ORION exposes a Maker API for liquidity providers, a proof verification endpoint anyone can call, an eligibility registry and the same privacy router the app uses. Cryptography underneath: Ed25519, X25519 + XSalsa20-Poly1305 (NaCl), Poseidon, Groth16 over BN254, Token-2022 confidential transfers.
lib/solana/client · deriveKeys()ElGamal + AES keys from one wallet signature (solana-conf-bal/v1).planConfigureAccount / planDeposit / planApplyPendingToken-2022 confidential account lifecycle.planConfidentialTransfer / planWithdrawZK equality, validity and range proofs, verified onchain.lib/rfq/client · createSignedRfq()Sign an RFQ, sealed-quote key from orion-rfq-enc/v1.decryptAndVerifyQuotes()Open NaCl boxes, verify maker signature, binding, commitment.proveBestExecution()Groth16 proof over the committed QuoteSet (MAX_QUOTES 8).buildAndSignSettlement()Atomic settlement: both parties sign identical bytes.lib/disclosure/grant · verifyGrant()Ed25519 verification of a disclosure grant token.@orion/zk/prover · prove() / verify()Browser and server prover/verifier for all five circuits.import { deriveKeys, planDeposit, planApplyPending, executePlan } from "@/lib/solana/client";
const keys = await deriveKeys(messageSigner); // one wallet signature
await executePlan(txSigner, await planDeposit(txSigner, mint, 2_500_000n, 6));
await executePlan(txSigner, await planApplyPending(txSigner, mint, keys));
// balance is now ElGamal-encrypted onchain; only your keys decrypt it/api/rfqCreate a signed private RFQ (taker)/api/rfq/:idRFQ state, sealed quotes, declines (session auth)/api/rfq/:id/closeCommit the QuoteSet root, anchor on Solana/api/rfq/:id/settleMaker co-signs the taker's atomic settlement/api/rfq/:id/quoteMaker API: submit a sealed quote/api/maker/registerMaker API: register identity + encryption key/api/maker/rfqsMaker API: open RFQs for your markets (session auth)/api/proofsStore a proof after server verification (anchored)/api/proofs/verifyStateless Groth16 verification/api/eligibilityEligibility root, policy, Merkle path/api/disclosure/revokeSigned revocation registry/api/solana/portfolio?owner=Live balances incl. confidential-capable flags/api/rhc/assetsRobinhood Chain stock token registry + Chainlink pricesAll endpoints use strongly typed schemas mirrored in types/.
Interfaces in lib/providers/interfaces.ts. Live implementations: Solana RPC + Jupiter (lib/solana), Robinhood Chain + Chainlink (api/rhc), ORION MM (services/orion-mm), RFQ network (services/rfq), ZK (packages/zk).
ORION owns protocol rules, message formats, circuits and routing. It never invents hash functions, curves, AEADs or signature schemes: Poseidon, BN254 Groth16 (snarkjs), NaCl box, Ed25519 and Token-2022 confidential transfers do that work. The Groth16 setup shipped today is a single-party development ceremony; a multi-party ceremony republishes the keys without changing the proof format.