Security model
Threat model
The MVP defends against accidental wallet disclosure, cross-origin message confusion, challenge replay, nullifier reuse, and stale or revoked policy use.
Trust assumptions
The issuer, host verifier deployment, browser runtime, configured verifier keys, host database, and contract/policy source are trusted within their documented boundaries. The integrator must protect these components and keep policy reads fresh. Compromised endpoints, malicious extensions, traffic analysis, and endpoint malware are out of scope.
Logging
Prefer a request ID, a typed public error code, a coarse safe stage, and operational timing that cannot be joined to a user. Never log wallet addresses, proof bytes or request bodies, credential secrets, challenge IDs/digests/raw values, private app IDs, nullifiers, revocation hashes, cookies, or signature data. Ensure APM, reverse proxies, and error-reporting SDKs do not capture them automatically.