Paying for an API without an account
The Ethereum Foundation's zkAPI turns a deposit into private notes, so a provider can be paid without learning who is paying.
2 minZero-Knowledge ProofsFresh · 1 Oct
The Ethereum Foundation has introduced zkAPI, a way to buy metered API usage without the billing trail that normally ties every request to an identity. A user deposits credits into a vault contract on Ethereum in one ordinary transaction. From then on the balance lives as a private note, and spending it means producing a zero-knowledge proof that a funded note covers the spend and has not been spent before.
Two primitives keep that both private and safe. Deposits are commitments in a Merkle tree, so a proof can show membership without pointing at a particular deposit. Every spend publishes a nullifier, a one-way serial number derived from the note's secret: staying within the balance stays unlinkable, while trying to spend twice produces a duplicate nullifier that exposes the attempt and nothing else. The implementation uses Groth16 on BN254, Poseidon for commitments and nullifiers, and a tree 32 levels deep.
Two parties, neither of which sees both halves
The flow splits money from content. A local client sends the zkAPI server a payment proof carrying no prompt and no identity; the server mints a fresh API key, short-lived and capped in dollars, which exists only in the device's memory. Prompts then go straight from the device to the AI provider. When the key expires, the provider returns a signed receipt of actual usage and the server deducts that amount rather than the reserved cap. The payment server learns that a valid payment exists and the dollar total; the provider learns the prompts but not who pays.
Because the vault is a contract rather than a company account, a user can close a balance and withdraw on chain even if every zkAPI server disappears, and the client speaks the standard OpenAI and Ollama APIs so existing tools work by pointing them at localhost.
The Foundation names the limits rather than leaving them to be discovered. A provider still sees request contents and network metadata such as an IP address, and can attempt to correlate sessions by timing. Network anonymity and content privacy are separate layers, and the suggested answer for the first is Tor with a fresh circuit per session.
Retold from Ethereum Foundation. This is a summary in our own words; follow the link for the original reporting.