Skip to content

LibraryConfidential compute2022Design paperCorpus record

Noir: a language that compiles to a constraint system

Noir language. Aztec.

Noir publishes a language for writing programs that compile to constraints a proving backend can prove. The language is not the backend.

A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.

Noir publishes a language for writing programs that compile to constraints a proving backend can prove. The language is not the backend.
Evidence
Primary paper
Re-measured
No
Assumptions
3
Records linked
2

01 Claim ledger

What the paper is allowed to say

Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.

  1. Claim 01 · Paper model

    The defect

    A circuit language feels like ordinary code. The constraint system it emits is the object a verifier checks, and the two can diverge if the compiler is wrong.

  2. Claim 02 · Paper model

    The proposal

    Noir publishes a language for writing programs that compile to constraints a proving backend can prove. The language is not the backend.

  3. Claim 03 · Paper model

    The mechanism

    The programmer writes Noir. The compiler produces an intermediate constraint system. A backend, which might be Barretenberg or another prover, produces the proof.

  4. Claim 04 · Paper model

    The bound

    This note does not say Noir proofs are verified on any particular chain.

02 Three cuts

Observation, model, falsifier

A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.

  1. 01 The defect

    Observation

    What the study says

    A circuit language feels like ordinary code. The constraint system it emits is the object a verifier checks, and the two can diverge if the compiler is wrong.

    Model

    What has to hold

    You are reading Noir's documentation. Aztec's protocol is a different document that may use this language.

    Falsifier

    What would retire it

    Is the verifier checking Noir source, or an artefact the compiler emitted?

  2. 02 The proposal

    Observation

    What the study says

    Noir publishes a language for writing programs that compile to constraints a proving backend can prove. The language is not the backend.

    Model

    What has to hold

    You are reading Noir's documentation. Aztec's protocol is a different document that may use this language.

    Falsifier

    What would retire it

    Which backend verifies the program you mean?

  3. 03 The mechanism

    Observation

    What the study says

    The programmer writes Noir. The compiler produces an intermediate constraint system. A backend, which might be Barretenberg or another prover, produces the proof.

    Model

    What has to hold

    No price, supply, yield, or adoption figure is added by this desk.

    Falsifier

    What would retire it

    Which backend verifies the program you mean?

  4. 04 The bound

    Observation

    What the study says

    This note does not say Noir proofs are verified on any particular chain.

    Model

    What has to hold

    You are reading Noir's documentation. Aztec's protocol is a different document that may use this language.

    Falsifier

    What would retire it

    Which backend verifies the program you mean?

03 Sequence

One action, as an operating tape

  1. 01The programmer writes Noir. The compiler produces an intermediate constraint system. A backend, which might be Barretenberg or another prover, produces the proof.
  2. 02Changing backends is possible only if both accept that intermediate form. The proof objects are not automatically the same.
  3. 03Private inputs and public inputs are a distinction the language forces you to write down. That distinction is the application's privacy claim.

04 Load-bearing

The argument, and where a pitch drops it

  1. What the name has to mean

    The cut

    Noir publishes a language for writing programs that compile to constraints a proving backend can prove. The language is not the backend.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A backend bug and a compiler bug are different failures.

  2. What actually moves

    The cut

    Changing backends is possible only if both accept that intermediate form. The proof objects are not automatically the same.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A later client, parameter or reward formula is a different object from this paragraph.

  3. What a later deployment may change

    The cut

    Private inputs and public inputs are a distinction the language forces you to write down. That distinction is the application's privacy claim.

    Why it carries weight

    If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.

    Where it is dropped

    A later client, parameter or reward formula is a different object from this paragraph.

05 Register

What has to be true

  • Model · Not re-measured

    You are reading Noir's documentation. Aztec's protocol is a different document that may use this language.

  • Model · Not re-measured

    The document is the one at the source URL. A marketing page with the same brand is not this text.

  • Model · Not re-measured

    No price, supply, yield, or adoption figure is added by this desk.

06 Divergence

What happened after the paper

Noir is not Cairo, though both are circuit languages.

A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.

07 Pre-mortem

What to check before you use the idea

  1. 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.

08 Anatomy

The paper, in the order a builder needs

The problem it names

A circuit language feels like ordinary code. The constraint system it emits is the object a verifier checks, and the two can diverge if the compiler is wrong.

What the design proposes

  • The programmer writes Noir. The compiler produces an intermediate constraint system. A backend, which might be Barretenberg or another prover, produces the proof.
  • Changing backends is possible only if both accept that intermediate form. The proof objects are not automatically the same.
  • Private inputs and public inputs are a distinction the language forces you to write down. That distinction is the application's privacy claim.

How the mechanism is specified

  • The programmer writes Noir. The compiler produces an intermediate constraint system. A backend, which might be Barretenberg or another prover, produces the proof.
  • Changing backends is possible only if both accept that intermediate form. The proof objects are not automatically the same.
  • Private inputs and public inputs are a distinction the language forces you to write down. That distinction is the application's privacy claim.

What this page does not treat as proven

  • This note does not say Noir proofs are verified on any particular chain.
  • A backend bug and a compiler bug are different failures.
  • Noir is not Cairo, though both are circuit languages.

Why the desk still reads it

Noir publishes a language for writing programs that compile to constraints a proving backend can prove. The language is not the backend.

09 Lexicon

Terms, opened into the record

Backend
The prover and verifier that consume the compiler's output.
Public input
A value the verifier sees. A private input is the opposite, and the circuit must mark it.

10 Repository

Every linked record on this page

Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.