The Ethereum Foundation on October 1 deployed zkAPI to mainnet, a protocol that lets users pay for AI model inference and other metered APIs without revealing their identity. Developed jointly with the Open Anonymity Project and based on a February 2026 design by Vitalik Buterin and Davide Crapis...
"If AI doesn't have the properties we care about — self-sovereignty, censorship resistance, privacy — and then we use AI for everything, basically no one has those properties anymore." — Davide Crapis, AI Lead, Ethereum Foundation
The Ethereum Foundation on October 1 deployed zkAPI to mainnet, a protocol that lets users pay for AI model inference and other metered APIs without revealing their identity. Developed jointly with the Open Anonymity Project and based on a February 2026 design by Vitalik Buterin and Davide Crapis, the system uses Groth16 zero-knowledge proofs to decouple payment from identity: the payment server never sees the prompt, and the AI provider never learns who paid.
The launch arrives as the global AI API market reaches an estimated $82.6 billion in 2026, according to Grand View Research, with Anthropic and OpenAI alone generating a combined $135 billion in annualized revenue. Every one of those API calls carries an identity trail — an API key tied to an account, tied to a payment method, tied to a behavioral profile spanning months or years. zkAPI is the Ethereum ecosystem's first production attempt to break that chain.
The system is labeled experimental, has not been formally audited, and does not conceal IP addresses or prompt content from providers. Its significance lies not in its current scale but in the architectural claim it stakes: that zero-knowledge cryptography can insert a privacy layer between the $82.6 billion AI API economy and the users funding it.
The standard AI API model works as follows: a developer or user registers an account, attaches a credit card or billing method, receives an API key, and sends prompts. The provider — OpenAI, Anthropic, Google, or any inference endpoint — can link every prompt to a specific identity through the API key. The billing system creates a permanent record of what was asked, when, and by whom.
This creates a comprehensive behavioral profile. As the Ethereum Foundation stated in its announcement: "People ask AI models about their health, their finances, their doubts." The prompts contain some of the most sensitive information users generate. Yet the payment infrastructure guarantees that this information is permanently associated with a named individual.
The legal environment has made this more than a theoretical concern. In May 2025, a federal court ordered OpenAI to preserve user chat logs in a copyright lawsuit. In August 2025, OpenAI, Google, and Anthropic all reversed user privacy protections, enabling training data retention and content monitoring unless users actively opt out. Anthropic's standard API log retention, while reduced from 30 to 7 days in September 2025, still creates a window of linkable identity.
For enterprise API consumers — who account for roughly 70-75% of Anthropic's $65 billion annualized revenue and a significant share of OpenAI's approximately $12 billion in API consumption — the current model means every query is traceable.
The system operates through five steps, separating the "who paid" from the "what was asked" at the protocol level:
1. Deposit. A user sends ETH or USDC to an Ethereum vault contract. This is a single, ordinary on-chain transaction. From this point forward, the user's balance exists as a private note — a cryptographic commitment that only the depositor can spend.
2. Proof Generation. When the user needs API access, client-side software running on their device generates a Groth16 zero-knowledge proof. The proof demonstrates two things: that the user controls an unspent note with sufficient balance, and that the note has not been previously spent (via a unique nullifier). The proof reveals neither the deposit address nor the note's value.
3. Key Issuance. The zkAPI server receives the proof — with no identity, no account, no prompts attached. After verification, it issues a short-lived, dollar-capped API key. The key exists only in device memory.
4. Inference. The user sends prompts directly to the AI provider using the temporary key. The provider processes the request normally. It sees the prompt content but has no information about who funded the key.
5. Settlement. When the key expires, the provider records usage in a signed receipt. The zkAPI server deducts the metered amount from the user's private balance. The settlement is cryptographic — no identity lookup occurs.
The result: the payment server sees money but not content. The AI provider sees content but not money. Neither can reconstruct the full picture.
The cryptographic stack is compact:
The client software emulates OpenAI and Ollama API interfaces via localhost, meaning existing applications that use these formats require zero code changes. The system currently integrates with OpenRouter as an inference provider.
Ken Liu of the Open Anonymity Project described it as "a generalization of OA's unlinkable reasoning, while also abstracting away payments." The design targets any metered API, not only AI: blockchain RPC queries, image generation, VPN bandwidth, and machine-to-machine services are listed as supported use cases.
The system's relevance scales with the market it targets:
| Metric | Value | Source | |--------|-------|--------| | Global AI API market (2026) | $82.6 billion | Grand View Research | | Projected AI API market (2030) | $246.9 billion | Grand View Research | | OpenAI annualized revenue (Sept. 2026) | ~$70 billion | Value Add VC | | Anthropic annualized revenue (July 2026) | $65 billion | Sacra | | Anthropic revenue from API (%) | 70-75% | Sacra | | OpenAI API revenue share | ~$12 billion | Multiple sources | | OpenAI weekly ChatGPT users | 900 million+ | OpenAI |
The Ethereum Foundation's dAI team, established September 2025, has framed its thesis around a specific prediction: Crapis has stated that most Ethereum traffic will originate from machines within three to five years. If AI agents are the primary consumers of API services — and if those agents transact on Ethereum — the payment identity problem compounds. Each agent call generates a traceable record. At scale, that creates a surveillance surface that no enterprise privacy policy can contain.
This positions zkAPI not as a consumer privacy tool but as infrastructure for machine-to-machine commerce where identity linkage creates systemic risk.
The Ethereum Foundation's own documentation identifies several constraints:
IP exposure. The zkAPI gateway can correlate request patterns from stable IP addresses. The recommended mitigation — routing through Tor with fresh circuits per session — adds latency and complexity that most users will not accept.
Prompt content. The AI provider receives the full prompt text. Writing style analysis, personal details disclosed in queries, conversation history patterns, and shared documents can all be used to re-link sessions to a specific user. The Foundation describes this as a "privacy-utility tradeoff."
No formal audit. The codebase is labeled experimental. No third-party security audit has been conducted as of launch. The cryptographic primitives (Groth16, BN254, Poseidon) are well-studied, but the implementation and the vault contract have not been independently verified.
Single-chain limitation. The vault contract lives on Ethereum mainnet. Users must bridge or hold ETH/USDC on L1 to participate, inheriting Ethereum's gas costs and settlement times.
Provider adoption. The system currently integrates with OpenRouter. Major providers — OpenAI, Anthropic, Google — have not announced support. Without provider integration, the system remains a privacy layer for a subset of available models.
These are not minor caveats. IP correlation alone can defeat the payment-identity separation in many real-world scenarios. The system provides cryptographic guarantees at the payment layer but offers no protection at the network or content layer.
zkAPI enters a growing zero-knowledge applications market. According to The Business Research Company, the ZK proofs market reached $1.32 billion in 2025, is expected to hit $1.73 billion in 2026 (30.9% CAGR), and is projected to reach $5.12 billion by 2030.
The number of ZK-based applications has grown from approximately 150 in 2022 to an estimated 2,000+ in 2026. The dominant use cases have been scaling (ZK-rollups like zkSync, Scroll, Polygon zkEVM) and identity verification. Privacy-preserving payments represent a smaller but growing segment, historically anchored by Zcash and Tornado Cash.
zkAPI represents a different design point: it applies ZK proofs not to on-chain transaction privacy but to off-chain service consumption privacy. The user's on-chain deposit is visible. What becomes invisible is the link between that deposit and the API calls it funds.
This aligns with a broader Ethereum Foundation strategy. In August 2025, Crapis and Marco De Rossi proposed ERC-8004, a standard for AI agent identity and discovery. In January 2026, ERC-8004 was deployed. zkAPI now provides the payment layer that lets those agents transact without creating linkable identity trails.
The dAI team's thesis is that Ethereum should become the trust and settlement layer for AI. zkAPI is one component of that strategy, alongside ERC-8004 for agent identity and the broader push toward on-chain AI coordination.
The economic logic is straightforward. If AI agents generate the majority of Ethereum traffic within 3-5 years, as Crapis has predicted, then Ethereum needs to offer something that centralized payment rails cannot: privacy-preserving, permissionless API payment. Traditional payment systems require identity by regulation (KYC/AML). zkAPI routes around this by making identity cryptographically unnecessary at the payment layer — the vault contract handles compliance at the deposit stage, while individual API calls carry no identity.
Whether this architecture can scale from an experimental system with one inference provider to a protocol handling meaningful API volume remains unproven. The next milestones to watch: formal audit completion, integration with major AI providers, and any L2 deployment to reduce gas costs.
zkAPI solves a narrow but precisely defined problem: it makes it cryptographically impossible for an AI API provider to learn who funded a given API call. It does not solve prompt privacy, network anonymity, or provider censorship. What it does do is demonstrate that zero-knowledge proofs can be deployed at the API payment layer — not just for blockchain transactions or rollup compression — to create privacy where the existing market offers none.
The $82.6 billion AI API market currently operates on a model where every call is identity-linked by default. zkAPI proposes an alternative where payment verification requires no identity at all. Whether that proposition can move from an experimental Ethereum mainnet deployment to a meaningful share of AI API traffic depends on audit results, provider adoption, and whether the privacy-utility tradeoff is acceptable to the developers and agents that consume these services.
For now, the system is a technical proof of concept from the Ethereum Foundation's AI team. Its significance is architectural: it establishes a design pattern for privacy-preserving metered payments that did not previously exist in production. The market will determine whether that pattern finds demand.