ltk_ key the token came from. A request paid with a token has no API key, no cookie and no wallet attached to it.
Tokens follow open standards: Privacy Pass (RFC 9578, token type 0x0002) with Blind RSA signatures (RFC 9474).
How it works
1
Get tokens (identity visible, prompts absent)
Your client generates random tokens, blinds them and sends only the blinded values to
POST /v1/tokens. You authorize the batch in one of two ways:- Pay in USDC via x402 on Base or Solana. The price is $0.01 per token, in batches of 10 to 100.
- Spend allowance. A wallet session or
ltk_key converts part of its daily allowance into tokens, up to 50 per batch.
2
Spend tokens (prompts visible, identity absent)
Each call sends one token instead of a key:LETHE verifies the signature, marks the token’s random nonce as spent and serves the call. The token matches nothing LETHE saw when it signed.
Easiest path: lethe-proxy
Most tools, including Claude Code, Codex and SDKs, can only send a fixed API key. lethe-proxy runs on your machine, keeps a stash of tokens and swaps your tool’s key for a fresh token on every call.
~/.lethe/tokens.json. count_tokens calls are checked against a token but don’t spend it.
Web chat
When you’re signed in with a wallet, chat automatically converts part of your daily allowance into tokens and spends them. Those chat requests are sent without your wallet cookie. You can also buy tokens with USDC on Base at/cli. Unspent tokens stay in your browser’s local storage.
Endpoints
Anyone can check the published key. If every client sees the same key, LETHE can’t tag individual users by signing their tokens with different keys.
Errors
If a call fails upstream with a
5xx, the token is refunded and can be used again.
What tokens don’t hide
Be precise about the limits:- Your IP address is still visible to LETHE’s servers. Use Tor or a VPN if that matters to you.
- Timing. Buying tokens and spending one a second later links the two in practice. Buy ahead of time.
- Prompt content. If a prompt names you, the token can’t un-name it.
- The model provider still processes the prompt in plaintext. Encrypted, attested execution is covered in Privacy Model & TEE.
