Skip to main content

Authenticator

Struct Authenticator 

Source
pub struct Authenticator { /* private fields */ }
Expand description

The Authenticator is the main component with which users interact with the World ID Protocol.

Implementations§

Source§

impl Authenticator

Source

pub fn init_storage(&self, now: u64) -> Result<(), WalletKitError>

Initializes storage using the authenticator’s leaf index.

§Errors

Returns an error if the leaf index is invalid or storage initialization fails.

Source

pub fn destroy_storage(&self) -> Result<(), WalletKitError>

Permanently destroys all credential storage data.

Removes the encryption keys, vault database, and cache database. After this call the authenticator can no longer generate proofs or access stored credentials. Intended for logout or account deletion.

§Errors

Returns an error if the storage destruction fails.

Source§

impl Authenticator

Source

pub async fn init_with_config( seed: &[u8], config: Config, artifacts: Arc<dyn WalletKitZkArtifactSource>, store: Arc<CredentialStore>, ) -> Result<Self, WalletKitError>

Initializes a new Authenticator from a seed and an already-parsed Config.

§Errors

See CoreAuthenticator::init for potential errors.

Source§

impl Authenticator

Source

pub fn packed_account_data(&self) -> Uint256

Returns the packed account data for the holder’s World ID.

The packed account data is a 256 bit integer which includes the user’s leaf index, their recovery counter, and their pubkey id/commitment.

Source

pub fn leaf_index(&self) -> u64

Returns the leaf index for the holder’s World ID.

This is the index in the Merkle tree where the holder’s World ID account is registered. It should only be used inside the authenticator and never shared.

Source

pub fn onchain_address(&self) -> String

Returns the Authenticator’s onchain_address.

See world_id_core::Authenticator::onchain_address for more details.

Source

pub async fn get_packed_account_data_remote( &self, ) -> Result<Uint256, WalletKitError>

Returns the packed account data for the holder’s World ID fetching it from the on-chain registry.

§Errors

Will error if the provided RPC URL is not valid or if there are RPC call failures.

Source

pub async fn generate_credential_blinding_factor_remote( &self, issuer_schema_id: u64, ) -> Result<FieldElement, WalletKitError>

Generates a blinding factor for a Credential sub (through OPRF Nodes).

See CoreAuthenticator::generate_credential_blinding_factor for more details.

§Errors
  • Will generally error if there are network issues or if the OPRF Nodes return an error.
  • Raises an error if the OPRF Nodes configuration is not correctly set.
Source

pub fn compute_credential_sub( &self, blinding_factor: &FieldElement, ) -> FieldElement

Compute the sub for a credential from the authenticator’s leaf index and a blinding_factor.

Source

pub fn danger_sign_challenge( &self, challenge: Vec<u8>, ) -> Result<Vec<u8>, WalletKitError>

Signs an arbitrary challenge with the authenticator’s on-chain key.

§Warning

This is considered a dangerous operation because it leaks the user’s on-chain key, hence its leaf_index. The only acceptable use is to prove the user’s leaf_index to a Recovery Agent. The Recovery Agent is the only party beyond the user who needs to know the leaf_index.

§Errors

May error if very unexpectedly the signing process fails. Not expected.

Source

pub async fn danger_sign_initiate_recovery_agent_update( &self, new_recovery_agent: String, ) -> Result<RecoveryUpdateSignature, WalletKitError>

Signs the EIP-712 InitiateRecoveryAgentUpdate payload and returns the raw signature bytes and signing nonce without submitting anything to the gateway.

Callers can use the returned bytes to build and submit the gateway request themselves.

§Warning

This method uses the onchain_signer (secp256k1 ECDSA) and produces a recoverable signature. Any holder of the signature together with the EIP-712 parameters can call ecrecover to obtain the onchain_address, which can then be looked up in the registry to derive the user’s leaf_index. Only expose the output to trusted parties (e.g. a Recovery Agent).

§Arguments
  • new_recovery_agent — the checksummed hex address of the new recovery agent (e.g. "0x1234…").
§Errors
  • Returns WalletKitError::InvalidInput if new_recovery_agent is not a valid address.
  • Returns an error if the nonce fetch or signing step fails.
Source

pub async fn update_recovery_agent( &self, new_recovery_agent: String, ) -> Result<String, WalletKitError>

Updates the holder’s recovery agent (WIP-102).

On a V2 registry the new agent becomes effective immediately, but for a revert window any authenticator can call Self::revert_recovery_agent_update to roll back. During that window the previous agent remains the only valid signer for recoverAccount, which mitigates a compromised authenticator silently swapping in an attacker-controlled recovery address.

§Arguments
  • new_recovery_agent — the checksummed hex address of the new recovery agent (e.g. "0x1234…").
§Errors
Source

pub async fn revert_recovery_agent_update( &self, ) -> Result<String, WalletKitError>

Reverts an in-flight recovery agent update during the revert window (WIP-102).

Must be called within the revert window after Self::update_recovery_agent. During that window any authenticator can revert the update; the previous recovery agent stays effective until the window expires.

Signs an EIP-712 CancelRecoveryAgentUpdate payload (the typehash is reused on V2) and submits it to the gateway.

§Errors

Returns a network error if the gateway request fails.

Source

pub async fn insert_authenticator( &self, new_authenticator_pubkey: String, new_authenticator_address: String, ) -> Result<String, WalletKitError>

Inserts an authenticator into the holder’s World ID account.

§Arguments
  • new_authenticator_pubkey — a compressed BabyJubJub public key encoded as a 0x-prefixed, zero-padded 32-byte hex string.
  • new_authenticator_address — the Ethereum address associated with the new authenticator. Callers may pass the zero address for a proving-only authenticator.
§Errors
  • Returns WalletKitError::InvalidInput if the public key or address is invalid.
  • Returns a network error if an indexer or gateway request fails.
Source

pub async fn has_authenticator_pubkey( &self, authenticator_pubkey: String, ) -> Result<bool, WalletKitError>

Returns whether the holder’s account already contains an authenticator public key.

This performs a read-only indexer fetch and does not submit an account operation.

§Arguments
  • authenticator_pubkey — a compressed BabyJubJub public key encoded as a 0x-prefixed, zero-padded 32-byte hex string.
§Errors
Source

pub async fn get_authenticator_pubkeys( &self, ) -> Result<Vec<Option<String>>, WalletKitError>

Returns the account’s authenticator public keys, indexed by key-set slot.

Each entry is the compressed BabyJubJub public key at that slot encoded as a 0x-prefixed, zero-padded 32-byte hex string, or None for an empty slot. A key’s position in this list is the pubkey_id expected by Self::remove_authenticator.

This performs a read-only indexer fetch and does not submit an account operation.

§Errors
  • Returns a network error if the indexer request fails.
  • Returns an error if a stored public key cannot be encoded.
Source

pub async fn remove_authenticator( &self, authenticator_address: String, pubkey_id: u32, expected_authenticator_pubkey: String, ) -> Result<String, WalletKitError>

Removes an authenticator from the holder’s World ID account.

§Arguments
  • authenticator_address — the Ethereum address associated with the authenticator being removed. Callers must pass the zero address for a proving-only authenticator.
  • pubkey_id — the stable key-set slot of the authenticator being removed.
  • expected_authenticator_pubkey — the compressed BabyJubJub public key the caller intends to remove, encoded as a 0x-prefixed, zero-padded 32-byte hex string. The removal is refused if pubkey_id currently holds a different key, catching callers acting on a stale key-set view (see Self::get_authenticator_pubkeys). This check is best-effort: the signing flow re-reads the key set afterwards, so a concurrent change to the slot between the check and that read can still remove whichever key the slot holds at signing time. Callers that need an exact-target guarantee must serialize account operations across the account’s authenticators.
§Errors
  • Returns WalletKitError::InvalidInput if the address or public key is invalid, if pubkey_id is out of range, if the slot is empty, or if the slot holds a different key.
  • Returns a network error if an indexer or gateway request fails.
Source

pub async fn poll_status( &self, request_id: String, ) -> Result<GatewayRequestStatus, WalletKitError>

Polls the gateway once for the status of an account operation.

§Errors

Returns a network error if the gateway request fails.

Source§

impl Authenticator

Source

pub async fn init_with_defaults( seed: Vec<u8>, rpc_url: Option<String>, environment: &Environment, region: Option<Region>, artifacts: Arc<dyn WalletKitZkArtifactSource>, store: Arc<CredentialStore>, ) -> Result<Self, WalletKitError>

Initializes a new Authenticator from a seed and with SDK defaults.

The user’s World ID must already be registered in the WorldIDRegistry, otherwise a WalletKitError::AccountDoesNotExist error will be returned.

§Errors

See CoreAuthenticator::init for potential errors.

Source

pub async fn init_with_ohttp_defaults( seed: Vec<u8>, rpc_url: Option<String>, environment: &Environment, region: Option<Region>, artifacts: Arc<dyn WalletKitZkArtifactSource>, store: Arc<CredentialStore>, ) -> Result<Self, WalletKitError>

Initializes a new Authenticator from a seed using SDK defaults routed through the OHTTP relay. Opt-in alternative to Authenticator::init_with_defaults.

The user’s World ID must already be registered in the WorldIDRegistry, otherwise a WalletKitError::AccountDoesNotExist error will be returned.

§Errors

See CoreAuthenticator::init for potential errors.

Source

pub async fn init( seed: Vec<u8>, config: &str, artifacts: Arc<dyn WalletKitZkArtifactSource>, store: Arc<CredentialStore>, ) -> Result<Self, WalletKitError>

Initializes a new Authenticator from a seed and config.

The user’s World ID must already be registered in the WorldIDRegistry, otherwise a WalletKitError::AccountDoesNotExist error will be returned.

§Errors

Will error if the provided seed is not valid or if the config is not valid.

Source

pub async fn generate_proof( &self, proof_request: &ProofRequest, now: Option<u64>, ) -> Result<ProofResponse, WalletKitError>

Generates a proof for the given proof request.

§Errors

Returns an error if proof generation fails.

Source

pub async fn prove_credential_sub( &self, nonce: &FieldElement, context: &FieldElement, blinding_factor: &FieldElement, sub: &FieldElement, ) -> Result<OwnershipProof, WalletKitError>

Generates a WIP-103 Ownership Proof for Issuers.

An Ownership Proof lets the user prove they own the credential sub associated with a stored credential without revealing their leaf_index.

§Security-critical usage constraint

This method MUST only be called as part of a direct user-initiated action in the client. Callers MUST NOT expose this method to issuer-triggered, backend-triggered, or unauthenticated request flows.

§Arguments
  • nonce - A field element provided by the Issuer to prevent replay.
  • context - A field element identifying the issuer operation being authorized.
  • blinding_factor - The credential blinding factor previously used to derive the credential sub.
  • sub - The credential sub (commitment) to prove ownership of.
§Errors
  • Returns WalletKitError::InvalidInput if blinding_factor and sub are inconsistent with each other (i.e. sub was not derived from this authenticator’s leaf index and the provided blinding factor).
  • Returns a network error if the Merkle inclusion proof cannot be fetched from the indexer.
  • Returns WalletKitError::ProofGeneration if the ZK proof fails.

Trait Implementations§

Source§

impl Debug for Authenticator

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<UT> LiftRef<UT> for Authenticator

Source§

impl<UT> LowerError<UT> for Authenticator

Source§

fn lower_error(obj: Self) -> RustBuffer

Lower this value for scaffolding function return Read more
Source§

impl<UT> LowerReturn<UT> for Authenticator

Source§

type ReturnType = <Arc<Authenticator> as LowerReturn<UniFfiTag>>::ReturnType

The type that should be returned by scaffolding functions for this type. Read more
Source§

fn lower_return(obj: Self) -> Result<Self::ReturnType, RustCallError>

Lower the return value from an scaffolding call Read more
Source§

fn handle_failed_lift( error: LiftArgsError, ) -> Result<Self::ReturnType, RustCallError>

Lower the return value for failed argument lifts Read more
Source§

impl<UT> TypeId<UT> for Authenticator

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CompatExt for T

Source§

fn compat(self) -> Compat<T>
where T: Sized,

Applies the Compat adapter by value. Read more
Source§

fn compat_ref(&self) -> Compat<&T>

Applies the Compat adapter by shared reference. Read more
Source§

fn compat_mut(&mut self) -> Compat<&mut T>

Applies the Compat adapter by mutable reference. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, UT> HandleAlloc<UT> for T
where T: Send + Sync,

Source§

fn new_handle(value: Arc<T>) -> Handle

Create a new handle for an Arc value Read more
Source§

unsafe fn clone_handle(handle: Handle) -> Handle

Clone a handle Read more
Source§

unsafe fn consume_handle(handle: Handle) -> Arc<T>

Consume a handle, getting back the initial Arc<> Read more
Source§

unsafe fn get_arc(handle: Handle) -> Arc<Self>

Get a clone of the Arc<> using a “borrowed” handle. Read more
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Layering for T

Source§

fn add_layer<L, F>(self, other: L) -> Layer<L, T>

Layer an executor on top of this one. The other executor will be called first.
Source§

impl<T> MaybeSend for T
where T: Send,

Source§

impl<D> OwoColorize for D

Source§

fn fg<C>(&self) -> FgColorDisplay<'_, C, Self>
where C: Color,

Set the foreground color generically Read more
Source§

fn bg<C>(&self) -> BgColorDisplay<'_, C, Self>
where C: Color,

Set the background color generically. Read more
Source§

fn black(&self) -> FgColorDisplay<'_, Black, Self>

Change the foreground color to black
Source§

fn on_black(&self) -> BgColorDisplay<'_, Black, Self>

Change the background color to black
Source§

fn red(&self) -> FgColorDisplay<'_, Red, Self>

Change the foreground color to red
Source§

fn on_red(&self) -> BgColorDisplay<'_, Red, Self>

Change the background color to red
Source§

fn green(&self) -> FgColorDisplay<'_, Green, Self>

Change the foreground color to green
Source§

fn on_green(&self) -> BgColorDisplay<'_, Green, Self>

Change the background color to green
Source§

fn yellow(&self) -> FgColorDisplay<'_, Yellow, Self>

Change the foreground color to yellow
Source§

fn on_yellow(&self) -> BgColorDisplay<'_, Yellow, Self>

Change the background color to yellow
Source§

fn blue(&self) -> FgColorDisplay<'_, Blue, Self>

Change the foreground color to blue
Source§

fn on_blue(&self) -> BgColorDisplay<'_, Blue, Self>

Change the background color to blue
Source§

fn magenta(&self) -> FgColorDisplay<'_, Magenta, Self>

Change the foreground color to magenta
Source§

fn on_magenta(&self) -> BgColorDisplay<'_, Magenta, Self>

Change the background color to magenta
Source§

fn purple(&self) -> FgColorDisplay<'_, Magenta, Self>

Change the foreground color to purple
Source§

fn on_purple(&self) -> BgColorDisplay<'_, Magenta, Self>

Change the background color to purple
Source§

fn cyan(&self) -> FgColorDisplay<'_, Cyan, Self>

Change the foreground color to cyan
Source§

fn on_cyan(&self) -> BgColorDisplay<'_, Cyan, Self>

Change the background color to cyan
Source§

fn white(&self) -> FgColorDisplay<'_, White, Self>

Change the foreground color to white
Source§

fn on_white(&self) -> BgColorDisplay<'_, White, Self>

Change the background color to white
Source§

fn default_color(&self) -> FgColorDisplay<'_, Default, Self>

Change the foreground color to the terminal default
Source§

fn on_default_color(&self) -> BgColorDisplay<'_, Default, Self>

Change the background color to the terminal default
Source§

fn bright_black(&self) -> FgColorDisplay<'_, BrightBlack, Self>

Change the foreground color to bright black
Source§

fn on_bright_black(&self) -> BgColorDisplay<'_, BrightBlack, Self>

Change the background color to bright black
Source§

fn bright_red(&self) -> FgColorDisplay<'_, BrightRed, Self>

Change the foreground color to bright red
Source§

fn on_bright_red(&self) -> BgColorDisplay<'_, BrightRed, Self>

Change the background color to bright red
Source§

fn bright_green(&self) -> FgColorDisplay<'_, BrightGreen, Self>

Change the foreground color to bright green
Source§

fn on_bright_green(&self) -> BgColorDisplay<'_, BrightGreen, Self>

Change the background color to bright green
Source§

fn bright_yellow(&self) -> FgColorDisplay<'_, BrightYellow, Self>

Change the foreground color to bright yellow
Source§

fn on_bright_yellow(&self) -> BgColorDisplay<'_, BrightYellow, Self>

Change the background color to bright yellow
Source§

fn bright_blue(&self) -> FgColorDisplay<'_, BrightBlue, Self>

Change the foreground color to bright blue
Source§

fn on_bright_blue(&self) -> BgColorDisplay<'_, BrightBlue, Self>

Change the background color to bright blue
Source§

fn bright_magenta(&self) -> FgColorDisplay<'_, BrightMagenta, Self>

Change the foreground color to bright magenta
Source§

fn on_bright_magenta(&self) -> BgColorDisplay<'_, BrightMagenta, Self>

Change the background color to bright magenta
Source§

fn bright_purple(&self) -> FgColorDisplay<'_, BrightMagenta, Self>

Change the foreground color to bright purple
Source§

fn on_bright_purple(&self) -> BgColorDisplay<'_, BrightMagenta, Self>

Change the background color to bright purple
Source§

fn bright_cyan(&self) -> FgColorDisplay<'_, BrightCyan, Self>

Change the foreground color to bright cyan
Source§

fn on_bright_cyan(&self) -> BgColorDisplay<'_, BrightCyan, Self>

Change the background color to bright cyan
Source§

fn bright_white(&self) -> FgColorDisplay<'_, BrightWhite, Self>

Change the foreground color to bright white
Source§

fn on_bright_white(&self) -> BgColorDisplay<'_, BrightWhite, Self>

Change the background color to bright white
Source§

fn bold(&self) -> BoldDisplay<'_, Self>

Make the text bold
Source§

fn dimmed(&self) -> DimDisplay<'_, Self>

Make the text dim
Source§

fn italic(&self) -> ItalicDisplay<'_, Self>

Make the text italicized
Source§

fn underline(&self) -> UnderlineDisplay<'_, Self>

Make the text underlined
Make the text blink
Make the text blink (but fast!)
Source§

fn reversed(&self) -> ReversedDisplay<'_, Self>

Swap the foreground and background colors
Source§

fn hidden(&self) -> HiddenDisplay<'_, Self>

Hide the text
Source§

fn strikethrough(&self) -> StrikeThroughDisplay<'_, Self>

Cross out the text
Source§

fn color<Color>(&self, color: Color) -> FgDynColorDisplay<'_, Color, Self>
where Color: DynColor,

Set the foreground color at runtime. Only use if you do not know which color will be used at compile-time. If the color is constant, use either OwoColorize::fg or a color-specific method, such as OwoColorize::green, Read more
Source§

fn on_color<Color>(&self, color: Color) -> BgDynColorDisplay<'_, Color, Self>
where Color: DynColor,

Set the background color at runtime. Only use if you do not know what color to use at compile-time. If the color is constant, use either OwoColorize::bg or a color-specific method, such as OwoColorize::on_yellow, Read more
Source§

fn fg_rgb<const R: u8, const G: u8, const B: u8>( &self, ) -> FgColorDisplay<'_, CustomColor<R, G, B>, Self>

Set the foreground color to a specific RGB value.
Source§

fn bg_rgb<const R: u8, const G: u8, const B: u8>( &self, ) -> BgColorDisplay<'_, CustomColor<R, G, B>, Self>

Set the background color to a specific RGB value.
Source§

fn truecolor(&self, r: u8, g: u8, b: u8) -> FgDynColorDisplay<'_, Rgb, Self>

Sets the foreground color to an RGB value.
Source§

fn on_truecolor(&self, r: u8, g: u8, b: u8) -> BgDynColorDisplay<'_, Rgb, Self>

Sets the background color to an RGB value.
Source§

fn style(&self, style: Style) -> Styled<&Self>

Apply a runtime-determined style
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more