Ethereum's zkAPI Aims to Decouple AI Payments From User Identity
Key Takeaways
- •zkAPI, launched Oct. 1 by the Ethereum Foundation and the Open Anonymity Project, allows users to pay for AI API access from an Ethereum vault funded with ETH, USDC, or other supported credits without exposing their billing identity.
- •The system uses zero-knowledge proofs, 32 Merkle trees, and nullifier-based double-spend protection so servers can authorize spending without linking it to a specific deposit.
- •Rather than issuing permanent API keys, zkAPI creates short-lived keys with dollar caps, and providers submit signed usage receipts so only the actual consumed amount is deducted from the private note.
- •zkAPI does not conceal prompt content or network metadata, and the Foundation cautions that repeated personal details in prompts can act as identifying fingerprints, with Tor suggested for stronger network anonymity.
- •Beyond AI, the same mechanism could support blockchain RPC queries, image and video jobs, VPN bandwidth, and payments between autonomous software agents.

Every request sent to a commercial AI model can leave a longer trail than most users realize. An API key links to an account, the account links to money, and prompts accumulate behind both. The Ethereum Foundation (EF) frames the problem bluntly: “Every AI API call today carries an identity.” zkAPI, the Foundation's newly launched tool, is built to break exactly that link.
Launched Oct. 1 by the Ethereum Foundation and the Open Anonymity Project, zkAPI lets a user deposit ETH, USDC — a dollar-backed stablecoin — or other supported credits into an Ethereum vault and then pay for AI requests without telling the payment server who they are. The AI provider receives the request, but not the billing identity behind it.
The concern is personal as much as financial. “Prompts are personal. People ask AI models about their health, their finances, their doubts,” the Foundation's blog post, titled “Introducing zkAPI: private usage credits for any API,” states. Pile enough of those questions under one account and the provider holds more than a bill — it can hold a years-long record of what someone has been thinking about.
A Vault, a Private Note and a Zero-Knowledge Proof
zkAPI's mechanism begins with an ordinary Ethereum transaction. A user deposits credits into a vault contract, after which the funds are represented by a private note that can be spent without revealing which original deposit supplied the money. As the EF description puts it, “zkAPI separates payment identity.”
Software running on the user's device then generates a zero-knowledge proof showing that a funded note covers the requested spending and has not already been spent. Zero-knowledge proofs are a family of cryptographic techniques that let one party demonstrate a statement is true without revealing the data behind it, and they have become a common building block across blockchain privacy and scaling designs. The proof here attests only to validity, so the server can authorize the spend without learning which note belongs to the user.
The plumbing underneath is technical. Deposits are commitments inside a Merkle tree — a structure that lets anyone verify a deposit's inclusion without exposing which entry it is — 32 levels deep. Spending produces one-way serial numbers called nullifiers, while Groth16 proofs on the BN254 curve and Poseidon hashing handle the cryptographic heavy lifting. The nullifier acts as the double-spend guard: try to spend the same balance twice and the duplicate gives the game away, while staying within the balance is designed to keep the note unlinkable. In the Foundation's words, “A user who stays within their balance stays unlinkable.”
Disposable Keys Instead of Permanent Accounts
The cleverest part comes after payment authorization. Instead of handing the AI provider a permanent API key tied to an ordinary customer account, zkAPI's server checks the payment proof and creates a fresh, short-lived key with a dollar cap. The key lives only in the user's device memory, and the prompt then heads directly to the AI provider.
“The server that handles money never sees content, and the that sees content never learns the billing identity behind a key,” the Foundation explained.
When the temporary key expires, the provider records the amount actually consumed in a signed usage receipt. zkAPI deducts that amount from the user's private note rather than automatically taking the entire spending cap, so a single authorization can cover a whole session instead of requiring an Ethereum transaction for every question.
The split is deliberate: the payment system knows somebody paid, the AI knows somebody asked, and neither is supposed to know enough to connect the two. Ethereum itself sees even less. The public blockchain can observe deposits, closes and withdrawals, but not what the balance purchased. The money can also be reclaimed if the zkAPI servers vanish. “You can close your balance and withdraw onchain, even if every zkAPI server disappears,” the EF blog post explains.
The Limits of the Privacy Cloak
There is, however, no invisibility cloak. zkAPI separates billing identity from API usage; it does not hide what somebody types into an AI model. The provider still receives prompts and responses because it has to run the model. Network information can also betray the person on the other end — a stable IP address, timing patterns or repeated behavior can help reconnect supposedly separate sessions.
The Foundation is equally candid about a subtler risk: “Shared prompt contents can act as fingerprints for anyone who can read the prompts.” Keep mentioning the same employer, family members, writing habits, project documents or old conversation history, and the content itself can start piecing an identity back together. Users seeking stronger network anonymity are pointed toward Tor, the long-running anonymity network, and fresh circuits for separate sessions, and the protocol's repository labels zkAPI experimental — a designation that leaves room for the design to evolve as development continues.
Beyond AI
AI is merely first through the door. The same system could handle blockchain RPC queries, image and video jobs, VPN bandwidth and machine-to-machine services where software agents pay for work without maintaining conventional customer accounts.
That makes zkAPI's proposition both narrower and more interesting than anonymous AI. It doesn't promise that nobody knows anything. It tries to make sure nobody knows everything.