The Ethereum Foundation launched zkAPI on Thursday, a system that lets people pay for AI models and other metered APIs without revealing who they are. It's live on Ethereum mainnet and was built with the Open Anonymity Project, an open-source AI privacy effort.
The system implements a design that Ethereum co-founder Vitalik Buterin and Ethereum Foundation dAI Lead Davide Crapis published on the Ethereum Research forum on February 11. Crapis leads the Foundation's dAI team, which formed in September 2025 to improve Ethereum's capabilities as a settlement and coordination layer for AI.
Users deposit tokens like ETH or USDC into a vault contract on Ethereum. The contract records the balance as a private note, which means the funds exist on-chain but the link between a deposit and a spender is not publicly visible. To spend those funds, software on the user's device generates a zero-knowledge proof.
This proof shows that a request is backed by a funded note without revealing which note or deposit it came from. A zkAPI server checks the proof and issues a temporary API key with a spending cap.
The user sends prompts directly to the AI model provider with that key, and when it expires, the server deducts the usage from the private balance. A serial number called a nullifier gets published each time a user pays.
Someone who tries to spend the same balance twice produces a duplicate nullifier, which exposes the attempt and nothing else. The client works with existing AI tools. It exposes the standard OpenAI and Ollama APIs on your own machine, so existing apps, editors, and chat clients work by pointing them at localhost.
What it's for and where it falls short
The Foundation lists AI chat and agents as the first use case. Other applications include blockchain RPC queries, image and video generation, VPN bandwidth, and machine-to-machine payments between AI agents. The system does not provide network anonymity.
The gateway can potentially correlate requests sent from a stable IP address, and users seeking stronger privacy may route traffic through Tor. Sessions can also be re-linked through the content of prompts, such as personal details, writing style, or conversation history. The project's GitHub repository describes the protocol as experimental.
Why the Foundation is building this
The Foundation's blog post frames the problem in plain terms. Every AI API call today carries an identity. Your API key points to an account, the account to a payment method, and every prompt you send joins the record attached to both.
The provider can connect years of usage into a single profile. zkAPI breaks that chain. The payment server sees a valid proof but not the payer. The AI provider sees a temporary key but not the account behind it.
Neither side can build the profile that today's API economy runs on. The project is early. It's experimental, it has known privacy gaps, and it's not clear how many AI providers will accept zkAPI keys.
But the design has the backing of Ethereum's co-founder and a working mainnet deployment. That's more than most privacy protocols can say at launch.