Appearance
Relayer Network
A withdrawal that the recipient signed would put the recipient on the transaction as the fee payer. That address would need SOL, and the source of that SOL often recreates the link the pool just broke.
A relayer signs instead. The relayer pays the Solana fee and is repaid from the withdrawal through the relayer share of the protocol fee. The recipient is a writable account on the instruction, not a signer.
What a relayer can and cannot do
A relayer sees the public withdrawal: proof, nullifiers, commitments, amount, fee, recipient, and encrypted outputs. That is the same data the chain will store.
A relayer cannot:
- redirect the payment, because the recipient is inside the proof
- raise or lower the fee after the proof is built, for the same reason
- learn the spending key or which deposit created the note
- spend the change note
A relayer can refuse the job, go offline, or delay it. The note stays unspent until a withdrawal confirms. Another relayer can submit a fresh proof for the same note. Two relayers cannot both succeed: the first nullifier recorded wins, and the second transaction fails.
How one is chosen
The indexer lists active relayers for the cluster. The client asks each one for status and keeps those that respond with a reward account and a fee.
The client then uses:
- a specific relayer URL
- an index into that list
- or a random list entry
Private Send can pin every item in a batch to one randomly chosen relayer, or let each item choose.
The reward account in the proof is the account that relayer published. The fee in the proof is that relayer’s fee plus the current platform fee.
How a job is submitted
Two paths reach the same withdrawal instruction:
| Path | When |
|---|---|
POST {relayerUrl}/relay | A single withdrawal. The client polls the relayer’s job until it confirms or fails. |
POST {indexer}/submit | Private Send, up to 8 proofs per request. The indexer returns a submission id. The client polls that id. |
Both paths carry the same public payload. Neither path includes the note string.
Operators
Anyone the indexer marks active can take jobs. The indexer records operational fields for each relayer, including a staked amount, recent volume, and fee earnings. Those fields describe the operator listing. They are not a second token inside the shielded tree.
On devnet, the relayer registry mint is GAFN64LvtCBoc5BHncVn3JEJGpq42rUzQjPmvMK2UhZH.
The relayer’s own fee is competitive: a higher fee makes that relayer’s quotes worse, and the user can pick another URL.