The Ethereum Foundation announced that zkAPI, a system developed with the Open Anonymity Project, is now live on Ethereum mainnet. The protocol allows users to pay for AI and other API services without disclosing their billing identities. Users deposit funds into an Ethereum vault and utilize zero-knowledge proofs to demonstrate sufficient credit for API requests without linking specific deposits to individual users. Vittorio Rivabella, AI coordinator at the Foundation’s dAI team, detailed the mechanism in a recent post.
The system issues short-lived API keys with predefined spending limits, sending prompts directly to providers while settling usage separately through the payment layer. A local client, software development kit, and browser-based AI chat implementation have also been released. This launch operationalizes a February proposal by researcher Davide Crapis and co-founder Vitalik Buterin for ZK-based API usage credits. However, the Foundation noted that zkAPI does not conceal prompt contents or network metadata from providers, meaning users may still be linked across sessions via IP addresses, timing, or request information.
The deployment of zkAPI marks a tangible shift toward integrating privacy-preserving infrastructure directly into mainstream blockchain utility layers. By leveraging zero-knowledge proofs to decouple payment identity from service consumption, the Ethereum Foundation addresses a critical friction point in the emerging machine-to-machine economy. This architecture enables institutional and individual users to access metered AI services without exposing sensitive financial relationships, potentially lowering barriers to adoption for entities concerned about data sovereignty and competitive intelligence leakage. The move signals a maturation of privacy tools beyond simple transaction obfuscation, targeting complex application-level interactions where metadata and billing trails are significant privacy vectors.
Despite the technical achievement, the explicit limitation regarding prompt content and network metadata reveals a nuanced compliance and risk landscape. While billing identities remain hidden, the persistence of linkage risks through IP addresses and timing suggests that true anonymity is not achieved, only pseudonymous separation of financial and operational layers. For enterprises evaluating this infrastructure, the residual traceability implies that regulatory scrutiny or adversarial analysis could still reconstruct user activity patterns. Consequently, the value proposition lies less in absolute anonymity and more in reducing the attack surface associated with traditional payment integrations, requiring careful assessment of how these partial privacy guarantees align with broader data protection obligations.


