Protocol
Covenants
A covenant is a script that limits how coins or assets can be spent, not only who can spend them: where they may go, how much, when, and in which form. Neurai's testnet adds 33 new and re-enabled opcodes to Script, active since block 10, so contracts such as vaults, escrows, swaps and payment channels run at the consensus layer without a virtual machine.
Introspection
Scripts read inputs, outputs, values, locktime and chain height.
Asset-native
Covenants see asset names and amounts, not only XNA.
Post-quantum
AuthScript accepts ML-DSA-44 signatures, alone or mixed with ECDSA.
Zero-knowledge
Groth16 verification and Poseidon hashing inside Script.
Execution environment
AuthScript
Covenants are meant to run inside AuthScript, the witness v1 output type
(tnc1p… addresses). An AuthScript output is OP_1 <32-byte commitment>; the
commitment binds an authentication type (none, ML-DSA-44 or ECDSA) and the hash of the witness script.
AuthScript adds:
- Script trees (NIP-044): several spending branches, only the one used is revealed.
- Execution budgets (NIP-046): up to 512 operations and 65,536 hash units per execution.
- Mixed multisig: ECDSA and post-quantum keys in the same threshold.
- OP_ZKVERIFY, which is only available here.
Each opcode has its own consensus flag, so once active the others also work in Legacy, P2SH and witness v0 scripts.
Reference
The new opcodes
Byte values as defined in src/script/script.h. All are active on testnet from block 10 and unscheduled on mainnet.
Covenant primitives
Commit to how coins may be spent next.
-
Requires the spending transaction to match a fixed template (BIP 119).
OP_CHECKTEMPLATEVERIFY0xb3 -
Checks an ECDSA or ML-DSA signature over arbitrary data: oracles and delegation.
OP_CHECKSIGFROMSTACK0xb4 -
Hashes the transaction fields chosen by a 16-bit mask (NIP-042).
OP_TXHASH0xb5
Input introspection
Read the inputs being spent.
-
A field of the input being spent, such as its own scriptPubKey: the basis of recursive covenants.
OP_TXFIELD0xb6 -
A field of any spent input (NIP-043).
OP_INPUTFIELD0xc4 -
The value of an input (NIP-024).
OP_INPUTVALUE0xd6 -
How many inputs the transaction has.
OP_INPUTCOUNT0xd0
Output introspection
Constrain where the coins go.
-
The value of an output.
OP_OUTPUTVALUE0xcc -
The scriptPubKey of an output.
OP_OUTPUTSCRIPT0xcd -
The AuthScript commitment of an output (NIP-023).
OP_OUTPUTAUTHCOMMITMENT0xd5 -
The destination of an AuthScript output, by family (NIP-041).
OP_OUTPUTAUTHDEST0xc2 -
How many outputs the transaction has.
OP_OUTPUTCOUNT0xd1
Transaction and chain context
Time, height and chain identity.
-
The transaction's nLockTime.
OP_TXLOCKTIME0xc5 -
Block height, median time past or chain id (NIP-026).
OP_CHAINCONTEXT0xd7
Reference inputs
Read an output without spending it (transaction v3, NIP-014).
-
How many reference inputs the transaction carries.
OP_REFINPUTCOUNT0xd4 -
A field of a reference input: shared state, price feeds, registries.
OP_REFINPUTFIELD0xd2
Native asset introspection
Covenants that understand Neurai assets.
-
Asset name, amount, units, reissuable flag, IPFS hash, type or message of an output.
OP_OUTPUTASSETFIELD0xce -
The same fields for a spent input.
OP_INPUTASSETFIELD0xcf -
The same fields for a reference input.
OP_REFINPUTASSETFIELD0xd3
Bytes and arithmetic
Build and parse data on the stack.
-
Concatenates two stack items.
OP_CAT0x7e -
Splits an item at a position.
OP_SPLIT0xb7 -
Reverses byte order (endianness).
OP_REVERSEBYTES0xbc -
64-bit multiplication, division and modulo; numeric opcodes widened to 8 bytes.
OP_MUL / OP_DIV / OP_MOD0x95–0x97
Hashes
Interoperate with other chains and with zero-knowledge circuits.
-
Keccak-256, as used by Ethereum.
OP_KECCAK2560xba -
BLAKE2b.
OP_BLAKE2B0xbb -
BLAKE3.
OP_BLAKE30xc8 -
SHA3-256.
OP_SHA3_2560xca -
SHA-512.
OP_SHA5120xcb -
Poseidon over BN254, the SNARK-friendly hash (NIP-036), with a per-block work budget.
OP_POSEIDON0xc9
Signatures and proofs
Multisig, other curves and zero-knowledge verification.
-
Counts valid signatures for threshold multisig.
OP_CHECKSIGADD0xde -
Verifies an Ed25519 signature.
OP_CHECKSIG_ED255190xdd -
Proves that a leaf belongs to a Merkle root.
OP_CHECKMERKLEINCLUSION0xc1 -
Verifies a Groth16 proof over BN254. AuthScript only; powers the privacy pools.
OP_ZKVERIFY0xc3
Patterns
What you can build
Each pattern below is worked out, script included, in the node's covenant documentation.
Rate-limited vault
A hot key may withdraw at most 1 XNA per block; a recovery key can only send everything to a cold wallet.
On-chain asset swap
A limit order anyone can fill by paying a fixed amount of another asset to the seller in the same transaction.
Recurring payments
A stream that releases a fixed amount per period to one recipient and returns the rest to the covenant.
CTV congestion tree
Commit to many payouts with one output now and expand them later.
Asset reissuance gate
Reissue an asset only under rules written into the owner token's script.
Escrow with timeout
Two of buyer, seller and arbitrator release the funds; after a deadline anyone can refund the buyer.
DePIN payment channel
Pay a device per use, with the channel state enforced on-chain.
Example
A vault that limits theft
A hot key can take at most 1 XNA per block and must send the rest back to the same script; a recovery key can only move everything to a cold wallet. A stolen hot key is worth 1 XNA per block.
// Rate-limited vault (AuthType 0x00: each branch checks its own key)
OP_INPUTCOUNT 1 OP_NUMEQUALVERIFY
OP_IF
<hot_pubkey> OP_CHECKSIGVERIFY
1 OP_CHECKSEQUENCEVERIFY OP_DROP // one withdrawal per block
OP_OUTPUTCOUNT 2 OP_NUMEQUALVERIFY
0 OP_OUTPUTSCRIPT <hot_wallet_script> OP_EQUALVERIFY
0 OP_OUTPUTVALUE 100000000 OP_LESSTHANOREQUAL OP_VERIFY // ≤ 1 XNA
1 OP_OUTPUTSCRIPT 0x03 OP_TXFIELD OP_EQUALVERIFY // change back to the vault
0 OP_INPUTVALUE 0 OP_OUTPUTVALUE OP_SUB <max_fee> OP_SUB
1 OP_OUTPUTVALUE OP_LESSTHANOREQUAL
OP_ELSE
<recovery_pubkey> OP_CHECKSIGVERIFY
OP_OUTPUTCOUNT 1 OP_NUMEQUALVERIFY
0 OP_OUTPUTSCRIPT <cold_wallet_script> OP_EQUAL
OP_ENDIF
Build it in JavaScript
neurai-scripts
@neuraiproject/neurai-scripts has the opcode table, a ScriptBuilder, standard
scripts and ready-made covenants such as partial-fill sell orders.
import { ScriptBuilder, opcodes } from "@neuraiproject/neurai-scripts";
// "Output 0 must pay at least 5 XNA to recipientScript"
const covenant = new ScriptBuilder()
.op(opcodes.OP_0, opcodes.OP_OUTPUTSCRIPT)
.pushHex(recipientScriptHex)
.op(opcodes.OP_EQUALVERIFY)
.op(opcodes.OP_0, opcodes.OP_OUTPUTVALUE)
.pushInt(500_000_000n)
.op(opcodes.OP_GREATERTHANOREQUAL)
.buildHex();
npm install @neuraiproject/neurai-scripts ·
README
Compared
Neurai covenants and other chains
| Feature | Neurai testnet | Bitcoin | Ethereum |
|---|---|---|---|
| CTV (BIP 119) | Integrated | Proposed | Not needed (Turing-complete) |
| CHECKSIGFROMSTACK | Integrated | Proposed | Native (ecrecover) |
| OP_CAT | Integrated | Proposed | Native |
| Transaction introspection | OP_TXHASH and field opcodes | Not available | Native |
| Native asset introspection | 3 opcodes | No native assets | ERC-20 calls |
| Post-quantum authorisation | ML-DSA-44 AuthScript | Not available | Not available |
| Execution model | Script, budgeted | Script | EVM, metered gas |