Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$85,051▲ 0.76%ETH$2,686▼ 0.12%SOL$119.90▲ 1.89%TOTAL CRYPTO$2.9T▼ 1.81%S&P 5007,726.78▲ 0.79%NASDAQ27,212.63▲ 1.27%DOW51,165.35▲ 0.47%GOLD4,168.70▼ 0.80%WTI91.46▼ 1.52%BRENT102.42▲ 0.11%EUR/USD1.1263▼ 0.57%USD/JPY157.81▲ 0.16%DXY101.91▼ 0.18%
Crypto

Ethereum Foundation’s zkAPI Pays for AI Without Your Name

zkAPI went live on Ethereum mainnet, letting users pay for AI models and metered APIs with zero-knowledge proofs instead of an account tied to their identity.

Pexels – Jonathan Borba

The Ethereum Foundation launched zkAPI on Ethereum mainnet, a payment system that lets people pay for AI models and other metered APIs without linking requests to their identity. The Foundation built it with the Open Anonymity Project, an open-source privacy effort, and published the technical documentation alongside a working vault contract on Thursday.

The design answers a problem that has grown sharper with every year of AI adoption. Every API call to a large language model carries an API key, every key points to an account, and every account points to a payment method. The provider can connect years of prompts into a single profile. Early token deployments show a live vault holding USDC, a Sepolia test deployment and a browser-based chat client for private AI conversations.

Why the billing trail matters

People use AI models for things they would not hand to a stranger. Health questions. Financial worries. Drafts of difficult conversations. The Ethereum Foundation’s blog post puts it plainly: using AI under the current model means handing a running transcript of your thinking to whoever holds the billing relationship.

The alternatives so far were weak. Paying per request onchain is slow, expensive, and traceable by anyone on a public blockchain. Trusting a privacy intermediary means trusting an intermediary. zkAPI’s pitch is that neither tradeoff is necessary.

The design draws on “ZK API usage credits,” a proposal posted on Ethereum Research in February by Davide Crapis and Vitalik Buterin. The Foundation’s dAI team turned that research into running code with the Open Anonymity team. The system proves spends with Groth16 on the BN254 curve and hashes commitments with Poseidon, both standard choices in the zero-knowledge field.

How it works

A user deposits ETH or USDC into a vault contract on Ethereum in one ordinary transaction. From that point, the balance exists as a private note that only the depositor can spend and that cannot be traced back to the deposit.

To authorize a spend, software running on the user’s own device produces a zero-knowledge proof saying a funded note covers the spend and has not been spent before. The server can verify the statement without learning which note, which deposit or which person made it.

The flow runs in four steps. The user’s app talks to a small client on their own machine, which speaks the standard OpenAI and Ollama formats, so existing editors and chat tools work unchanged. The client sends the zkAPI server a proof of payment with no prompt and no identity attached. The server checks the proof and mints a fresh, short-lived API key capped in dollars, which exists only in the device’s memory. Prompts then go straight from the user’s device to the AI provider with that key.

Two pieces of cryptography keep the arrangement safe. Deposits sit as commitments in a Merkle tree, so a proof can show a note is valid without pointing at any particular one. Every spend publishes a nullifier, a one-way serial number derived from the note’s secret. A user who spends within their balance stays unlinkable. A double-spend attempt produces a duplicate nullifier, exposing the attempt and nothing else.

One proof can cover a whole session of requests. When the key expires, the provider records the key’s usage in a signed receipt and the server deducts that amount from the note. Neither side can rewrite the bill afterward.

What each party learns

Party Learns Never learns
zkAPI server A valid payment exists, total dollars per session Who the payer is, what was asked, which deposit paid
AI provider Prompts and responses Who is paying
Ethereum public chain Deposits, closes, withdrawals What any balance paid for

The vault is a contract on Ethereum rather than a company account. Users can close their balance and withdraw onchain even if every zkAPI server disappears. A simpler proxy mode exists that relays requests to the provider, but the relay sees traffic, which is why the runtime-key mode is the default offering.

Runs today, limits acknowledged

The Foundation is direct about what zkAPI does not fix. The team’s documentation names two blind spots. Network anonymity is not included, so a gateway could correlate request patterns from a user sending requests from a stable IP address. The Foundation suggests routing through Tor with a fresh circuit per session for users who need network privacy.

Prompt contents can also leak. A provider reading prompts can re-link sessions if the same personal details, writing style or reused conversation history show up. Standalone queries are more private but less useful, since past context is missing. The Open Anonymity project suggests using local or trusted-execution models to generate requests from shared memory as one mitigation.

Providers have little to change on their side. Integrating means accepting a proof instead of an API key and settling signed usage receipts instead of maintaining accounts. Pricing and rate limits stay as they are.

The practical use cases are wider than AI chat. The same client and contracts can front any service that charges per use: blockchain RPC queries, image and video generation jobs, VPN connections, and machine-to-machine payments where an agent pays per task without holding an account anywhere.

For Ethereum, zkAPI is part of a broader push by the Foundation’s AI team to position the network as settlement infrastructure for machine commerce rather than only a ledger for trading tokens. Whether the privacy layer attracts real usage depends on providers accepting proofs at scale, which no major AI lab has committed to yet. But the plumbing now exists, and it is live on mainnet.

SourcesEthereum Foundation blog, October 1, 2026; The Block; KuCoin News; Open Anonymity project documentation.
Share: X