Format version 1 of the token payment info: the V0 fields plus a shielded payment. The
document action’s token cost is paid out of the token’s shielded pool by shielded_payment
instead of the document owner’s token balance; the identity signing the batch still pays
the credit fee and receives nothing.
A spend bundle in the payment token’s shielded pool that pays a document action’s token
cost. The notes it spends leave the pool: amount of them go where the document type’s
token cost effect sends them (the contract owner’s balance, or out of the supply) and the
change returns to the pool as new notes. The note owner authorizes the spend; the batch
owner still signs the batch and pays its fee in credits.