“Complete KYC and you can start on-chain trading”—I’m increasingly skeptical of that claim. Dusk’s Citadel 2 separates access control into credential issuance and zero-knowledge proofs, then hands the decision over to the service provider. The License Provider performs offline verification of the user; after the user signs the attributes, it publishes an encrypted license and registers it to the contract. The user only proves they hold a valid credential—without disclosing personal attributes—and without revealing the details of the specific license.

It’s like entering a members-only vault. The door access panel only shows “credential is valid,” so you don’t need to photocopy your ID. The contract verifies the proof and records the Session; the user gives the Cookie to the Service Provider, and the latter decides whether to grant entry. Dusk makes least disclosure coexist with verifiable access.

The boundaries are very clear. The official documentation explicitly states that cryptography being valid doesn’t mean the policy is in effect. The Service Provider still has to decide which issuers and attributes it trusts, check for expiration or revocation, and restrict Cookie reuse. Even the full JavaScript SDK is still marked as “to be provided.” Citadel 2 provides the technical skeleton—but only whether the issuer is trustworthy, whether the tooling is mature, and whether integration actually happens will determine if it can hold up.

@Dusk_Foundation $DUSK #dusk