Ethereum's zkAPI Goes Live: How Zero-Knowledge Proofs Are Decoupling AI Payments From Identity

Ethereum's zkAPI launched Oct 1 on mainnet, enabling anonymous prepaid API credits with ZK proofs for metered AI—ETH and USDC supported.

7 min read

When the Ethereum Foundation published its zkAPI announcement on October 1, 2026, the headline was deceptively simple: pay for metered APIs without being known. Behind that sentence sits a full protocol stack—vault contracts on Ethereum mainnet, browser-based Groth16 provers, note-bound state transitions, and a billing server that can verify spending authority without learning which deposit funded a request. Built by the Open Anonymity Project in collaboration with the Foundation, zkAPI is now the working implementation of research that Ethereum co-founder Vitalik Buterin and dAI lead Davide Crapis published earlier in 2026 under the title "ZK API Usage Credits."

The timing matters. AI inference has become a metered utility: every chat completion, embedding call, and tool invocation carries a marginal cost. Traditional billing ties those requests to accounts, credit cards, API keys, and persistent identifiers. For developers experimenting with sensitive prompts, for users in jurisdictions with uneven data protections, and for anyone who simply does not want their payment history stitched to their queries, that linkage is the privacy problem zkAPI targets. It does not promise perfect anonymity—more on that below—but it does introduce a cryptographic separation between who paid and what was asked.

From research paper to mainnet vault

The intellectual lineage of zkAPI begins in Ethereum Research forums, where Crapis and Buterin outlined a model for prepaid API credits backed by on-chain deposits and spent through zero-knowledge proofs. The design goal was narrow and precise: the API provider should see requests; the payment infrastructure should see spend authorizations; neither should learn the mapping between a payer and a prompt.

The Open Anonymity team translated that sketch into runnable software: a local wallet client, a serverd verification service, browser SDK with WASM proving, and the ZkApiVault contract live on Ethereum mainnet. Users deposit native ETH or USDC into the vault. The deposit enters a Merkle tree as a commitment while the spendable balance lives as a private note on the user's device—secret material, blinding factors, anchor state, and server signatures that advance with each authorized spend.

Protocol version two, circuit revision zkapi-v2-note-bound-v1, uses Groth16 proofs over the BN254 curve, Poseidon hashing, and Baby-JubJub commitments with Schnorr signatures. Each authorization consumes a nullifier tied to the user's current spend state; after usage settles, the server signs the next private balance bound to the same note. Reusing a nullifier is rejected, preventing double-spend at the authorization layer.

How a single AI request gets paid privately

The user journey is designed to feel like modern API consumption while shifting trust assumptions. A developer funds a note once, then authorizes bounded usage from the browser without re-identifying on every call.

When software on the user's machine wants to spend credits, it generates a zero-knowledge proof attesting—in effect—that a funded note covers the spend, the note is active in the current Merkle root, and the nullifier has not been spent before. One proof can cover a single HTTP request or an entire session, depending on how the client batches authorizations. The proof hides the note identifier, deposit amount, exact balance, expiry, anchor, and state signature. What remains visible outside the proof is a different category of metadata: public deposits and withdrawals, network timing, and—critically—the content of prompts sent to upstream model providers.

For OpenRouter-compatible flows, zkAPI supports a prompt-free lease pattern. The browser sends a lease authorization to the billing server, receives a short-lived OpenRouter key, and talks to the model endpoint directly. The billing server does not proxy inference; it measures usage after retirement and settles against the proof-bound native ETH quote accepted at authorization time. That architecture keeps prompts off the payment rail even though the model provider still sees them.

Developers can also point compatible stacks at OpenAI-style or Ollama endpoints where the gateway pattern fits the same prepaid credit model. The Foundation's launch post highlighted OA Chat—a browser-based private AI chat requiring no install—as the most approachable on-ramp, alongside Sepolia test deployments for experimentation without mainnet funds.

What zkAPI hides—and what it cannot

Honest documentation is a feature here. zkAPI's own materials state plainly that request proofs do not hide information outside the proof boundary. Deposits and withdrawals are public on-chain events. Network observers can see IP addresses, timing patterns, and session structure. Upstream providers receive prompts and can attempt correlation through content, writing style, or repeated context.

The protocol therefore occupies a specific layer in a privacy stack: payment unlinkability. It is complementary to, not substitutable for, network anonymity tools like Tor and content-side protections like local preprocessing or confidential compute. The Foundation's blog explicitly recommends routing through Tor with a fresh circuit per session when users want stronger network privacy, and it notes that confidential GPU offerings are emerging for content-side needs.

Cryptographically, the current construction is not post-quantum, and the checked-in proving keys reflect a single-party setup without a multiparty ceremony. Artifact hashes pin identity across client, server, and verifier deployments; operators must match circuit revisions and immutable vault adapter keys. These are operational constraints serious integrators will audit before production workloads.

Why AI billing needed a chain-native answer

Metered AI APIs sit at an uncomfortable intersection of finance and surveillance capitalism. Subscription tiers bundle uncertainty; pay-as-you-go API keys create durable identifiers; enterprise contracts reintroduce KYC. For autonomous agents that may fire hundreds of micro-requests per task, any system that requires human account provisioning becomes friction—and any system that logs payer identity creates a longitudinal record of intellectual activity.

zkAPI's answer is Ethereum-native prepaid notes: fund once, prove spend many times, close the note to withdraw unspent balance through a mutual close flow that includes server clearance signatures and on-chain withdrawal verification. Escape withdrawal paths exist for adversarial scenarios, with challenge services guarding against double use of states that already authorized spending.

The economic design also matters for providers. They receive settlement against measured usage without maintaining per-user billing databases for zkAPI-routed clients. Fraud resistance shifts toward cryptographic nullifier uniqueness and proof verification rather than identity reputation alone—though providers remain free to apply their own abuse policies to content they can see.

Early ecosystem signals and open questions

Within days of mainnet launch, zkAPI became a reference point in broader privacy-AI experiments—including public tests by Buterin combining local models, Tor routing, and zkAPI payment layers for health-adjacent recommendations. Pull requests extending the client for Tor-routed traffic signal that the core team and contributors expect real users to stack protocols rather than treat zkAPI as a standalone privacy panacea.

Competitive context is forming on two axes. Payment-rail competitors on other chains emphasize HTTP-native 402 flows and stablecoin settlement for agents, sometimes with faster finality profiles than Ethereum L1 vault operations. zkAPI's bet is that Ethereum's security model and the Foundation's research alignment give it credibility for high-value, privacy-sensitive credits even if per-authorization latency includes proof generation in the browser.

Open questions heading into late 2026 include multiparty proving ceremonies, post-quantum migration paths, facilitator markets that compete on settlement UX, and standardized metadata for cross-provider credit portability. None of those diminish the significance of what shipped October 1: a credible, audited-shaped path from Buterin-Crapis research to a vault contract holding real USDC and ETH on mainnet.

What integrators should do next

Teams evaluating zkAPI should start on Sepolia, pin protocol artifacts explicitly, and threat-model three leakage channels: on-chain deposit linkage, network metadata, and prompt content. Product designers should communicate clearly that "private payment" is not "private chat" unless additional layers are added. Security reviewers should examine nullifier lifecycle, server key compromise scenarios, and escape withdrawal game theory.

For the Ethereum narrative, zkAPI is also a concrete expression of the Foundation's dAI agenda: cryptographic mechanisms that let decentralized infrastructure participate in AI economies without importing Web2 identity rails wholesale. Whether that participation scales to consumer millions or remains a power-user and developer niche in 2026 depends on proof latency improvements, wallet UX, and provider adoption—but the decoupling of AI payments from identity is no longer theoretical. It is live on mainnet, open source, and waiting for the next layer of the stack to meet it halfway.

More in blockchain

Cubed

Write about the technologies shaping the future.

For developers, founders, and curious minds exploring AI, crypto, Web3, and emerging tech—signal over noise.

One free account across In Plain English, Stackademic, Venture, and Cubed.

How it works
  • AI, crypto & Web3
  • Software & emerging technologies
  • Analysis & practical resources
  • Thoughtful voices, not hype
1

Sign in

Google or GitHub

2

Complete profile

Takes a few minutes

3

Get approved & publish

Start sharing

Why write for Cubed?

The future deserves thoughtful voices, not just louder headlines.

Comments

Loading comments…

Posts Across the Network