phantom@anon:~$ _

THE AI API
THAT CAN'T
READ YOU.

Pay any major crypto. Get an OpenAI-compatible API key. 20+ TEE-attested models, 60+ total catalog. No account. No email. No logs.

Starts at $10. 90-day validity. No subscription.

XMR for max privacy. BTC, ETH, USDT, USDC, LTC, SOL, DOGE accepted. No crypto yet? 5-min guide ↗

~/inference.sh
# anonymous inference via TEE-attested endpoint
$ curl https://phantom.codes/v1/chat/completions \
    -H "Authorization: Bearer sk-A1xZ9k7eF..." \
    -d '{"model":"phantom/kimi-k2.6",
        "messages":[{"role":"user","content":"hello"}]}'

# response, TEE-signed, leaves no trace
{
  "id": "chatcmpl-h3K9d...",
  "choices": [{
    "message": {
      "role": "assistant",
      "content": "Hello. How can I help?"
    }
  }],
  "usage": { "prompt_tokens": 4, "completion_tokens": 7 }
}
▌ ATTESTATION  OK  · TDX quote verified · NVIDIA CC verified

// TWO STRINGS, ZERO REWRITES

point your OpenAI client at us. ship.

Same SDK. Same call signature. Two lines change.

~/swap.py · openai → phantom
- client = OpenAI()
+ client = OpenAI(
+     base_url="https://phantom.codes/v1",
+     api_key="sk-A1xZ9k7eF...",
+ )

# everything else identical. agents, function calling, vision, streams.
resp = client.chat.completions.create(
    model="phantom/kimi-k2.6",
    messages=[{"role": "user", "content": "ship it"}],
)
openai-python openai-node LangChain opencode Cline Aider OpenHands Continue OpenWebUI + full configs ↗

// HOW IT STACKS UP

OpenAI / Anthropic / Google TEE provider direct Phantom
Account required + KYC email none
Payment credit card card / crypto any major crypto
Logs prompts yes (30d default) no no
Logs IP yes yes no
Hardware-attested no per request per request

+30% on TEE models, +50% on closed-weight proxy (Claude/GPT/Gemini) vs going direct. Flat price on every coin: XMR, BTC, ETH, USDT, USDC, LTC, SOL, DOGE. Need anonymity? Pay it. Don't need it? Go direct.

// RULES WE DON'T BREAK

01

Hardware-enforced privacy

Inference runs inside Intel TDX + NVIDIA Confidential Computing. Verify per-request via /v1/inference-attest. Math, not promises.

02

Two strings, zero rewrites

Change baseUrl + apiKey. Works with opencode, Cline, Aider, OpenHands, Continue, OpenWebUI, openai-python, openai-node.

03

Pay any crypto, stay anonymous

No email. No card. No KYC. Pay XMR for max privacy, or BTC, ETH, USDT, USDC, LTC, SOL, DOGE.

// HOW IT WORKS

pay. point. run.

01 ▸

Pay any crypto

Pick a bundle or any amount $10-$1000. Redirect to hosted crypto checkout. Pay in XMR (max privacy), BTC, ETH, USDT, USDC, LTC, SOL, DOGE from your wallet.

02 ▸

Get an API key

Wait ~2-20 min depending on coin and network (USDT/USDC fastest, BTC slowest). Your sk-… key drops in the browser. We store only its SHA-256 hash. Re-fetch it anytime with your payment ID. Lose the payment ID, lose the key.

03 ▸

Point and ship

Set base_url, pass the Bearer key, send your first chat. Inference runs inside a hardware enclave (Intel TDX + NVIDIA CC). Verify per request via /v1/inference-attest.

// PRICING

credit, in USD. paid in crypto.

No crypto yet? 5-min guide ↗

SMALL

$10 any coin

XMR, BTC, ETH, USDT, USDC, LTC, SOL, DOGE

$10 credit · 90d

≈ 25M tokens GPT-OSS 120B
≈ 2.5M tokens Kimi K2.6

LARGE

$200 any coin

XMR, BTC, ETH, USDT, USDC, LTC, SOL, DOGE

$230 credit · 180d · +15%

≈ 600M tokens GPT-OSS 120B
≈ 60M tokens Kimi K2.6

WHALE

$500 any coin

XMR, BTC, ETH, USDT, USDC, LTC, SOL, DOGE

$600 credit · 365d · +20%

≈ 1.5B tokens GPT-OSS 120B
≈ 160M tokens Kimi K2.6

Token estimates are balanced input/output. Live rates: model catalog.

// CUSTOM AMOUNT

$10 minimum, $1000 maximum. 1:1 credit. 90-day validity.

$ USD

// ALREADY PAID? RECOVER YOUR KEY

Paste your payment ID. Key drops anytime, as long as you have the ID. full recovery page ↗

// CATALOG

pick by what you want to do.

60+ models across two privacy tiers:

TEE Hardware-sealed

Prompt invisible to everyone, including us. Verifiable per request via /v1/inference-attest.

PROXY Anonymous to vendor

Closed-weight frontier (Claude, GPT, Gemini). Vendor sees content but not who you are.

▸ browse full catalog ↗

// MODEL AUTHORS

60+ frontier models. Closed-weight from the names you know. Open-weight from the labs pushing the edge. full catalog ↗

// COMPATIBLE TOOLS

OpenAI-compatible. full configs ↗

openai-pythonofficial SDK · drop-in base_url swap
openai-nodeofficial SDK · drop-in baseURL swap
LangChainframework · honors OPENAI_BASE_URL

plus opencode, Cline, Continue.dev, Aider, OpenHands, OpenWebUI. all configs ↗

// PRIVACY SPECTRUM

where we sit on the privacy stack.

Four tiers of "private AI." Most products skip the one that matters.

T1

Cloud default

OpenAI · Anthropic · Google

  • Account + card
  • IP logged
  • Prompts retained 30d
T2

Anonymizing proxy

Most "private" AI APIs

  • Strips metadata
  • Prompt still cleartext to vendor
  • Account usually required
T3

TEE + anonymous pay

PHANTOM

  • Hardware-sealed inference
  • Crypto, no account, no email
  • Per-request attestation
T4

Local on-device

Self-hosted open-weight runtimes

  • Max privacy
  • You pay the GPU
  • Model gap vs frontier

// WHAT'S GUARANTEED

hardware enforces it. code shows it. math proves it.

// LIVE · TDX + NVIDIA CC VERIFICATION CHAIN ~840ms
  1. Fetch TDX quote tdx_quote.bin · 8.2 KB
  2. Verify Intel TDX signature intel-root → quote ✓
  3. Verify NVIDIA CC attestation nvidia-root → gpu ✓
  4. Match enclave measurement mrtd: 7a9b…c2d1
  5. Bind to TLS certificate cert-key ↔ quote ✓

ATTESTATION OK  ·  run it yourself: GET /v1/inference-attest

// TOR HIDDEN SERVICE

http://jzqvbfmrlt5ye467joz75dg6xdurc6bniozautqlil5b3tbf777zmsid.onion

Open in Tor Browser. No clearnet exit. No DNS lookup. Same API, same keys.

// CRYPTOGRAPHIC

Three guarantees you can't get from OpenAI.

  • Per-invoice payment address. Fresh address per order. XMR payers opaque on-chain.
  • SHA-256 key storage. Auth gate stores only the hash. Recovery: customer holds payment_id; ciphertext decrypts to plaintext only with that secret.
  • SQLCipher AES-256. DB encrypted at rest. Passphrase manual per boot, never on disk.

Plus what we refuse to be, what we can't fully control, and the trade-offs of running on the public web. Read the full trust boundaries →

// QUESTIONS

what people ask before paying.

Can you read my prompts?

No. Inference runs inside Intel TDX with NVIDIA Confidential Computing. The enclave decrypts your request, runs the model, and only the response leaves. We can't dump enclave memory. Verify per request with GET /v1/inference-attest.

What if you get subpoenaed?

You'd hand over: hashed API keys, token counts per key, and the wallet flow. No prompts, no completions, no IPs, no payment-to-key linkage in plaintext. The DB is SQLCipher-encrypted at rest; the passphrase is typed at SSH unlock, never on disk.

Why not go direct to a TEE provider?

You can. They take card + email. Phantom adds the anonymous-payment layer in front: pay in any major crypto (XMR for max privacy), get a key, no identity attached. Markup: +30% on TEE models, +50% on closed-weight proxy (Claude/GPT/Gemini). Flat price on every coin. Cost of the no-account, no-card, no-IP layer.

What happens if I lose my API key?

Re-fetch it with your payment ID at /recover.html. We store only the key's SHA-256 hash, but the payment ID re-derives the key. What you can't recover is the payment ID itself: it's bearer-equivalent to the key, so guard it. Use /v1/key/rotate to retire a key if you suspect a leak.

How fast does the key drop after payment?

Typically ~2-20 min, varies by coin + network. USDT/USDC on TRC-20 fastest (~1 min). BTC slowest (~30 min). Tab open: key drops automatically. Tab closed: /recover.html with your payment ID anytime.

What models do I get?

60+ catalog. ~20 run TEE-attested: frontier open-weight reasoning, coding, vision, embeddings, uncensored. Plus closed-weight proxy to Claude, GPT, Gemini, Grok, Llama: anonymous to vendor, but the vendor still reads the prompt. browse catalog ↗

Refunds?

No. There's no email to send them to and no card to refund. That's the trade for no-KYC. Start small.

Is this legal?

Yes. Anonymous payment for a software service is legal in every jurisdiction we serve. The AUP bans the obvious abuses. We have no way to filter prompt content because we can't read prompts. We can suspend keys at the proxy layer for credible abuse reports.

Why monospace everywhere? Looks like 1995.

It's a terminal. You're going to use this from a terminal. We're not selling a productivity SaaS.


stop hoping they don't log it.
verify they can't.

No refunds. Keep your payment ID. Start with the $10 bundle. Test the whole flow before scaling.

>> BUY CREDIT