Crypto Media • Analytics • Investigations
Ethereum Launches zkAPI
Новости

Ethereum Launches zkAPI

КЛЁ
КЛЁ 2 октября, 2026 6 минут чтения

On October 1, the Ethereum Foundation, together with the Open Anonymity Project, launched zkAPI on Ethereum Mainnet. The system allows users to pay for AI model requests with ETH, USDC, and other supported assets without directly linking a specific deposit to a specific AI request.

The main difference from a standard AI API is that instead of using a permanent API key tied to an account and payment method, zkAPI uses a zero-knowledge proof. The user proves that sufficient funds are available without revealing which exact deposit is being used.

How zkAPI Works

The system is built around four main steps.

1. Deposit

The user deposits ETH, USDC, or another supported asset into an Ethereum vault smart contract.

The balance then exists inside the system as a private cryptographic record called a note.

2. Zero-Knowledge Proof

Before using an AI service, the local client generates a ZK proof.

It confirms several things at once:

  • the deposit exists;
  • there are enough funds;
  • the balance has not already been spent;
  • the user is authorized to spend a certain amount.

At the same time, the server does not learn which specific deposit stands behind the proof.

3. Temporary API Key

After verifying the proof, the server creates a short-lived API key.

The key has a predefined maximum spending limit in dollars.

It exists only in the user device’s memory and remains valid for a limited period.

4. The Request Goes Directly to the AI Provider

The prompt is sent from the user’s device directly to the model provider.

At this stage, the payment server does not see the content of the request.

After the session ends, the AI provider generates a signed receipt showing the actual amount of API usage. The system deducts only the amount that was actually spent from the private balance.

What Each Side Can See

The architecture is designed to separate information between participants.

The zkAPI server knows:

  • that a valid payment exists;
  • how much money may be spent;
  • how much was actually spent.

But the server does not know:

  • who the user is;
  • the contents of the prompt;
  • which exact Ethereum deposit was used.

The AI provider knows:

  • the prompt;
  • the model response;
  • the amount of API usage.

But it does not know which deposit paid for the request.

Ethereum sees:

  • the deposit;
  • position closure;
  • withdrawals.

But the network does not see which AI requests were paid for by that balance.

What Is Under the Hood

The Ethereum Foundation has also disclosed the cryptographic architecture behind the system.

zkAPI uses Groth16 proofs over the BN254 curve.

Poseidon is used to hash commitments and nullifiers.

Deposits are stored in a 32-level Merkle tree.

Ordinary spending proofs are verified off-chain.

The Ethereum smart contract verifies proofs during vault operations such as creation, closure, and emergency exits.

Why the Nullifier Matters

One of the main problems in private payment systems is double spending.

If the system does not know the user’s identity and does not expose the underlying balance, it still needs a way to ensure that the same funds are not spent twice.

zkAPI uses a nullifier for this purpose.

It is a one-way unique identifier generated from the secret associated with the note.

If the user attempts to spend the same balance again, the system detects the repeated nullifier and rejects the operation.

At the same time, the user’s identity and original deposit remain undisclosed.

One Proof Can Pay for an Entire Session

zkAPI does not require a new ZK proof for every single prompt.

A single proof can reserve a fixed amount for an entire AI session.

For example, the user may authorize spending of up to $5.

The AI provider then processes a series of requests.

If the actual cost is $1.37, only $1.37 is deducted when the session is closed, rather than the full $5.

The final amount is confirmed through a signed usage receipt.

OpenAI and Ollama Are Already Supported

The local zkAPI client exposes a standard interface compatible with the OpenAI API and Ollama.

This allows existing applications to work through zkAPI without being completely rebuilt.

An application can simply send requests to a local endpoint instead of directly to the usual API provider.

The project also includes:

  • a local client;
  • a server;
  • a browser SDK;
  • a Mainnet contract;
  • a Sepolia test deployment;
  • the browser-based OA Chat.

The ZkApiVault is already live on Ethereum Mainnet and supports USDC credits.

Two Operating Modes

The main mode is called runtime-key mode.

In this setup, the prompt goes directly to the AI provider, while zkAPI handles only payment authorization.

There is also a simpler proxy mode.

In proxy mode, the request first passes through the zkAPI server and is then forwarded to the model provider.

This architecture is easier to deploy, but privacy is weaker because the intermediary server receives the network traffic and may potentially see the request content.

This Is Not Full Anonymity

The most important limitation is that zkAPI hides the payment link, but it does not make the user fully anonymous.

The AI provider still receives the prompt.

It may also see:

  • the IP address;
  • request timestamps;
  • recurring writing patterns;
  • conversation history;
  • uploaded documents;
  • personal data included inside the prompt.

The developers explicitly warn about these limitations.

A persistent IP address may still allow different sessions to be linked together.

For stronger network-level privacy, they suggest using Tor or other tools that hide the user’s IP address.

So it is more accurate to describe zkAPI as payment privacy for AI, rather than anonymous AI usage.

Not Just for AI

AI inference is the first use case, but the architecture is designed for any service that charges based on usage.

The Ethereum Foundation lists:

  • AI chat and AI agents;
  • blockchain RPC services;
  • image and video generation;
  • VPN and bandwidth services;
  • machine-to-machine services.

This also means that an autonomous AI agent could theoretically pay another service without creating a traditional account or exposing its broader payment history.

From Vitalik’s Idea to Mainnet

zkAPI is a working implementation of the ZK API Usage Credits concept previously published on Ethereum Research by Davide Crapis and Vitalik Buterin.

It is no longer just a research proposal.

As of October 1, the system is live on Ethereum Mainnet.

What It Means

zkAPI solves a very specific problem.

A traditional API model looks like this:

account → API key → payment method → request history

zkAPI changes that chain to:

deposit → ZK proof → temporary key → request

The AI provider receives the prompt.

The payment system receives the money.

Ethereum confirms that the funds exist.

But the full connection between all three parts no longer has to sit in one place.

That is what the Ethereum Foundation calls private usage credits.

Sources

Ethereum Foundation — Introducing zkAPI: private usage credits for any API

Ваша реакция на материал

Оставить комментарий