Trusted boundary
Server verifier
Bind each challenge to the trusted deployment origin and gate, then consume challenge and nullifier in one atomic operation.
Verify
The verifier checks the strict schema, proof timestamps, trusted expected origin, expected gate, current active policy, epoch, root, credential expiry, optional credential revocation, and the cryptographic verifier callback. It delegates challenge digest comparison, challenge expiry/binding, one-time challenge consumption, and atomic nullifier uniqueness to your ChallengeStore.consume implementation. The policy, store, verifier callback, and request ID must all be server-owned dependencies.
import { verifyVeilPassProof } from "@veilpass/server";
const verified = await verifyVeilPassProof({
proofResult,
expectedOrigin: "https://app.example",
expectedGateId: "premium-holder",
policy,
store: durableChallengeStore,
verifyProof: verifyNoirMembershipProof,
requestId,
});Response minimization
Return the documented success object only. Error responses contain a safe public error code and request ID, never raw verifier diagnostics.
Production adapter checklist
Use a durable database shared by all host instances. Lock the challenge row, verify stored digest/origin/gate/expiry, insert a unique nullifier digest, and mark the challenge spent in one transaction. Resolve active root, epoch, and revocation from trusted chain/policy state and fail closed if unavailable; implement `GatePolicy.isRevoked` when the gate supports credential-level revocation because omission means the primitive performs no per-credential revocation lookup. Pin the verification key to the exact circuit release. Add request size limits, rate limits, CSRF/origin controls, no-store responses, and a host-only session cookie with expiry no later than the proof. The library does not implement those adapters for you.