zk_protocol/lib.rs
1/// General protocol for ZK attestation between agents
2/// This library provides common types and serialization helpers
3/// that any agent can use without depending on other agents' code.
4
5use serde::{Deserialize, Serialize};
6use serde_json::Value;
7
8/// Request to the attester service to generate a ZK proof
9#[derive(Serialize, Deserialize, Debug, Clone)]
10pub struct AttestRequest {
11 pub program_id: String,
12 /// Input data as raw bytes (bincode-serialized)
13 /// Will be passed to the zkVM program via stdin as a single buffer entry.
14 /// For programs that call io::read() multiple times, use `stdin_items` instead.
15 pub input_bytes: Vec<u8>,
16 /// Multiple stdin buffer entries (each pushed separately).
17 /// When present, each entry maps to one sp1_zkvm::io::read() call.
18 /// Takes precedence over `input_bytes` when non-empty.
19 #[serde(default)]
20 pub stdin_items: Vec<Vec<u8>>,
21 /// Expected output for verification (optional, format defined by agent)
22 pub claimed_output: Option<Value>,
23 /// Whether to verify the proof locally before returning
24 #[serde(default = "default_verify")]
25 pub verify_locally: bool,
26 /// Optional external transaction ID (payment processor binding).
27 /// When present, the attester auto-saves the proof keyed by this ID
28 /// so the payment processor can pull it directly — bypassing the LLM.
29 #[serde(default, skip_serializing_if = "Option::is_none")]
30 pub external_id: Option<String>,
31 /// Intent commitment: SHA-256(proof_hash || "||" || external_id).
32 /// Stored alongside the proof for retrieval by the payment processor.
33 #[serde(default, skip_serializing_if = "Option::is_none")]
34 pub intent_commitment: Option<String>,
35 /// Fields verified in the proof (e.g. ["amount", "quantity", "product_id"]).
36 #[serde(default, skip_serializing_if = "Option::is_none")]
37 pub verified_fields: Option<Vec<String>>,
38 /// Actual field values proven (e.g. {"recipient_address": "0x...", "token": "ETH"}).
39 /// Stored alongside the proof so the payment processor can validate values
40 /// without re-running the ZKP — the commitment scheme ensures correctness.
41 #[serde(default, skip_serializing_if = "Option::is_none")]
42 pub field_values: Option<std::collections::HashMap<String, String>>,
43}
44
45fn default_verify() -> bool {
46 true
47}
48
49/// A single field commitment extracted from the proof's public values.
50#[derive(Serialize, Deserialize, Debug, Clone)]
51pub struct FieldCommitment {
52 /// Field name (e.g., "amount", "product_id")
53 pub field: String,
54 /// Hex-encoded SHA-256 commitment: SHA-256(field:value:external_id:secret_salt)
55 pub commitment: String,
56}
57
58/// Response from the attester service
59#[derive(Serialize, Deserialize, Debug, Clone)]
60pub struct AttestResponse {
61 /// Hex-encoded Groth16 proof for on-chain verification
62 pub proof: String,
63 /// Public values committed by the zkVM program (hex-encoded)
64 pub public_values: String,
65 /// VK hash for on-chain verifier (bytes32)
66 pub vk_hash: String,
67 /// Output from the zkVM program
68 pub verified_output: Value,
69 /// Echo back the external_id if one was provided in the request.
70 #[serde(default, skip_serializing_if = "Option::is_none")]
71 pub external_id: Option<String>,
72 /// Field commitments extracted from the proof's public values.
73 /// Each entry is SHA-256(field:value:external_id:secret_salt).
74 #[serde(default, skip_serializing_if = "Option::is_none")]
75 pub field_commitments: Option<Vec<FieldCommitment>>,
76}
77
78/// Response from POST /register-elf
79#[derive(Serialize, Deserialize, Debug, Clone)]
80pub struct RegisterResponse {
81 /// Content-addressable program ID (e.g. "sha256:<hex>")
82 pub program_id: String,
83 /// Version number (defaults to 1)
84 #[serde(default = "default_version")]
85 pub version: i32,
86 /// ISO-8601 timestamp
87 pub registered_at: String,
88}
89
90fn default_version() -> i32 {
91 1
92}
93
94/// Response from an agent's pricing/booking endpoint
95#[derive(Serialize, Deserialize, Debug, Clone)]
96pub struct AgentResponse {
97 /// Agent-specific response data (price, booking ID, etc.)
98 #[serde(flatten)]
99 pub data: Value,
100 /// Program ID for ZK verification
101 pub program_id: String,
102 /// ELF hash of the zkVM program
103 pub elf_hash: String,
104}
105
106/// Helper to serialize any serde-compatible type to bincode bytes
107pub fn serialize_input<T: Serialize>(input: &T) -> Result<Vec<u8>, bincode::Error> {
108 bincode::serialize(input)
109}
110
111/// Helper to deserialize bincode bytes to any serde-compatible type
112pub fn deserialize_output<T: for<'de> Deserialize<'de>>(bytes: &[u8]) -> Result<T, bincode::Error> {
113 bincode::deserialize(bytes)
114}
115
116/// Convert bincode bytes to JSON array format for HTTP transport
117pub fn bytes_to_json_array(bytes: &[u8]) -> Value {
118 Value::Array(bytes.iter().map(|b| Value::Number((*b).into())).collect())
119}
120
121/// Extract bytes from JSON array format
122pub fn json_array_to_bytes(value: &Value) -> Option<Vec<u8>> {
123 if let Value::Array(arr) = value {
124 Some(arr.iter().filter_map(|v| v.as_u64().map(|n| n as u8)).collect())
125 } else {
126 None
127 }
128}