Skip to main content
Use this page after choosing a backend to see how that choice flows through Stoffel.toml, CLI flags, Rust SDK builders, bytecode metadata, local execution, and network/client configuration. If you need the app-level input, execution, and output flow, use MPC Integration. For backend selection guidance, start with MPC Backends. For advanced evaluation of the implementation selected by this configuration, use the phase-specific security model, protocol cost reference, and protocol-to-paper map in the MPC Protocols tab. Stoffel records the selected MPC backend in the compiled program and carries it through the CLI, Rust SDK, VM, and network/client layers.

End-to-end path

Networked MPC runtime diagram separating the application boundary, coordinator control plane, and symbolic MPC party mesh, with party-local preprocessing and client-side output reconstruction. At runtime, clients submit protected inputs, the coordinator manages session lifecycle and routing metadata, and the parties execute the VM while exchanging backend-specific protocol messages. Output shares return to the authorized client for reconstruction; the coordinator is not drawn as the computation or reconstruction endpoint. The important invariant is that the compiled bytecode and the runtime agree on:
  • backend: HoneyBadgerMPC or AVSS;
  • curve/field where applicable;
  • parties and threshold;
  • client input/output schemas;
  • preprocessing demand for operations such as multiplication and randomness.

Backend selectors

At the SDK level, backend selection is represented as:
At the CLI/config level, the accepted string selectors are:
--field / curve = "..." sets the AVSS curve. HoneyBadgerMPC does not take a curve selector in the SDK config; it uses the field configuration expected by the HoneyBadger path.

Backend-specific protocol constraints

Choose topology according to the selected backend’s protocol constraint: HoneyBadgerMPC’s stronger party requirement comes from correcting up to t bad evaluations while reconstructing degree-2t values during preprocessing: 2t + 2t + 1 = 4t+1. AVSS verifies degree-t Feldman shares before interpolation and uses 3t+1 for Byzantine quorum intersection, but introduces public commitments and curve-group work. SDK summaries also expose the minimum reconstruction shares:

Bytecode manifest

The .stflb manifest stores backend metadata so a runtime can reject mismatched execution settings early.
StoffelLang compilation writes this metadata from compiler options. The CLI and SDK set those options from project config or builder overrides.

Local MPC execution

stoffel run, stoffel dev, and SDK .execute_local().await? run the compiled program against a local MPC test network on the developer machine. The local runner receives:
  • the compiled program;
  • entrypoint name;
  • backend kind;
  • curve config;
  • parties and threshold;
  • ClientStore inputs and expected output-client metadata.
This lets the same source program be checked against HoneyBadgerMPC or AVSS by changing backend configuration instead of changing application code.

Network and off-chain client execution

The Rust SDK can generate network deployment configs and build client/server handles. Backend selection is part of those configs:
AVSS can be selected in the same builder:
The current SDK off-chain client I/O path supports HoneyBadgerMPC and AVSS over bls12_381. Other AVSS curves are still selectable for bytecode/runtime paths and curve-aware StoffelLang protocol examples; validate the specific client/network path you plan to use.

VM boundary

The VM does not expose different application syntax for each backend. Secret-register operations and builtins yield backend-specific work through the MPC runtime: This separation lets developers write StoffelLang around secret T, Share, ClientStore, Mpc, and MpcOutput while selecting the backend in config.

Backend-specific notes

HoneyBadgerMPC

HoneyBadgerMPC share data is field-oriented and supports the general arithmetic path. Its local/network execution path uses robust field-share reconstruction and preprocessing for multiplication-heavy workloads.

AVSS

AVSS share data can carry Feldman commitment material. StoffelLang exposes AvssShare helpers and Share.get_commitment(...) when the output boundary needs public commitments, curve-encoded values, or scalar responses. Curve selection matters because scalar-field and group encodings must match the external verifier or protocol boundary.

Troubleshooting

See also