{
  "data": {
    "a": {
      "slug": "l402",
      "name": "L402",
      "vendor": "Lightning Labs",
      "vendorUrl": "https://l402.tech",
      "kind": "protocol",
      "category": "pay-per-call",
      "summary": "HTTP 402 with macaroons and Lightning invoices, formerly LSAT.",
      "url": "https://www.anchorterminal.com/tools/l402",
      "markdownUrl": "https://www.anchorterminal.com/tools/l402.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/l402.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/l402.json",
      "repo": "https://github.com/lightninglabs/L402",
      "license": "MIT (per l402.tech)",
      "transports": [],
      "packages": [
        {
          "registry": "go",
          "name": "github.com/lightninglabs/aperture"
        },
        {
          "registry": "go",
          "name": "github.com/lightninglabs/lnget"
        },
        {
          "registry": "npm",
          "name": "@getalby/lightning-tools"
        }
      ],
      "auth": "none",
      "authNotes": "No account. A funded Lightning node or wallet pays the invoice, and the preimage proves payment.",
      "pricing": "free",
      "pricingNotes": "No protocol fee. The payer pays Lightning routing fees.",
      "priceSummary": "Free",
      "where": "spec",
      "x402": {
        "level": "no",
        "evidence": "A payment protocol, not a tool that accepts payment.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 89,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-26"
      },
      "docsUrl": "https://docs.lightning.engineering/the-lightning-network/l402",
      "capabilities": [
        "payments.protocol",
        "payments.lightning"
      ],
      "tags": [
        "protocol",
        "bitcoin",
        "lightning",
        "account-free"
      ],
      "lastRelease": "2026-03-25",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.5,
        "grade": "C",
        "agentReady": false,
        "rank": 0,
        "ranked": false,
        "notRankedWhy": "A protocol, graded on the same scale but not ranked against tools",
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 61,
          "maintenance": 27,
          "payments": 97,
          "reliability": 55,
          "schema": 65,
          "security": 58,
          "transparency": 50
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Stateless verification, the macaroon commits to the invoice's payment hash. Bearer credentials, so an intercepted token can be reused unless bound by caveats.",
        "strengths": [
          "Stateless verification, the macaroon commits to the invoice's payment hash",
          "Caveats let a client narrow a token's expiry and scope before handing it on",
          "A short RFC-style spec plus an agent spec of about 560 tokens",
          "Aperture serves L402 and MPP from one proxy",
          "No account and no protocol fee"
        ],
        "weaknesses": [
          "Bearer credentials, so an intercepted token can be reused unless bound by caveats",
          "No tagged release since 25 March 2026, and l402sdk has never been released",
          "No `LICENSE` file in the spec repository",
          "No error codes beyond 402 and 401",
          "Named production users are Lightning Labs' own Loop and Pool"
        ],
        "agentNotes": [
          "Run lnget with `--max-cost` and `--max-fee` set",
          "Check the invoice amount before paying, the server can ask for anything",
          "Accept both `LSAT` and `L402` in challenges, servers still send both",
          "Reuse a paid token for later calls until its caveats expire rather than paying again",
          "Keep macaroons and preimages out of logs, they're bearer credentials"
        ],
        "metrics": {
          "kind": "spec",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.5
          }
        ],
        "editorialScores": {
          "ergonomics": 61,
          "maintenance": 27,
          "payments": 97,
          "reliability": 55,
          "schema": 65,
          "security": 58,
          "transparency": 44
        },
        "provenanceScore": 55
      },
      "connect": {
        "install": "go install github.com/lightninglabs/lnget@latest"
      },
      "letme": {
        "capability": "https://letme.dev/payments.protocol",
        "tool": "https://letme.dev/l402"
      },
      "area": "payments",
      "provenance": {
        "legalEntity": "Lightning Labs, Inc.",
        "domain": "lightning.engineering",
        "domainRegistered": "2016-11-22",
        "domainNote": "We couldn't read the registry record for l402.tech, so this uses Lightning Labs' own domain.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-09-26",
        "score": 55
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/l402.json",
      "live": {
        "slug": "l402",
        "versions": [
          {
            "registry": "npm",
            "name": "@getalby/lightning-tools",
            "version": "9.0.1",
            "seenAt": "2026-10-04T16:31:03.778496818Z"
          }
        ],
        "githubStars": 91,
        "npmWeekly": 34567,
        "securityTxt": {
          "url": "https://lightning.engineering/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:53.393565232Z"
        },
        "domain": {
          "domain": "lightning.engineering",
          "registered": "2016-11-22",
          "source": "https://rdap.identitydigital.services/rdap/domain/lightning.engineering",
          "checkedAt": "2026-10-04T13:06:44.931012068Z"
        },
        "updatedAt": "2026-10-04T16:31:04.633930376Z"
      }
    },
    "b": {
      "slug": "mpp",
      "name": "Machine Payments Protocol (MPP)",
      "vendor": "Tempo and Stripe",
      "vendorUrl": "https://mpp.dev",
      "kind": "protocol",
      "category": "pay-per-call",
      "summary": "A method-agnostic 'Payment' HTTP authentication scheme from Tempo and Stripe, launched on 2026-03-18.",
      "url": "https://www.anchorterminal.com/tools/mpp",
      "markdownUrl": "https://www.anchorterminal.com/tools/mpp.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/mpp.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/mpp.json",
      "repo": "https://github.com/tempoxyz/mpp-specs",
      "license": "CC0-1.0 (spec)",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "mppx"
        },
        {
          "registry": "pypi",
          "name": "pympp"
        },
        {
          "registry": "go",
          "name": "github.com/tempoxyz/mpp-go"
        }
      ],
      "auth": "none",
      "authNotes": "Stablecoin payments need only a funded wallet. Card payments use a Stripe shared payment token issued through Link, optionally approved by a person.",
      "pricing": "free",
      "pricingNotes": "No protocol fee. Tempo gas is paid in stablecoin, capped around $0.0006 for a 50k-gas transfer, and the server can sponsor it. Stripe charges 1.5% on stablecoins, its card pricing on cards, and $0.15 per shared payment token (https://docs.stripe.com/payments/machine).",
      "priceSummary": "Free",
      "where": "spec",
      "x402": {
        "level": "no",
        "evidence": "A payment protocol, not a tool that accepts payment.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 93,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-26"
      },
      "docsUrl": "https://mpp.dev",
      "llmsTxt": "https://mpp.dev/llms.txt",
      "capabilities": [
        "payments.protocol",
        "payments.stablecoin",
        "payments.card-token"
      ],
      "tags": [
        "protocol",
        "ietf-draft",
        "stablecoin",
        "cards",
        "stripe"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 81.1,
        "grade": "A",
        "agentReady": true,
        "rank": 0,
        "ranked": false,
        "notRankedWhy": "A protocol, graded on the same scale but not ranked against tools",
        "rankOf": 452,
        "categoryRank": 1,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 91,
          "maintenance": 95,
          "payments": 94,
          "reliability": 85,
          "schema": 89,
          "security": 79,
          "transparency": 45
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-03-26, three advisories in mppx eight days after launch, GHSA-8x4m-qw58-3pcx (critical, multiple payment bypass and griefing bugs), GHSA-mv9j-8jvg-j8mr (high, Tempo session close voucher bypass) and GHSA-8mhj-rffc-rcvw (moderate, Stripe credential replay). Fixed and published, so we deduct 2 (https://github.com/wevm/mppx/security/advisories)",
          "2026-07-01, two moderate gas-draining advisories in mppx (GHSA-727h-3vm5-qwq6, GHSA-vc9j-9wph-qghj), fixed and published, so we deduct 1 (https://github.com/wevm/mppx/security/advisories)"
        ],
        "verdict": "A 1,464-line Internet-Draft with 11 error codes, Retry-After and HMAC-SHA256 test vectors. Individual Internet-Draft, not adopted by any IETF working group.",
        "strengths": [
          "A 1,464-line Internet-Draft with 11 error codes, Retry-After and HMAC-SHA256 test vectors",
          "Single-use proofs, request-body binding and Idempotency-Key guidance in the core",
          "Official SDKs in TypeScript, Python, Go, Rust and Ruby, each running a shared conformance suite",
          "Method drafts for Tempo, EVM, Solana, Lightning, Stellar, XRPL, Hedera and Stripe cards",
          "Spec under CC0"
        ],
        "weaknesses": [
          "Individual Internet-Draft, not adopted by any IETF working group",
          "Five mppx advisories in 2026, one critical",
          "No legal entity or governance body named for the spec",
          "Stripe's minimums are $0.50 for card tokens and 0.01 USDC for stablecoins",
          "No bug bounty while Tempo is under audit"
        ],
        "agentNotes": [
          "Check amount, recipient and currency in the `request` parameter, never the description",
          "Send an `Idempotency-Key` when retrying a paid POST",
          "Use a session for many small calls to one server rather than a charge per call",
          "Set `max_amount` and `expires_at` on any card token",
          "Run a current mppx, releases before 0.4.11 had payment-bypass and session-voucher bugs"
        ],
        "metrics": {
          "kind": "spec",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 4,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 81.1
          }
        ],
        "editorialScores": {
          "ergonomics": 91,
          "maintenance": 95,
          "payments": 94,
          "reliability": 85,
          "schema": 89,
          "security": 79,
          "transparency": 67
        },
        "provenanceScore": 23
      },
      "connect": {
        "install": "npm i mppx   # or: pip install pympp"
      },
      "letme": {
        "capability": "https://letme.dev/payments.protocol",
        "tool": "https://letme.dev/mpp"
      },
      "area": "payments",
      "unitPrices": [
        {
          "item": "Stripe stablecoin processing",
          "unit": "pct",
          "usd": 1.5
        },
        {
          "item": "Stripe shared payment token",
          "unit": "tx",
          "usd": 0.15
        }
      ],
      "provenance": {
        "legalEntity": "",
        "domain": "mpp.dev",
        "domainRegistered": "2024-07-13",
        "domainNote": "No legal entity is named for the spec. Its authors work at Tempo and Stripe.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-09-26",
        "score": 23
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/mpp.json",
      "live": {
        "slug": "mpp",
        "versions": [
          {
            "registry": "github",
            "name": "tempoxyz/mpp-specs",
            "version": "spec-artifacts-27a274a94d34461e875d4593cf36e066c207aab4",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:33:55.546899701Z"
          },
          {
            "registry": "npm",
            "name": "mppx",
            "version": "0.13.1",
            "seenAt": "2026-10-04T16:33:54.568061805Z"
          },
          {
            "registry": "pypi",
            "name": "pympp",
            "version": "0.11.0",
            "released": "2026-08-28",
            "seenAt": "2026-10-04T16:33:55.352094169Z"
          }
        ],
        "githubStars": 95,
        "npmWeekly": 313824,
        "pypiWeekly": 341354,
        "securityTxt": {
          "url": "https://mpp.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:54.126428074Z"
        },
        "llmsTxt": {
          "url": "https://mpp.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:01.223058209Z"
        },
        "domain": {
          "domain": "mpp.dev",
          "registered": "2024-07-13",
          "source": "https://pubapi.registry.google/rdap/domain/mpp.dev",
          "checkedAt": "2026-10-04T13:07:45.084861159Z"
        },
        "pages": [
          {
            "url": "https://datatracker.ietf.org/doc/draft-ryan-httpauth-payment/",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:22.620595223Z",
            "changedAt": "2026-10-02T15:18:41.703193102Z",
            "fingerprint": "2492d95f5cde"
          }
        ],
        "updatedAt": "2026-10-04T16:33:55.546899701Z"
      }
    },
    "summary": "Machine Payments Protocol (MPP) has a score of 81.1 (A) against L402's 60.5 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 68 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/l402-vs-mpp",
    "json": "https://www.anchorterminal.com/compare/l402-vs-mpp.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/l402-vs-mpp.md",
    "slim": "https://www.anchorterminal.com/compare/l402-vs-mpp.min.md"
  },
  "markdown": "Machine Payments Protocol (MPP) has a score of 81.1 (A) against L402's 60.5 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 68 points.\n\n- L402: grade C, 60.5/100, rank graded, not ranked against tools. Markdown https://www.anchorterminal.com/tools/l402.md · JSON https://www.anchorterminal.com/api/v1/tools/l402.json\n- Machine Payments Protocol (MPP): grade A, 81.1/100, rank graded, not ranked against tools. Markdown https://www.anchorterminal.com/tools/mpp.md · JSON https://www.anchorterminal.com/api/v1/tools/mpp.json\n\n## Which one, for what\n\nPick L402 for transparency \u0026 trust (+5).\n\nPick Machine Payments Protocol (MPP) for reliability (+30), schema \u0026 documentation (+24), agent ergonomics (+30), security \u0026 auth (+21), maintenance \u0026 community (+68).\n\n## Score by category\n\n| Category | Weight | L402 | Machine Payments Protocol (MPP) | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 55 | 85 | Machine Payments Protocol (MPP) +30 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 65 | 89 | Machine Payments Protocol (MPP) +24 |\n| Agent ergonomics | 13% (16.2 this run) | 61 | 91 | Machine Payments Protocol (MPP) +30 |\n| Security \u0026 auth | 14% (17.5 this run) | 58 | 79 | Machine Payments Protocol (MPP) +21 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 97 | 94 | L402 +3 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 27 | 95 | Machine Payments Protocol (MPP) +68 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 50 | 45 | L402 +5 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **60.5 · C** | **81.1 · A** | |\n\n## Facts side by side\n\n| Fact | L402 | Machine Payments Protocol (MPP) |\n| --- | --- | --- |\n| Kind | Payment protocol | Payment protocol |\n| Vendor | Lightning Labs | Tempo and Stripe |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | None | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | MIT (per l402.tech) | CC0-1.0 (spec) |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-03-25 | 2026-09-29 |\n| Popularity | 89 stars | 93 stars |\n| Agent reviews | 3/5 (2) | 4/5 (2) |\n\n## Verdicts\n\n**L402.** Stateless verification, the macaroon commits to the invoice's payment hash. Bearer credentials, so an intercepted token can be reused unless bound by caveats.\n\n**Machine Payments Protocol (MPP).** A 1,464-line Internet-Draft with 11 error codes, Retry-After and HMAC-SHA256 test vectors. Individual Internet-Draft, not adopted by any IETF working group.\n\n## Before you call either\n\n### L402\n\n1. Run lnget with `--max-cost` and `--max-fee` set\n2. Check the invoice amount before paying, the server can ask for anything\n3. Accept both `LSAT` and `L402` in challenges, servers still send both\n4. Reuse a paid token for later calls until its caveats expire rather than paying again\n5. Keep macaroons and preimages out of logs, they're bearer credentials\n\n### Machine Payments Protocol (MPP)\n\n1. Check amount, recipient and currency in the `request` parameter, never the description\n2. Send an `Idempotency-Key` when retrying a paid POST\n3. Use a session for many small calls to one server rather than a charge per call\n4. Set `max_amount` and `expires_at` on any card token\n5. Run a current mppx, releases before 0.4.11 had payment-bypass and session-voucher bugs\n\n## Other comparisons with L402 or Machine Payments Protocol (MPP)\n\n- [Agentic Commerce Protocol (ACP) vs L402](https://www.anchorterminal.com/compare/acp-vs-l402.md)\n- [Agentic Commerce Protocol (ACP) vs Machine Payments Protocol (MPP)](https://www.anchorterminal.com/compare/acp-vs-mpp.md)\n- [Agent Payments Protocol (AP2) vs L402](https://www.anchorterminal.com/compare/ap2-vs-l402.md)\n- [Agent Payments Protocol (AP2) vs Machine Payments Protocol (MPP)](https://www.anchorterminal.com/compare/ap2-vs-mpp.md)\n- [L402 vs x402](https://www.anchorterminal.com/compare/l402-vs-x402.md)\n- [Machine Payments Protocol (MPP) vs x402](https://www.anchorterminal.com/compare/mpp-vs-x402.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "L402 vs Machine Payments Protocol (MPP)",
        "url": ""
      }
    ],
    "description": "Machine Payments Protocol (MPP) has a score of 81.1 (A) against L402's 60.5 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 68 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "L402 C 60.5",
      "Machine Payments Protocol (MPP) A 81.1",
      "scores"
    ],
    "h1": "L402 vs Machine Payments Protocol (MPP)",
    "image": "https://www.anchorterminal.com/assets/og/compare-l402-vs-mpp.png",
    "path": "/compare/l402-vs-mpp",
    "published": "2026-10-01",
    "section": "tools",
    "title": "L402 vs Machine Payments Protocol (MPP) for AI agents",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/l402-vs-mpp"
  },
  "tokens": {
    "markdown": 1300,
    "slim": 380
  },
  "version": 1
}
