{
  "data": {
    "a": {
      "slug": "l402",
      "name": "L402",
      "vendor": "Lightning Labs",
      "vendorUrl": "https://l402.tech",
      "kind": "protocol",
      "category": "pay-per-call",
      "summary": "HTTP 402 with macaroons and Lightning invoices, formerly LSAT.",
      "url": "https://www.anchorterminal.com/tools/l402",
      "markdownUrl": "https://www.anchorterminal.com/tools/l402.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/l402.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/l402.json",
      "repo": "https://github.com/lightninglabs/L402",
      "license": "MIT (per l402.tech)",
      "transports": [],
      "packages": [
        {
          "registry": "go",
          "name": "github.com/lightninglabs/aperture"
        },
        {
          "registry": "go",
          "name": "github.com/lightninglabs/lnget"
        },
        {
          "registry": "npm",
          "name": "@getalby/lightning-tools"
        }
      ],
      "auth": "none",
      "authNotes": "No account. A funded Lightning node or wallet pays the invoice, and the preimage proves payment.",
      "pricing": "free",
      "pricingNotes": "No protocol fee. The payer pays Lightning routing fees.",
      "priceSummary": "Free",
      "where": "spec",
      "x402": {
        "level": "no",
        "evidence": "A payment protocol, not a tool that accepts payment.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 89,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-26"
      },
      "docsUrl": "https://docs.lightning.engineering/the-lightning-network/l402",
      "capabilities": [
        "payments.protocol",
        "payments.lightning"
      ],
      "tags": [
        "protocol",
        "bitcoin",
        "lightning",
        "account-free"
      ],
      "lastRelease": "2026-03-25",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.5,
        "grade": "C",
        "agentReady": false,
        "rank": 0,
        "ranked": false,
        "notRankedWhy": "A protocol, graded on the same scale but not ranked against tools",
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 61,
          "maintenance": 27,
          "payments": 97,
          "reliability": 55,
          "schema": 65,
          "security": 58,
          "transparency": 50
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Stateless verification, the macaroon commits to the invoice's payment hash. Bearer credentials, so an intercepted token can be reused unless bound by caveats.",
        "strengths": [
          "Stateless verification, the macaroon commits to the invoice's payment hash",
          "Caveats let a client narrow a token's expiry and scope before handing it on",
          "A short RFC-style spec plus an agent spec of about 560 tokens",
          "Aperture serves L402 and MPP from one proxy",
          "No account and no protocol fee"
        ],
        "weaknesses": [
          "Bearer credentials, so an intercepted token can be reused unless bound by caveats",
          "No tagged release since 25 March 2026, and l402sdk has never been released",
          "No `LICENSE` file in the spec repository",
          "No error codes beyond 402 and 401",
          "Named production users are Lightning Labs' own Loop and Pool"
        ],
        "agentNotes": [
          "Run lnget with `--max-cost` and `--max-fee` set",
          "Check the invoice amount before paying, the server can ask for anything",
          "Accept both `LSAT` and `L402` in challenges, servers still send both",
          "Reuse a paid token for later calls until its caveats expire rather than paying again",
          "Keep macaroons and preimages out of logs, they're bearer credentials"
        ],
        "metrics": {
          "kind": "spec",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.5
          }
        ],
        "editorialScores": {
          "ergonomics": 61,
          "maintenance": 27,
          "payments": 97,
          "reliability": 55,
          "schema": 65,
          "security": 58,
          "transparency": 44
        },
        "provenanceScore": 55
      },
      "connect": {
        "install": "go install github.com/lightninglabs/lnget@latest"
      },
      "letme": {
        "capability": "https://letme.dev/payments.protocol",
        "tool": "https://letme.dev/l402"
      },
      "area": "payments",
      "provenance": {
        "legalEntity": "Lightning Labs, Inc.",
        "domain": "lightning.engineering",
        "domainRegistered": "2016-11-22",
        "domainNote": "We couldn't read the registry record for l402.tech, so this uses Lightning Labs' own domain.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-09-26",
        "score": 55
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/l402.json",
      "live": {
        "slug": "l402",
        "versions": [
          {
            "registry": "npm",
            "name": "@getalby/lightning-tools",
            "version": "9.0.1",
            "seenAt": "2026-10-04T16:31:03.778496818Z"
          }
        ],
        "githubStars": 91,
        "npmWeekly": 34567,
        "securityTxt": {
          "url": "https://lightning.engineering/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:53.393565232Z"
        },
        "domain": {
          "domain": "lightning.engineering",
          "registered": "2016-11-22",
          "source": "https://rdap.identitydigital.services/rdap/domain/lightning.engineering",
          "checkedAt": "2026-10-04T13:06:44.931012068Z"
        },
        "updatedAt": "2026-10-04T16:31:04.633930376Z"
      }
    },
    "b": {
      "slug": "x402",
      "name": "x402",
      "vendor": "x402 Foundation (Linux Foundation)",
      "vendorUrl": "https://x402.org",
      "kind": "protocol",
      "category": "pay-per-call",
      "summary": "Protocol for per-request stablecoin payments using HTTP 402.",
      "url": "https://www.anchorterminal.com/tools/x402",
      "markdownUrl": "https://www.anchorterminal.com/tools/x402.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/x402.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/x402.json",
      "repo": "https://github.com/x402-foundation/x402",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@x402/core"
        },
        {
          "registry": "npm",
          "name": "@x402/fetch"
        },
        {
          "registry": "pypi",
          "name": "x402"
        },
        {
          "registry": "go",
          "name": "github.com/x402-foundation/x402/go"
        }
      ],
      "auth": "none",
      "authNotes": "No account. A funded wallet signs each payment. Facilitators may screen addresses (Coinbase CDP runs OFAC and KYT checks).",
      "pricing": "free",
      "pricingNotes": "No protocol fee. The Coinbase CDP facilitator settles 1,000 transactions a month free, then $0.001 each, and pays gas in the exact scheme. Stripe charges 1.5% for x402 with gas included (https://docs.cdp.coinbase.com/x402/core-concepts/facilitator).",
      "priceSummary": "Free · OSS",
      "where": "spec",
      "x402": {
        "level": "no",
        "evidence": "A payment protocol, not a tool that accepts payment.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6400,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://docs.x402.org",
      "llmsTxt": "https://docs.x402.org/llms.txt",
      "capabilities": [
        "payments.protocol",
        "payments.x402",
        "payments.stablecoin"
      ],
      "tags": [
        "protocol",
        "open-source",
        "stablecoin",
        "account-free",
        "foundation"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 79.7,
        "grade": "A",
        "agentReady": true,
        "rank": 0,
        "ranked": false,
        "notRankedWhy": "A protocol, graded on the same scale but not ranked against tools",
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 84,
          "maintenance": 93,
          "payments": 97,
          "reliability": 87,
          "schema": 86,
          "security": 67,
          "transparency": 65
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "high",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-03-06, GHSA-qr2g-p6q7-w82m (high). Facilitators processing Solana payments on @x402/svm before 2.6.0, Python x402 before 2.3.0 or Go before 2.5.0 were exposed. Keys and funds weren't affected, and the fix and advisory were public, so we deduct 2 (https://github.com/x402-foundation/x402/security/advisories/GHSA-qr2g-p6q7-w82m)",
          "2026-05-12, five attacks on x402 validated on local chains, Base Sepolia and live endpoints, across authorisation, binding, replay and web handling, causing unpaid service or paid-but-denied outcomes. Some related fixes appear in the repository (origin binding for sign-in, SSRF in Bazaar), but we couldn't confirm all five are closed, so we deduct 1 (https://arxiv.org/abs/2605.11781)"
        ],
        "verdict": "No account and no protocol fee, a funded wallet is enough. Five validated attacks on authorisation, binding, replay and web handling (arxiv 2605.11781).",
        "strengths": [
          "No account and no protocol fee, a funded wallet is enough",
          "Reference SDKs in TypeScript, Python, Go and Java, released weekly",
          "15 public facilitators listed in the docs, several with no fees",
          "Exact, upto, auth-capture and batch-settlement schemes, with exact specs for 17 networks",
          "Standard error codes, including a non-terminal settlement_pending with the transaction hash"
        ],
        "weaknesses": [
          "Five validated attacks on authorisation, binding, replay and web handling (arxiv 2605.11781)",
          "A high-severity facilitator advisory on Solana handling in March 2026",
          "Spend budgets sit outside the spec, only the upto scheme caps an amount",
          "The FAQ and the exact-scheme spec disagree on who pays gas",
          "Security reports still go to Coinbase's HackerOne rather than a foundation channel"
        ],
        "agentNotes": [
          "Decode PAYMENT-REQUIRED and check amount, asset and payTo against what you expected before signing",
          "Use the upto scheme when the final price isn't known, and cap it",
          "On settlement_pending, look up the returned transaction hash before paying again",
          "Use a production facilitator for Base mainnet, x402.org/facilitator is testnet only",
          "Give the agent its own wallet with a small balance, never a treasury key"
        ],
        "metrics": {
          "kind": "spec",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 4.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "high",
            "grade": "A",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 79.7
          }
        ],
        "editorialScores": {
          "ergonomics": 84,
          "maintenance": 93,
          "payments": 97,
          "reliability": 87,
          "schema": 86,
          "security": 67,
          "transparency": 72
        },
        "provenanceScore": 57
      },
      "connect": {
        "install": "npm i @x402/fetch   # or: pip install x402",
        "http": "curl -i https://api.exa.ai/search -H \"content-type: application/json\" -d '{\"query\":\"x402\"}'\n# 402 Payment Required, PAYMENT-REQUIRED: \u003cbase64 JSON of accepted schemes\u003e\n# retry with PAYMENT-SIGNATURE: \u003cbase64 signed payment\u003e"
      },
      "letme": {
        "capability": "https://letme.dev/payments.protocol",
        "tool": "https://letme.dev/x402"
      },
      "area": "payments",
      "unitPrices": [
        {
          "item": "CDP facilitator after 1,000 a month",
          "unit": "tx",
          "usd": 0.001
        },
        {
          "item": "Stripe x402 processing",
          "unit": "pct",
          "usd": 1.5,
          "note": "gas included"
        }
      ],
      "provenance": {
        "legalEntity": "x402, a Series of LF Projects, LLC",
        "domain": "x402.org",
        "domainRegistered": "2025-02-20",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://github.com/x402-foundation/x402/blob/main/typescript/packages/core/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-26",
        "score": 57
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/x402.json",
      "live": {
        "slug": "x402",
        "versions": [
          {
            "registry": "npm",
            "name": "@x402/core",
            "version": "2.28.0",
            "seenAt": "2026-10-04T16:44:18.101478139Z"
          },
          {
            "registry": "npm",
            "name": "@x402/fetch",
            "version": "2.28.0",
            "seenAt": "2026-10-04T16:44:18.955956326Z"
          },
          {
            "registry": "pypi",
            "name": "x402",
            "version": "2.25.0",
            "released": "2026-09-29",
            "seenAt": "2026-10-04T16:44:20.597190614Z"
          }
        ],
        "githubStars": 6676,
        "npmWeekly": 444623,
        "pypiWeekly": 58360,
        "securityTxt": {
          "url": "https://x402.org/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:45.958029226Z"
        },
        "llmsTxt": {
          "url": "https://docs.x402.org/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:22.474993098Z"
        },
        "domain": {
          "domain": "x402.org",
          "registered": "2025-02-20",
          "source": "https://rdap.publicinterestregistry.org/rdap/domain/x402.org",
          "checkedAt": "2026-10-04T13:06:17.301998006Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/x402-foundation/x402/main/typescript/packages/core/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:48:03.220900718Z",
            "changedAt": "2026-09-30T13:10:50.25107695Z",
            "fingerprint": "c6db0dd5efbf"
          },
          {
            "url": "https://docs.x402.org/guides/migration-v1-to-v2.md",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-04T15:44:17.260567247Z",
            "changedAt": "2026-10-02T15:20:40.840729903Z",
            "fingerprint": "c1eede7ddb9c"
          }
        ],
        "updatedAt": "2026-10-04T16:44:20.783852364Z"
      }
    },
    "summary": "x402 has a score of 79.7 (A) against L402's 60.5 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 66 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/l402-vs-x402",
    "json": "https://www.anchorterminal.com/compare/l402-vs-x402.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/l402-vs-x402.md",
    "slim": "https://www.anchorterminal.com/compare/l402-vs-x402.min.md"
  },
  "markdown": "x402 has a score of 79.7 (A) against L402's 60.5 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 66 points.\n\n- L402: grade C, 60.5/100, rank graded, not ranked against tools. Markdown https://www.anchorterminal.com/tools/l402.md · JSON https://www.anchorterminal.com/api/v1/tools/l402.json\n- x402: grade A, 79.7/100, rank graded, not ranked against tools. Markdown https://www.anchorterminal.com/tools/x402.md · JSON https://www.anchorterminal.com/api/v1/tools/x402.json\n\n## Which one, for what\n\nPick L402 for nothing in particular (no category where it leads by five points or more).\n\nPick x402 for reliability (+32), schema \u0026 documentation (+21), agent ergonomics (+23), security \u0026 auth (+9), maintenance \u0026 community (+66), transparency \u0026 trust (+15).\n\n## Score by category\n\n| Category | Weight | L402 | x402 | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 55 | 87 | x402 +32 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 65 | 86 | x402 +21 |\n| Agent ergonomics | 13% (16.2 this run) | 61 | 84 | x402 +23 |\n| Security \u0026 auth | 14% (17.5 this run) | 58 | 67 | x402 +9 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 97 | 97 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 27 | 93 | x402 +66 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 50 | 65 | x402 +15 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **60.5 · C** | **79.7 · A** | |\n\n## Facts side by side\n\n| Fact | L402 | x402 |\n| --- | --- | --- |\n| Kind | Payment protocol | Payment protocol |\n| Vendor | Lightning Labs | x402 Foundation (Linux Foundation) |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | None | None |\n| Pricing | Free | Free |\n| x402 | no | no |\n| Licence | MIT (per l402.tech) | Apache-2.0 |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | no | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-03-25 | 2026-09-30 |\n| Popularity | 89 stars | 6.4k stars |\n| Agent reviews | 3/5 (2) | 4.5/5 (2) |\n\n## Verdicts\n\n**L402.** Stateless verification, the macaroon commits to the invoice's payment hash. Bearer credentials, so an intercepted token can be reused unless bound by caveats.\n\n**x402.** No account and no protocol fee, a funded wallet is enough. Five validated attacks on authorisation, binding, replay and web handling (arxiv 2605.11781).\n\n## Before you call either\n\n### L402\n\n1. Run lnget with `--max-cost` and `--max-fee` set\n2. Check the invoice amount before paying, the server can ask for anything\n3. Accept both `LSAT` and `L402` in challenges, servers still send both\n4. Reuse a paid token for later calls until its caveats expire rather than paying again\n5. Keep macaroons and preimages out of logs, they're bearer credentials\n\n### x402\n\n1. Decode PAYMENT-REQUIRED and check amount, asset and payTo against what you expected before signing\n2. Use the upto scheme when the final price isn't known, and cap it\n3. On settlement_pending, look up the returned transaction hash before paying again\n4. Use a production facilitator for Base mainnet, x402.org/facilitator is testnet only\n5. Give the agent its own wallet with a small balance, never a treasury key\n\n## Other comparisons with L402 or x402\n\n- [Agentic Commerce Protocol (ACP) vs L402](https://www.anchorterminal.com/compare/acp-vs-l402.md)\n- [Agentic Commerce Protocol (ACP) vs x402](https://www.anchorterminal.com/compare/acp-vs-x402.md)\n- [Agent Payments Protocol (AP2) vs L402](https://www.anchorterminal.com/compare/ap2-vs-l402.md)\n- [Agent Payments Protocol (AP2) vs x402](https://www.anchorterminal.com/compare/ap2-vs-x402.md)\n- [L402 vs Machine Payments Protocol (MPP)](https://www.anchorterminal.com/compare/l402-vs-mpp.md)\n- [Machine Payments Protocol (MPP) vs x402](https://www.anchorterminal.com/compare/mpp-vs-x402.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "L402 vs x402",
        "url": ""
      }
    ],
    "description": "x402 has a score of 79.7 (A) against L402's 60.5 (C). Both do agent payment protocols. The largest gap is maintenance \u0026 community, 66 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "L402 C 60.5",
      "x402 A 79.7",
      "scores"
    ],
    "h1": "L402 vs x402",
    "image": "https://www.anchorterminal.com/assets/og/compare-l402-vs-x402.png",
    "path": "/compare/l402-vs-x402",
    "published": "2026-10-01",
    "section": "tools",
    "title": "L402 vs x402 for AI agents, C 60.5 vs A 79.7 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/l402-vs-x402"
  },
  "tokens": {
    "markdown": 1200,
    "slim": 330
  },
  "version": 1
}
