Proof-of-Backtest. Turn a (spec, data) pair into a deterministic backtest report and a canonical blake3 hash that anyone can recompute byte-for-byte in ten languages.
▶ Live demos: the backtester compiled to WebAssembly, an equity curve building bar by bar — backtest-live.wickra.org; one StrategySpec side by side in Python, Rust, JS and Go — playground.wickra.org; all 514 indicators of the core over a real Binance feed — live.wickra.org. Zero backend, all of them.
Part of the Wickra ecosystem: the same data-driven core and ten-language binding surface also power wickra-exchange, wickra-backtest, wickra-terminal and 20 more — see the full list.
wickra-proof is a thin, deterministic layer over the Wickra backtest engine.
Given a strategy spec and candle data it produces a BacktestReport and a
report_hash (blake3 over a canonical serialization). The same core logic is
callable from Rust, Python, Node.js, WASM, C, C++, C#, Go, Java and R over a
single JSON-over-C-ABI boundary, so the hash is identical everywhere — that
identity is the proof.
Stop trusting backtest screenshots. A screenshot proves nothing: numbers can be
typed, curves can be drawn. A wickra-proof claim ships the spec, the data
commitment, the report and the hash — anyone, in any supported language,
recomputes the hash and either matches it or doesn't. This is the foundation for
fund transparency, reproducible research and higher-order tools
(wickra-verify,
wickra-zk).
use wickra_proof_core::{prove, verify, ProofSpec};
// A ProofSpec is the strategy and a dataset reference; the candles are
// supplied beside it. `prove` folds the two into a report and its hashes.
let spec = ProofSpec::from_json(spec_json)?;
let proof = prove(&spec, &candles_by_symbol)?;
println!("report_hash: {}", proof.report_hash);
// Anyone with the same spec and data recomputes the same bytes, in any of
// the ten languages -- and a proof that does not recompute is not valid.
assert!(verify(&proof, &spec, &candles_by_symbol)?);The same two calls from the command line, over the spec and candles shipped
in examples/data:
cargo run -p wickra-proof-cli -- prove \
--spec examples/data/config.json \
--data examples/data/candles/AAA.csv \
--format json
cargo run -p wickra-proof-cli -- verify \
--proof examples/data/config.proof.json \
--spec examples/data/config.json \
--data examples/data/candles/AAA.csv0.1.3 — the current release. The core
(wickra-proof-core), the CLI, all ten language
bindings, the byte-exact golden corpus, property + fuzz tests, benchmarks and
one runnable example per language are in place and green across the full CI
matrix (10 languages × 3 OS). Track progress in ROADMAP.md.
- Architecture — the core, the canonicalization boundary, the binding surface.
- Deep dives in
docs/: Architecture internals · Canonicalization (normative) · Proof format · Verifying a foreign proof. - ROADMAP.md · BENCHMARKS.md · THREAT_MODEL.md · SECURITY.md.
- Canonical JSON before hashing: keys sorted at every depth (
BTreeMap), floats quantized to1e-8by pure decimal rounding ({:.8}, trailing zeros trimmed, whole values collapsed to their integer token so a host language's1.0-vs-1ambiguity can never shift the hash), no whitespace, and noNaN/±inf(rejected at parse time). - No RNG, fixed float operation order — the same inputs always reduce to the same bytes.
engine_versionpinned and embedded — a different backtest engine version produces a different, visibly-labelled hash by design.- Any divergence of
report_hashbetween two languages or two runs is a bug, caught by the byte-exact golden corpus and the canonicalize fuzz target.
--spec takes a config file ({ "spec": <ProofSpec> }); --data a CSV or a
directory of <SYMBOL>.csv files. prove prints the BacktestReport and its
report_hash; verify re-runs the proof against the same spec and data and
prints valid only if the recomputed hash matches the claimed one. Tamper
with a single field of the proof and verification fails.
A proof carries everything a third party needs to reproduce it:
spec— the strategy definition (ProofSpec): indicators, rules and parameters, plus the pinnedengine_version.- data commitment — a hash of the candle series the report was computed over.
report— the resultingBacktestReport(metrics, equity, trades).report_hash— the blake3 of the canonical serialization of the report.
Because the spec and the data commitment travel with the report, a verifier never has to trust the prover: it recomputes and compares.
The hash is only as trustworthy as the serialization it runs over, so
canonicalization is the load-bearing contract every binding reproduces exactly
(see crates/wickra-proof-core/src/canonical.rs):
- Object keys sorted ascending by Unicode code point.
- No structural whitespace.
- Floats quantized to
1e-8by decimal rounding, trailing zeros trimmed, whole values collapsed to their integer token; magnitudes at or above the point where the f64 ULP reaches the1e-8grid fall back to the shortest round-trippable form so canonicalization stays a fixed point. NaN/±infcannot occur.- Arrays keep their order; strings use the standard JSON escaping.
blake3 over that canonical string yields the 64-hex report_hash. The
canonicalize fuzz target pins the fixed-point property (canonicalize → parse → canonicalize yields identical bytes) across the full finite f64 range.
Any supported language can verify a proof produced by any other — that is the
whole point. Each binding exposes the same JSON-over-C-ABI command surface
(prove / verify), returns the core's canonical response verbatim, and the
cross-language golden tests assert byte-for-byte equality. A proof minted in
Python verifies in Go; a proof minted in Rust verifies in the browser over WASM.
engine_version is embedded in the spec and folded into the report, so a proof
is bound to the exact backtest semantics that produced it. Upgrade the engine and
the same (spec, data) produces a different, clearly-labelled hash — divergence
is surfaced, never hidden.
The core is a JSON-over-C-ABI data API (Prover::command) exposed natively in
Rust, Python, Node.js and WASM, and over the C ABI hub in C, C++, C#, Go, Java
and R. One runnable example per language lives under examples/; the
per-binding quickstarts are in each bindings/<lang>/README.md.
crates/wickra-proof-core the library: canonicalize + prove + verify
crates/wickra-proof-cli reference CLI (prove / verify), binary `wickra-proof`
crates/proof-bench Criterion benchmarks
bindings/{c,python,node,wasm,go,csharp,java,r} ten-language surface
golden/ fixed (spec, data) -> expected (report, hash)
examples/ runnable per-language demos
fuzz/ cargo-fuzz targets (spec parse, canonicalize, prove, verify)
cargo build --workspace
cargo test --workspace --all-features
cargo clippy --workspace --all-targets --all-features -- -D warningsEach binding builds from its own directory — see the per-binding READMEs under
bindings/.
Run the suites with the commands in Building everything from source.
wickra-proof-core— unit tests for canonicalization (key ordering, float quantization, whitespace), the prove/round-trip path, tamper detection, and the engine-version pin. The golden fixtures ingolden/are the anchor: the same(spec, data)pair must fold to the same canonical bytes and the same blake3 hash here as in every binding.- Every binding asserts the same golden bytes. That is the whole
cross-language claim, so it is checked the same way in each one rather than
approximated per language: Python with pytest, Node with
node --test, WASM withwasm-bindgen-test, C and C++ throughctest, C# withdotnet test, Go withgo test, Java with JUnit, and R with the shippedtests/smoke.Rplus the repository-leveltests/run_tests.R. fuzz/— libfuzzer targets over the JSON boundary, run as a time-boxed smoke in CI. The goal is catching a regression in the harness, not discovering novel bugs; long campaigns belong on dedicated infrastructure.- Repository checks —
scripts/check_version_sync.py,check_license_copies.pyandcheck_readme_links.pyrun in CI and assert what the repository ships rather than what it computes.
- Rust — workspace MSRV 1.86 (the Node binding needs 1.88).
- Optional per binding: Python 3.9+, Node.js 22+, a C toolchain + CMake, .NET 8 SDK, JDK 22+, Go 1.23+, R ≥ 4.1.
Criterion benchmarks live in crates/proof-bench and run
nightly in CI; see BENCHMARKS.md.
Part of the Wickra family — each one a data-driven core with a CLI and the same ten-language binding surface:
- wickra — main library (Rust core + Python / Node.js / WASM bindings + a C ABI for C / C++ / C# / Go / Java / R)
- wickra-playground — a polyglot strategy playground: one StrategySpec live side by side in Python, Rust, JS and Go, entirely in the browser
- wickra-exchange — unified market-data + execution across ten crypto exchanges
- wickra-backtest — event-driven backtester over the Wickra core
- wickra-terminal — the trading terminal: a TUI and a browser renderer over the stack
- wickra-screener — parallel multi-symbol screening over 514 streaming indicators
- wickra-radar — perp-universe alert radar: OI delta, funding flip, book imbalance, liquidation clusters, OI/price divergence
- wickra-copilot — local market copilot grounded in real order-book, liquidation and funding microstructure
- wickra-shazam — match an asset's current microstructure fingerprint against its entire history
- wickra-benchmark — reproducible, golden-verified benchmark suite — recompute any (strategy, dataset, report) in ten languages and confirm it byte-for-byte
- wickra-strategy-ci — Jest for trading strategies: golden-pin the report, catch regressions in CI, property-test against fuzzed data
- wickra-verify — confirm or refute a claimed backtest report against its strategy and data, in ten languages
- wickra-proof — Proof-of-Backtest: deterministic (spec, data) → report + blake3 hash, recomputable byte-for-byte in ten languages
- wickra-zk — prove a backtest zero-knowledge — on-chain-verifiable performance without revealing the data or the strategy
- wickra-impact — the backtester that knows you would have moved the market: agent-based fills on the real historical L2 order book
- wickra-darwin — evolutionary strategy search at millions of backtests per second, mutating and crossing JSON specs across the 514-indicator space
- wickra-gym — a Gymnasium-compatible, microstructure-aware backtest environment with O(1) steps for deterministic RL rollouts
- wickra-feature-store — OHLCV and microstructure streams into ML-ready feature matrices over 514 O(1) streaming indicators
- wickra-genome — a vector database of the whole market: every asset a 514-dim live vector, for similarity search, clustering and anomaly detection
- wickra-timemachine — scrub the whole market like a video — every symbol, full order book, rewound to any moment via deterministic re-fold
- wickra-synth — deterministic synthetic market microstructure: OHLCV, order book, trades and funding from a single seed
- wickra-compile — compile a strategy spec into a standalone deployable: a WASM module, a self-contained binary, or a
no_stdartifact - wickra-embed — allocation-free,
no_stdstreaming indicators for bare-metal and HFT, byte-for-byte identical to the core - wickra-pico — the O(1) indicator core running bare-metal on a $5 Raspberry Pi Pico — the LED blinks on the EMA cross
Docs at docs.wickra.org; the marketing site and in-browser demo at wickra.org.
See CONTRIBUTING.md. All commits are signed and DCO-signed off; CI must be green across every language before merge.
Report vulnerabilities per SECURITY.md. The trust model — what a proof does and does not guarantee — is in THREAT_MODEL.md.
Licensed under either of
- Apache License, Version 2.0 (LICENSE-APACHE or http://www.apache.org/licenses/LICENSE-2.0)
- MIT license (LICENSE-MIT or http://opensource.org/licenses/MIT)
at your option. Use it, fork it, modify it, redistribute it — commercially or not — file issues, send pull requests; all welcome.
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.
wickra-proof is research and engineering tooling, not financial advice. A proof
attests only that a given report is the deterministic result of a given spec over
given data — it makes no claim about the quality, profitability or future
performance of any strategy. Trading carries risk; you are responsible for your
own decisions.
Built on Wickra. If it saved you time, the cheapest way to say thanks is to ⭐ the repo.
