# Sharing private data with Authentication Witness

**URL:** <https://forum.aztec.network/t/sharing-private-data-with-authentication-witness/2551>\
**Category:** Aztec\
**Created:** [November 17, 2023, 7:09pm UTC](https://forum.aztec.network/t/sharing-private-data-with-authentication-witness/2551 "2023-11-17T19:09:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fouda](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.aztec.network/fouda/32/849_2.png) [@Fouda](https://forum.aztec.network/u/Fouda)\
**Post date:** [November 17, 2023, 7:09pm UTC](https://forum.aztec.network/t/sharing-private-data-with-authentication-witness/2551/1 "2023-11-17T19:09:17Z")

</div>

I am trying to improve my understanding of composability in the Aztec protocol.

I understand that AuthWit allows another account/contract to perform actions on behalf of the user as described here: [Authentication Witness | Privacy-first zkRollup | Aztec Documentation](https://docs.aztec.network/concepts/foundation/accounts/authwit)

My questions are

1. Does this mean that the execution of private functions will be performed by someone else (DeFi contract in the example in the docs)
2. Does the user share the private data for execution? Do they share a specific decryption key and nullifier with the executor to decrypt that private data?

---

<div class="post-metadata">

**Author:** ![Jan](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.aztec.network/jan/32/2727_2.png) [@Jan](https://forum.aztec.network/u/Jan)\
**Post date:** [November 21, 2023, 6:10pm UTC](https://forum.aztec.network/t/sharing-private-data-with-authentication-witness/2551/2 "2023-11-21T18:10:52Z")

</div>

> 1. Does this mean that the execution of private functions will be performed by someone else (DeFi contract in the example in the docs)

All the private execution is hapenning in Private eXecution Environment (PXE) so the execution is “physically” happening on user’s device. What authwit does is that it allows a different contract to initiate execution on behalf of someone else (typically the user’s account contract).

To summarise:

- In a private context authwit allows users to give permission to a contract to initiate a function call on a different contract on behalf of user (user’s account contract) and it’s happening locally on user’s device (in PXE) because private functions work with private state and private state is decrypted only locally (that’s how it stays private, without homomorphic encryption it’s not possible for external parties to perform computation on encrypted data and we don’t support FHE on Aztec yet).
- In a public context the execution is performed by a sequencer.

> 1. Does the user share the private data for execution? Do they share a specific decryption key and nullifier with the executor to decrypt that private data?

It does not have to because as I pointed out in point 1. execution happens on user’s device because executor is user’s PXE.

**Note** : I was simplifying a bit here. There might be a case where user would want to allow a 3rd party to execute a private function on their behalf and when authwit would be used. This scenario might happen during mass emergency exits from L2. But this is an edge case and it does not represent a typical flow. In such a case a user would indeed have to share their decryption key with the 3rd party.

---

<div class="post-metadata">

**Author:** ![Fouda](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.aztec.network/fouda/32/849_2.png) [@Fouda](https://forum.aztec.network/u/Fouda)\
**Post date:** [November 23, 2023, 3:19pm UTC](https://forum.aztec.network/t/sharing-private-data-with-authentication-witness/2551/3 "2023-11-23T15:19:42Z")

</div>

Thanks a lot for the explanation @Jan
