zkAPI Zero Knowledge Proofs: Private AI Payments Explained

Share
zkAPI Zero Knowledge Proofs: Private AI Payments Explained

Picture a nurse asking an AI model about a patient's rare condition late at night. Or a founder testing a pitch for a company nobody knows about yet. Or someone quietly researching a diagnosis of their own. Every one of those prompts goes out with a name attached, because the API key that pays for it is tied to a credit card, an email address and a billing address.

That is the problem zkAPI was built for. zkAPI applies zero knowledge proofs to an everyday job, paying for an API, so that the service gets paid without learning who paid. It went live on Ethereum mainnet on October 1, 2026, according to the Ethereum Foundation's launch announcement, and was built with the Open Anonymity Project.

This guide assumes you have never touched cryptography. By the end you'll know what a zero-knowledge proof is, how zkAPI uses one, and the three things it can't hide from anyone.

Key Takeaways:zkAPI is a private payment system for metered APIs such as AI models, launched on Ethereum mainnet on October 1, 2026 by the Ethereum Foundation and the Open Anonymity Project.A zero-knowledge proof lets you prove a statement is true, such as "I have enough funds," without revealing the information behind it.zkAPI separates who pays from what is asked: the payment server never sees your prompts, and the AI provider never learns who paid.zkAPI does not hide your prompt content, your IP address, or patterns that link one session to the next, as CryptoPotato's coverage points out.Users can withdraw unspent funds straight from the zkAPI vault contract, even if zkAPI's servers stop running.

Table of Contents

What Is zkAPI?

zkAPI is an Ethereum-based payment system that lets you pay for API calls, such as requests to an AI model, using a cryptographic proof instead of an account tied to your identity. The "zk" stands for zero-knowledge. The "API" stands for application programming interface: the door software uses to talk to a service like a chatbot, an image generator or a data feed.

The Ethereum Foundation's dAI team, with researcher Vittorio Rivabella leading the work, built it alongside the Open Anonymity Project. Tangem's report on the launch describes it as a live mainnet deployment, not a testnet experiment. In other words, real money is involved.

The idea underneath it is short enough to put on a sticky note: The people who handle your money shouldn't see your questions, and the people who answer your questions shouldn't see your money. Most online services link those two things on purpose, because your billing record is the account. zkAPI deliberately splits them apart, much like other privacy-focused systems such as Zcash separate payment identity from transaction details.

What Is a Zero-Knowledge Proof, in Plain English?

A zero-knowledge proof (ZKP) is a way to convince someone that a statement is true without telling them anything except that it's true. MIT researchers Shafi Goldwasser and Silvio Micali, together with Charles Rackoff, introduced the idea in their 1985 paper "The Knowledge Complexity of Interactive Proof Systems". For decades it was mostly a subject for theory classes; only in the last ten years or so has it started running inside actual products.

The nightclub analogy

A bouncer needs to know you're over 21. Today you hand over a driver's licence, which also shows your name, home address, exact birthday and organ-donor status. That's far more than the bouncer needs. Now imagine a magic card that lights up green only when its holder is over 21, and that nobody can forge. The bouncer sees green and lets you in. That's all they learn. A zero-knowledge proof does the same job with math.

The three properties that make it work

  • Completeness: if the statement is true, an honest prover can always convince the verifier.
  • Soundness: if the statement is false, a cheater can't convince the verifier (except with a vanishingly small probability).
  • Zero-knowledge: the verifier learns nothing beyond the fact that the statement is true.

For zkAPI, the statement being proved is roughly: "I own an unspent balance in this system that's big enough to cover this request." The server checks that claim. It never learns which balance is yours.

Why Do AI Payments Need Privacy?

AI payments need privacy because a billing record plus a prompt history adds up to one of the most revealing profiles of a person that can exist. A search history shows what you looked for. A prompt history shows what you were thinking about, often in full paragraphs, sometimes with your medical records, contracts or source code pasted in.

With a normal API key, every request is labelled with the key, the key is labelled with an account, and the account is labelled with a card. That chain is very convenient for the provider. It also means that if anyone gets access to the provider's logs, through a breach, a subpoena or an insider, they get a full transcript with your name on it.

There's a second reason, which matters more for crypto: AI agents. More and more software agents make API calls by themselves and pay per request. An agent with a corporate credit card leaks its owner's strategy one call at a time. Private cryptocurrency payments for AI let an agent buy compute without broadcasting who is behind it.

From where we sit, building payment infrastructure, this is the less glamorous half of "crypto meets AI" that tends to get missed. The hard part of machine-to-machine payments isn't moving value. It's moving value without leaking metadata. Public blockchains are very good at the first job and very bad at the second.

How Does zkAPI Work, Step by Step?

zkAPI works by turning an ordinary on-chain deposit into a private "note" that only your device knows about, then spending that note through zero-knowledge proofs. Here's the full flow, based on the Ethereum Foundation's technical description.

Six zkAPI steps: deposit to the vault, private note, ZK proof, temporary key, request to the AI provider, nullifier and withdrawal.
Only the deposit links to your wallet. After that, you spend with proofs, not your identity.
  1. Deposit. You send ETH, USDC or another supported asset to the ZkAPIVault smart contract on Ethereum. This is a normal, public transaction. Apart from any later withdrawal, it's the only step where your wallet is visibly involved.
  2. Get a private note. Your balance becomes a commitment, which you can think of as a sealed envelope whose contents only you can open. The commitment is added to a Merkle tree, a data structure that compresses thousands of envelopes into one short fingerprint. The note itself lives only on your device.
  3. Generate a proof. When you want to use an AI service, your device builds a zero-knowledge proof that says: "one of the envelopes in this tree is mine, it holds enough money, and it hasn't been spent." One proof can cover a single request or a whole session.
  4. Get a temporary key. The zkAPI server checks the proof. If it's valid, the server issues a short-lived API key with a capped dollar limit. The server doesn't know which envelope you used.
  5. Send your request. Your device sends the prompt and the temporary key to the AI provider. The provider sees a valid, paid-up key with no name on it.
  6. Settle and prevent double-spending. Metered usage is later settled against your private balance. A nullifier, a one-way serial number derived from your note's secret, is revealed so the same funds can't be spent twice, and it can't be traced back to the original deposit. When you're done, you can withdraw what's left straight from the vault contract, even if zkAPI's servers go offline.

An analogy: arcade tokens with amnesia

You swap cash for tokens at the arcade counter. The cashier sees your face. Once the tokens are in your pocket, though, the machines can't tell whose they are. zkAPI goes one better: you never hand over a physical token, only proof that you have one, so nothing you spend can be traced back to the cash you paid at the counter.

The cryptography under the hood

For readers who want the names, the published technical details list these components:

  • Groth16 proofs: a proof system from Jens Groth's 2016 paper, known for producing very small proofs that are cheap to verify.
  • BN254 elliptic curve: the curve Ethereum supports natively through built-in precompiled contracts, which keeps verification costs low on-chain.
  • Poseidon hashing: a hash function designed specifically for ZK circuits, many times cheaper to prove than SHA-256.

What Does zkAPI Hide, and What Doesn't It?

zkAPI hides the link between your payment and your requests. It doesn't hide the requests themselves. Of everything in this article, this is the point most worth remembering.

Matrix of what Ethereum, the zkAPI server and the AI provider can see. Nobody sees which deposit paid, but the provider sees prompts.
zkAPI cuts the payment-to-request link. Prompts, IP and timing can still be seen.

Here's who can see what:

InformationEthereum (public)zkAPI serverAI provider
Your deposit wallet and amountVisibleVisibleNot visible
Which deposit funds a given requestHiddenHiddenHidden
Your prompt contentHiddenHiddenVisible
Your IP addressN/AVisible unless maskedVisible unless masked
Timing and frequency of requestsHiddenPartially visibleVisible
WithdrawalsVisibleVisibleNot visible

The three things zkAPI cannot hide, as CryptoPotato's analysis notes, are your prompts, your network address, and session linkage. Your prompts must be readable by the AI provider to be answered. Your IP address travels with every request unless masked with a tool like Tor. Reused conversation history, recognisable writing style, personal details in prompts and regular timing patterns can tie "anonymous" sessions back together.

The way we'd put it: the prompt is the fingerprint. Perfect payment privacy does nothing for you if you paste your CV into the chat window. zkAPI fixes the billing leak. It can't fix what you type.

How Does zkAPI Compare to Other Ways of Paying?

zkAPI is the only option in this comparison built for private, per-request payments with payment and content separated by design, but it needs a crypto deposit and offers no protection for content. Here's how it compares with the alternatives most people would think of first.

Matrix of five ways to pay for an API by payment privacy, content privacy and separation. Only zkAPI separates them by design.
zkAPI is the only option built to separate payment from content. None of them protect your prompts.
MethodPayment privacyContent privacyPayment and content separated?Needs crypto?Main weakness
Standard API key + credit cardNoneNoneNo, fully linkedNoFull identity on every request
Prepaid gift card for API creditsPartialNonePartlyNoAccount email and IP still link usage
Plain on-chain crypto paymentNone, publicly traceableNoneNoYesEvery payment visible on a public ledger
Privacy mixer, then payYes (via mixing)NoneYesYesRegulatory risk; doesn't solve per-request metering
zkAPIYes (cryptographically proven)NoneYes, by designYesPrompts, IP and timing still visible to provider

The mixer row is worth a moment. Anonymous blockchain transactions have a complicated regulatory history: the U.S. Treasury sanctioned Tornado Cash in August 2022, then lifted those sanctions in March 2025. zkAPI is a different kind of product, since it pays for a service rather than breaking up the trail of transferred funds. Its deposits and withdrawals still sit on a public ledger, which regulators can see.

What Are Other Zero Knowledge Proof Use Cases?

Zero-knowledge proofs already protect private payments, compress blockchain transactions and verify identity attributes, and zkAPI adds paying for metered services to that list. Some well-known examples:

Use caseWhat gets provedReal-world example
Private payments"This transaction is valid" without revealing sender, receiver or amountZcash, launched in 2016
Blockchain scaling (zk-rollups)"These thousands of transactions were executed correctly"zkSync, Starknet, Scroll (tracked on L2BEAT)
Identity and age checks"I'm over 18" or "I'm a citizen" without showing the documentZK passport and credential projects
Private voting"I'm an eligible voter and voted once" without revealing the voteGovernance experiments in DAOs
Private API payments"I have an unspent balance large enough for this request"zkAPI (October 2026)

One distinction trips up a lot of beginners. Not every cryptographic proof is a zero-knowledge proof. Bitcoin's SPV (Simplified Payment Verification) proofs, for example, show that a transaction was included in a block, and they reveal the transaction while doing it. They're about verifiability, not privacy. Both kinds swap trust in people for checkable math, but they solve different problems.

What Are the Risks and Limitations?

zkAPI's biggest risks are a small anonymity set, dependence on a central server for verification, and the habits of the people using it. Here they are one at a time.

1. The anonymity set starts small

A zero-knowledge proof hides which deposit you're using, but only among the deposits that exist. If just 40 people have deposited, you're one of 40. Suppose you deposit an unusual amount, such as 137.42 USDC, and an equally unusual withdrawal shows up two days later. Someone watching the chain can probably connect the two. Privacy systems get stronger as more people use them, so the first adopters get the least protection.

2. A centralized verification server

Proof verification and temporary-key issuance run through the zkAPI server. If it goes down or gets censored, you can't make new requests. Your funds remain withdrawable, because withdrawals go directly through the vault contract, but the service stops. The launch materials don't describe a decentralized fallback.

3. Cryptographic assumptions

Groth16 usually needs a one-off "trusted setup" ceremony for each circuit. If every participant in that ceremony colluded, they could in theory forge proofs. The launch coverage we reviewed doesn't describe zkAPI's setup ceremony, so check the project's documentation before depositing a significant sum. Separately, BN254's estimated security level fell from about 128 bits to roughly 100 bits after improved attacks published by Kim and Barbulescu. That's still far out of reach for practical attacks today, but it's a known compromise made in exchange for cheap verification on Ethereum.

4. Your device is part of the security model

Your private note lives on your device. If malware takes it, it can spend your balance and connect your sessions. Lose the device without a backup, and you may lose access to the note.

5. Compliance friction

AI providers that take zkAPI payments will know less about who their customers are. Depending on where they operate, that could make KYC, tax reporting or sanctions screening harder. Expect some providers to wait and see how regulators respond.

How to Use zkAPI Without Leaking Your Identity

To get real privacy out of zkAPI, pair it with network privacy and careful habits, because the cryptography only protects the payment layer. Here's a checklist:

  1. Deposit round, common amounts. 50 or 100 USDC blends in. 73.18 doesn't.
  2. Wait before you use it. Leave some time, and let other deposits arrive, between depositing and your first request.
  3. Use Tor, with a fresh circuit for each session. The zkAPI developers recommend this for hiding your IP address.
  4. Start every session clean. Don't carry conversation history across sessions.
  5. Keep identifiers out of your prompts. No names, employers, addresses or unique documents.
  6. Don't withdraw the exact amount you deposited, right after depositing it. That pattern links the two ends.
  7. Back up your private note securely. It's effectively your money.

What if your crypto is in Bitcoin?

zkAPI's vault runs on Ethereum, so you'll need ETH or USDC there first. If you hold Bitcoin, one route is TeleSwap, a Bitcoin bridge that verifies BTC deposits with SPV light client proofs instead of custodians. It can swap BTC to USDC on Ethereum or BTC to ETH in one step, and fast swaps settle in about 10 minutes. The bridge has handled $500.6M in volume across 531,371 transactions, according to TeleSwap network stats.

Be honest with yourself about the trail, though. A bridge transaction is public on both chains, exactly like a zkAPI deposit. Treat the swap as the "cash at the arcade counter" step and follow tips 1, 2 and 6 above, so the swap and your later activity aren't easy to match up.

Frequently Asked Questions

What is zkAPI?

zkAPI is a private payment system on Ethereum that lets you pay for API services, such as AI models, using zero-knowledge proofs instead of an identity-linked account. The Ethereum Foundation and the Open Anonymity Project launched it on Ethereum mainnet on October 1, 2026. You deposit crypto once, and after that you pay for requests without revealing which deposit is yours.

Is zkAPI completely anonymous?

No. zkAPI only hides the link between your payment and your requests. The AI provider can still read your prompts, see your IP address unless you use something like Tor, and potentially connect your sessions through writing style, reused context or timing. Your initial deposit and any withdrawals are also public on Ethereum.

Do I need cryptocurrency to use zkAPI?

Yes. You need to deposit crypto, such as ETH or USDC, into the zkAPIVault contract on Ethereum. The deposit is a single ordinary on-chain transaction. After that, the balance becomes a private note stored on your device, which you spend through zero-knowledge proofs.

What happens to my money if zkAPI's servers shut down?

You can still withdraw your remaining balance directly from the vault smart contract. The zkAPI servers handle proof verification and temporary API keys, but your funds sit in the on-chain contract, not with the server operator. If the servers go offline, you can't make new requests, but your money is still recoverable.

How is zkAPI different from a crypto mixer?

A mixer hides where transferred funds came from, while zkAPI hides who is paying for a specific service request. zkAPI is built for metered usage. It issues capped, short-lived API keys and settles usage against a private balance. Its deposits and withdrawals stay visible on Ethereum, so it isn't designed to obscure the source of funds.

What are the most common zero knowledge proof use cases?

The most common uses are private payments, blockchain scaling with zk-rollups, identity checks, private voting, and now private API payments. Zcash has used zero-knowledge proofs for shielded transactions since 2016. zk-rollups such as zkSync and Starknet use them to prove that large batches of transactions were executed correctly.

Can I pay for zkAPI with Bitcoin?

Not directly. zkAPI accepts deposits on Ethereum, so Bitcoin holders first need to convert BTC into ETH or USDC on Ethereum. A cross-chain bridge or swap can handle that step. Keep in mind that the conversion is public on-chain, so use common amounts and leave time between swapping and depositing.

Conclusion

zkAPI deals with one specific, real leak: the billing record that links your name to every question you ask an AI. With zero-knowledge proofs, Merkle-tree commitments and nullifiers, it lets an AI provider get paid without learning who paid, and keeps your prompts away from whoever handles the money.

It isn't an invisibility cloak. Your prompts, your IP address and your habits can still give you away, and the system's privacy only improves as more people use it. Used with Tor, clean sessions and sensible deposit habits, though, it's one of the most credible attempts so far at private cryptocurrency payments for AI.

If your savings are in Bitcoin and you want to try it, the first step is getting ETH or USDC onto Ethereum. You can do that in a single swap at TeleSwap, with fees paid in Bitcoin and verification that doesn't depend on a custodian.