Request for Comments: 0x20CC
Category: Standards Track
October 2026
Ethereum, chain id 1
PRIVATE SESSION
zkAPI for the Pool
Abstract
Deposit once, in public. Trade in private sessions that point at nobody. Withdraw only to yourself.
zkAPI lets a person pay for an API without being known: deposit once, then authorize each session of use with a zero-knowledge proof. On Ethereum the most used API is the pool. PRIVATE SESSION is zkAPI for the pool, and its server is a contract with no owner.
Status of This Memo
Not launched This memo describes a protocol that is not deployed yet. The figures in section 1.4 are read from Ethereum as this page loads; until the contracts exist, every one of them reads nil.
PRIVATE SESSION is not affiliated with zkAPI, the Ethereum Foundation or the Open Anonymity Project. It has no owner, no admin and no upgrade path, and it has not been audited.
Table of Contents
1.Introduction
1.1.The Idea
zkAPI (the Ethereum Foundation and the Open Anonymity Project, October 2026) separates paying for an API from being known to it. You deposit into a vault contract once. From then on, each session of use is authorized by a proof that your private balance covers it. The proof says that some deposit pays. It does not say which.
The API most used on Ethereum is not a model. It is the pool: every swap is a metered call to a Uniswap contract, and every call is signed by somebody. PRIVATE SESSION puts zkAPI's shape around one pool, ETH / SESSION on Uniswap v4, and makes the server a contract that nobody runs.
1.2.What the Server Learns
zkAPI's server is software run by an operator; this one is a contract, so whatever it learns, everybody learns. The comparison below is the whole point of the design.
| zkAPI | PRIVATE SESSION | |
|---|---|---|
| metered | calls to an AI model | swaps on one Uniswap v4 pool |
| the server | a service, run off chain | a contract with no owner |
| a deposit | public, into a vault contract | public, into the Server: who, how much, when |
| a session | a short-lived API key, capped in dollars | a program of up to 8 orders, capped by what it reserves, 30 days at most |
| it learns | that a valid payment exists, and the total per session | every session in full: its program, trades and balances |
| it never learns | who you are, what you asked, which deposit paid | which note paid, which sessions are yours, which deposit a withdrawal came through |
| the content | seen by the provider, not the payer | the trades are public; the trader is not |
| withdrawal | close the balance on chain | a proof, paid only to the address that deposited |
| proofs | Groth16 over BN254, checked by the server | PS-PLONK over BLS12-381, checked on chain by the EIP-2537 precompiles |
| the setup | single-party, per its own repository | Ethereum's KZG ceremony: 141,416 contributions |
1.3.How It Works
YOUR DEVICE ETHEREUM
+----------------+ +--------------------------------+
| your app | (1) deposit | the Server no owner |
| (this page) |---------------->| |
+-------+--------+ in public | notes hidden balances, |
| | a Poseidon tree |
| (2) the secret | |
| stays here | sessions public accounts, |
v | owned by nobody |
+----------------+ | |
| your prover | (3) proof | |
| (a Web Worker) |---------------->| |
+----------------+ from any +------+-------------------^-----+
address | |
(4) | fire (5) | toll
v |
+--------------------------+-----+
| the pool ETH / SESSION |
| Uniswap v4 hook: Meter |
+--------------------------------+
+--------------+
| your app |
+--+--------+--+
| | (2) the secret
| | stays here
| (1) v
| +--------------+
| | your prover |
| +------+-------+
| | (3) proof and
| | program
v v
+--------------------------+
| the Server no owner |
| notes hidden |
| sessions public |
+-----+--------------^-----+
| |
| (4) fire | (5) 2% toll
v |
+--------------------+-----+
| the pool ETH / SESSION |
| Uniswap v4, the Meter |
+--------------------------+
- A deposit is public: who, how much, when. The contract writes the depositing address into the note as its tag, so the note can only ever be paid out there.
- The note's secret is derived from one signature of your wallet and never leaves this device.
- A proof moves part of a note into a session with a program. The proof names no note and no deposit. Any address MAY submit it, and a relayer is repaid from the session.
- Anyone MAY fire an order whose conditions hold, and is paid gas plus at most 1 gwei a unit of it, from the session.
- Every swap on the pool pays 2% of its ether leg to the Server, which streams it over one day to hidden SESSION: the crowd that hides you is paid by the trading.
- When the program is done, or the session expires, it closes, and what it holds becomes a fresh note of the same tag.
- A withdrawal is a proof too. It pays only to the address that deposited, so no value moves between people except through the pool, as a trade.
1.4.The Numbers
Read from Ethereum as this page loads. Nothing here is estimated.
- hidden SESSION
- notes in the treenil
- nullifiers publishednil
- sessions openednil
- tolls received, all timenil
- streaming to hidden SESSIONnil
- the stream runs untilnil
- cover accumulator, accnil
- read at blocknil
1.5.Requirements Language
The key words MUST, MUST NOT, SHOULD and MAY on these pages are to be read as in RFC 2119. They describe what the contracts enforce, not what anyone promises.
To start, open Notes (page 2). To check the cryptography before you trust it, read Trust (page 5) first.