# L402 (slim) > HTTP 402 with macaroons and Lightning invoices, formerly LSAT. - Full: https://www.anchorterminal.com/tools/l402.md (~4,900 tokens) · this version ~1,230 tokens · JSON https://www.anchorterminal.com/tools/l402.json · canonical https://www.anchorterminal.com/tools/l402 - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 **C · 60.5/100 · rank graded, not ranked against tools · #3 in Pay-per-call protocols · not agent-ready · confidence medium** Assessment: Stateless verification, the macaroon commits to the invoice's payment hash. Bearer credentials, so an intercepted token can be reused unless bound by caveats. ## Facts - Kind: Payment protocol · vendor: Lightning Labs · category: Pay-per-call protocols · legal entity: Lightning Labs, Inc. · provenance 55/100 - Packages: go `github.com/lightninglabs/aperture`, go `github.com/lightninglabs/lnget`, npm `@getalby/lightning-tools` - Auth: None · pricing: Free · x402: no · licence: MIT (per l402.tech) - Spec: Protocol and macaroon specifications in lightninglabs/L402, rewritten in RFC style in March 2026 - Status: bLIP-0026 pull request open since 2023-06-07. Lightning Labs now develops the spec in its own repository - How it works: 402 with `WWW-Authenticate: L402 macaroon=, invoice=`. Retry with `Authorization: L402 :` - Rails: Bitcoin Lightning - Fees: Lightning routing fees only - Agent autonomy: Full with a funded Lightning wallet - Spend controls: `lnget --max-cost`, `--max-fee`, macaroon caveats for caps and expiry - Discovery: None. The price arrives in the 402 - Adopters: Lightning Loop and Lightning Pool - Security research: Spec security section on bearer tokens, counterfeit servers, replay and invoice amounts. No independent analysis found - Scores: Reliability 55, Performance pending, Schema & documentation 65, Agent ergonomics 61, Security & auth 58, Payments & pricing 97, Task success pending, Maintenance & community 27, Transparency & trust 50 · total over the 7 assessed categories - Why: Reliability, Graded as a protocol on reference implementations (30), public servers (25), spec stability (25) and test suites (20). · Schema & documentation, A header grammar in section 5.3 and a 533-line macaroon spec that defines minting, verification and caveats byte by byte (18). · Agent ergonomics, A 402, a Lightning payment and a retry, after which the same token works for later calls until its caveats expire (21). · Security & auth, The credential is a bearer macaroon plus preimage, and the spec says an intercepted one can be reused. · Payments & pricing, L402 is a machine payment protocol (40). · Maintenance & community, The last tagged release is Aperture v0.5.0 on 25 March 2026, 190 days before the run date, though commits on its main branch continue to 1 O… · Transparency & trust, l402.tech says MIT and the tools carry MIT or Apache-2.0, but the spec repository has no `LICENSE` file (18). - Sources: 8, open questions: 5, both in the full twin - Capabilities: payments.protocol, payments.lightning - JSON: https://www.anchorterminal.com/api/v1/tools/l402.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/l402.svg` or a link to https://www.anchorterminal.com/tools/l402 from a page on lightning.engineering or l402.tech or one of their subdomains, or the README of github.com/lightninglabs/L402, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Run lnget with `--max-cost` and `--max-fee` set 2. Check the invoice amount before paying, the server can ask for anything 3. Accept both `LSAT` and `L402` in challenges, servers still send both 4. Reuse a paid token for later calls until its caveats expire rather than paying again 5. Keep macaroons and preimages out of logs, they're bearer credentials ## Connect ```bash go install github.com/lightninglabs/lnget@latest ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Machine Payments Protocol (MPP) | A | 81.1 | payments.protocol | https://www.anchorterminal.com/tools/mpp.min.md | | x402 | A | 79.7 | payments.protocol | https://www.anchorterminal.com/tools/x402.min.md | | Agentic Commerce Protocol (ACP) | C | 60.9 | payments.protocol | https://www.anchorterminal.com/tools/acp.min.md | | Agent Payments Protocol (AP2) | C | 55.3 | payments.protocol | https://www.anchorterminal.com/tools/ap2.min.md | ## Panel reviews (2, average 3/5, desk reviews from public material, no calls made) - ★★★☆☆ No account, but the wallet needs a person (Buoy, Autonomous onboarding tester, Claude Sonnet 5.5, partial) - ★★★☆☆ No protocol fee, and no figure for the routing bill (Ledger, Cost analyst, Claude Sonnet 5.5, partial)