Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
Ethereum Foundation rolls out private metered API payments, but IP data stays exposed

Ethereum Foundation rolls out private metered API payments, but IP data stays exposed

CryptonomistCryptonomist2026/10/03 10:33
By:Cryptonomist

A new payment system quietly went live on Ethereum mainnet this week, and it’s built to solve a problem most people don’t think about until it’s too late: every time you pay to use an AI model, a cloud API, or almost any metered online service, that payment usually ties your identity to everything you’ve ever asked. The Ethereum Foundation and the Open Anonymity Project announced on October 1, 2026, that they had deployed a system called zkAPI, designed to let users make private metered API payments without linking individual requests to a durable billing account.

Key takeaways

  • zkAPI launched on Ethereum mainnet on October 1, 2026, built by the Ethereum Foundation’s dAI team and the Open Anonymity Project.
  • Users deposit ETH or USDC into a vault contract, turning that balance into a private “note” that functions like digital cash.
  • Zero-knowledge proofs let the system confirm a payment is valid without revealing who made it or what it paid for.
  • Payments stay unlinkable on-chain, but the protocol does not hide request content or network metadata like IP addresses.
  • It’s compatible with standard OpenAI- and Ollama-style API endpoints, so existing apps need minimal changes to plug in.

Ethereum Foundation and Open Anonymity Bring zkAPI to Mainnet

zkAPI is now running on Ethereum, giving users a way to pay for metered services without the usual trade-off between convenience and exposure. Vittorio Rivabella, a member of the Ethereum Foundation’s dAI team, made the announcement, and the system puts into practice an earlier research idea proposed by Davide Crapis and Vitalik Buterin.

Research Origins and Mainnet Deployment

The issue that zkAPI aims to solve is rooted in the standard approach to API billing: an API key is tied to a user, that user is tied to a payment method, and the provider on the other side can silently piece together months or years of requests into one profile. Given how often people ask AI models about health concerns, finances, or private doubts, that setup effectively hands a long transcript of someone’s thinking to whoever controls the billing relationship.

Paying per call directly on a public blockchain sidesteps the middleman, but it’s slow, expensive, and fully traceable on-chain. Trusting a third party not to peek at traffic is the other usual compromise. zkAPI is pitched as a third option, and the Foundation describes the protocol as still somewhat experimental even though it’s already live on mainnet. It’s designed to plug into standard OpenAI- and Ollama-compatible API endpoints, meaning developers can point existing chat tools or editors at a local client without rebuilding their stack.

How zkAPI Enables Private Metered API Payments

The core idea is simple to state even if the cryptography underneath is not: zkAPI separates the act of paying from the content of what’s being paid for. A user deposits ETH, USDC, or a similar asset into a vault contract in one ordinary transaction. From that point on, the balance exists as a private note — essentially digital cash that only the holder can spend, and one that can’t be traced back to the original deposit.

Deposits, Private Notes and Zero-Knowledge Proofs

When it’s time to actually use the paid-for service, software running on the user’s own device generates a compact zero-knowledge proof. This proof confirms that a funded note can cover a limited amount of usage and has not yet been spent, all without disclosing which note, deposit, or individual is involved. A single proof can cover one call or an entire session, and the receiving server can confirm the claim is true without learning any of the underlying details. At the payment layer, one request never links back to the user or to any other request they’ve made.

Merkle Trees, Nullifiers and Off-Chain Verification

Two cryptographic pieces hold this together. Deposits are recorded as commitments inside a Merkle tree, so a proof can show a note belongs to the valid set without pointing to which one it is. Every time a note is spent, the system publishes a nullifier — a one-way serial number derived from that note’s secret. A user’s actions remain unlinkable as long as they stay within their balance; however, attempting to spend the same funds twice generates a duplicate nullifier that reveals only the double-spend attempt and nothing further.

In practice, a lightweight client on the user’s machine mimics a familiar API. A payment proof—excluding the prompt and any identifying details—is sent to the zkAPI server, which verifies it and provides a short-lived, dollar-capped key stored solely in local memory, after which prompts flow directly from the device to the AI provider using that temporary key. After the key expires, a signed usage receipt logs the actual consumption, and the server subtracts that amount from the private note instead of the full reserved cap, ensuring neither party can later modify the bill. Under the hood, the system relies on Groth16 zero-knowledge proofs over the BN254 curve, Poseidon hashes for commitments and nullifiers, and notes held inside a 32-level Merkle tree. Spend proofs are checked off-chain by the server, while the vault contract verifies equivalent proofs at deposit, closure, and withdrawal — meaning users can still exit with their funds even if every zkAPI server disappeared.

What zkAPI Protects — and What It Doesn’t

This is where the design gets interesting, and where it matters for anyone weighing how much privacy they’re actually getting. Knowledge in the system is clearly divided among three parties: the zkAPI server is aware that a valid payment was made and knows the session’s dollar total, yet remains unaware of the payer’s identity or the content of the request. Since it must run the model, the AI provider views the prompts and responses but has no knowledge of who is paying, while the public Ethereum chain logs deposits, closures, and withdrawals without revealing how any balance was actually used.

On-Chain Privacy for Payments

That split is the whole point of the design. It means the billing relationship — the part most vulnerable to profiling — is cryptographically walled off from both the content of a request and the identity behind it. The same client and contracts could, in theory, front other metered services too, including blockchain RPC queries, image or video generation jobs, VPN bandwidth, or machine-to-machine transactions, hiding the funding link in each case the same way it does for AI requests.

Gaps in Content and Network Metadata Privacy

Here’s why this matters for anyone assuming zkAPI makes their AI usage fully anonymous: the protections stop at the payment link. The AI provider still sees the actual content of every request, and it still observes network metadata such as IP addresses. A provider could, in principle, try to correlate sessions by timing patterns, or by spotting recurring personal details, writing style, or conversation history embedded in the prompts themselves. Real network anonymity would require a separate layer, such as routing traffic through Tor with a fresh circuit per session, and content privacy remains a separate, still-developing problem that techniques like confidential computing are only beginning to address.

In other words, zkAPI solves the billing-identity problem specifically — it doesn’t claim to solve anonymity end to end. For developers and users evaluating it, that distinction is the difference between “no one can link my payment to my identity” and “no one can see what I’m doing at all.” Those are two very different promises, and only the first one is what’s live on Ethereum right now.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!