Ethereum’s zkAPI Aims to Separate AI Payments From User Identity, but Not Hide Prompts
zkAPI is designed to make AI API payments harder to link directly to a user’s funding source. It does not hide prompts from a hosted AI provider. The model still needs to receive them.
- Launch: The Ethereum Foundation and Open Anonymity Project said zkAPI went live on Ethereum mainnet on October 1, 2026.
- Privacy goal: Use zero-knowledge proofs to authorize API spending without exposing the funding record as an ordinary billing identity.
- Key limit: Prompt content and network metadata can still identify or link activity.
- Still to establish: Real-world anonymity, security review, data retention and metering protections.
What zkAPI is intended to change
With conventional AI APIs, users commonly make requests with an account-linked API key. That can let a provider connect usage to its billing records. zkAPI works differently: users fund credits through an Ethereum vault, then use zero-knowledge proofs to authorize spending without presenting the funding record directly as their API billing identity.
A zero-knowledge proof can show that a condition is true without revealing the information used to prove it. Here, the intended claim is that a user has valid credits to pay for API access. EthDaily reports that zkAPI is live on Ethereum mainnet and describes it as a system that separates payment from API use.
That is a more limited promise than anonymous AI. The proof addresses information in the payment flow, not data sent outside it. A hosted model needs the prompt to generate a response, so its provider receives it. The available reporting does not establish that a provider can never connect a request to a person or other activity.
API compatibility is not the same as where a model runs
EthDaily reports that zkAPI includes a local client compatible with OpenAI and Ollama APIs. That describes how software communicates with the client. It does not mean OpenAI and Ollama handle prompts in the same way.
A hosted model provider receives prompts sent to its service. Ollama can also run models locally, so prompts sent to a local model need not go to an outside AI provider. That distinction matters. Privacy depends in part on the model and routing a user chooses, not just the API format.
The available reporting does not establish whether every client or integration uses the same routing setup, or fully document what each service can observe. Before assuming a setup keeps prompts, network details or other data away from an intermediary, users should check the current product documentation.
Payment privacy is not network or content privacy
There are at least three separate questions: who can connect API use to a payment, who can identify a network connection, and who can read the prompt. zkAPI’s stated focus is the first. It does not, by itself, answer the other two.
An IP address, request timing, repeated usage patterns or distinctive details in a prompt may help connect activity to a user. A provider may also keep requests under its own policies. The available information does not establish how long providers retain prompts or what telemetry the zkAPI client collects.
Practical privacy also depends on how large and varied the group is that a user can blend into, known as the anonymity set. A cryptographic system may be designed to conceal which funded credit was used, but that does not tell us how many people have funded credits or whether their activity looks alike. The launch reporting does not establish a verified user count or a measured anonymity set. For a plain-language explanation of the cryptography, see how zero-knowledge proofs work.
Onchain records and billing still need scrutiny
Ethereum records transactions publicly. The report on zkAPI’s privacy-preserving API payments says users can deposit credits and withdraw remaining balances onchain. Those transactions are visible. The privacy question is whether they can be linked to later API activity. EthDaily’s report also describes the withdrawal option, but users should review the deployed contract and its exit conditions rather than assume that any onchain exit is risk-free.
EthDaily says users pay for what they use instead of losing an entire spending cap. That sounds useful, but the reporting does not explain how metering is verified, how failed requests are handled, or how users can challenge an incorrect charge.
If a system uses signed usage records, a signature can help verify who issued a record and whether it was changed. But a signature alone does not prove that the usage or price was measured correctly. Clear settlement and dispute rules matter just as much as the cryptography.
Independent review is another unanswered question. A useful assessment would cover the vault contract, proof system, client, routing, data storage and billing process. The launch reporting does not establish the scope or results of an independent security review.
What to know about zkAPI
-
Does zkAPI hide prompts from a hosted AI provider?
No. A hosted provider receives the prompts it processes. A locally run model, such as an Ollama setup, may keep prompts on the user’s machine, depending on the configuration.
-
What privacy goal does zkAPI pursue?
It aims to make API spending less directly linkable to its funding source. That does not automatically conceal an IP address, prompt details or usage patterns.
-
Are deposits and withdrawals invisible on Ethereum?
No. Ethereum records transactions publicly. Whether those records can be linked to API activity is a separate question.
-
What should users check before relying on it?
Confirm which routing options are active, what data the client and providers retain, how usage is metered, whether an independent review exists, and how withdrawals and billing disputes work.
Separating payment from API access gives cryptography a meaningful privacy use, but it does not make an AI conversation private. The practical test is whether users can verify who sees what, understand the limits of each configuration, and judge whether the real user pool offers meaningful cover. Until those details are clear, “private AI payments” is more accurate than “private AI.”