Fund once.
Blend in.
Send ETH to the shared vault. Your browser mints a secret note and drops its commitment into a 32-level Merkle tree with everyone else's. From now on you're one leaf in a forest.
Prove it.
Don't show it.
Before each session your browser builds a Groth16 proof: "I own an unspent note worth at least X". It never says which. A one-time nullifier stops anyone spending the same note twice.
A key that
self-destructs.
The router issues an API key capped at the amount you proved, alive for minutes. Use it in the app, your IDE, or any OpenAI SDK. Even if it leaks, it can't spend a wei more.
Pay exactly
what you used.
When the key closes, usage is metered, the provider is paid from the vault, and your change becomes a brand-new note nobody can tie to the old one. Key deleted.
calls 0 · scope chat, search