofs let you run the arithmetic yourself, so you don't have to rely on the platform's reported figures. It's the same check described in the Administrator guide. In sandbox, push the reserve figures below the threshold on purpose and confirm the proof fails with the right rule name. Testing the failing case matters just as much as testing the passing one.
