Security model
Threat model
The MVP defends against accidental wallet disclosure, cross-origin message confusion, challenge replay, nullifier reuse, and stale or revoked policy use.
Trust assumptions
The issuer, host verifier deployment, browser runtime, and configured verifier keys are trusted within their documented boundaries. Compromised endpoints, malicious extensions, traffic analysis, and endpoint malware are out of scope.
Logging
Log request ID, gate ID, normalized origin, public error code, and timing. Never log wallet addresses, proof bytes, credential secrets, nullifiers, revocation handles, or raw challenges.