Reference

CLI

The tally command and the repository's pnpm scripts.

tally

The standalone verification tool, in cli/tally.ts. Run it with npx tsx cli/tally.ts <command> from the repository root.

tally challenge [--out challenge.json]
tally prove   --funder <G…> --round <hex> --keys <file> [--challenge f] [--out f]
tally verify  --funder <G…> --round <hex> [--challenge f] [--bundle f]

common:  --registry <C…>  --deployment <file>

challenge (donor)

Creates the donor's disclosure keypair and a fresh nonce and writes them to --out (default challenge.json). Give the funder only p_r_x, p_r_y and nu. Keep secret_r_R.

prove (funder)

FlagDefaultMeaning
--funderrequiredThe funder address that declared the round
--roundrequiredThe round id, hex
--keysrequiredA file with the lane spending keys, such as demo/last-round.json
--challengechallenge.jsonThe donor's challenge
--outbundle.jsonWhere to write the bundle

prove reads the round and its transfers from the chain, re-derives each transfer's ephemeral scalar from the lane key and the event, and refuses any event it cannot re-derive. It writes a zero-knowledge proof and the sealed total.

verify (donor)

FlagDefaultMeaning
--funderrequiredThe funder address
--roundrequiredThe round id, hex
--challengechallenge.jsonThe donor's own challenge
--bundlebundle.jsonThe funder's answer

From the bundle, verify reads exactly three values: the proof, r_disc_x/y and v_tilde_disc. Everything else it resolves from the chain or from the donor's own challenge. See Verifying a round.

Common flags

FlagDefaultMeaning
--registryTALLY_REGISTRY, else the registry in the deployment fileThe round registry contract
--deploymentdemo/deployment.testnet.jsonThe deployment file
--rpcTALLY_RPC, else the file's rpcUrlAn RPC endpoint; an archive node serves a longer event window
--sourcea fixed probe accountA funded account used only to shape read-only simulations; nothing is submitted

--rpc and --source are read in the code but not listed in the usage text.

Exit codes are on Exit codes.

pnpm scripts

From the root package.json:

ScriptWhat it doesNetwork
pnpm demoRuns one full round and donor verificationTestnet transactions
pnpm verify:evidenceVerifies the round named in evidence/latest.jsonTestnet reads
pnpm evidence:refreshRuns a fresh round and publishes the next evidence/round-NNNTestnet transactions
pnpm testSecret guard and its negative tests, typecheck, conformance vectors, local proving, retention logic, contract testsNone
pnpm test:registrationNon-custodial registration against live testnetTestnet transactions
pnpm check:secretsThe secret guard aloneNone
pnpm test:conformanceOpenZeppelin v0.9.0 primitive vectorsNone
pnpm test:proveBuilds, proves and verifies a register and a transfer locallyNone
pnpm build:circuitsRebuilds the aggregate circuits and re-pins their keys (nargo 1.0.0-beta.11)None
pnpm build:contractsBuilds the round registry and the v0.9.0 contracts (stellar contract build)None
pnpm deploy:testnetDeploys a fresh stack; writes the auditor secret to ~/.config/tally onlyTestnet transactions
pnpm measureRe-measures on-chain costs into ct/measurements.testnet.jsonTestnet transactions
pnpm bench:aggregateLocal proving benchmark for the aggregate circuitsNone
pnpm site:factsRebuilds the site's facts file from repository files and testnet RPCTestnet reads