The Ethereum Foundation said on Oct. 1 that zkAPI is live on Ethereum mainnet. zkAPI is a payment layer that lets you pay for AI models and other metered APIs without tying the payment to your identity. The Open Anonymity Project built it with the Foundation.
The AI provider still reads your prompts, but it no longer gets the billing identity behind them. In its main runtime-key mode, the payment server sees that you paid, not what you asked.
Key facts
- What it is: a working implementation of ZK API usage credits, a design Davide Crapis and Vitalik Buterin published on Ethereum Research.
- What you pay with: credits deposited into a vault contract on Ethereum. The announcement names ETH and USDC as examples.
- What it hides: the link between your payment and your requests.
- What it does not hide: prompt content, your IP address, and patterns in how you write.
Why AI billing is a privacy problem
Today an API key points to an account, and the account points to a payment method. Every prompt joins that record. The Foundation's post says a provider "can connect years of your usage into a single profile."
The old workarounds were weak, the post says. Paying per request onchain is slow, costly and public. Paying through an intermediary means trusting it not to look.
How a zkAPI payment works

- Deposit once. You put credits into the vault contract in one ordinary Ethereum transaction. Your balance then exists as a private "note" that only you can spend.
- Send a proof. A small client on your device sends the zkAPI server a zero-knowledge proof. A zero-knowledge proof is a way to show a statement is true without revealing the data behind it. Here the statement is, in effect, that a funded note covers this spend and nobody has spent it before. The proof contains no prompt and no identity.
- Get a capped key. The server checks the proof and issues a fresh API key right away. The key is short-lived, capped in dollars, and kept only in your device's memory.
- Talk to the model. Your prompts go straight from your device to the AI provider with that key.
- Pay for actual use. When the key expires, the provider side writes total usage into a signed receipt. The server deducts that amount from your note. The cap was only a reservation.
One proof can cover a whole session, so you are not generating a proof for every call. According to the post, neither side can rewrite the bill afterward.
The client exposes the standard OpenAI and Ollama APIs on your own machine. Existing apps and editors work by pointing them at localhost.
Who sees what

| Party | Learns | Never learns |
|---|---|---|
| zkAPI server | A valid payment exists; total dollars per session | Who you are, what you asked, which deposit paid |
| AI provider | Prompts and responses, since it runs the model | Who is paying |
| Ethereum (public) | Deposits, closes, withdrawals | What any balance paid for |
There is also a simpler proxy mode, where the zkAPI server relays your requests to the provider itself. It is easier to run, but the relay sees your traffic. Runtime-key mode, described above, exists so that no payment intermediary does.
What zkAPI does not hide
The Foundation lists two limits.
Your network. The provider still sees network metadata such as your IP address and can try to link sessions by timing. The zkAPI gateway may also be able to correlate request patterns if you always connect from the same IP address. The post suggests routing through Tor with a fresh circuit for each session.
Your words. If you paste the same personal details, documents or chat history into different sessions, the provider can link them. Your writing style can do the same. The post calls this a privacy-utility tradeoff: standalone questions are more private but less useful.
| Layer | What can leak | Covered by zkAPI? | What the post suggests |
|---|---|---|---|
| Payment | Who paid for which request | Yes | Deposit to the vault, spend with proofs |
| Network | IP address, timing | No | A VPN or Tor; with Tor, a fresh circuit per session |
| Content | Repeated details, style, documents | No | Local or TEE models to write requests; confidential GPU computing is emerging |
Getting your money out, and blocking double spends
Your balance sits in an Ethereum contract, not a company account. The vault verifies proofs at deposit, close and escape, so you can withdraw onchain "even if every zkAPI server disappears," the Foundation says.
Deposits sit in a Merkle tree as commitments, so a zero-knowledge proof can show your note is valid without pointing at it. Every spend also publishes a nullifier. A nullifier is a one-way serial number derived from the note's secret. Spending the same balance twice produces a duplicate nullifier, which exposes the attempt and nothing else. That blocks double spends. The proofs use Groth16 on the BN254 curve, Poseidon hashing and a Merkle tree 32 levels deep.
How to try it
- No install: OA Chat, a private AI chat in the browser.
- Your own apps: run the local gateway and follow the docs to point any OpenAI-compatible app at it.
- Inspect the contracts: the mainnet vault holds USDC credits. A Sepolia deployment runs the same contracts with test funds.
From design to launch
Davide Crapis and Vitalik Buterin published the ZK API usage credits design on Ethereum Research on Feb. 11, 2026. That design used rate-limit nullifiers, under which a double-spender reveals a secret key and can be slashed. The launch post does not mention slashing. It says a duplicate nullifier "exposes the attempt and nothing else." The Foundation announced the mainnet system on Oct. 1, almost eight months after the design post.
Not only for chatbots
The same client and contracts can front any pay-per-use service. The post lists blockchain RPC queries, image and video generation jobs, VPN bandwidth and machine-to-machine services, where agents pay without an account.
Analysis: who benefits today
ZIPMEX's reading of the announcement: by design, zkAPI removes the link between payment and prompts. The announcement cites no security audit, so that rests on the Foundation's description and open-source code. How private you are in practice depends on how you use it. Someone who asks sensitive one-off questions over Tor gets the most separation the post describes. Someone who uploads the same project files every day to the same provider gets much less, because the repeated content lets the provider link those sessions.
Adoption is the open question. For providers, the Foundation says, integrating means accepting a proof instead of an API key and settling signed usage receipts. Pricing, rate limits and infrastructure stay as they are, the Foundation says. The announcement does not name providers that have done this, list fees or give a timeline. The next signal to watch is a major model provider settling zkAPI receipts directly.
Sources: Ethereum Foundation, "Introducing zkAPI" (Oct. 1, 2026) · Ethereum Research design post · zkAPI on GitHub · Open Anonymity Project post on unlinkable inference · ZkApiVault on Etherscan.
ZIPMEX promotes trading on trade.zipmex.com. Promotions are labelled and kept separate from news coverage, which is selected and checked without regard to them.