The Ethereum Foundation and the Open Anonymity Project have launched zkAPI, a live zero-knowledge protocol on Ethereum mainnet that enables users to pay for artificial intelligence services and paid APIs without connecting their personal identity to their queries.
Originally conceptualized by Ethereum researcher Davide Crapis and co-founder Vitalik Buterin, the client, server, smart contracts, and browser integration were built by the Open Anonymity team. The launch follows the team's September 25, 2026 announcement introducing public AI chat service OA-chat, followed by formal promotion from the Ethereum Foundation on October 2, 2026.
How zkAPI Decouples Payments From Requests
To use the system, users deposit ETH directly into the ZkAPIVault smart contract on Ethereum mainnet. This deposit is recorded as a commitment using a Merkle tree structure, while the user's spending balance is maintained locally as a private note on their device.
At the beginning of an API session, the user's browser generates a zero-knowledge proof verifying that sufficient funds exist and have not been spent. Once verified, an API key with a designated spending cap is issued, allowing prompts to transmit directly from the browser to the AI service provider. Upon key expiration, a usage receipt is generated, and a one-way serial number called a nullifier prevents double-spending. The underlying cryptographic stack utilizes Groth16 proofs, BN254 cryptography, and Poseidon hashing. Users retain the ability to withdraw remaining funds directly from the ZkAPIVault contract even if the zkAPI servers go offline.
Key Takeaways
- Deposit Mechanism: Users deposit ETH into the ZkAPIVault contract, tracking balances via local private notes and Merkle tree commitments.
- Cryptographic Stack: Uses Groth16 proofs, BN254 cryptography, Poseidon hashing, and nullifiers to prove solvency without revealing identities.
- Unlinked Transactions: Generates capped API keys that allow payment processing without exposing which specific deposit funded the request.
Network Visibility and Privacy Scope
While zkAPI prevents payment records from linking to specific API requests, it does not encrypt overall network traffic or prompt content. Service providers still receive IP addresses and prompt data, leaving open the risk of session matching through timing, writing style, or personal details. The project's developers suggest using Tor with a fresh circuit per session to mitigate network-level linking.
As AI agents and automated traffic continue to expand across web infrastructure, privacy-preserving payment pathways are becoming increasingly vital.
Why It Matters
This deployment marks a concrete step in turning theoretical zero-knowledge cryptography into practical infrastructure for everyday web utilities. By decoupling identity from financial settlement, zkAPI offers a working blueprint for how decentralized networks can power private microtransactions. However, because content-level data and IP addresses remain exposed, full user privacy will depend on integrating network-level anonymity tools alongside cryptographic payment proofs.



