DocumentationPrivacy & settlement
DocsProtocol

Understand the boundary.

What remains private, what settles publicly, and how the toolkit handles the payment lifecycle.

On this page

Payment lifecycle

  1. 01Fund

    Deposit ETH

  2. 02Prove

    Keep state local

  3. 03Spend

    Pay per request

  4. 04Exit

    Settle on Ethereum

Public settlement at the edges. Private payment state in the middle.

A deposit funds a note through a public Ethereum transaction. The browser uses private note state to prove valid payments, acquires limited inference access, and settles usage. A mutual withdrawal closes the remaining balance back to Ethereum.

What stays local

The note’s secret state is held by the browser SDK. Payment proofs let the protocol verify the required relation without sending the full private balance or note secrets to the service.

  • Note secrets and private wallet state remain in the browser.
  • The toolkit exposes a snapshot for your local interface.
  • Inference receipts and the burn journal are stored locally on a best-effort basis.

A note fingerprint is a display identifier. It is not a recovery secret or a substitute for the SDK’s stored note state.

What remains visible

Privacy boundaries
SurfaceVisible information
EthereumDeposit and withdrawal transactions and their public settlement data.
Inference providerThe request sent to it, including prompt and optional system messages.
Payment serviceThe information required to verify and settle the protocol operation.
Your browserPrivate note state, displayed balance, and locally stored history.

Payment privacy does not conceal the contents of an inference request from the provider, or make the browser’s network traffic anonymous. Keep the payment claim separate from application-level data privacy.

Exits and recovery

The toolkit’s withdrawal interface uses mutual close: the coordinator supplies clearance and the wallet submits the withdrawal. The contract’s escape path is a separate protocol mechanism; this wrapper does not expose an escape-withdrawal method.

reset() clears a hook’s interaction state. It does not erase, restore, or export the private note. Handle note recovery through the underlying SDK and deployment procedures.

Client API

Read the mutual withdrawal and state-subscription interfaces.

Documentation for the OpenZK browser toolkit. Report a documentation issue ↗