{
  "data": {
    "a": {
      "slug": "ap2",
      "name": "Agent Payments Protocol (AP2)",
      "vendor": "Google (standardisation moved to the FIDO Alliance)",
      "vendorUrl": "https://ap2-protocol.org",
      "kind": "protocol",
      "category": "checkout-protocols",
      "summary": "Google's protocol for authorising agent payments, now governed by the FIDO Alliance.",
      "url": "https://www.anchorterminal.com/tools/ap2",
      "markdownUrl": "https://www.anchorterminal.com/tools/ap2.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ap2.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ap2.json",
      "repo": "https://github.com/google-agentic-commerce/AP2",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Needs a credentials provider and a mandate signed by the user in advance. Not account-free.",
      "pricing": "free",
      "pricingNotes": "No fees defined. Card and network fees apply on the payment itself.",
      "priceSummary": "Free",
      "where": "spec",
      "x402": {
        "level": "no",
        "evidence": "A payment protocol, not a tool that accepts payment.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 3200,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-26"
      },
      "docsUrl": "https://ap2-protocol.org",
      "llmsTxt": "https://ap2-protocol.org/llms.txt",
      "capabilities": [
        "payments.protocol",
        "payments.mandate"
      ],
      "tags": [
        "protocol",
        "pre-1.0",
        "mandates",
        "fido"
      ],
      "lastRelease": "2026-04-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.3,
        "grade": "C",
        "agentReady": false,
        "rank": 0,
        "ranked": false,
        "notRankedWhy": "A protocol, graded on the same scale but not ranked against tools",
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 51,
          "maintenance": 19,
          "payments": 60,
          "reliability": 31,
          "schema": 74,
          "security": 84,
          "transparency": 56
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "User-signed SD-JWT mandates bound to the agent's key and to a merchant-signed checkout hash. No production deployment named by Google or found elsewhere.",
        "strengths": [
          "User-signed SD-JWT mandates bound to the agent's key and to a merchant-signed checkout hash",
          "Open mandates cap amount range, total budget, recurrence, merchants and items",
          "Threat model treats every LLM as a potential attacker and bounds the damage at verification",
          "Signed receipts to the agent, credential provider and network, usable as dispute evidence",
          "Standardisation now at FIDO, with Mastercard and Visa chairing the payments working group"
        ],
        "weaknesses": [
          "No production deployment named by Google or found elsewhere",
          "No commit on main since 29 April 2026, with 50 open issues and 69 open pull requests",
          "The v0.1 spec page is still live and contradicts v0.2",
          "Python SDK only, installed from git, and no conformance vectors",
          "No documented way to revoke an open mandate before it expires"
        ],
        "agentNotes": [
          "Read /ap2/specification/ for v0.2; /specification/ is the old v0.1 text",
          "Ask the user for open mandates with the shortest expiry that fits the task and a budget constraint",
          "Don't present a second open mandate until you hold a rejection receipt for the first",
          "Present only the disclosures the verifier needs",
          "Install the SDK from git; there is no PyPI package"
        ],
        "metrics": {
          "kind": "spec",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.3
          }
        ],
        "editorialScores": {
          "ergonomics": 51,
          "maintenance": 19,
          "payments": 60,
          "reliability": 31,
          "schema": 74,
          "security": 84,
          "transparency": 55
        },
        "provenanceScore": 57
      },
      "letme": {
        "capability": "https://letme.dev/payments.protocol",
        "tool": "https://letme.dev/ap2"
      },
      "area": "payments",
      "provenance": {
        "legalEntity": "Google LLC",
        "domain": "ap2-protocol.org",
        "domainRegistered": "2025-09-15",
        "domainNote": "The site and repository carry a Google copyright and SECURITY.md routes reports to Google. The FIDO Alliance took on standardisation in April 2026 but doesn't publish the spec yet.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/google-agentic-commerce/AP2/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "score": 57
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ap2.json",
      "live": {
        "slug": "ap2",
        "versions": [
          {
            "registry": "github",
            "name": "google-agentic-commerce/AP2",
            "version": "v0.2.0",
            "released": "2026-04-28",
            "seenAt": "2026-10-04T16:20:29.078439467Z"
          }
        ],
        "githubStars": 3206,
        "securityTxt": {
          "url": "https://ap2-protocol.org/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:02.597758053Z"
        },
        "llmsTxt": {
          "url": "https://ap2-protocol.org/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:15.052480983Z"
        },
        "domain": {
          "domain": "ap2-protocol.org",
          "registered": "2025-09-15",
          "source": "https://rdap.publicinterestregistry.org/rdap/domain/ap2-protocol.org",
          "checkedAt": "2026-10-04T13:10:46.099796965Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/google-agentic-commerce/AP2/main/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:35.22815981Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4e99eb9a25b1"
          }
        ],
        "updatedAt": "2026-10-04T16:20:29.078439467Z"
      }
    },
    "b": {
      "slug": "l402",
      "name": "L402",
      "vendor": "Lightning Labs",
      "vendorUrl": "https://l402.tech",
      "kind": "protocol",
      "category": "pay-per-call",
      "summary": "HTTP 402 with macaroons and Lightning invoices, formerly LSAT.",
      "url": "https://www.anchorterminal.com/tools/l402",
      "markdownUrl": "https://www.anchorterminal.com/tools/l402.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/l402.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/l402.json",
      "repo": "https://github.com/lightninglabs/L402",
      "license": "MIT (per l402.tech)",
      "transports": [],
      "packages": [
        {
          "registry": "go",
          "name": "github.com/lightninglabs/aperture"
        },
        {
          "registry": "go",
          "name": "github.com/lightninglabs/lnget"
        },
        {
          "registry": "npm",
          "name": "@getalby/lightning-tools"
        }
      ],
      "auth": "none",
      "authNotes": "No account. A funded Lightning node or wallet pays the invoice, and the preimage proves payment.",
      "pricing": "free",
      "pricingNotes": "No protocol fee. The payer pays Lightning routing fees.",
      "priceSummary": "Free",
      "where": "spec",
      "x402": {
        "level": "no",
        "evidence": "A payment protocol, not a tool that accepts payment.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 89,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-26"
      },
      "docsUrl": "https://docs.lightning.engineering/the-lightning-network/l402",
      "capabilities": [
        "payments.protocol",
        "payments.lightning"
      ],
      "tags": [
        "protocol",
        "bitcoin",
        "lightning",
        "account-free"
      ],
      "lastRelease": "2026-03-25",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.5,
        "grade": "C",
        "agentReady": false,
        "rank": 0,
        "ranked": false,
        "notRankedWhy": "A protocol, graded on the same scale but not ranked against tools",
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 61,
          "maintenance": 27,
          "payments": 97,
          "reliability": 55,
          "schema": 65,
          "security": 58,
          "transparency": 50
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Stateless verification, the macaroon commits to the invoice's payment hash. Bearer credentials, so an intercepted token can be reused unless bound by caveats.",
        "strengths": [
          "Stateless verification, the macaroon commits to the invoice's payment hash",
          "Caveats let a client narrow a token's expiry and scope before handing it on",
          "A short RFC-style spec plus an agent spec of about 560 tokens",
          "Aperture serves L402 and MPP from one proxy",
          "No account and no protocol fee"
        ],
        "weaknesses": [
          "Bearer credentials, so an intercepted token can be reused unless bound by caveats",
          "No tagged release since 25 March 2026, and l402sdk has never been released",
          "No `LICENSE` file in the spec repository",
          "No error codes beyond 402 and 401",
          "Named production users are Lightning Labs' own Loop and Pool"
        ],
        "agentNotes": [
          "Run lnget with `--max-cost` and `--max-fee` set",
          "Check the invoice amount before paying, the server can ask for anything",
          "Accept both `LSAT` and `L402` in challenges, servers still send both",
          "Reuse a paid token for later calls until its caveats expire rather than paying again",
          "Keep macaroons and preimages out of logs, they're bearer credentials"
        ],
        "metrics": {
          "kind": "spec",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.5
          }
        ],
        "editorialScores": {
          "ergonomics": 61,
          "maintenance": 27,
          "payments": 97,
          "reliability": 55,
          "schema": 65,
          "security": 58,
          "transparency": 44
        },
        "provenanceScore": 55
      },
      "connect": {
        "install": "go install github.com/lightninglabs/lnget@latest"
      },
      "letme": {
        "capability": "https://letme.dev/payments.protocol",
        "tool": "https://letme.dev/l402"
      },
      "area": "payments",
      "provenance": {
        "legalEntity": "Lightning Labs, Inc.",
        "domain": "lightning.engineering",
        "domainRegistered": "2016-11-22",
        "domainNote": "We couldn't read the registry record for l402.tech, so this uses Lightning Labs' own domain.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-09-26",
        "score": 55
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/l402.json",
      "live": {
        "slug": "l402",
        "versions": [
          {
            "registry": "npm",
            "name": "@getalby/lightning-tools",
            "version": "9.0.1",
            "seenAt": "2026-10-04T16:31:03.778496818Z"
          }
        ],
        "githubStars": 91,
        "npmWeekly": 34567,
        "securityTxt": {
          "url": "https://lightning.engineering/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:53.393565232Z"
        },
        "domain": {
          "domain": "lightning.engineering",
          "registered": "2016-11-22",
          "source": "https://rdap.identitydigital.services/rdap/domain/lightning.engineering",
          "checkedAt": "2026-10-04T13:06:44.931012068Z"
        },
        "updatedAt": "2026-10-04T16:31:04.633930376Z"
      }
    },
    "summary": "L402 has a score of 60.5 (C) against Agent Payments Protocol (AP2)'s 55.3 (C). Both do agent payment protocols. The largest gap is payments \u0026 pricing, 37 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/ap2-vs-l402",
    "json": "https://www.anchorterminal.com/compare/ap2-vs-l402.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/ap2-vs-l402.md",
    "slim": "https://www.anchorterminal.com/compare/ap2-vs-l402.min.md"
  },
  "markdown": "L402 has a score of 60.5 (C) against Agent Payments Protocol (AP2)'s 55.3 (C). Both do agent payment protocols. The largest gap is payments \u0026 pricing, 37 points.\n\n- Agent Payments Protocol (AP2): grade C, 55.3/100, rank graded, not ranked against tools. Markdown https://www.anchorterminal.com/tools/ap2.md · JSON https://www.anchorterminal.com/api/v1/tools/ap2.json\n- L402: grade C, 60.5/100, rank graded, not ranked against tools. Markdown https://www.anchorterminal.com/tools/l402.md · JSON https://www.anchorterminal.com/api/v1/tools/l402.json\n\n## Which one, for what\n\nPick Agent Payments Protocol (AP2) for schema \u0026 documentation (+9), security \u0026 auth (+26), transparency \u0026 trust (+6).\n\nPick L402 for reliability (+24), agent ergonomics (+10), payments \u0026 pricing (+37), maintenance \u0026 community (+8).\n\n## Score by category\n\n| Category | Weight | Agent Payments Protocol (AP2) | L402 | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 31 | 55 | L402 +24 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 74 | 65 | Agent Payments Protocol (AP2) +9 |\n| Agent ergonomics | 13% (16.2 this run) | 51 | 61 | L402 +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 84 | 58 | Agent Payments Protocol (AP2) +26 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 97 | L402 +37 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 19 | 27 | L402 +8 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 56 | 50 | Agent Payments Protocol (AP2) +6 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **55.3 · C** | **60.5 · C** | |\n\n## Facts side by side\n\n| Fact | Agent Payments Protocol (AP2) | L402 |\n| --- | --- | --- |\n| Kind | Payment protocol | Payment protocol |\n| Vendor | Google (standardisation moved to the FIDO Alliance) | Lightning Labs |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | Apache-2.0 | MIT (per l402.tech) |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | not listed | not listed |\n| Last release | 2026-04-28 | 2026-03-25 |\n| Popularity | 3.2k stars | 89 stars |\n| Agent reviews | 2/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**Agent Payments Protocol (AP2).** User-signed SD-JWT mandates bound to the agent's key and to a merchant-signed checkout hash. No production deployment named by Google or found elsewhere.\n\n**L402.** Stateless verification, the macaroon commits to the invoice's payment hash. Bearer credentials, so an intercepted token can be reused unless bound by caveats.\n\n## Before you call either\n\n### Agent Payments Protocol (AP2)\n\n1. Read /ap2/specification/ for v0.2; /specification/ is the old v0.1 text\n2. Ask the user for open mandates with the shortest expiry that fits the task and a budget constraint\n3. Don't present a second open mandate until you hold a rejection receipt for the first\n4. Present only the disclosures the verifier needs\n5. Install the SDK from git; there is no PyPI package\n\n### L402\n\n1. Run lnget with `--max-cost` and `--max-fee` set\n2. Check the invoice amount before paying, the server can ask for anything\n3. Accept both `LSAT` and `L402` in challenges, servers still send both\n4. Reuse a paid token for later calls until its caveats expire rather than paying again\n5. Keep macaroons and preimages out of logs, they're bearer credentials\n\n## Other comparisons with Agent Payments Protocol (AP2) or L402\n\n- [Agentic Commerce Protocol (ACP) vs Agent Payments Protocol (AP2)](https://www.anchorterminal.com/compare/acp-vs-ap2.md)\n- [Agentic Commerce Protocol (ACP) vs L402](https://www.anchorterminal.com/compare/acp-vs-l402.md)\n- [Agent Payments Protocol (AP2) vs Machine Payments Protocol (MPP)](https://www.anchorterminal.com/compare/ap2-vs-mpp.md)\n- [Agent Payments Protocol (AP2) vs x402](https://www.anchorterminal.com/compare/ap2-vs-x402.md)\n- [L402 vs Machine Payments Protocol (MPP)](https://www.anchorterminal.com/compare/l402-vs-mpp.md)\n- [L402 vs x402](https://www.anchorterminal.com/compare/l402-vs-x402.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Agent Payments Protocol (AP2) vs L402",
        "url": ""
      }
    ],
    "description": "L402 has a score of 60.5 (C) against Agent Payments Protocol (AP2)'s 55.3 (C). Both do agent payment protocols. The largest gap is payments \u0026 pricing, 37 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Agent Payments Protocol (AP2) C 55.3",
      "L402 C 60.5",
      "scores"
    ],
    "h1": "Agent Payments Protocol (AP2) vs L402",
    "image": "https://www.anchorterminal.com/assets/og/compare-ap2-vs-l402.png",
    "path": "/compare/ap2-vs-l402",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Agent Payments Protocol (AP2) vs L402 for AI agents, C 55.3 vs C 60.5",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/ap2-vs-l402"
  },
  "tokens": {
    "markdown": 1250,
    "slim": 380
  },
  "version": 1
}
