According to the Ethereum Foundation's announcement post, written by dAI team member Vittorio Rivabella, every AI API call today carries an identity. The API key points to an account, the account points to a payment method, and every prompt sent becomes part of a record tied to both. That design worked when humans typed the queries. It breaks down when millions of autonomous agents make purchases, and on October 1, the Ethereum Foundation shipped a working answer: a private payment system called zkAPI, now live on Ethereum mainnet.

Built with the Open Anonymity Project, zkAPI implements the "ZK API Usage Credits" design that Ethereum co-founder Vitalik Buterin and Ethereum Foundation dAI lead Davide Crapis published in February. The idea is simple to state and hard to build: deposit funds once, make thousands of API calls, stay unlinkable.

How zkAPI Separates Payment From Identity

The flow starts with a deposit. A user locks assets such as ETH or USDC into an on-chain vault contract, and their balance then exists as a private note. When an API call is needed, software on the user's machine generates a zero-knowledge proof showing that sufficient funds exist, without revealing which deposit the proof came from.

Once the proof verifies, the system issues a short-lived API key with a defined spending limit. Requests go directly to the AI provider under that temporary key. When the key expires, the metered usage settles against the private balance. The payment server therefore proves funds without ever seeing prompt content, while the AI provider sees prompts and responses without learning the billing identity behind them.

The design also prevents double-spending without de-anonymizing anyone. As reported by The Block, "a user who tries to spend the same balance twice produces a duplicate nullifier, which exposes the attempt and nothing else." And a single authorization can cover an entire session, so every request does not need its own on-chain transaction. Deposits, withdrawals, and balance closures touch the blockchain; routine spending proofs verify off-chain.

Agents Are the Real Audience

The launch announcement lists AI chat and agents as the first use case, alongside blockchain RPC queries, image and video generation, VPN bandwidth, and machine-to-machine payments between AI agents. That last category matters most. An agent that needs to buy services automatically currently has no good options: opening conventional accounts with every provider is slow and leaks identity, while raw on-chain payments expose the entire financial trail.

zkAPI gives agents funded credits and temporary credentials per task instead. A shopping agent can authorize one session with a hard spending cap; a research agent can burn through thousands of RPC queries without leaving a billing fingerprint. According to the launch documentation, the integration burden is deliberately low: "the client exposes the standard OpenAI and Ollama APIs on your own machine," so existing applications can point at the privacy layer without being rebuilt.

This is part of a broader 2026 program in which the Ethereum Foundation is organizing protocol work around scaling, user experience, and Layer-1 improvements. The same dAI team behind zkAPI, formed in September 2025 to make Ethereum the settlement and coordination layer for AI, also shipped ERC-8004, a standard for AI agent identity that went live on mainnet in January. Identity and payments are arriving as a matched pair.

The Privacy Limits Nobody Should Ignore

According to the Ethereum Foundation, zkAPI does not provide complete anonymity. The gateway can potentially correlate requests sent from a stable IP address, so users seeking stronger protection are advised to route traffic through Tor with a fresh circuit per session. Prompt content creates another link: personal details, writing style, reused conversation history, and project documents can let an inference provider associate separate sessions.

That distinction matters for agents, too. A deployment that keeps its billing identity private but reuses the same memory files and writing style across tasks may still be re-linkable by content alone. One mitigation the project suggests is generating requests on top of shared memory with local or TEE models rather than pasting history by hand. Privacy of payment, network, and content remain three separate problems, and zkAPI solves only the first.

The software is also still experimental. Wider use depends on developer integration, support from API providers, and real-world performance as usage scales. But the move from a February research proposal to a working mainnet implementation in eight months is a signal that private agent commerce has moved from theory to shipping code.

The Race for Agent Payment Rails Is Crowded

Ethereum is not alone in chasing this problem. According to industry coverage, Visa introduced Intelligent Commerce Connect in April, folding payment initiation, tokenization, authentication, and spending controls into infrastructure built for AI agents, and Mastercard answered with Agent Pay and Agent Connect. Both networks are betting that the winning rail is the one that enforces spending policy outside the model itself.

Crypto-native challengers are moving too. Verona, the network formerly known as XION, launched verUSD on September 28, a dollar stablecoin it describes as built for AI agents, arriving with more than $100 million in commitments. Cardano integrated with the x402 payment SDK to let agents pay in ADA without traditional checkout. Each approach makes a different bet: the card networks on permission and control, the stablecoin projects on programmability, and zkAPI on unlinkability.

That crowded field is itself the story. The agent economy is generating enough real transaction volume — agents now outnumber humans in web requests, and regulators are circling rogue agent incidents — that payment rails have become strategic infrastructure rather than back-office plumbing. Whoever controls how agents pay for compute, data, and services will shape what the agent internet is allowed to do.

Ethereum's wager is that privacy will be a feature agents and their operators demand rather than a compliance risk to avoid. Stanford researcher Ken Liu, participating in the Open Anonymity Project, described the launch as infrastructure that treats privacy and sovereignty as foundational, putting real control back in users' hands. Whether that vision wins against the card networks' control-first model is the experiment now running on mainnet.

Sources: the Ethereum Foundation's announcement post by Vittorio Rivabella; The Block's reporting on the launch and the February research design; Analytics Insight on the mainnet mechanics; MyToken on the verUSD launch.