VeilPass docs
Developer documentation
Integrate origin-scoped, eligibility-gated login without receiving the user's Stellar address.
What the host receives
A successful login returns only eligibility, a private app ID, gate ID, epoch, normalized origin, and expiry. The host never receives the Stellar wallet address or balance. During verification, the host browser and server do receive the raw proof and public inputs, including the credential commitment, revocation hash, and one-time nullifier; treat those as sensitive request data and do not log or persist them.
MVP status
This repository is testnet software. The hosted login generates a local Noir/UltraHonk membership proof and the verifier checks it with the pinned verification key. The separately labeled Simulated proof endpoint is only a non-production compatibility fixture; /api/verify never accepts it.
Choose the correct integration path
The published browser SDK is a popup client, not a hosted authentication backend. It calls POST /api/challenges and POST /api/verify on the host application's own origin. The host developer must implement those routes, trusted origin/gate policy, durable atomic challenge and nullifier storage, a real pinned proof-verification callback, rate limits, and the application's session cookie. The @veilpass/server package supplies a verification primitive; it does not supply these adapters. Follow the quickstart and server guide before using the SDK in an application.
Document set
Start with Quickstart, then read Client SDK, Server verifier, API reference, Identity semantics, Enrollment, Privacy model, Threat model, Errors, and Examples. The GitHub repository README covers the project and local setup; each npm package README documents that package's exact public API and limitations.
Source packages and release references
Install only the public packages listed below. Their npm READMEs are part of each published tarball; source links point to the corresponding workspace directories. The contract-bindings workspace is not a published npm integration package.