Ethereum symbol between private payment credits and protected API access paths

Ethereum’s zkAPI Brings Private AI Payments to Mainnet—But It Doesn’t Hide Your Prompts

• October 1, 2026 11:11 pm • Comments

Ethereum has put a new privacy experiment on mainnet, and it is aimed directly at one of the fastest-growing markets in technology: metered access to artificial intelligence and other APIs.

The system is called zkAPI. It was built by the Open Anonymity Project with the Ethereum Foundation, and its pitch is simple: a user should be able to pay for API usage without handing the provider a durable billing identity that connects every request into one long profile.

That meaningfully changes the normal API-key model, but the word “private” needs a boundary. zkAPI breaks the link between payment and usage.

Request content, IP addresses, and other clues that can connect sessions remain visible outside that payment layer.

How zkAPI separates the money from the request

According to the Ethereum Foundation, a user first deposits assets such as ETH or USDC into an Ethereum vault. That deposit creates a private note representing the funded balance.

When the user wants to access a metered service, software on the user’s own device creates a zero-knowledge proof. The proof establishes that a valid note can cover a bounded amount of usage, without identifying which deposit funded it or who controls the balance.

The zkAPI server verifies that proof and issues a short-lived API key with a dollar cap. The request then goes to the service provider.

The provider sees the request because it must process it, but it does not receive the underlying billing identity. The payment side sees a valid spend and the eventual charge, but it does not see the request content.

The spending cap works like a reservation. When the key expires, the provider signs a receipt for the actual usage and the system deducts that amount from the private balance.

One authorization can cover an entire session rather than forcing a new onchain payment for every call.

The cryptography is doing two different jobs

The design uses commitments stored in a Merkle tree so a user can prove a note belongs to the valid set without pointing to that note. It also publishes a nullifier for each spend.

The nullifier prevents the same balance from being spent twice without revealing the note itself.

The Foundation says the implementation uses Groth16 proofs on the BN254 curve and Poseidon hashing. Verification happens offchain for normal usage, while the Ethereum vault gives users an onchain route to close a balance and withdraw funds even if a zkAPI server disappears.

That last feature matters because users do not have to rely on a middleman’s promise to keep billing records separate. Software and cryptographic proofs enforce the separation, while a contract holds the funded balance.

What zkAPI leaves exposed

The launch comes with unusually clear caveats. The API provider still sees the content it is asked to process.

Repeated personal details, writing patterns, files, or conversation history may let the provider connect sessions even when the payment trail is hidden.

Network metadata is another limit. A stable IP address and consistent timing patterns can reveal links between requests.

Stronger network anonymity still requires a separate tool such as Tor, while confidential request processing requires a trusted execution environment or a local model.

That distinction is why this launch is more interesting than a blanket promise of “private AI.” The technology solves one concrete problem: it lets a person or software agent buy bounded usage without building a permanent identity into the payment relationship.

Why this matters for Ethereum

The immediate product is aimed at AI inference, but the same architecture can sit in front of blockchain RPC calls, image generation, VPN bandwidth, machine-to-machine services, and other usage-priced tools.

Existing applications can point to a local gateway that speaks familiar OpenAI-compatible or Ollama interfaces.

For Ethereum, that creates utility beyond token trading and lending pools. Mainnet becomes the settlement and exit layer for private usage credits, while most requests and proof checks happen away from the chain.

The launch remains an early implementation. Providers must integrate the receipt model, users must accept new local software, and the privacy protections have sharp boundaries.

Still, zkAPI puts a working version of the idea on mainnet today. Ethereum now has a credible role in the growing market for machine-paid services.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.