Skip to main content
Stoffel separates application code from the MPC protocol used to run it. The selected backend determines how secret values are shared, computed over, and reconstructed across MPC parties. Stoffel currently supports two MPC backend families: The backend choice determines which share representation, curve/field, preprocessing, and client I/O path Stoffel records in the bytecode manifest. Security and completion guarantees differ between preprocessing and online execution. See Security and fault model before treating the configured threshold as an end-to-end Byzantine-security guarantee.
mpc-protocols has received an external audit from Zellic. Audit scope matters: validate the specific protocol version, integration code, deployment configuration, and threat model you rely on. Other Stoffel components have also had AI-assisted security review, including tools such as veria.dev. Treat audit and review coverage as component-scoped when evaluating a deployment.

Choose by workload shape

Start from the shape of the secret work, not the name of the application. Backend-selection diagram comparing HoneyBadgerMPC and AVSS by representation, preprocessing, application boundary, and deployment topology. This comparison is about the application boundary as well as protocol internals. HoneyBadgerMPC accepts general field-compatible values. AVSS exposes a scalar-and-curve-oriented boundary in which commitments and group encodings may be public protocol artifacts.

Security and cost reference

Topology depends on the backend: HoneyBadgerMPC requires n >= 4t+1, while AVSS requires n >= 3t+1. These constraints do not by themselves guarantee preprocessing availability, fairness, or output delivery under arbitrary delays. Use the backend-specific parameter table and security matrix, protocol costs, and paper map to evaluate your deployment. Select AVSS with a specific curve:
You can also keep backend = "avss" and set the curve separately:
Accepted curve names include bls12_381, bn254, curve25519, ed25519, secp256k1, and p-256.

Select a backend from the CLI

stoffel check, stoffel compile, stoffel build, stoffel run, and stoffel dev accept the same backend/field overrides when they compile source or project settings.

Select a backend from Rust

On program builders, use .backend(...) or .curve(...):
Generated manifests can carry the bytecode backend and curve into SDK builders, so app code does not need to duplicate backend literals by hand.

Topology constraints

With threshold one, this means five HoneyBadgerMPC parties or four AVSS parties. HoneyBadgerMPC needs the extra party because its preprocessing reconstructs degree-2t values while correcting up to t errors. AVSS verifies degree-t shares against public commitments and uses 3t+1 Byzantine quorum intersection. Its lower party count comes with public commitments and group-operation costs; it is not a drop-in replacement for private application arithmetic.

Further reading