The Ethereum Foundation introduced zkAPI on Oct. 1 in collaboration with the Open Anonymity Project. The system is live on mainnet and enables users to deposit ETH, USDC or other supported assets into an on-chain vault before authorizing API usage with zero-knowledge proofs.
The infrastructure decouples the payer's identity from the services they consume. Traditional API models link a specific API key to an account and its payment method, allowing providers to compile usage history tied to a single user—including sensitive AI prompts.
zkAPI generates short-lived spending credentials that allow users to access services without exposing the specific Ethereum deposit that funded the request. Users deposit funds into a designated smart-contract vault. Their balance is represented privately and not revealed with each subsequent API request.
When service access is required, the user's device generates a zero-knowledge proof confirming sufficient funds in the vault and that the same balance has not been previously spent—all without disclosing the exact balance or deposit details.
The zkAPI server verifies the proof and issues a temporary API key with a defined spending cap. This key facilitates direct communication between the user's device and the AI provider.
The design separates information flows: the payment server processes the zero-knowledge proof but cannot access the AI prompt content. The AI provider receives the prompt but does not learn which specific Ethereum deposit funded the request.
AI inference is the initial focus for zkAPI due to the sensitive nature of data often contained in AI prompts. The underlying infrastructure extends to blockchain RPC calls, image and video generation services, VPN bandwidth allocation and machine-to-machine payment scenarios—allowing services to charge per request without requiring persistent user accounts.
The launch aligns with Ethereum's broader emphasis on privacy through advanced zero-knowledge cryptography. Despite the privacy benefits, some limitations exist: zkAPI obscures the payment relationship but does not anonymize all request aspects. The AI provider still views the prompt content and may receive network information such as the user's IP address. Consistent writing patterns or specific personal details embedded in prompts could potentially allow separate sessions to be linked over time.
