On October 1, the Ethereum Foundation and the Open Anonymity Project announced the launch of zkAPI on Ethereum mainnet. This system enables users to prepay in USDC and receive capped, short-lived API keys through zero-knowledge proofs, effectively separating payment information from user identity. The design follows a February 2026 proposal by Davide Crapis, who leads the foundation's dAI team, and Vitalik Buterin. The protocol allows users to deposit credits into a vault contract, creating private notes that cannot be traced back to the original deposit. When requesting AI services, software generates a proof verifying sufficient funds without revealing details, which the server validates to issue a temporary key. The provider sees the prompt but not the payer, while the payment layer sees the cost but not the content.
The project documentation identifies OpenRouter as the AI provider behind the keys, supporting hundreds of models via one connection. This development addresses privacy concerns highlighted when a federal court ordered OpenAI to preserve deleted chat logs in May 2025 during a copyright lawsuit. The repository labels the protocol experimental and does not list a formal audit. Beyond AI, the infrastructure could support blockchain data queries, image generation, VPNs, and machine-to-machine payments, requiring providers to accept proofs instead of traditional API keys.
The introduction of zkAPI marks a structural shift in how decentralized infrastructure interfaces with centralized AI services. By decoupling financial settlement from data transmission, the protocol mitigates the risk of identity-linked surveillance that has become a significant concern following recent legal mandates on data preservation. This approach leverages Ethereum’s existing liquidity rails, specifically USDC, to create a compliant yet private transaction layer, potentially setting a precedent for other metered digital services where user anonymity is critical but regulatory oversight of fund flows remains necessary.
However, the experimental status of the protocol and the absence of a formal audit introduce substantial operational risks. While the cryptographic design theoretically prevents linkage between payment and prompt, the reliance on OpenRouter as a single integration point creates a potential bottleneck or failure vector. Institutional adoption will likely remain cautious until independent security assessments validate the implementation against real-world attack surfaces. Furthermore, the success of this model depends on broader acceptance by AI providers willing to integrate zero-knowledge verification rather than standard API keys, a transition that may face resistance due to increased technical complexity and compliance verification burdens.


