Skip to content
Testnet

Protocol

Covenants

A covenant is a script that limits how coins or assets can be spent, not only who can spend them: where they may go, how much, when, and in which form. Neurai's testnet adds 33 new and re-enabled opcodes to Script, active since block 10, so contracts such as vaults, escrows, swaps and payment channels run at the consensus layer without a virtual machine.

Introspection

Scripts read inputs, outputs, values, locktime and chain height.

Asset-native

Covenants see asset names and amounts, not only XNA.

Post-quantum

AuthScript accepts ML-DSA-44 signatures, alone or mixed with ECDSA.

Zero-knowledge

Groth16 verification and Poseidon hashing inside Script.

Execution environment

AuthScript

Covenants are meant to run inside AuthScript, the witness v1 output type (tnc1p… addresses). An AuthScript output is OP_1 <32-byte commitment>; the commitment binds an authentication type (none, ML-DSA-44 or ECDSA) and the hash of the witness script. AuthScript adds:

  • Script trees (NIP-044): several spending branches, only the one used is revealed.
  • Execution budgets (NIP-046): up to 512 operations and 65,536 hash units per execution.
  • Mixed multisig: ECDSA and post-quantum keys in the same threshold.
  • OP_ZKVERIFY, which is only available here.

Each opcode has its own consensus flag, so once active the others also work in Legacy, P2SH and witness v0 scripts.

Reference

The new opcodes

Byte values as defined in src/script/script.h. All are active on testnet from block 10 and unscheduled on mainnet.

Covenant primitives

Commit to how coins may be spent next.

  • OP_CHECKTEMPLATEVERIFY 0xb3
    Requires the spending transaction to match a fixed template (BIP 119).
  • OP_CHECKSIGFROMSTACK 0xb4
    Checks an ECDSA or ML-DSA signature over arbitrary data: oracles and delegation.
  • OP_TXHASH 0xb5
    Hashes the transaction fields chosen by a 16-bit mask (NIP-042).

Input introspection

Read the inputs being spent.

  • OP_TXFIELD 0xb6
    A field of the input being spent, such as its own scriptPubKey: the basis of recursive covenants.
  • OP_INPUTFIELD 0xc4
    A field of any spent input (NIP-043).
  • OP_INPUTVALUE 0xd6
    The value of an input (NIP-024).
  • OP_INPUTCOUNT 0xd0
    How many inputs the transaction has.

Output introspection

Constrain where the coins go.

  • OP_OUTPUTVALUE 0xcc
    The value of an output.
  • OP_OUTPUTSCRIPT 0xcd
    The scriptPubKey of an output.
  • OP_OUTPUTAUTHCOMMITMENT 0xd5
    The AuthScript commitment of an output (NIP-023).
  • OP_OUTPUTAUTHDEST 0xc2
    The destination of an AuthScript output, by family (NIP-041).
  • OP_OUTPUTCOUNT 0xd1
    How many outputs the transaction has.

Transaction and chain context

Time, height and chain identity.

  • OP_TXLOCKTIME 0xc5
    The transaction's nLockTime.
  • OP_CHAINCONTEXT 0xd7
    Block height, median time past or chain id (NIP-026).

Reference inputs

Read an output without spending it (transaction v3, NIP-014).

  • OP_REFINPUTCOUNT 0xd4
    How many reference inputs the transaction carries.
  • OP_REFINPUTFIELD 0xd2
    A field of a reference input: shared state, price feeds, registries.

Native asset introspection

Covenants that understand Neurai assets.

  • OP_OUTPUTASSETFIELD 0xce
    Asset name, amount, units, reissuable flag, IPFS hash, type or message of an output.
  • OP_INPUTASSETFIELD 0xcf
    The same fields for a spent input.
  • OP_REFINPUTASSETFIELD 0xd3
    The same fields for a reference input.

Bytes and arithmetic

Build and parse data on the stack.

  • OP_CAT 0x7e
    Concatenates two stack items.
  • OP_SPLIT 0xb7
    Splits an item at a position.
  • OP_REVERSEBYTES 0xbc
    Reverses byte order (endianness).
  • OP_MUL / OP_DIV / OP_MOD 0x95–0x97
    64-bit multiplication, division and modulo; numeric opcodes widened to 8 bytes.

Hashes

Interoperate with other chains and with zero-knowledge circuits.

  • OP_KECCAK256 0xba
    Keccak-256, as used by Ethereum.
  • OP_BLAKE2B 0xbb
    BLAKE2b.
  • OP_BLAKE3 0xc8
    BLAKE3.
  • OP_SHA3_256 0xca
    SHA3-256.
  • OP_SHA512 0xcb
    SHA-512.
  • OP_POSEIDON 0xc9
    Poseidon over BN254, the SNARK-friendly hash (NIP-036), with a per-block work budget.

Signatures and proofs

Multisig, other curves and zero-knowledge verification.

  • OP_CHECKSIGADD 0xde
    Counts valid signatures for threshold multisig.
  • OP_CHECKSIG_ED25519 0xdd
    Verifies an Ed25519 signature.
  • OP_CHECKMERKLEINCLUSION 0xc1
    Proves that a leaf belongs to a Merkle root.
  • OP_ZKVERIFY 0xc3
    Verifies a Groth16 proof over BN254. AuthScript only; powers the privacy pools.

Patterns

What you can build

Each pattern below is worked out, script included, in the node's covenant documentation.

Rate-limited vault

A hot key may withdraw at most 1 XNA per block; a recovery key can only send everything to a cold wallet.

On-chain asset swap

A limit order anyone can fill by paying a fixed amount of another asset to the seller in the same transaction.

Recurring payments

A stream that releases a fixed amount per period to one recipient and returns the rest to the covenant.

CTV congestion tree

Commit to many payouts with one output now and expand them later.

Asset reissuance gate

Reissue an asset only under rules written into the owner token's script.

Escrow with timeout

Two of buyer, seller and arbitrator release the funds; after a deadline anyone can refund the buyer.

DePIN payment channel

Pay a device per use, with the channel state enforced on-chain.

Example

A vault that limits theft

A hot key can take at most 1 XNA per block and must send the rest back to the same script; a recovery key can only move everything to a cold wallet. A stolen hot key is worth 1 XNA per block.

Script
// Rate-limited vault (AuthType 0x00: each branch checks its own key)
OP_INPUTCOUNT 1 OP_NUMEQUALVERIFY
OP_IF
    <hot_pubkey> OP_CHECKSIGVERIFY
    1 OP_CHECKSEQUENCEVERIFY OP_DROP          // one withdrawal per block
    OP_OUTPUTCOUNT 2 OP_NUMEQUALVERIFY
    0 OP_OUTPUTSCRIPT <hot_wallet_script> OP_EQUALVERIFY
    0 OP_OUTPUTVALUE 100000000 OP_LESSTHANOREQUAL OP_VERIFY   // ≤ 1 XNA
    1 OP_OUTPUTSCRIPT 0x03 OP_TXFIELD OP_EQUALVERIFY          // change back to the vault
    0 OP_INPUTVALUE 0 OP_OUTPUTVALUE OP_SUB <max_fee> OP_SUB
    1 OP_OUTPUTVALUE OP_LESSTHANOREQUAL
OP_ELSE
    <recovery_pubkey> OP_CHECKSIGVERIFY
    OP_OUTPUTCOUNT 1 OP_NUMEQUALVERIFY
    0 OP_OUTPUTSCRIPT <cold_wallet_script> OP_EQUAL
OP_ENDIF

Build it in JavaScript

neurai-scripts

@neuraiproject/neurai-scripts has the opcode table, a ScriptBuilder, standard scripts and ready-made covenants such as partial-fill sell orders.

JavaScript
import { ScriptBuilder, opcodes } from "@neuraiproject/neurai-scripts";

// "Output 0 must pay at least 5 XNA to recipientScript"
const covenant = new ScriptBuilder()
  .op(opcodes.OP_0, opcodes.OP_OUTPUTSCRIPT)
  .pushHex(recipientScriptHex)
  .op(opcodes.OP_EQUALVERIFY)
  .op(opcodes.OP_0, opcodes.OP_OUTPUTVALUE)
  .pushInt(500_000_000n)
  .op(opcodes.OP_GREATERTHANOREQUAL)
  .buildHex();

npm install @neuraiproject/neurai-scripts · README

Compared

Neurai covenants and other chains

FeatureNeurai testnetBitcoinEthereum
CTV (BIP 119)IntegratedProposedNot needed (Turing-complete)
CHECKSIGFROMSTACKIntegratedProposedNative (ecrecover)
OP_CATIntegratedProposedNative
Transaction introspectionOP_TXHASH and field opcodesNot availableNative
Native asset introspection3 opcodesNo native assetsERC-20 calls
Post-quantum authorisationML-DSA-44 AuthScriptNot availableNot available
Execution modelScript, budgetedScriptEVM, metered gas

Read the full specification

doc/covenants.md covers every opcode, its stack contract and limits, the patterns above and the security pitfalls. doc/new-opcodes-depin-branch.md lists byte values, flags and error codes.