The Ethereum Foundation announced on October 1 that zkAPI, a billing system for metered APIs, is now running on Ethereum mainnet. The system was built by Open Anonymity in collaboration with the Ethereum Foundation, based on a design published by Davide Crapis and Vitalik Buterin on February 11.
zkAPI addresses a key challenge in prepaid billing: how users can recover unspent funds when a billing server becomes unavailable. The system documents an onchain withdrawal route that does not require server clearance, though a user's ability to recover their balance depends on which spending state they hold and whether they can initiate an exit before certain deadlines.
Two Withdrawal Routes
The protocol offers two paths for users to access their prepaid balance. The first is a cooperative route called mutual close, which requires server authorization through a separate signing key. The server provides a signature that the wallet includes in its withdrawal proof, and the vault pays the remaining balance to a specified destination.
The second route is an escape withdrawal, which users can initiate without server clearance. When a user starts an escape withdrawal, the vault removes the note from the active set and records a pending payout. The mainnet configuration specifies a 24-hour challenge period. If no valid challenge succeeds before the deadline, the remaining balance is paid to the user and the difference between the deposit and balance goes to the treasury.
Each spending state has a cryptographic identifier called a nullifier to prevent reuse. To challenge an escape withdrawal, a challenger can supply proof that the state already authorized service by submitting an original request proof with the same nullifier. A valid challenge before the deadline cancels the pending payout and restores the note to the active set without imposing a separate penalty.
Time and Access Constraints
The vault code includes a pause switch controlled by the owner, which prevents deposits, mutual close operations, and new escape withdrawals from starting while active. However, escape withdrawals that have already been initiated and challenges or expiry claims are not blocked by the pause function.
The mainnet configuration specifies a 30-day note lifetime. Once an active note expires, the code permits an expiry claim that sends the full recorded deposit to the treasury, rather than to the user. This differs from normal withdrawals, where the remaining balance goes to the user. Notes already in pending withdrawal status do not qualify for the expiry claim.
Denomination and Dependencies
The mainnet vault holds native ETH, with balances accounted for in whole gwei. Users are charged in dollar-denominated amounts based on a Chainlink ETH/USD price quote that is fixed at the time of authorization. The dollar value of a user's remaining ETH balance is not stabilized between sessions.
The manifest describes the integration as experimental and not production-audited. Users' ability to recover their balance depends on state recovery, timely access to the vault, and completing an exit before the active note expires. Provider usage receipts and the billing server's signed successor states remain operational parts of settlement, while Ethereum supplies the exit mechanism through the smart contract.


