{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "paid",
    "name": "Paid",
    "vendor": "Agent Paid Limited",
    "vendorUrl": "https://paid.ai",
    "kind": "http-api",
    "category": "payment-platforms",
    "summary": "Paid is a billing and metering platform for companies that sell AI agents. It records usage signals and model costs and runs credits, plans, invoices and checkout, through a REST API, five SDKs, a CLI and a hosted MCP server.",
    "url": "https://www.anchorterminal.com/tools/paid",
    "markdownUrl": "https://www.anchorterminal.com/tools/paid.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/paid.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/paid.json",
    "repo": "https://github.com/paid-ai/paid-node",
    "license": "Proprietary service under Paid's Master Subscription Agreement. The Node and Python SDKs on GitHub are MIT",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://api.agentpaid.io/api/v2",
    "packages": [
      {
        "registry": "npm",
        "name": "@paid-ai/paid-node"
      },
      {
        "registry": "pypi",
        "name": "paid-python"
      },
      {
        "registry": "go",
        "name": "github.com/paid-ai/paid-go"
      },
      {
        "registry": "npm",
        "name": "@paid-ai/cli"
      }
    ],
    "auth": "mixed",
    "authNotes": "The REST API takes an organisation API key as a Bearer token. A person creates it at app.paid.ai under Settings, API keys. Keys are full-access or restricted by scope, and customer API keys are bound to one customer and one route. The MCP server at mcp.agentpaid.io accepts OAuth 2.1 with PKCE and automatic client registration through auth.paid.ai, or an API key. Access is self-serve with no review step found.",
    "pricing": "freemium",
    "pricingNotes": "Free plan at $0 for up to $100,000 of billings a year, with no card required per the pricing page. Paid plans are $300, $600 and $1,000 a month by billings tier, with a 14-day trial and 20 per cent off for annual billing, and Enterprise is priced on request. No per-call price or percentage fee is published. Test-mode organisations work as a sandbox (https://paid.ai/pricing, checked 2026-10-09).",
    "priceSummary": "$300 / mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the 178-operation API reference index, the guides read or the pricing page. End customers pay through the builder's connected Stripe account (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 24363,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.paid.ai",
    "llmsTxt": "https://docs.paid.ai/llms.txt",
    "capabilities": [
      "payments.metering",
      "payments.checkout",
      "payments.card"
    ],
    "tags": [
      "hosted",
      "freemium",
      "no-card",
      "mcp",
      "oauth",
      "llms-txt",
      "cli",
      "webhooks",
      "typescript",
      "python",
      "go",
      "ruby",
      "java",
      "closed-source"
    ],
    "lastRelease": "2026-09-15",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 55.1,
      "grade": "C",
      "agentReady": false,
      "rank": 669,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 11,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 70,
        "maintenance": 77,
        "payments": 30,
        "reliability": 35,
        "schema": 64,
        "security": 65,
        "transparency": 51
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 35,
          "points": 7,
          "reason": "Hosted lines. No status page was found in the pricing page footer, the docs index or the pages read, and trust.paid.ai was not read (0). With no history to read, the incident line takes 5. Rate limits are described as a token bucket per organisation on signal ingestion, counted per signal, with a 500-signal cap a request, but no bucket size or refill rate is published and other endpoints are not yet limited (7 of 15). A 429 carries `Retry-After`, the docs ask for exponential backoff with jitter, a per-signal `idempotencyKey` makes batch retries safe and the SDKs retry twice by default. No idempotency key was found on orders or payments (13 of 15). The agreement promises commercially reasonable efforts at 24-hour availability and 48 hours' notice of planned downtime, with no percentage or credit (0). The v2 API is the default version with no beta label, and custom views are marked experimental (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 64,
          "points": 10.4,
          "reason": "The docs index says an OpenAPI 3.1 file is at /v-2/openapi.json and /v-2/openapi.yaml, and both returned 404 on 9 October 2026. Each reference page has a typed Markdown twin and the SDKs are generated from the specification, so 10 of 25. llms.txt per version and Markdown for every page (10). The pages read state purpose and limits well on signals and customer keys and tersely on list calls (15 of 20). Inputs carry enums, defaults and required flags, with free-form maps for `data` and `metadata` (12 of 15). Examples use placeholder values, and errors share one `error`, `code`, `details` shape with named codes in the guides (10 of 15). Docs and paths are versioned v1 and v2. No API changelog was found (7 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 70,
          "points": 11.38,
          "reason": "Graded on the REST API. List calls take `limit` and `offset` and return `total` and `hasMore`, with no field selection, and the MCP server's tool count could not be read (12 of 25). Customers filter by name, status, creation state, dates and external ID (17 of 20). Errors return a stable `code`, and the two kinds of 429 are told apart by it (15 of 20). Signals take an `idempotencyKey`, many resources have upsert or external-ID routes and order amendments have a preview call. MCP annotations were not checked (12 of 20). Official SDKs in five languages and a CLI, with short required lists on the calls read (14 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 65,
          "points": 11.38,
          "reason": "The MCP server uses OAuth 2.1 with PKCE and client registration, and tools run with the user's role. API keys are full-access or restricted by scope, and customer keys are bound to one customer and one route, expire on request, can be revoked and are stored as a hash. No full scope list was found (27 of 30). Viewers are read-only through MCP and restricted keys limit a workload. No confirmation step for deletes was found (14 of 20). The API returns customer-supplied names and metadata, and the MCP page warns about answers the tools did not produce, with no prompt-injection guidance (7 of 15). An audit log names the user or the key's creator, and keys show `lastUsedAt` (11 of 15). security.txt returned 404, the DPA gives a reporting address and lists TLS 1.2 and AES-256, and no certification or bounty was found in the pages read. trust.paid.ai was not read (6 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found on Paid's own API or for its merchants, whose customers pay by card or bank transfer through a connected Stripe account (0). Plan prices are public at $0, $300, $600 and $1,000 a month by billings tier, with no per-unit price (10). The Free plan covers up to $100,000 of billings a year and the page says no credit card is required (20). A person signs up at app.paid.ai and creates the first key in the dashboard (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 77,
          "points": 6.74,
          "reason": "The CLI `@paid-ai/cli` 1.2.0 was published on 15 September 2026, 24 days before the check (30). Five releases in 90 days, CLI 1.1.0 and 1.2.0, Node SDK 1.8.0, Python SDK 1.12.0 and Go SDK v1.1.0 (20). No public API changelog was found. Support is by email, with Slack on paid plans, and the issue queues were not read (5 of 15). Current official SDKs in five languages (15). The SDK repositories carry CI workflows and lockfiles. CI results were not read, and the Go module still declares go 1.13 (7 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 51,
          "points": 4.46,
          "note": "editorial 55, provenance 47",
          "reason": "The platform is closed under a published Master Subscription Agreement, and the Node and Python SDKs are MIT. The Go SDK repository has no licence file (17 of 30). The agreement, privacy policy and DPA agree with each other on a 30-day retrieval window, deletion from backups within 90 days, hosting on AWS US-East-1 and no training of general-purpose models on customer data. The agreement is undated (22 of 30). Six operations are marked deprecated with a named replacement and no removal date, and no deprecation policy was found (6 of 20). The DPA names AWS and its region and points to trust.paid.ai for the full sub-processor list, which was not read (10 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graded on the REST API. List calls take `limit` and `offset` and return `total` and `hasMore`, with no field selection, and the MCP server's tool count could not be read (12 of 25). Customers filter by name, status, creation state, dates and external ID (17 of 20). Errors return a stable `code`, and the two kinds of 429 are told apart by it (15 of 20). Signals take an `idempotencyKey`, many resources have upsert or external-ID routes and order amendments have a preview call. MCP annotations were not checked (12 of 20). Official SDKs in five languages and a CLI, with short required lists on the calls read (14 of 15).",
          "maintenance": "The CLI `@paid-ai/cli` 1.2.0 was published on 15 September 2026, 24 days before the check (30). Five releases in 90 days, CLI 1.1.0 and 1.2.0, Node SDK 1.8.0, Python SDK 1.12.0 and Go SDK v1.1.0 (20). No public API changelog was found. Support is by email, with Slack on paid plans, and the issue queues were not read (5 of 15). Current official SDKs in five languages (15). The SDK repositories carry CI workflows and lockfiles. CI results were not read, and the Go module still declares go 1.13 (7 of 10).",
          "payments": "Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found on Paid's own API or for its merchants, whose customers pay by card or bank transfer through a connected Stripe account (0). Plan prices are public at $0, $300, $600 and $1,000 a month by billings tier, with no per-unit price (10). The Free plan covers up to $100,000 of billings a year and the page says no credit card is required (20). A person signs up at app.paid.ai and creates the first key in the dashboard (0).",
          "reliability": "Hosted lines. No status page was found in the pricing page footer, the docs index or the pages read, and trust.paid.ai was not read (0). With no history to read, the incident line takes 5. Rate limits are described as a token bucket per organisation on signal ingestion, counted per signal, with a 500-signal cap a request, but no bucket size or refill rate is published and other endpoints are not yet limited (7 of 15). A 429 carries `Retry-After`, the docs ask for exponential backoff with jitter, a per-signal `idempotencyKey` makes batch retries safe and the SDKs retry twice by default. No idempotency key was found on orders or payments (13 of 15). The agreement promises commercially reasonable efforts at 24-hour availability and 48 hours' notice of planned downtime, with no percentage or credit (0). The v2 API is the default version with no beta label, and custom views are marked experimental (10).",
          "schema": "The docs index says an OpenAPI 3.1 file is at /v-2/openapi.json and /v-2/openapi.yaml, and both returned 404 on 9 October 2026. Each reference page has a typed Markdown twin and the SDKs are generated from the specification, so 10 of 25. llms.txt per version and Markdown for every page (10). The pages read state purpose and limits well on signals and customer keys and tersely on list calls (15 of 20). Inputs carry enums, defaults and required flags, with free-form maps for `data` and `metadata` (12 of 15). Examples use placeholder values, and errors share one `error`, `code`, `details` shape with named codes in the guides (10 of 15). Docs and paths are versioned v1 and v2. No API changelog was found (7 of 15).",
          "security": "The MCP server uses OAuth 2.1 with PKCE and client registration, and tools run with the user's role. API keys are full-access or restricted by scope, and customer keys are bound to one customer and one route, expire on request, can be revoked and are stored as a hash. No full scope list was found (27 of 30). Viewers are read-only through MCP and restricted keys limit a workload. No confirmation step for deletes was found (14 of 20). The API returns customer-supplied names and metadata, and the MCP page warns about answers the tools did not produce, with no prompt-injection guidance (7 of 15). An audit log names the user or the key's creator, and keys show `lastUsedAt` (11 of 15). security.txt returned 404, the DPA gives a reporting address and lists TLS 1.2 and AES-256, and no certification or bounty was found in the pages read. trust.paid.ai was not read (6 of 20).",
          "transparency": "The platform is closed under a published Master Subscription Agreement, and the Node and Python SDKs are MIT. The Go SDK repository has no licence file (17 of 30). The agreement, privacy policy and DPA agree with each other on a 30-day retrieval window, deletion from backups within 90 days, hosting on AWS US-East-1 and no training of general-purpose models on customer data. The agreement is undated (22 of 30). Six operations are marked deprecated with a named replacement and no removal date, and no deprecation policy was found (6 of 20). The DPA names AWS and its region and points to trust.paid.ai for the full sub-processor list, which was not read (10 of 20)."
        },
        "sources": [
          {
            "what": "Master Subscription Agreement",
            "url": "https://paid.ai/legal/msa",
            "seen": "2026-10-09"
          },
          {
            "what": "website terms",
            "url": "https://paid.ai/legal/terms",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://paid.ai/legal/privacy",
            "seen": "2026-10-09"
          },
          {
            "what": "data processing agreement",
            "url": "https://paid.ai/legal/dpa",
            "seen": "2026-10-09"
          },
          {
            "what": "fair usage policy",
            "url": "https://paid.ai/legal/fair-usage",
            "seen": "2026-10-09"
          },
          {
            "what": "pricing",
            "url": "https://paid.ai/pricing",
            "seen": "2026-10-09"
          },
          {
            "what": "docs index for agents",
            "url": "https://docs.paid.ai/v-2/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "API overview and SDK list",
            "url": "https://docs.paid.ai/api-reference/introduction/overview.md",
            "seen": "2026-10-09"
          },
          {
            "what": "rate limits and 429 handling",
            "url": "https://docs.paid.ai/api-reference/introduction/rate-limits.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP quickstart",
            "url": "https://docs.paid.ai/mcp/mcp/quickstart.md",
            "seen": "2026-10-09"
          },
          {
            "what": "MCP OAuth resource metadata",
            "url": "https://mcp.agentpaid.io/.well-known/oauth-protected-resource/mcp",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI command reference",
            "url": "https://docs.paid.ai/cli/cli/command-reference.md",
            "seen": "2026-10-09"
          },
          {
            "what": "customer API keys",
            "url": "https://docs.paid.ai/documentation/signals/send-signals-with-a-customer-api-key.md",
            "seen": "2026-10-09"
          },
          {
            "what": "webhooks",
            "url": "https://docs.paid.ai/documentation/billing/webhooks.md",
            "seen": "2026-10-09"
          },
          {
            "what": "bank transfers through Stripe",
            "url": "https://docs.paid.ai/documentation/billing/bank-transfers.md",
            "seen": "2026-10-09"
          },
          {
            "what": "checkout guide",
            "url": "https://docs.paid.ai/documentation/customers-users/checkout.md",
            "seen": "2026-10-09"
          },
          {
            "what": "list customers reference",
            "url": "https://docs.paid.ai/api-reference/api-reference/customers/list-customers.md",
            "seen": "2026-10-09"
          },
          {
            "what": "Node SDK repository, tags and README",
            "url": "https://github.com/paid-ai/paid-node",
            "seen": "2026-10-09"
          },
          {
            "what": "Python SDK repository and tags",
            "url": "https://github.com/paid-ai/paid-python",
            "seen": "2026-10-09"
          },
          {
            "what": "Go SDK repository and tags",
            "url": "https://github.com/paid-ai/paid-go",
            "seen": "2026-10-09"
          },
          {
            "what": "CLI release dates",
            "url": "https://registry.npmjs.org/@paid-ai%2Fcli",
            "seen": "2026-10-09"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@paid-ai%2Fpaid-node",
            "seen": "2026-10-09"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.org/domain/paid.ai",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: trust.paid.ai (the sub-processor list and any certifications). The website terms forbid automated access at scale to Paid's sites, so we stopped at the pages already fetched and the docs' published agent files",
          "unchecked: the paid.ai home page and product pages, for the same reason. A status page link may sit on a page we did not read. None is in the pricing page footer or the docs index",
          "unchecked: the OpenAPI document. Both addresses in the docs index returned 404, so operation counts come from the reference index and schema quality from six reference pages",
          "unchecked: the MCP server's tool names, count, schemas and annotations. The server needs a sign-in and its source is not public",
          "unchecked: who publishes the `paid` package on PyPI that the quickstart tells users to install. The PyPI project page answered with a client challenge. The SDK's README and `pyproject.toml` name `paid-python`",
          "unchecked: GitHub stars, issue queues and CI results for the SDK repositories, and PyPI download counts",
          "unchecked: the registration date of agentpaid.io. RDAP returned no events",
          "unchecked: the list of API key scopes. Three scope names appear in the pages read and no page listing them all was found",
          "The lead named the Python package `paid`. The SDK repository names it `paid-python`. The lead also listed only a docs MCP server, and Paid runs a product MCP server at mcp.agentpaid.io, a CLI, and Ruby and Java SDKs",
          "The plan prices were decoded from the transform values of the pricing page's digit columns, not read as plain text"
        ]
      },
      "negative": 0,
      "verdict": "Paid suits a builder who wants usage metering, credits and invoicing behind one API, with restricted and customer-bound keys, OAuth on the MCP server and a free plan that needs no card. No status page, SLA figure, API changelog or rate-limit numbers were found, both advertised OpenAPI links returned 404, and card payments need the builder's own Stripe account.",
      "bestFor": "A team selling an AI agent that needs usage metering, credit balances, cost and margin tracking and invoicing in one service, with Stripe as the payment rail.",
      "strengths": [
        "Free plan at $0 for up to $100,000 of billings a year, and the pricing page says no credit card is required",
        "The hosted MCP server signs in through OAuth 2.1 with PKCE and client registration, and tools run with the user's role, so viewers stay read-only",
        "Customer API keys are bound to one customer, can only send that customer's signals, take an optional expiry and are stored as a hash",
        "Rate-limited requests answer 429 with `Retry-After`, and an `idempotencyKey` on each signal makes a whole-batch retry safe",
        "The agreement says customer data is not used to train general-purpose models, and the DPA names AWS US-East-1 and a 30-day retrieval window"
      ],
      "weaknesses": [
        "The docs index advertises an OpenAPI 3.1 file at two addresses, and both returned 404 on 9 October 2026",
        "No status page, uptime figure or SLA percentage was found. The agreement promises commercially reasonable efforts only",
        "Rate limits are described as a token bucket per organisation with no published bucket size or refill rate",
        "No API changelog or deprecation policy was found. Six operations are marked deprecated with no removal date",
        "The API and MCP server run on agentpaid.io, a second domain, and collecting card or bank payments needs the builder's own connected Stripe account"
      ],
      "agentNotes": [
        "Call `https://api.agentpaid.io/api/v2` with `Authorization: Bearer \u003ckey\u003e`. A person creates the first key at app.paid.ai. No programmatic signup was found",
        "Give every signal a stable `idempotencyKey` and resend the same key on retry. Signals without one are not deduplicated",
        "Send at most 500 signals a request. A 429 rejects the whole batch, so wait for `Retry-After` and resend it all",
        "Read the `code` field on a 429. `CONCURRENCY_LIMIT_EXCEEDED` carries no `Retry-After` and clears when an analytics query finishes",
        "Install the Python SDK as `paid-python`, the name in its README and `pyproject.toml`. The quickstart's `pip install paid` names a package we could not check"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 55.1
        }
      ],
      "editorialScores": {
        "ergonomics": 70,
        "maintenance": 77,
        "payments": 30,
        "reliability": 35,
        "schema": 64,
        "security": 65,
        "transparency": 55
      },
      "provenanceScore": 47
    },
    "connect": {
      "install": "npm install @paid-ai/paid-node",
      "http": "curl -X POST https://api.agentpaid.io/api/v2/customers/external/customer_123/api-keys \\\n  -H \"Authorization: Bearer $PAID_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"name\": \"Tenant runtime (production)\"}'",
      "claudeCode": "claude mcp add --transport http paid https://mcp.agentpaid.io/mcp",
      "config": {
        "mcpServers": {
          "paid": {
            "type": "http",
            "url": "https://mcp.agentpaid.io/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/payments.metering",
      "tool": "https://letme.dev/paid"
    },
    "notable": [
      "The rate-limit page says a rejected signals request ingests nothing and that a stable `idempotencyKey` on each signal makes the retry safe (https://docs.paid.ai/api-reference/introduction/rate-limits.md)",
      "MCP tools run with the signed-in user's organisation role, so viewers keep read-only access, and each change is recorded in the audit log under that user's name (https://docs.paid.ai/mcp/mcp/quickstart.md)",
      "A customer API key can send signals for one customer through `POST /api/v2/signals/bulk` and every other route refuses it. Paid keeps only the key's hash (https://docs.paid.ai/documentation/signals/send-signals-with-a-customer-api-key.md)",
      "The docs index lists an OpenAPI 3.1 file at /v-2/openapi.json and /v-2/openapi.yaml. Both answered 404 on 9 October 2026 (https://docs.paid.ai/v-2/llms.txt)",
      "The Master Subscription Agreement says the services may not be accessed to monitor availability, performance or functionality, or for benchmarking, and that customer data is not used to train general-purpose models (https://paid.ai/legal/msa)",
      "The website terms define the Website to include dashboards, APIs and documentation portals and forbid scraping, crawling or automated access at scale (https://paid.ai/legal/terms)",
      "The pricing page draws plan prices as animated digit columns. We read $300, $600 and $1,000 a month from the page's markup (https://paid.ai/pricing)"
    ],
    "area": "payments",
    "details": [
      {
        "label": "API",
        "value": "REST at `https://api.agentpaid.io/api/v2`, 178 operations in the v2 reference index across customers, signals, costs, credits, orders, invoices, plans, products, pricing, checkouts, payments, value receipts, analytics and webhooks. A v1 reference with 59 operations is still published"
      },
      {
        "label": "MCP server",
        "value": "Hosted at `https://mcp.agentpaid.io/mcp` over HTTP. OAuth 2.1 with PKCE through auth.paid.ai with scopes `mcp:tools` and `offline_access`, or a Paid API key as a bearer token. The tool list is not published and the source is closed"
      },
      {
        "label": "Credentials",
        "value": "Organisation API keys, full-access or restricted with scopes such as `write:api-keys`, `write:usage` and `read:analytics`. Customer API keys (`paid_ck_live_`, `paid_ck_test_`) bound to one customer, with optional expiry and revocation, enabled on request"
      },
      {
        "label": "Rate limits",
        "value": "A token bucket per organisation on signal ingestion, counted per signal, with separate live and test buckets. No bucket size or refill rate is published. Other endpoints are not yet limited per organisation. Maximum 500 signals a request"
      },
      {
        "label": "Errors",
        "value": "JSON body with `error`, `code` and `details`. 429 with `Retry-After` in seconds for `RATE_LIMIT_EXCEEDED`, and a second 429 code, `CONCURRENCY_LIMIT_EXCEEDED`, for analytics queries"
      },
      {
        "label": "Pagination",
        "value": "`limit` (default 10) and `offset` on list calls, with `total` and `hasMore` in the response and filters by name, status, creation date and external ID on customers"
      },
      {
        "label": "SDKs",
        "value": "Node `@paid-ai/paid-node` 1.8.0 (11 September 2026), Python `paid-python` 1.12.0 (10 September 2026), Go `paid-go` v1.1.0 (5 August 2026), Ruby and Java, generated by Fern. CLI `@paid-ai/cli` 1.2.0 (15 September 2026)"
      },
      {
        "label": "Webhooks",
        "value": "Ten billing events, signed with HMAC-SHA256 in `x-webhook-signature` over the timestamp and raw body, one signing secret per organisation with a rotate call, five-minute replay window advised"
      },
      {
        "label": "Payment rails",
        "value": "Hosted checkout, cards and US virtual bank accounts for ACH and wire, all through the builder's connected Stripe account. Test-mode organisations use a Stripe sandbox"
      },
      {
        "label": "Plans",
        "value": "Free up to $100,000 of billings a year, Grow $300 a month up to $200,000, Scale $600 up to $500,000, Accelerate $1,000 up to $1 million, Enterprise custom with five-year data retention. Annual billing takes 20 per cent off. 14-day trial on paid plans"
      },
      {
        "label": "Data handling",
        "value": "DPA last updated 13 March 2026. Hosting on AWS US-East-1, breach notice within 72 hours where feasible, data retrievable as JSON for 30 days after termination and deleted from backups within 90 days, 30 days' notice of new sub-processors"
      },
      {
        "label": "Terms",
        "value": "The Master Subscription Agreement bars access for monitoring availability or performance and for benchmarking. The website terms bar automated access at scale to the site, dashboards, APIs and documentation"
      }
    ],
    "unitPrices": [
      {
        "item": "Grow plan",
        "unit": "month",
        "usd": 300,
        "note": "up to $200,000 of billings a year, billed monthly"
      },
      {
        "item": "Scale plan",
        "unit": "month",
        "usd": 600,
        "note": "up to $500,000 of billings a year, billed monthly"
      },
      {
        "item": "Accelerate plan",
        "unit": "month",
        "usd": 1000,
        "note": "up to $1 million of billings a year, billed monthly"
      }
    ],
    "provenance": {
      "legalEntity": "Agent Paid Limited",
      "domain": "paid.ai",
      "domainRegistered": "2017-12-16",
      "endpointOnVendorDomain": false,
      "terms": "https://paid.ai/legal/msa",
      "privacy": "https://paid.ai/legal/privacy",
      "statusPage": "",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The Master Subscription Agreement names Agent Paid Limited, company number 16113498, registered in England and Wales at 161 Farringdon Road, London, EC1R 3AL. It governs the service, free plan included, and carries no date.",
        "The privacy policy names the same company as controller and says processing done for business customers is governed by the customer contract and the DPA at https://paid.ai/legal/dpa (last updated 13 March 2026).",
        "The API answers at api.agentpaid.io and the MCP server at mcp.agentpaid.io. The MCP server's OAuth metadata names auth.paid.ai as its authorisation server.",
        "paid.ai/.well-known/security.txt returned 404. The DPA gives security@paid.ai for reporting suspected incidents.",
        "RDAP for paid.ai gives a registration date of 2017-12-16 and a transfer on 2025-02-13. Agent Paid Limited's SDK licence files are dated 2025.",
        "No status page or API changelog was found in the pricing page footer, the docs index or the pages read. trust.paid.ai was not read."
      ],
      "score": 47,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Agent Paid Limited",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "paid.ai, registered 2017-12-16 (8 years)",
          "points": 11,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.agentpaid.io is not on paid.ai",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://paid.ai/legal/msa",
          "state": "read",
          "readAt": "2026-10-09",
          "words": 7746,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Agreement and any dispute arising out of or in connection with it (including non-contractual disputes or claims) shall be governed by and construed in accordance with the laws of England and Wales, without regard to its conflicts of laws rules.",
              "says": "The law of England and Wales"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…UNDER APPLICABLE LAW IN WHICH CASE COMPANY'S LIABILITY WITH RESPECT TO THE SERVICES PROVIDED SHALL NOT EXCEED $1,000.00.",
              "says": "Capped at $1,000.00"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Customer agrees that the Company, in its sole discretion and for any or no reason, may terminate Customer's access to the Free Services or any part thereof."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "…by credit card or direct debit whose payment has been declined, the Company will give Customer at least 10 days' prior notice that its account is overdue, in accordance with the “Manner of Giving Notice” section below for billing notices, before suspending services to Customer.",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Unless otherwise expressly agreed in writing by the parties (including any additional safeguards required by applicable Data Protection Laws), Customer will not submit to the Services any special category Personal Data or Personal Data relating to criminal convictions and offences."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "In addition, the Services may not be accessed for purposes of monitoring their availability, performance, or functionality, or for any other benchmarking or competitive purposes.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Customer agrees that the Company, in its sole discretion and for any or no reason, may terminate Customer's access to the Free Services or any part thereof."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Paid may adjust per-unit pricing for any renewal term of a subscription.",
              "quote": "The per-unit pricing during any renewal term may be adjusted by Company."
            },
            {
              "date": "2026-10-08",
              "text": "After the agreement ends, customer data is available for retrieval for up to 30 days.",
              "quote": "Upon termination or expiration of this Agreement, and in accordance with the Documentation and applicable Data Protection Laws, the Company will make Customer Data available for retrieval for up to thirty (30) days."
            },
            {
              "date": "2026-10-08",
              "text": "Paid may name the customer and show its logo in customer lists, presentations and marketing materials, and the customer may opt out by written notice.",
              "quote": "Company may identify Customer by name and/or logo as a user of the Services in Company's customer lists, presentations, and marketing materials, provided that such usage does not imply any endorsement by Customer. Customer may opt out at any time by written notice."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://paid.ai/legal/privacy",
          "state": "read",
          "readAt": "2026-10-09",
          "words": 2934,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We're committed to protecting your privacy and being transparent about how we collect, use, and safeguard your personal data in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and other privacy regulations."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Business contact and marketing lead data is generally retained for up to 24 months after our last meaningful interaction with you, unless you opt out earlier, object to the processing, or a longer period is reasonably necessary to establish, exercise or defend legal claims.",
              "says": "Names a period of 24 months"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Where we process personal information on behalf of our business customers in connection with the Services, we do so as a processor or service provider under the applicable customer contract and data processing agreement."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Depending on where you live, you may have the right to opt out of certain processing for targeted advertising or similar advertising purposes."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Depending on where you live, you may have the right to opt out of certain processing for targeted advertising or similar advertising purposes."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have any questions about our privacy practices or this Privacy Policy, or to exercise your rights, please contact us at hello@paid.ai or write to us at 161 Farringdon Road, London, EC1R 3AL, United Kingdom.",
              "says": "hello@paid.ai"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Where we transfer personal information outside the UK or EEA, we use appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum (or other lawful transfer mechanism) in accordance with applicable data protection laws.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Paid says it does not use customer prompts or outputs to train third-party foundation models, and shares them with model providers only as needed to generate the requested output.",
              "quote": "We do not use customer prompts or outputs to train third-party foundation models, and we do not share prompts or outputs with model providers except as necessary to generate the requested output as part of providing the Services."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/paid.json",
    "live": {
      "slug": "paid",
      "probe": {
        "target": "https://api.agentpaid.io/api/v2",
        "method": "get",
        "lastAt": "2026-10-10T02:07:19.506927913Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 248,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 262,
        "p95ms24h": 378,
        "samples24h": 107,
        "samples30d": 107,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 85
          },
          {
            "date": "2026-10-10",
            "probes": 22,
            "ok": 22
          }
        ]
      },
      "versions": [
        {
          "registry": "github",
          "name": "paid-ai/paid-node",
          "version": "1.8.0",
          "released": "2026-09-11",
          "seenAt": "2026-10-09T17:11:50.219297356Z"
        },
        {
          "registry": "npm",
          "name": "@paid-ai/cli",
          "version": "1.2.0",
          "seenAt": "2026-10-09T17:11:49.525583861Z"
        },
        {
          "registry": "npm",
          "name": "@paid-ai/paid-node",
          "version": "1.8.0",
          "seenAt": "2026-10-09T17:11:47.801044563Z"
        },
        {
          "registry": "pypi",
          "name": "paid-python",
          "version": "1.12.0",
          "released": "2026-09-10",
          "seenAt": "2026-10-09T17:11:49.331417076Z"
        }
      ],
      "githubStars": 8,
      "npmWeekly": 24363,
      "pypiWeekly": 25035,
      "pages": [
        {
          "url": "https://paid.ai/pricing",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-09T18:42:59.277334688Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "687acc4a19a1"
        },
        {
          "url": "https://paid.ai/legal/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:42:57.335349283Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "7da60dff7a08"
        },
        {
          "url": "https://paid.ai/legal/msa",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:42:55.032947366Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "654fd46e6356"
        }
      ],
      "updatedAt": "2026-10-10T02:07:19.506927913Z"
    }
  }
}
