Selective disclosure
Show that a credential supports a claim without exposing every field in the credential.
A community-maintained C++ zero-knowledge system for existing identity and signature infrastructure — portable across native, mobile, and WebAssembly environments.
Show that a credential supports a claim without exposing every field in the credential.
Build proofs around widely deployed ECDSA and BIP340 signatures instead of replacing issuer infrastructure.
Longfellow combines sumcheck and Ligero, a hash-based argument system that avoids a ceremony-generated reference string.
The Dyne distribution targets C++20, WASI/WebAssembly, Android, iOS, and command-line workflows.
Application developers should follow Getting started to install and consume the base CMake package, then choose an ECDSA, BIP340, or mdoc package. Distribution maintainers should use the packaging recipe and 0.x ABI policy. Protocol reviewers can follow the specification map into the algorithms and test vectors.
Longfellow-ZK began at Google. Dyne.org maintains this European soft fork as a community-controlled implementation that can be deployed without depending on a proprietary mobile operating-system API. The work supports open digital identity infrastructure, including the European Digital Identity Wallet ecosystem, while keeping the core library reusable beyond identity.
Project status
Longfellow-ZK is pre-1.0 software and active cryptographic engineering. Read the security and qualification boundaries before a production deployment. Documentation, test matrices, and external reviews are evidence; they are not a substitute for a use-case-specific security assessment.
Longfellow-ZK is GPL-3.0-or-later free software. For integration, distribution, security, or licensing questions, contact info@dyne.org.