Credential Holding & Scoped Sharing
Share the claim that is needed, not an unnecessary identity dossier.
The holder’s role
Vault demonstrates holding a test credential and generating a proof for a scoped request. It is an evaluation interface, not a production encrypted document store or a recovery service.
Keep the private witness separate
The browser uses private witness values to generate a Groth16 proof. Those values are not included in the proof package. The current lab can lose the holder secret when the original tab is refreshed.
- Use test samples only
- Keep continuation and receipt links private
- Read the requested audience, policy and expiry
A request has boundaries
zkBridge prepares a request with a challenge and validity window. The holder completes it in Vault. This does not move tokens between chains or establish a universal digital identity.
What the verifier sees
The verifier receives the proof, public signals and registry evidence needed for its checks. Public inputs and workflow metadata are not hidden simply because a zero-knowledge proof is used.
Explore the tools
Follow the connected Vault pipeline or use the standalone Sandbox to learn each role. Wallet consent, encrypted storage and standards-based interoperability require separate implementation and evaluation.

