BENCHMARKS
v1.0.0 · Publication dataset · August 2026

ProveKit, measured against the field

A reproducible input-to-proof comparison against Noir + Barretenberg and Circom + Groth16. Real claims, a mid-tier iPhone, a 2 GB Android phone, and a multithreaded browser—with every gap and trade-off kept visible.

LIVE DEMO
ProveKit v1 · 9b2a6f37 · WebAssembly · no server

Try ProveKit right here, right now Try the demo

Edit the private input and generate a real zero-knowledge proof in your browser. Witness never leaves this page; only the public hash + proof get published.

01 · Circuit
02 · Private witness NEVER LEAVES BROWSER
03 · Public statement
I know x such that applying SHA-256 17 times produces y
y revealed after proof
17 full SHA-256 hashes · chained · 32-byte preimage BOOTING
Proving time
Avg. time / hash
Proof size
Constraints
Witnesses
Status
BOOTING
METHODOLOGY

How these numbers were captured

The headline clock starts with frozen structured input and ends with serialized proof bytes, so witness generation is included. Cold and warm modes were recorded separately; charts use cold medians. Each runnable lane had to accept a valid proof and reject a tampered proof.

Claims
3
Passport P1 · WebAuthn · OPRF
Targets
3
iPhone SE 3 · Moto E15 · Chrome/M4 Max
Boundary
Input → proof
Witness generation included
Samples
1 + 5
One warmup · five measured · median
Source
9b2a6f37
ProveKit v1 branch benchmark pin
01 · IPHONE SE 3 PROVING TIME

iPhone SE 3 proving time

On a mid-tier 2022 phone, ProveKit finishes the demanding Passport and WebAuthn claims in about three seconds from structured input to serialized proof.

2–3s
Test setup
  • iPhone SE 2022, iOS 15.4, native execution
  • Raw input → witness → serialized proof
  • Median of five measured samples after one warmup
Series
CIRCOM + GROTH16
NOIR + BARRETENBERG
PROVEKIT V1
0 s 4 s 8 s 12 s 16 s 14.34 4.9 2.43 Passport P1 151.42 5.12 3.03 WebAuthn 1.19 2.92 1.2 OPRF PROVABLE CLAIM · COLD MEDIAN
Passport P1
2.43s
WebAuthn
3.03s
OPRF
1.20s
Device
A15 / 4 GB
02 · MOTO E15 PROVING TIME

Moto E15 proving time

On a 2 GB, 32-bit Android phone, ProveKit keeps Passport P1 and WebAuthn below 30 seconds. Circom WebAuthn cannot complete its cold run because the proving key exhausts memory.

<30s
Test setup
  • Moto E15, Android 14 Go, 2 GB, 32-bit userspace
  • Circom WebAuthn cold run failed allocating its 1.73 GB zkey
  • Failed attempts are explicit gaps, never plotted as zero
Series
CIRCOM + GROTH16
NOIR + BARRETENBERG
PROVEKIT V1
0 s 63 s 125 s 188 s 250 s 241.61 117.15 22 Passport P1 OOM 114.65 27.9 WebAuthn 11.5 70.15 12.68 OPRF PROVABLE CLAIM · COLD MEDIAN
Passport P1
22.00s
WebAuthn
27.90s
OPRF
12.68s
Circom WebAuthn
OOM
03 · BROWSER PROVING TIME

Browser proving time

Chrome on an M4 Max used fixed 16-worker policies. ProveKit stays in the same interactive range across all claims; SnarkJS WebAuthn reached extreme memory pressure and produced no proof.

3–6s
Test setup
  • Chrome 151 on an Apple M4 Max MacBook Pro
  • Fixed 16-worker publication policy
  • SnarkJS WebAuthn stalled after extreme renderer memory pressure
Series
CIRCOM + GROTH16
NOIR + BARRETENBERG
PROVEKIT V1
0 s 4 s 7 s 11 s 14 s 12.56 4.95 5.48 Passport P1 OOM 5.5 5.08 WebAuthn 0.34 4.13 3.02 OPRF PROVABLE CLAIM · COLD MEDIAN
Passport P1
5.48s
WebAuthn
5.08s
OPRF
3.02s
Workers
16
04 · DOWNLOAD REQUIRED TO PROVE

Download required to prove

ProveKit needs no trusted setup and ships only a small circuit-specific proving payload. The alternatives require tens of megabytes to more than a gigabyte.

<3 MB
Test setup
  • Deduplicated circuit-specific proving payload
  • Excludes app bundles, test harnesses, and device uploads
  • Barretenberg includes reusable universal setup material
Series
CIRCOM + GROTH16
NOIR + BARRETENBERG
PROVEKIT V1
0 MB 450 MB 900 MB 1350 MB 1800 MB 508.33 271.71 2.55 Passport P1 1753.62 271.13 2.39 WebAuthn 26.81 271.06 1.65 OPRF DEDUPLICATED PROVING PAYLOAD
Passport P1
2.55 MB
WebAuthn
2.39 MB
OPRF
1.65 MB
Trusted setup
None
05 · SERIALIZED PROOF SIZE

Serialized proof size

Transparent, post-quantum proofs are larger than pairing-based proofs, but every measured ProveKit proof remains below the product target of one megabyte.

<1 MB
Test setup
  • Exact serialized proof bytes
  • Larger proofs are the transparent, post-quantum trade-off
  • All ProveKit results remain below one megabyte
Series
CIRCOM + GROTH16
NOIR + BARRETENBERG
PROVEKIT V1
0 KB 188 KB 375 KB 563 KB 750 KB 0.93 16.32 715.89 Passport P1 1 21.09 716.22 WebAuthn 0.13 16.55 634.96 OPRF SERIALIZED PROOF
Passport P1
716 KB
WebAuthn
716 KB
OPRF
635 KB
Product target
<1 MB
06 · MEMORY ON THE LOW-END PHONE

Memory on the low-end phone

Peak process RSS stays below the one-gigabyte design goal for every successful Moto E15 run. The missing Circom WebAuthn result is an out-of-memory gap, not a zero.

<500 MB
Test setup
  • Peak process RSS for successful cold samples
  • Median of five measured samples
  • Circom WebAuthn is unavailable because the 32-bit process ran out of memory
Series
CIRCOM + GROTH16
NOIR + BARRETENBERG
PROVEKIT V1
0 MB 138 MB 275 MB 413 MB 550 MB 293.37 465.15 474.07 Passport P1 OOM 493.38 494.33 WebAuthn 81.85 306.09 145.08 OPRF PEAK PROCESS RSS · COLD MEDIAN
Passport P1
474 MB
WebAuthn
494 MB
OPRF
145 MB
Design goal
<1 GB
SUMMARY

Passport P1, side-by-side

One circuit across six categories: input-to-proof time on iPhone, low-end Android, and the browser, followed by proving payload, proof size, and peak memory on the Moto E15.

Sorted by CIRCOM + GROTH16
Metric
CIRCOM + GROTH16
NOIR + BARRETENBERG
PROVEKIT V1
01 iPhone input-to-proof ↓ better
14 s
4.9 s
2.43 s best
02 Moto E15 input-to-proof ↓ better
242 s
117 s
22 s best
03 Browser input-to-proof ↓ better
13 s
4.95 s best
5.48 s
04 Proving payload ↓ better
508 MB
272 MB
2.55 MB best
05 Serialized proof ↓ better
0.93 KB best
16 KB
716 KB
06 Moto E15 peak RSS ↓ better
293 MB best
465 MB
474 MB