RFC 0x20CCPRIVATE SESSIONOctober 2026
Network Working Group
Request for Comments: 0x20CC
Category: Standards Track
PRIVATE SESSION
October 2026
Ethereum, chain id 1

PRIVATE SESSION

zkAPI for the Pool

A dark door in a slate wall, its reeded glass pane lit amber from inside, a line of light beneath it.
A closed door on a public pool.

Abstract

Deposit once, in public. Trade in private sessions that point at nobody. Withdraw only to yourself.

zkAPI lets a person pay for an API without being known: deposit once, then authorize each session of use with a zero-knowledge proof. On Ethereum the most used API is the pool. PRIVATE SESSION is zkAPI for the pool, and its server is a contract with no owner.

Status of This Memo

Not launched This memo describes a protocol that is not deployed yet. The figures in section 1.4 are read from Ethereum as this page loads; until the contracts exist, every one of them reads nil.

PRIVATE SESSION is not affiliated with zkAPI, the Ethereum Foundation or the Open Anonymity Project. It has no owner, no admin and no upgrade path, and it has not been audited.

Table of Contents

1.Introduction

1.1.The Idea

zkAPI (the Ethereum Foundation and the Open Anonymity Project, October 2026) separates paying for an API from being known to it. You deposit into a vault contract once. From then on, each session of use is authorized by a proof that your private balance covers it. The proof says that some deposit pays. It does not say which.

The API most used on Ethereum is not a model. It is the pool: every swap is a metered call to a Uniswap contract, and every call is signed by somebody. PRIVATE SESSION puts zkAPI's shape around one pool, ETH / SESSION on Uniswap v4, and makes the server a contract that nobody runs.

a sessionas the chain sees it (an illustration)
sent byany address here, a relayer it repays
paid from a proof names no note
holds0.52 ETH public
programbuy with 0.5 ETH, now public
returns to a commitment
belongs to nobody can say

1.2.What the Server Learns

zkAPI's server is software run by an operator; this one is a contract, so whatever it learns, everybody learns. The comparison below is the whole point of the design.

zkAPIPRIVATE SESSION
meteredcalls to an AI modelswaps on one Uniswap v4 pool
the servera service, run off chaina contract with no owner
a depositpublic, into a vault contractpublic, into the Server: who, how much, when
a sessiona short-lived API key, capped in dollarsa program of up to 8 orders, capped by what it reserves, 30 days at most
it learnsthat a valid payment exists, and the total per sessionevery session in full: its program, trades and balances
it never learnswho you are, what you asked, which deposit paidwhich note paid, which sessions are yours, which deposit a withdrawal came through
the contentseen by the provider, not the payerthe trades are public; the trader is not
withdrawalclose the balance on chaina proof, paid only to the address that deposited
proofsGroth16 over BN254, checked by the serverPS-PLONK over BLS12-381, checked on chain by the EIP-2537 precompiles
the setupsingle-party, per its own repositoryEthereum's KZG ceremony: 141,416 contributions
zkAPI, as described in its announcement (blog.ethereum.org, 1 October 2026) and in the ethereum/zkapi repository. Not affiliated.

1.3.How It Works

   YOUR DEVICE                        ETHEREUM

   +----------------+                 +--------------------------------+
   | your app       |   (1) deposit   | the Server            no owner |
   | (this page)    |---------------->|                                |
   +-------+--------+    in public    | notes      hidden balances,    |
           |                          |            a Poseidon tree     |
           | (2) the secret           |                                |
           |     stays here           | sessions   public accounts,    |
           v                          |            owned by nobody     |
   +----------------+                 |                                |
   | your prover    |   (3) proof     |                                |
   | (a Web Worker) |---------------->|                                |
   +----------------+  from any       +------+-------------------^-----+
                       address               |                   |
                                         (4) | fire          (5) | toll
                                             v                   |
                                      +--------------------------+-----+
                                      | the pool        ETH / SESSION  |
                                      | Uniswap v4      hook: Meter    |
                                      +--------------------------------+
 +--------------+
 | your app     |
 +--+--------+--+
    |        | (2) the secret
    |        |     stays here
    | (1)    v
    |    +--------------+
    |    | your prover  |
    |    +------+-------+
    |           | (3) proof and
    |           |     program
    v           v
 +--------------------------+
 | the Server   no owner    |
 | notes      hidden        |
 | sessions   public        |
 +-----+--------------^-----+
       |              |
       | (4) fire     | (5) 2% toll
       v              |
 +--------------------+-----+
 | the pool   ETH / SESSION |
 | Uniswap v4, the Meter    |
 +--------------------------+
Figure 1: a private session, from deposit to withdrawal
  1. A deposit is public: who, how much, when. The contract writes the depositing address into the note as its tag, so the note can only ever be paid out there.
  2. The note's secret is derived from one signature of your wallet and never leaves this device.
  3. A proof moves part of a note into a session with a program. The proof names no note and no deposit. Any address MAY submit it, and a relayer is repaid from the session.
  4. Anyone MAY fire an order whose conditions hold, and is paid gas plus at most 1 gwei a unit of it, from the session.
  5. Every swap on the pool pays 2% of its ether leg to the Server, which streams it over one day to hidden SESSION: the crowd that hides you is paid by the trading.
  6. When the program is done, or the session expires, it closes, and what it holds becomes a fresh note of the same tag.
  7. A withdrawal is a proof too. It pays only to the address that deposited, so no value moves between people except through the pool, as a trade.

1.4.The Numbers

Read from Ethereum as this page loads. Nothing here is estimated.

  • hidden SESSIONnil
  • notes in the treenil
  • nullifiers publishednil
  • sessions openednil
  • tolls received, all timenil
  • streaming to hidden SESSIONnil
  • the stream runs untilnil
  • cover accumulator, accnil
  • read at blocknil

1.5.Requirements Language

The key words MUST, MUST NOT, SHOULD and MAY on these pages are to be read as in RFC 2119. They describe what the contracts enforce, not what anyone promises.

To start, open Notes (page 2). To check the cryptography before you trust it, read Trust (page 5) first.