Private Network Auditor Explorer
The Private Network Auditor Explorer is a web interface for searching and inspecting the cross-chain transactions of a Rayls Private Network, decrypted. The Private Network operator runs it alongside its governance services. Its own title is "Rayls Auditor Explorer", and its code is rayls-sovereign-pnh-auditor-ui.
It shows what crosses the Private Network Hub: arbitrary messages, Enygma transfers and delivery-versus-payment (DvP) operations, with addresses and amounts in clear. It can't show transactions that stay inside one Rayls Sovereign chain (Privacy Node in the code), because they never reach the Hub.
Where the data comes from
The Auditor Explorer has no keys and does no decryption itself. It reads the governance API's /audit/transactions endpoints. The governance listener has already decrypted the Hub's traffic with the operator's view key and the participants' view keys, which every participant escrows to the operator when it joins. See Monitoring cross-chain transactions and Who sees what.
Who can see it
The Auditor Explorer has no login and no roles. Anyone who can open it sees every decrypted cross-chain transaction in the network, and so does anyone who can reach the governance API behind it.
- It is the operator's tool. Participants don't get access to it unless the operator gives it to them, and if they get access, they see everyone's transactions, not only their own.
- An auditor or regulator gets access the same way, and sees the same data. There is no scoped or partial view.
- Access control is up to the operator's deployment: run it, and the governance API, on a network the operator controls, behind whatever authentication the operator requires.
Pages
| Route | Page | What it shows |
|---|---|---|
/ | Latest Transactions | The most recent cross-chain transactions, newest first, and a search bar |
/message/{id} | Message Details | One transaction |
/batch/{id} | Batch Details | The transactions in a batch of messages, ten to a page |
/enygma/{id} | Enygma Details | The transfers in one Enygma transaction |
/dvpSwap/{id} | Swap Details | Both sides of a DvP swap |
Latest Transactions
Each row shows the protocol, the ID, the time, the source chain ID and the source address. The protocols include Custom (arbitrary message), Enygma, DvP Deposit, DvP Withdraw and DvP Swap.
To search, choose a field, type a value and select Add Filter. The fields are message ID, source chain ID, source address, destination chain ID, destination address and resource ID. Filters combine, and each one shows as a tag you can remove.
Selecting a row opens the page for that kind of transaction.
Message Details
For one transaction, the page shows the fields that apply:
- message ID;
- the Hub transaction hash, block number and timestamp;
- the source and destination transaction hashes and timestamps, and, if the transfer failed and was reversed, the reversing transaction's hash and timestamp;
- status, where the transaction has one;
- source and destination chain IDs, and from and to addresses;
- resource ID and message type;
- for tokens: amount, token symbol, protocol and token ID, with the token's metadata image and traits if it has them;
- for arbitrary messages: the decrypted payload, in hexadecimal.
Enygma Details
An Enygma transaction on the Hub can carry many client payments. This page lists them, decrypted, ten to a page: message ID, time, source chain and sender address, destination chain and receiver address, amount and token.
Swap Details
For a DvP swap, identified by its shared ID, the page shows the swap's status (pending, completed, cancelled, expired or failed), its Hub transaction hash and protocol, and then each side: the token name and symbol, chain IDs, from and to addresses, resource ID, amount or token ID, and source and destination transaction hashes.
What it doesn't show
- Participants, tokens, freezes, balances and flags. These are in the governance API only. See Monitoring cross-chain transactions and Flagging transactions.
- Anything the operator can change. The Auditor Explorer only reads.
Running it
The Docker image serves the app with nginx on port 80. Set RAYLS_API to the governance API's base URL; at start-up it is written into the app's assets/config.json. The image's nginx also forwards /api/ to http://governance-api:8080/, so when both run on the same Docker network, RAYLS_API=/api works.
docker run -p 8181:80 -e RAYLS_API='http://<governance-api>' rayls-auditor-explorerIn the local stack started with ./rayls init --full, the Auditor Explorer is at http://localhost:8181.
Updated about 2 hours ago
