BENCHMARKS
v1.0.0 · April 2026

ProveKit, measured against the field

A reproducible look at how ProveKit performs against Barretenberg and Circom across proving time, memory, and setup artifacts, measured on commodity client hardware, with the dataset and methodology published in full below.

LIVE DEMO
Run on this device · WebAssembly · no server

Try ProveKit right here, right now Try the demo

Pick a circuit, edit the private input, and generate a real zero-knowledge proof in your browser. Witness never leaves this page; only the public hash + proof get published.

01 · Circuit
02 · Private witness NEVER LEAVES BROWSER
03 · Public statement
I know x such that SHA256(x) = y
y revealed after proof
SHA-256 · 17 rounds · 32-byte preimage BOOTING
Proving time
Proof size
Constraints
Witnesses
Status
BOOTING
LIVE DEMO

Run a zero-knowledge proof in your browser

Run on this device · no server

Try Provekit right in your browser

Edit the inputs, then watch a zero-knowledge proof generate live. Nothing leaves this page.

01 · Private witnessLocal only · never leaves browser
Date of birth1995-08-14
02 · Public statement
I am at least 18 years old.
Min age·18Today·2026-05-13
03 · Hash function
8,192 constraints · est 1240 ms
Trace · 8,192 constraints · PoseidonREADY
01Compile circuit
02Build witness
03Generate proof
04Verify locally
Proof artifact0/192 bytes
Total time
Peak memory
Verifier gates
Status
READY
METHODOLOGY

How these numbers were captured

All three toolkits prove the same SHA-256 preimage statement on the same MacBook Air (Apple M2, 16 GB). Timings are full wall clock including witness generation; memory is peak resident set. ProveKit figures reflect the audited v1 branch. Circom is measured with native rapidsnark.

Hardware
MacBook Air
Apple M2 · 16 GB
Circuit
SHA-256
preimage proof · 52,029 R1CS constraints
Systems
3 stacks
WHIR · UltraHonk · Groth16 (rapidsnark)
Setup
2.86 s
one-time prepare · no ceremony
Branch
v1.0.0
audited release line
01 · PROVING TIME

Proving time

ProveKit proves SHA-256 in 0.37 s on a MacBook Air, ahead of Barretenberg at 0.39 s and Circom at 0.40 s, witness generation included.

0.37s
Test setup
  • SHA-256 preimage circuit · 52,029 R1CS constraints
  • Wall clock includes witness generation
  • Circom measured with native rapidsnark
Series
BARRETENBERG
CIRCOM
PROVEKIT
0.39 s
BARRETENBERG
0.4 s
CIRCOM
0.37 s
PROVEKIT
ProveKit
0.37s
Barretenberg
0.39s
Circom
0.40s
One-time setup
2.86s
02 · MEMORY FOOTPRINT

Memory footprint

Proving peaks at 118.9 MiB resident, well within a phone-class memory budget.

118.9 MiB
Test setup
  • Peak resident set while proving
  • Circom measured with native rapidsnark
  • All three fit comfortably in phone-class memory
Series
BARRETENBERG
CIRCOM
PROVEKIT
0 MiB 40 MiB 80 MiB 120 MiB 160 MiB 157.9 96.7 118.9 While proving PEAK RSS
ProveKit
118.9 MiB
Barretenberg
157.9 MiB
Circom
96.7 MiB
Hardware
M2 Air
03 · SETUP ARTIFACTS

Setup artifacts

A device downloads under 1 MiB of ProveKit keys to start proving, against a 128 MiB CRS for Barretenberg or a 50.9 MiB zkey for Circom.

<1 MiB
Test setup
  • Everything a device needs before proving: keys under 1 MiB
  • Circom additionally needs a 288 MiB ptau for its ceremony
  • Hash-based WHIR commitment, no trusted setup ceremony
Series
BARRETENBERG
CIRCOM
PROVEKIT
0 MiB 35 MiB 70 MiB 105 MiB 140 MiB 128 50.9 1 Per circuit SHA-256 CIRCUIT
Prover key (.pkp)
426 KiB
Verifier key (.pkv)
572 KiB
One-time prepare
2.86s
Trusted setup
None
SUMMARY

Side-by-side

Hover a row to compare across toolkits; click a toolkit header to sort by its strongest results. Best value per row reads in brand blue.

Sorted by PROVEKIT
Metric
BARRETENBERG
CIRCOM
PROVEKIT
01 Prove ↓ better
0.39s
0.4s
0.37s best
06 Prover artifacts ↓ better
128 MiB
51 MiB
1 MiB best
07 One-time setup ↓ better
0.37s best
46s
2.86s
03 Prove peak RSS ↓ better
158 MiB
97 MiB best
119 MiB
02 Verify ↓ better
10ms
1ms best
50ms
04 Verify peak RSS ↓ better
6 MiB
1.8 MiB best
46 MiB
05 Proof size ↓ better
14 KiB
0.7 KiB best
617 KiB