The Ethereum Foundation, working with the Open Anonymity Project, deployed zkAPI on Ethereum mainnet on October 1, 2026. It lets you pay for AI and other APIs from a private balance of ETH or USDC, using zero-knowledge proofs, so the service provider cannot link a given request to the person who paid for it.
The motivation is stated plainly: AI prompts contain personal details about health, finances and doubts, and whoever holds the billing relationship ends up with a continuing record of how you think. zkAPI tries to separate the payment from the prompt.
TL;DR — what people are asking
| Question | Answer |
|---|---|
| What is it? | Private pay-per-use for APIs using zero-knowledge proofs |
| Who built it? | Ethereum Foundation with the Open Anonymity Project |
| When? | Mainnet deployment October 1, 2026 |
| Currencies? | ETH or USDC |
| Vitalik's role? | Co-authored the "ZK API Usage Credits" proposal in February that led to it |
| Uses? | AI chat, agents, media generation, VPN bandwidth, OpenAI-compatible APIs |
| Ready-made app? | OA Chat, a browser-based private chatbot |
| Anonymity? | Hides payer-to-request link; not full anonymity |
| Audit? | None listed; protocol labeled experimental |
The problem it solves
Today, using an AI API means an account, a payment method and an API key. Every request is tied to that identity. Even if a provider promises not to train on your data, it can still hold a record of what you asked and when. For sensitive uses, that record is the risk.
Private payment is a different lever from private inference. Some approaches keep the model's processing confidential — see Google's homomorphic encryption work for private AI and the on-device approach of Underdog. zkAPI addresses billing identity: the provider serves your request without knowing which paying customer sent it.
How it works
The sources describe a flow in five steps:
- Deposit. You send ETH or USDC into a vault contract on Ethereum in one ordinary transaction. That deposit is public, like any transaction.
- Note. The deposit becomes a private cryptographic note representing a balance only you can spend. It cannot be traced from the deposit.
- Prove. Software on your machine creates a zero-knowledge proof that you hold sufficient balance, without revealing which deposit is yours. The proof can cover one request or a whole session.
- Authorize. The zkAPI server verifies the proof and issues a temporary API key with a spending limit.
- Settle. When the key expires, your private balance is charged. A nullifier, a unique serial number, is recorded so the same funds cannot be spent twice.
Two ideas make this work. Zero-knowledge proofs let you demonstrate you can pay without identifying your deposit. The nullifier prevents double-spending without linking spends to deposits.
What you can use it for
Supported uses listed in coverage include:
- AI chat and agents.
- Image and video generation.
- VPN bandwidth.
- OpenAI-compatible APIs, accessible through a local address, which means existing clients can point at zkAPI without a rewrite.
The Open Anonymity Project's OA Chat is the ready-made example: a browser-based private chatbot that needs no installation. It is the easiest way to see the system working before wiring it into your own code.
The OpenAI-compatible route is the one builders will care about. A local proxy that speaks the familiar API format and handles proofs underneath is the kind of integration that gets adopted. If you already run tools against an OpenAI-style endpoint, the switch should be a base-URL change plus running the local component.
What stays private, and what does not
Be precise here, because privacy claims are easy to overstate.
| Information | Protected? |
|---|---|
| Which paying account sent a given request | Intended to be hidden from the provider |
| That you deposited into the vault | Public on-chain |
| The text of your prompts | Visible to the provider that serves them |
| Your IP address and network metadata | Can still identify you unless you add network privacy |
| Patterns in what you ask | Can link requests to each other, and sometimes to you |
The coverage is explicit that zkAPI does not provide complete anonymity: network information and the contents of prompts can still reveal or connect a user's activity. If you paste your name and address into a prompt, no payment scheme helps. Use it alongside good habits — a VPN or Tor for network privacy, and prompts that avoid identifying details.
Why this is interesting for agents
Agents make payments a first-class problem. An autonomous agent that calls many APIs needs a way to pay without a human approving each charge. Our coverage of Cloudflare Wallets looked at stablecoin spending caps for agents, and the BitGo wallet challenge explored how far agents can be trusted with funds. zkAPI adds a third property: payment that does not tie every call to a single identity.
The temporary, limited API key is a good pattern independent of the cryptography. A key that expires and has a spending cap bounds the damage if an agent misbehaves or a key leaks. You can copy that idea with any payment system.
Risks and open questions
- Experimental status. The protocol is labeled experimental, and the sources list no formal audit. Smart-contract and cryptographic systems of this type can have bugs; treat deposits as at risk.
- Provider adoption. Privacy payment is only useful if providers accept it. Which major AI APIs are available through zkAPI beyond OA Chat is not clear from the sources I reviewed.
- Fees and UX. Coverage does not specify fees. On-chain deposits cost gas, and proof generation takes local compute.
- Abuse and compliance. Anonymous payment can be misused, and providers may impose limits. Terms of service and legal requirements for your use case still apply.
- Regulatory attention. Privacy-preserving payments sometimes draw regulatory scrutiny. Know your jurisdiction.
A mental model: cash for APIs
A useful way to hold the design in your head is a prepaid arcade token. You buy tokens at a counter, which is visible: the clerk knows you bought some. Later you drop a token in a machine. The machine can check that the token is genuine and has not been used, but it cannot tell which customer bought it. zkAPI replaces the physical token with a cryptographic one, and the machine's check with a proof.
The analogy also shows the limits. If you walk up to the machine and announce your name, the token does not help. If you are the only person who bought a token that day, an observer can guess whose it is. Privacy from payment systems depends on a crowd: the more people deposit and spend in the same pool, the harder it is to link a spend to a deposit. An early, small pool gives weaker protection than a large one, so be cautious about assuming strong anonymity on day one.
Should you try it?
A cautious path:
- Start with OA Chat to see the experience with no setup.
- Use a small deposit you can afford to lose.
- Read the project documentation and any audit status before depositing more.
- Add network privacy if your threat model needs it.
- For builders: prototype the local OpenAI-compatible endpoint against a non-sensitive workload first and measure latency and cost.
If your concern is less about the payment link and more about a team's use of unsanctioned tools, our guide to shadow AI and workplace privacy risk covers the organizational side.
What people are asking
Does this make my prompts private?
No. It hides the link between payment and request. The provider still sees the prompt text. For confidential inference you need a different approach.
Is it only for crypto users?
You need ETH or USDC and a wallet. That limits the audience today, though the OpenAI-compatible local endpoint hides much of the crypto plumbing once set up.
How is this different from using a prepaid card?
A prepaid card can still be linked to you through purchase records and the card network. zkAPI uses cryptographic proofs so even the service operator cannot link spending to a deposit.
Did Vitalik Buterin build it?
He co-authored the "ZK API Usage Credits" proposal in February 2026 that led to the product. The Ethereum Foundation and the Open Anonymity Project built and deployed it.
Can I run an agent on it?
Coverage lists AI agents among supported uses. Check the documentation for how to integrate your agent and what spending limits apply.
Honest limitations
- I relied on news coverage and did not review the protocol's code or documentation directly.
- Fees, audit status and provider list are not specified in the sources I reviewed.
- Privacy properties depend on correct implementation and user behavior.
- This is not legal or financial advice.
Bottom line
zkAPI is a serious attempt to decouple paying for AI from being identified by the provider, using a vault, private notes, zero-knowledge proofs and expiring spend-limited keys. It is experimental and not full anonymity. Try it with small amounts, pair it with network privacy, and borrow its expiring-key pattern for your own agents.
Related on explainx.ai
- Cloudflare Wallets: AI agent payments
- BitGo CEO's 100 BTC wallet challenge
- Google's homomorphic encryption for private AI
- Underdog: on-device private personal AI
- Shadow AI workplace privacy risk guide
- Cloudflare monetization gateway and x402 micropayments
- Mastercard Agent Pay for machines
Source: CoinCodex — Ethereum's zkAPI brings privacy-preserving API payments to mainnet
Details reflect news coverage as of October 3, 2026; the protocol is experimental and may change.
