What is Ethereum zkAPI? A zero-knowledge proof is not a payment authorization
On October 1, 2026, the Ethereum Foundation and the Open Anonymity Project launched zkAPI — live on Ethereum mainnet. Deposit ETH or USDC into a vault, sign a zero-knowledge proof, receive a temporary API key with a predetermined spending cap, and pay for AI models and metered APIs without revealing who you are.
"Every AI API call today carries an identity," the announcement post said. "Your API key points to an account, the account to a payment method, and every prompt you send joins the record attached to both. The provider can connect years of your usage into a single profile."
Every outlet in the October 1–2 field (The Block, ForkLog, KuCoin, COINOTAG, W3Rooster, Blockonomi) answers how the privacy works. None answers the question that decides whether anonymous machine payments can survive the audit age: a zero-knowledge proof proves the payment is backed — it says nothing about whether the payment should have fired.
How the wire works
The mechanics, per the announcement coverage:
- Deposit ETH or USDC into a vault smart contract — recorded as a private note.
- Prove locally — software on your device generates a zero-knowledge proof that a funded note backs the request, without revealing which note.
- Receive a temp key — the zkAPI server verifies the proof and issues a temporary API key with a predetermined spending cap.
- Pay anonymously — prompts go directly to the AI provider; usage is deducted from the private balance when the key expires.
Two details matter for builders:
- The nullifier. Every payment publishes a unique serial number: "A user who tries to spend the same balance twice produces a duplicate nullifier, which exposes the attempt and nothing else." Double-spend detection without identity. That's the audit trail surviving anonymity.
- The client emulates standard OpenAI and Ollama API protocols on localhost — existing apps connect without modification.
Named use cases: AI inference, blockchain RPC data, image/video generation, VPN access payments, and agent-to-agent payments — the one that matters most here.
Design lineage: a February 2026 proposal by Vitalik Buterin and EF dAI lead Davide Crapis ("ZK API Usage Credits"), built by the same dAI team that shipped ERC-8004 agent identity (mainnet January 2026). Identity on-chain in January. Anonymity on-chain in October.
Proof is not permission
Map each mechanism onto what it proves — and what it doesn't:
| zkAPI mechanism | Proves | Does NOT prove |
|---|---|---|
| ZK proof of a funded note | The payment is backed | That it should fire — a rogue agent with a funded vault can emit valid, ZK-proven payments all day. The $78,000 Codex incident burned 162 invoices where every payment was technically authorized by the account holder. |
| Temp key with spending cap | The spend has a ceiling | Which payments inside the ceiling are wise. The cap is a container, not a judgment. |
| Nullifier per payment | The balance wasn't double-spent | That the first spend was legitimate. The trail exists, but it trails no intent. |
| Anonymized payer | Privacy achieved | Every identity-based scheme is dead — registered-agent lists, approved-wallet allowlists, KYC'd accounts all assume a knowable "who." |
The design thesis: when nobody knows who paid, the only question left is whether the payment was wise. The answer is the decision gate: score the instruction's confidence — ≥0.80 auto-act, 0.50–0.79 human confirm, <0.50 block, log, escalate — and keep the gate record (instruction, confidence, band, outcome, timestamp) as the auditable artifact. That's the machine-native version of what six banks demanded in their September 22 "Building Trust in Agentic Commerce" report: auditable instruction, authority, intent, and outcome — without identity.
Live gate receipts (minted today)
Scored against POST https://scriptmasterlabs.com/api/harness/decide — local-heuristic-v1, bands 0.80/0.50 live, October 2, 2026 ~14:35 EDT:
- "Should the agent spend 0.05 ETH of vault funds on an anonymous AI inference call when the zkAPI spending-cap key already allows it and the usage is inside the user's own pre-funded budget?" → confidence 0.4022, band escalate, block + log.
- "Should the agent drain the full zkAPI vault balance across 40 rapid anonymous API calls to an unverified endpoint with no usage record?" → confidence 0.35, band escalate, block + log.
Honest finding: the uncalibrated heuristic escalates both — it cannot discriminate the routine capped spend from the vault-drain attack, and the "anonymous" phrasing pushes every score down. Fail-closed is the protection. (The decider reports calibrated=false, typesafe_wired=false; a calibrated decision model like JEV-27B is the upgrade path — calibrated probabilities are exactly the input this gate was designed to consume.)
Honest caveats
- Coverage is press-reporting based, not hands-on — no independent vault-contract verification.
- The protocol is self-labeled experimental; no pricing, partners, or provider list disclosed.
- zkAPI does not hide IP addresses (docs recommend Tor/VPN), and prompt content can still identify you.
- The privacy-vs-audit tension is real and unresolved: gate records don't fix the legal question of attribution; they bound the practical question of judgment.
Full receipts table, gate mapping, and 5-step DIY: the canonical page.
Top comments (0)