Zero-knowledge, shadow mode
OP_CHECKZKP & OP_RETURN index
Every OP_CHECKZKP use (dogecoin#3869) parsed in shadow mode, plus every OP_RETURN payload by tx, SHA-256 or magic. Proof verification is in progress.
The DogeSoft indexer watches every Dogecoin block for two things builders keep asking about:
OP_CHECKZKP, the zero-knowledge opcode proposed in
dogecoin/dogecoin#3869,
and OP_RETURN data outputs. Both are public, under
https://explorer.dogesoft.io/api/explorer.
What's live and what isn't
| Piece | Status | Notes |
|---|---|---|
| OP_CHECKZKP capture & parsing | Live | Every use of the opcode from block 4,728,316 onward, with proof, verifying key and public inputs split out. Older blocks are being added. |
| OP_RETURN index | Live | Payload, SHA-256 and a 4-byte magic prefix for every data output, same range. |
| Proof verification | In progress | Proofs are stored but not yet checked. shadow_valid stays null until the verifier ships. |
| Consensus enforcement | Not active | OP_CHECKZKP is still OP_NOP10 on Dogecoin. No activation height is set, so every record reads shadow. |
The opcode
OP_CHECKZKP reuses OP_NOP10 (0xB9). The pushes
before it carry a mode selector, then the proof, public inputs and verifying key:
| Mode | Proof system | Layout |
|---|---|---|
0 | Groth16 on BLS12-381 | Proof as 8 × 48-byte pushes, 2 × 32-byte public inputs, verifying key as 6 × 80-byte pushes. |
1 | PLONK / Halo2-KZG on BN256 | Stored as raw pushes while the format settles. |
Before activation, OP_NOP10 is a no-op anyone can put in a script, so the index also catches stray
uses that aren't proofs at all. Those come back with mode: null and a
parse_error. Treat a record as a proof attempt only when
mode is set and parse_error is empty.
OP_CHECKZKP endpoints
| Endpoint | Auth | Description |
|---|---|---|
GET /api/explorer/zkp/status | Public | Proposal, opcode, modes, activation height (null = shadow), event count, indexing progress, verifier status. |
GET /api/explorer/zkp/recent?limit= | Public | Newest events first (1-100, default 25). |
GET /api/explorer/zkp/tx/:txid | Public | Every OP_CHECKZKP use in one transaction, inputs and outputs. |
GET /api/explorer/zkp/vk/:sha256 | Public | Every use of one verifying key, by the SHA-256 of its bytes. Handy for following one circuit. |
{
"txid": "…", "block_height": 6398495, "confirmations": 436,
"role": "redeem_script", "input_index": 0, "op_index": 0,
"mode": 0, "mode_name": "groth16-bls12-381",
"proof_hex": "…", "vk_hex": "…", "vk_sha256": "…", "public_inputs": ["…", "…"],
"parse_error": null, "shadow_valid": null,
"consensus_enforced": false, "status": "shadow (not consensus-enforced)"
}
OP_RETURN endpoints
| Endpoint | Auth | Description |
|---|---|---|
GET /api/explorer/opreturn/recent?limit=&magic= | Public | Newest data outputs. magic filters by the first 4 bytes, e.g. ORA1 for Origin stamps. |
GET /api/explorer/opreturn/tx/:txid | Public | Data outputs in one transaction. |
GET /api/explorer/opreturn/sha256/:hash | Public | Was this exact payload ever written? Returns anchored, the first time it appeared, and up to 50 matches. |
Each output returns payload_hex, payload_utf8
(when it's text), payload_sha256, magic,
bytes, block and confirmations. To write a stamp from DogeOS, use
Origin Services.
Inscribing proofs
The ZKP ACTION tag in the inscription standard
is for committing proof data to Dogecoin as an inscription today, while the opcode isn't active.
DogeOS contracts can pay for one through Origin Services.