Skip to main content

Supported Proofs

Proof TypeSupported Versions / CurvesLimits
EZKLReusable Verifier only (v0.1.0), BN254 (Curve), BDFG21 (batch opening scheme), no accumulatorMax number of Public Inputs: 32
FflonkBN128Max number of Public Inputs: 1
Groth16BLS12-381, BN128, BN254Max number of Public Inputs: 64
Noir UltraHonkNoir v1.0.0-beta.14 to v1.0.0-beta.18, bb and bb.js v3.0.x (v4.0.0 and later not supported yet), both ZK and non-ZK variants, Keccak256 only (evm / evm-no-zk verifier target). Submission variants: V0_84, V3_0, and Legacy (backward-compatible alias for V0_84 that reproduces the pre-versioning statement hash).Max number of Public Inputs: 32, Max Evaluation Domain Size: 2252^{25}
Noir UltraPlonkNoir â‰Ĩ v0.31.0, bb ≤ v0.76.4Max number of Public Inputs: 32
Risc0v2.1, v2.2, v2.3Max Public Inputs Size: 2052 bytes (2048 bytes user input), Format: cbor
Plonky2Keccak256, PoseidonMax number of Public Inputs: 64, Max Proof Size: 256 KiB, Max Verification Key Size: 50 KB
SP1v5.xMax Public Inputs Size: 2048 bytes
TEEIntel TDX, AWS NitroMax Proof Size: 8192 bytes, Max VK Size: 8192 bytes per field, Public Inputs: none