{"circuit_id":"giwa_attestation","display_name":"GIWA Attestation","description":"Prove the configured GIWA attestation, optionally authorizing one exact EIP-712 action with the same wallet.","e2e_encryption":{"enabled":false,"description":"This deployment provides no hardware TEE attestation. HTTPS protects transport; the prover receives proof inputs.","sdk_usage":"generateProof checks the actual challenge for teePublicKey and encrypts when available."},"local_mcp_server":{"recommended":true,"npm_package":"@zkproofport-ai/mcp","version":"0.3.0","install":"npm install -g @zkproofport-ai/mcp@latest","command":"zkproofport-mcp","transport":"stdio","discovery":"Connect, call tools/list, and follow generate_proof inputSchema. Keys stay in the local signer process.","required_arguments":["circuit"],"optional_arguments":["scope","action","pay_with","pay_on","max_payment"],"generate_proof":{"circuit":"giwa_attestation","scope":"myapp:membership"},"action_bound_example":{"circuit":"giwa_attestation","scope":"myapp:membership","action":"<complete EIP-712 typed action supplied by the trusted application>"},"verification":"Call verify_proof with the returned result. Check the proof on GIWA Sepolia; action authorization additionally requires application policy checks.","credentials":"ATTESTATION_KEY stays local. The SDK uses its built-in GIWA Sepolia RPC and explorer for witness preparation; server GIWA_RPC_URL/GIWA_EXPLORER_URL configure the server-side path. PAYMENT_PRIVATE_KEY is a separate key-based payment option, not a fallback to the attestation signer."},"sdk":{"package":"@zkproofport-ai/sdk","quick_start":"import { createConfig, generateProof } from '@zkproofport-ai/sdk';\n// Supply an explicitly selected funded payment wallet when this service charges.\nconst result = await generateProof(\n  createConfig({ baseUrl: 'https://ai.zkproofport.app' }),\n  { attestation: existingAttestationSigner, payment },\n  { circuit: 'giwa_attestation', scope: 'myapp:membership', action },\n);\n// Omit action above for an identity-only proof.","cli":"PROOFPORT_URL=https://ai.zkproofport.app zkproofport-prove giwa_attestation --scope myapp:membership --action action.json --silent","identity_only":"PROOFPORT_URL=https://ai.zkproofport.app zkproofport-prove giwa_attestation --scope myapp:membership --silent","action_bound":"PROOFPORT_URL=https://ai.zkproofport.app zkproofport-prove giwa_attestation --scope myapp:membership --action action.json --silent","payment_selection":"Choose an offered network and an existing funded payment wallet explicitly. Payment is independent of the circuit verification chain."},"constants":{"attestation_source":{"chain_id":91342,"rpc_url":"https://sepolia-rpc.giwa.io/","explorer_url":"https://sepolia-explorer.giwa.io"},"contracts":{"attester":"0x6646d970499BBeD728636823A5A7e551E811b414","verifier_address":"0x5Da234546874304F8c51BBEed00fC632938211c1","chain_id":91342},"authorized_signers":["0xEE099845CDfF93e73aDcBcB36A9B93578bcCed4b"],"payment":{"required":true,"recipient":"0xc5B29033e63A986b601Fe430806A2C9735F2ea97","price":"$0.10","source":"Use the live 402 accepts list."},"x402":{"protocol":"x402 v2; use the selected live offer","chains":[{"network":"eip155:8453","network_name":"base","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","decimals":6,"settlement":"facilitator","eip712_domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}},{"network":"eip155:1","network_name":"ethereum","asset":"0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48","decimals":6,"settlement":"payee","eip712_domain":{"name":"USD Coin","version":"2","chainId":1,"verifyingContract":"0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48"}}],"single_step_flow":"POST /api/v1/prove → 402 PAYMENT-REQUIRED and accepts → sign the selected offer → retry with PAYMENT-SIGNATURE. Return X-Payment-Nonce when the challenge supplied one.","nonce_details":"X-Payment-Nonce is single-use and circuit-bound; required with X-Payment-TX. Signed authorization payments also have their own replay protection.","nanopayments":"For arc-testnet-nano, use @circle-fin/x402-batching. Circle Agent Wallet backing EOA signs GatewayWalletBatched; Gateway settles against deposited balance. USDC in the wallet and deposited Gateway balance are separate."},"verification":{"verifier_address":"0x5Da234546874304F8c51BBEed00fC632938211c1","chain_id":91342,"chain_name":"GIWA Sepolia","rpc_url":"https://sepolia-rpc.giwa.io/","function_signature":"verify(bytes proof, bytes32[] publicInputs) external view returns (bool)","public_input_count":192,"input_format":"192 bytes32 field words encoding six [u8;32] values. Keep proof and publicInputs separate."}},"action":{"required":false,"type":"EIP-712 TypedData","required_fields_when_present":["domain","types","primaryType","message"],"domain":"Bind name, version, chainId and verifyingContract to the intended application.","message":"Use the complete application-provided typed action. The schema is application-defined; do not replace it with a fixed deposit or delegation example.","security":"The application must compare domain, action hash, trusted attester root, scope and its replay/expiry policy. An identity-only proof does not authorize an action."},"formulas":{"identity_signature":"Without action, personal_sign(signal_hash). Circuit action_hash and domain_separator are zero.","signing_digest":"With action, keccak256(0x1901 || domain_separator || action_hash); signal_hash is zero in the circuit witness.","domain_separator":"EIP-712 domain hash","action_hash":"EIP-712 hashStruct(primaryType, message)","scope":"keccak256(UTF8(scope))","nullifier":"keccak256(keccak256(address_bytes || keccak256(UTF8(circuitId))) || scope_bytes)","nullifier_note":"Same wallet, circuit and scope produce the same nullifier with or without action."},"input_schema":{"preparation":"Use generate_proof locally. On the REST wire omit both domain_separator and action_hash for identity-only mode; for action mode provide both 32-byte hashes.","public_fields":["signal_hash","domain_separator","action_hash","signer_list_merkle_root","scope","nullifier"],"private_inputs":"Wallet public key and signature, signed attestation transaction and attester membership proof. Never expose these through an LLM."},"endpoints":{"prove":{"method":"POST","url":"https://ai.zkproofport.app/api/v1/prove","content_type":"application/json","flow":"x402 single-step: POST with {circuit} → 402 with nonce and live offers → pay when required → retry with {circuit, inputs} over HTTPS and payment headers","timeout_hint":"10-30 seconds","description":"Settles the selected payment and generates the proof. Encrypt with teePublicKey when the challenge supplies it; otherwise the prover receives the witness over HTTPS."},"guide":{"method":"GET","url":"https://ai.zkproofport.app/api/v1/guide/giwa_attestation","description":"Returns this guide as JSON (the document you are reading)"}}}