Open proof infrastructure for Solana
Prove it on Solana without publishing the data.
Provera lets a crypto project prove a fact about its own data and record that proof on-chain. You run it yourself: no Provera server sees your data, holds your keys or sits between you and Solana.
Pre-release and not audited. The on-chain programs are tested on a local validator and have no public deployment yet; you deploy your own with one script.
# 1. Prove on your own machine. The dataset never leaves it.
prover prove --manifest airdrop.json --out proof
# 2. Wrap the STARK so Solana can verify it.
prover wrap --receipt proof/receipt.bin --out proof
# 3. Register it on Solana from your own wallet.
provera submit --report proof/report-groth16.json \
--deployment deployment.json --keypair wallet.json
# 4. Anyone holding the data can check the receipt.
provera check airdrop.json --receipt <address> \
--deployment deployment.jsonWhy a proof
A spreadsheet is a claim. A proof can be checked by someone who does not trust you.
Projects publish allocation tables, leaderboards and reward lists and ask their communities to take the arithmetic on faith. A proof binds the published result to a commitment of the exact input data, so anyone can confirm the rule was applied to all of it, without re-running anything and without seeing the data.
- 01Working
Your computation runs in a zkVM
Each proof type is an ordinary Rust program executed inside the RISC Zero zkVM on your hardware. The same code is unit-tested natively, so what is proved is what was tested.
- 02Working
A STARK proves the execution
The zkVM emits a STARK: a hash-based proof with no trusted setup that this exact program accepted your data and produced these public outputs. Anyone can verify it off-chain.
- 03Working
A Groth16 wrapper makes it fit on Solana
A STARK is too large for a Solana transaction. It is wrapped in a 256-byte Groth16 SNARK, which a Solana program checks with the alt_bn128 syscalls. Solana verifies the wrapper, not the STARK, and the wrapper relies on a trusted setup.
- 04Tested locally, no public deployment
A receipt account anyone can read
The registry program writes a receipt only inside a transaction where verification succeeded. Wallets, websites and other programs read that account directly from Solana.
Nothing to trust in the middle
Proving happens on your machine and the transaction is signed by your wallet. There is no account to create and no service that can be switched off.
Your data stays yours
Only a commitment and the public outputs go on-chain. The dataset is never uploaded anywhere unless you choose to share it.
Checkable by anyone
A receipt is a normal Solana account. This site reads it straight from an RPC node in your browser, and so can any wallet or program.
Proof types
One statement at a time
Token distributions
Prove that a committed allocation list has unique wallets and that no wallet exceeds a stated share of the total.
Airdrop and holder rewards
Prove that reward amounts follow published eligibility rules, with Merkle claims and double-claim protection.
Trading leaderboards
Prove that volume, realized PnL and rankings follow agreed rules over a committed trade set, in integer arithmetic.
What a proof does not tell you
Read the fine print before you cite one
A proof is exact about what it covers and silent about everything else.
It covers the dataset that was proved.
Wallets left out of the list are invisible to the proof. It cannot show that no other insider wallets exist.
It does not read the chain.
Mint, category and snapshot slot are labels chosen by whoever made the proof.
Wallets are not people.
Fifty wallets holding 2% each satisfy a 2% cap, whoever controls them.
A receipt is only as good as its registry and guest image.
Check which program owns the receipt and that the guest image ID is one built from source you have read.
Run it yourself
Build the prover, deploy the programs to a cluster of your choice, and submit from your own wallet.