# Introduction to o1js

> o1js is a general-purpose zk framework with the tools to create zk proofs. o1js is a TypeScript library for writing general-purpose zk programs and writing zk smart contracts for Mina.

Canonical URL: https://docs.minaprotocol.com/zkapps/o1js/

:::info

To protect end users and ensure your zkApps are secure, consider the information at [Security and zkApps](/zkapps/writing-a-zkapp/introduction-to-zkapps/secure-zkapps) while architecting your solution and consider a third-party security audit before deploying to Mina mainnet.

:::

# Introduction to o1js

o1js is a TypeScript library for:

- Writing general-purpose zero knowledge (zk) programs
- Writing zk smart contracts for Mina

This is TypeScript code that you might write when using o1js:

```ts


function knowsPreimage(preimage: Field) {
  let hash = Poseidon.hash([preimage]);
  hash.assertEquals(expectedHash);
}

const expectedHash =
  0x1d444102d9e8da6d566467defcc446e8c1c3a3616d059facadbfd674afbc37ecn;
```

In a zkApp, this code can be used to prove that you know a secret value whose hash is publicly known without revealing the secret.
The code is plain TypeScript and is executed as normal TypeScript. You might call o1js an _embedded domain-specific language (DSL)_.

o1js provides data types and methods that are _provable_: You can prove their execution.

In the example code, `Poseidon.hash()` and `Field.assertEquals()` are examples of provable methods. Proofs are _zero knowledge_, because they can be verified without learning their inputs and execution trace. Selected parts of the proof can be made public, if it suits your application.

o1js is a general-purpose zk framework that gives you the tools to create zk proofs. It lets you write arbitrary zk programs leveraging a rich set of built-in provable operations, like basic arithmetic, hashing, signatures, boolean operations, comparisons, and more. Use the o1js framework to write zkApps on Mina, smart contracts that execute client-side and have private inputs.

All of the o1js framework is packaged as a single TypeScript library that can be used in major web browsers and Node.js. The best way to get started with o1js is [using the zkApp CLI](/zkapps/writing-a-zkapp/introduction-to-zkapps/how-to-write-a-zkapp). You can also install o1js from npm with `npm i o1js`.

Start your o1js journey by learning about [basic zk programming concepts](/zkapps/o1js/basic-concepts).

## Advanced o1js topics

These topics are maintained by o1Labs alongside the library itself and have no
counterpart in these docs. Follow the links for the current material.

- [Native prover](https://docs.o1labs.org/o1js/advanced-concepts/native-prover) —
  the native proving backend introduced in o1js 2.15.0, and when to use it.
- [Serialization](https://docs.o1labs.org/o1js/advanced-concepts/serialization) —
  serializing provable types and proofs.
- [Side-loaded verification keys](https://docs.o1labs.org/o1js/advanced-concepts/sideloaded-vks) —
  verifying proofs whose verification key is supplied at run time.
- [Analyzing constraint systems](https://docs.o1labs.org/o1js/writing-constraint-systems/analyzing-constraint-systems) —
  measuring and profiling the size of a circuit.
- [ZkProgram](https://docs.o1labs.org/o1js/writing-constraint-systems/zk-program) and
  [ZkProgram proofs](https://docs.o1labs.org/o1js/zkapps/zkprogram-proofs) —
  writing provable programs outside a `SmartContract`.

For the full o1js API, see the
[o1js API reference](https://docs.o1labs.org/o1js/api-reference/Introduction).

## Audits of o1js

* [**Veridise external audit (Q3 2024)**](https://github.com/o1-labs/o1js/blob/a09c5167c4df64f879684e5af14c59cf7a6fce11/audits/VAR_o1js_240318_o1js_V3.pdf).  We engaged Veridise, a security auditing company, to do a full audit of o1js version 1.  Veridise spent 39 person-weeks reviewing o1js in depth, and all issues of medium severity and higher were fixed.

* [**Internal audit (Q1 2024)**](https://github.com/o1-labs/o1js/files/15192821/Internal.o1js.audit.Q1.2024.pdf). In March 2024, the o1js team spent roughly two person-weeks to conduct an internal audit of parts of the o1js code base. The audit focused on reviewing core provable code. A number of issues were found and fixed.

Please see our page on [Security and zkApps](/zkapps/writing-a-zkapp/introduction-to-zkapps/secure-zkapps) for more information on ensuring your zkApp is secure.
