Lago
by Get Lago Corp. HTTP API in Payment & monetisation platforms
Get Lago Corp. · getlago.com since 2020 · who's behind it
Lago is open-source billing software from Get Lago Corp. for usage metering, subscriptions, prepaid credits and invoicing. It is self-hosted under AGPL-3.0 or bought as Lago Cloud, and driven through a REST API, SDKs, a CLI and an MCP server.
Good for A team that wants usage metering, plans, wallets and invoicing under its own control and can run PostgreSQL and Redis.
Is this your product? Claim this listing or verify it
Assessment. Lago's open-source edition runs usage metering, plans, wallets and invoicing on the owner's servers at no charge, with an OpenAPI 3.1 file of 217 operations and releases about every two weeks. The free edition has one unscoped API key and no audit logs, and Lago's llms.txt understates what its MCP server can change.
Facts
- Transport
- HTTP
- Auth
- API key
- Pricing
- Freemium · Freemium
- x402
- No
- Licence
- AGPL-3.0 (platform). The MCP server and agent SDKs are MIT. Premium capabilities and Lago Cloud are commercial
- Packages
ocigetlago/lagopypilago-python-clientnpmlago-javascript-clientgogithub.com/getlago/lago-go-client- Source
- github.com/getlago/lago
- llms.txt
- published
- Last release
- GitHub stars
- 11k
- npm / week
- 48k
- API
- REST under
/api/v1on the owner's host, orhttps://api.getlago.com/api/v1andhttps://api.eu.getlago.com/api/v1on Lago Cloud. The OpenAPI 3.1 description (version 1.55.0) has 217 operations on 136 paths, 339 schemas and 76 webhook events - Graded edition
- The open-source edition an owner runs. Lago Cloud and Premium self-hosted are sold by quote and were not graded
- Credentials
- Organisation API key as a Bearer token. One key in the free edition, rotatable at once. More keys and scheduled rotation need a Premium licence, and
read,writeorread_writepermissions per resource need an enterprise add-on - Install
getlago/lagoDocker image, Docker Compose files or Helm chart 2.x. PostgreSQL 15+ with pg_partman, Redis 7.x or Valkey 7.2+, Kubernetes 1.26+, and ClickHouse 25.6+ for the ClickHouse event store and logs- Rate limits
- The docs give per-organisation defaults of 500 requests a second for event ingestion, 200 for current usage and 50 for other endpoints, with
X-RateLimit-Limit,X-RateLimit-RemainingandX-RateLimit-Resetheaders on 429. Whether they apply to a self-hosted instance was not established - Retries
- Events are deduplicated on
transaction_id. Postgres rejects a repeat with 422value_already_exist. ClickHouse also keys ontimestampand keeps the latest copy. NoIdempotency-Keyheader was found in the API description for other writes - Errors
- JSON with
status,error,codeanderror_details. Documented codes includevalidation_errors,subscription_not_found,feature_unavailableandtoo_many_provider_requests_error - Pagination
pageandper_page, default 100 in most cases, withmetagivingcurrent_page,next_page,prev_page,total_pagesandtotal_count- SDKs
- Python
lago-python-client, JavaScriptlago-javascript-client, Rubylago-ruby-clientand Golago-go-client, each with a v1.55.0 tag. The Lago CLI is at v1.0.2 and the Python agent SDK at v0.3.1 - MCP server
- Rust server
lago-mcp-server0.2.1 from getlago/lago-agent-toolkit, MIT, run as a Docker image over stdio withLAGO_API_KEYandLAGO_API_URL. 57 tools in the source, 25 of which change state. No annotations and no read-only mode - Webhooks
- 76 event types. Signed with a JWT by default or HMAC, in
X-Lago-SignaturewithX-Lago-Signature-Algorithm, and each delivery carriesX-Lago-Unique-Key - Payment collection
- Lago is not a payment processor. Invoices are collected through Stripe, Adyen, GoCardless and other processors. Stripe Shared Payment Token collection is a public preview behind a feature flag
- Telemetry
- Product analytics go to Segment by default, with the events listed in the docs and no invoice amounts collected, per Lago.
LAGO_DISABLE_SEGMENT=trueturns them off. The CLI sends no telemetry, per the changelog - Audit
- Activity logs, API logs and security logs exist for paid tiers and need ClickHouse. Free users have no access to activity logs
- Support life
- Long-term-support releases get two years of full support and two years of limited support under the Service Life Policy of 1 January 2026. Other releases are outside it
- Capabilities
- payments.metering payments.card
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- The whole platform is AGPL-3.0 and installs from the official
getlago/lagoDocker image or Helm charts, with no software fee - Public OpenAPI 3.1 description with 217 operations, 339 schemas and 76 webhook events, plus llms.txt, a full-text docs export and Markdown twins
- Six tagged releases between 27 July and 7 October 2026, and the five latest test runs on the API's main branch passed on 8 and 9 October
- Usage events are deduplicated on
transaction_id, so a retried event is billed once when it is resent unchanged - Self-hosted analytics are listed event by event and switched off with
LAGO_DISABLE_SEGMENT=true, which the source confirms
Weaknesses
- The free edition has one organisation API key with full access. Creating more keys needs a Premium licence and per-resource permissions need an enterprise add-on
- Activity logs are closed to free users, and activity, API and security logs also need ClickHouse
- Lago's llms.txt says the MCP server has one write action. Its source defines 57 tools, 25 of which create, update, delete, void or retry, with no read-only mode
- Lago Cloud and Premium have no public price. The pricing summary states a five-figure minimum annual commitment and a custom quote
- The pricing summary says a Lago Cloud free trial is available, and the docs FAQ says Premium plans have no free trial
- No security.txt, repository security policy or published advisory was found, and the privacy policy does not cover data held in the product
Before you call it notes for agents
- Call
<your Lago API origin>/api/v1withAuthorization: Bearer <key>. On Lago Cloud the hosts areapi.getlago.comandapi.eu.getlago.com - Send every usage event with a deterministic
transaction_idand an explicittimestamp, and resend the same payload on retry. On the ClickHouse event store a changed timestamp is billed again - Expect 422
value_already_existfor a repeated event on the Postgres event store. Treat it as success for a retry - Page with
pageandper_pageand readmeta.next_pageandmeta.total_count. The default page size is 100 in most cases - Treat the free edition's API key as full access. It can void invoices and terminate subscriptions, so keep it out of prompts and ask a person before financial changes
- Before giving an assistant the MCP server, note that it includes
delete_invoice,void_invoice,delete_planandcreate_paymentand sets no read-only annotations
Who's behind it provenance 41/100
- Legal entity namedGet Lago Corp.20/20
- Domain agegetlago.com, registered 2020-11-27 (5 years)11/15
- Endpoint on the vendor's domain is not on getlago.com0/15
- Terms of servicenot found0/10
- Privacy policynot found0/10
- Status pagenot found0/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service none to read
TL;DR We found no terms of service published for this product, so there is nothing to read and the check scores 0.
Privacy policy none to read
TL;DR We found no privacy policy published for this product, so there is nothing to read and the check scores 0.
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The privacy policy and the Lago Cloud terms name Get Lago Corp., 1111B S Governors Ave #7455, Dover, DE 19904, United States, company number 86-3963083.
No terms link is given because the edition graded is AGPL-3.0 software the owner runs. The Lago Self-Hosted Terms and Conditions (updated 9 March 2024) say they apply to self-hosted Premium plans, and the Lago Cloud terms apply through an order form.
No privacy link is given. The privacy policy (updated 18 September 2026) covers customers' representatives, suppliers, candidates and site visitors, and does not address data held in a self-hosted instance or the Segment analytics it sends.
The API answers on the owner's own host. Lago Cloud answers at api.getlago.com and api.eu.getlago.com.
status.getlago.com, on incident.io, covers the US and EU Lago Cloud clusters only, so no status page is recorded for the graded edition.
getlago.com/.well-known/security.txt returned 404. The security page gives security@getlago.com.
RDAP for getlago.com gives a registration date of 2020-11-27 and Gandi SAS as registrar.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-09 18:39 UTC
- github
getlago/lagov1.55.0, released 2026-10-07 - npm
lago-javascript-client1.55.0 - pypi
lago-python-client1.55.0, released 2026-10-07 - GitHub stars 11k
- npm downloads a week 48k
- PyPI downloads a week 4.5k
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| getlago.com/docs/changelog/product | changelog | 6 hours ago · 200 | no change seen |
| getlago.com/pricing.md | pricing | 6 hours ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/lago.json
Notable
- The free edition has one API key. Creating more is a Premium capability and per-resource permissions are an enterprise add-on source
- Event deduplication differs by event store. Postgres rejects a repeat with 422, and ClickHouse keys on
transaction_idandtimestampand keeps the latest copy source - Self-hosted instances send product analytics to Segment by default, and
LAGO_DISABLE_SEGMENT=truestops it source - The MCP server in getlago/lago-agent-toolkit defines 57 tools, 25 of which change state, and sets no annotations. Lago's llms.txt describes it as read-mostly with one write action source
- The Service Life Policy of 1 January 2026 gives long-term-support releases two years of full support and two years of limited support source
- Lago Cloud carries a five-figure minimum annual commitment and no published rate source
- The site's llms.txt, the docs llms.txt and the pricing summary carry instructions addressed to AI agents. We record them as a fact and did not treat them as instructions source
- The Lago CLI, announced in September 2026 and at v1.0.2, is generated from the API description, prints the request with
--dry-runand asks before destructive commands source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 17.2 | |
Read with the local-software lines, on the open-source edition an owner runs. Lago Cloud is sold by quote with a five-figure minimum annual commitment, so it is not the surface an agent can start on. Official getlago/lago Docker image, Docker Compose files and Helm charts, with a compatibility matrix naming PostgreSQL 15+, Redis 7.x or Valkey 7.2+ and Kubernetes 1.26+ for the latest release (20). Public CI with 2,605 spec files in getlago/lago-api, and the five latest runs of the spec workflow on main, on 8 and 9 October 2026, all passed (25). The main repository has 28 open issues and pull requests against 10,665 stars. About 16 are issues, and several bug reports from 2024 and 2025 carry a stale label with no fix, among them installation, sign-up and CORS problems (17 of 25). Versions follow v1.x numbering and breaking changes get migration guides, but they arrive in minor releases such as v1.50.0, and GitHub release notes are lists of pull requests with no changelog file (9 of 15). Version 1.55.0, past 1.0 (15). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 14.1 | |
A public OpenAPI 3.1 description in getlago/lago-openapi, version 1.55.0, with 217 operations on 136 paths, 339 schemas and 76 webhook events (25). llms.txt on the site and the docs, a full-text docs export and a Markdown twin of each page (10). Every operation has an operation ID, and 94 of 217 have a description longer than 80 characters. The docs index says when to use the docs and the event pages explain retries, while few operations say when not to use them (13 of 20). The file has 372 enums and 787 required lists, with free-form event properties and metadata (13 of 15). About 2,000 examples, and an errors page with named codes. No operation documents a 429 response although the rate-limit page describes one (13 of 15). The path is versioned /api/v1, a versioning and deprecation page exists, the description's version follows each release, and the product changelog is dated by month (13 of 15). | |||
| Agent ergonomics | 13%16.2 | 11.5 | |
Graded on the REST API. List calls take page and per_page, with a default of 100 in most cases. No field selection or summary view was found (13 of 25). Page-number pagination with meta giving next_page, total_pages and total_count, and filters as simple and array query parameters (17 of 20). Errors carry status, error, code and error_details, with codes such as subscription_not_found, feature_unavailable and value_is_mandatory (17 of 20). Usage events are deduplicated on transaction_id, with a documented caveat that the ClickHouse event store also keys on timestamp. No Idempotency-Key header was found in the API description for other writes such as invoices, payments and credit notes. The CLI has --dry-run and asks before destructive commands. The MCP server sets no readOnlyHint or destructiveHint (10 of 20). Official SDKs for Python, JavaScript, Ruby and Go, each tagged v1.55.0, and a CLI generated from the API description (14 of 15). | |||
| Security & auth | 14%17.5 | 6.5 | |
Scored on the free self-hosted edition. One organisation API key sent as a Bearer token, which can be rotated at once. Creating further keys needs a Premium licence, which the source enforces, and read, write or read_write permissions per resource need an enterprise add-on (12 of 30). With no scopes in the free edition, least privilege is not available. The CLI prompts before delete, void, finalise and terminate in live mode, and the MCP server has no read-only mode and relies on a tool description asking the model to confirm a deletion (6 of 20). The API returns customer-supplied names, metadata and event properties. The docs tell agents to keep financial changes behind approval, and no prompt-injection guidance for the API or MCP server was found (5 of 15). The docs say free users have no access to activity logs, and activity, API and security logs need ClickHouse. The owner keeps its own server logs (4 of 15). The security page states SOC 2 Type II and regular third-party penetration tests and gives security@getlago.com. security.txt returned 404, neither repository has a security policy file, GitHub lists no published advisories for getlago/lago or getlago/lago-api, no bounty was found and the trust centre could not be read (10 of 20). | |||
| Payments & pricing | 10%12.5 | 6.2 | |
Read with the self-hosted rule. No x402, MPP or L402. Lago's own llms.txt says direct x402 and general agent-wallet support are not available, and its Stripe Shared Payment Token support is a public preview behind a feature flag for collecting a merchant's invoices (0). The open-source edition is free. Lago Cloud and Premium have no public price, only a stated five-figure minimum annual commitment and a custom quote, so half marks (10). Free to run with no card (20). An owner can install it without a sales contact, and the Docker Compose files accept LAGO_CREATE_ORG and LAGO_ORG_API_KEY to create the organisation and key at start-up, as read in the repository (20). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 8.0 | |
| v1.55.0 was tagged on 7 October 2026, two days before the check (30). Six tags fall in the 90 days to 9 October, from v1.51.0 on 27 July (20). The API repository's last 100 commits span 24 September to 9 October 2026. Recent issues in the main repository have three to six comments, while a feature request of 24 September has none and several older bug reports are marked stale (17 of 25). The Python, Ruby and Go SDKs carry a v1.55.0 tag, as does the JavaScript SDK, and the CLI is at v1.0.2 (15). CI is green, Renovate and Dependabot updates are merged, and the MCP server's images are rebuilt on hardened bases as of 6 October (9 of 10). | |||
| Transparency & trusteditorial 77, provenance 41 | 7%8.8 | 5.2 | |
The platform is AGPL-3.0, and the MCP server and agent SDKs are MIT. Premium capabilities are gated by a licence check in the same code (28 of 30). Data in a self-hosted instance stays with the owner. The privacy policy of 18 September 2026 covers customers' representatives, suppliers, candidates and site visitors, not data held in the product, and still names the EU-US Privacy Shield as a transfer safeguard. The Lago Cloud terms let the company use Customer Data to improve the services. No public DPA or sub-processor list was found (15 of 30). A versioning and deprecation page says deprecations are marked in the API description and that migration guides give retirement dates, with no fixed notice period. A Service Life Policy of 1 January 2026 gives long-term-support releases two years of full support and two of limited support (16 of 20). Self-hosted analytics through Segment are on by default, the events are listed and LAGO_DISABLE_SEGMENT=true turns them off, which the source confirms (18 of 20). | |||
| Negative events | ≤15 |
| -3 |
| Total | 65.7 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 28 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Lago, or have the agent fetch /fixes/lago.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Lago From Anchor Terminal's listing at https://www.anchorterminal.com/tools/lago, the October 2026 research run, assessed 9 October 2026. Grade B, 65.7 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Lago: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Security & auth, 37 out of 100, up to 11 more on the total Why it scored 37: Scored on the free self-hosted edition. One organisation API key sent as a Bearer token, which can be rotated at once. Creating further keys needs a Premium licence, which the source enforces, and `read`, `write` or `read_write` permissions per resource need an enterprise add-on (12 of 30). With no scopes in the free edition, least privilege is not available. The CLI prompts before delete, void, finalise and terminate in live mode, and the MCP server has no read-only mode and relies on a tool description asking the model to confirm a deletion (6 of 20). The API returns customer-supplied names, metadata and event properties. The docs tell agents to keep financial changes behind approval, and no prompt-injection guidance for the API or MCP server was found (5 of 15). The docs say free users have no access to activity logs, and activity, API and security logs need ClickHouse. The owner keeps its own server logs (4 of 15). The security page states SOC 2 Type II and regular third-party penetration tests and gives security@getlago.com. security.txt returned 404, neither repository has a security policy file, GitHub lists no published advisories for getlago/lago or getlago/lago-api, no bounty was found and the trust centre could not be read (10 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 2. Payments & pricing, 50 out of 100, up to 6.3 more on the total Why it scored 50: Read with the self-hosted rule. No x402, MPP or L402. Lago's own llms.txt says direct x402 and general agent-wallet support are not available, and its Stripe Shared Payment Token support is a public preview behind a feature flag for collecting a merchant's invoices (0). The open-source edition is free. Lago Cloud and Premium have no public price, only a stated five-figure minimum annual commitment and a custom quote, so half marks (10). Free to run with no card (20). An owner can install it without a sales contact, and the Docker Compose files accept `LAGO_CREATE_ORG` and `LAGO_ORG_API_KEY` to create the organisation and key at start-up, as read in the repository (20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Agent ergonomics, 71 out of 100, up to 4.7 more on the total Why it scored 71: Graded on the REST API. List calls take `page` and `per_page`, with a default of 100 in most cases. No field selection or summary view was found (13 of 25). Page-number pagination with `meta` giving `next_page`, `total_pages` and `total_count`, and filters as simple and array query parameters (17 of 20). Errors carry `status`, `error`, `code` and `error_details`, with codes such as `subscription_not_found`, `feature_unavailable` and `value_is_mandatory` (17 of 20). Usage events are deduplicated on `transaction_id`, with a documented caveat that the ClickHouse event store also keys on `timestamp`. No `Idempotency-Key` header was found in the API description for other writes such as invoices, payments and credit notes. The CLI has `--dry-run` and asks before destructive commands. The MCP server sets no readOnlyHint or destructiveHint (10 of 20). Official SDKs for Python, JavaScript, Ruby and Go, each tagged v1.55.0, and a CLI generated from the API description (14 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Transparency & trust, 59 out of 100, up to 3.6 more on the total Made of editorial 77, provenance 41. Why it scored 59: The platform is AGPL-3.0, and the MCP server and agent SDKs are MIT. Premium capabilities are gated by a licence check in the same code (28 of 30). Data in a self-hosted instance stays with the owner. The privacy policy of 18 September 2026 covers customers' representatives, suppliers, candidates and site visitors, not data held in the product, and still names the EU-US Privacy Shield as a transfer safeguard. The Lago Cloud terms let the company use Customer Data to improve the services. No public DPA or sub-processor list was found (15 of 30). A versioning and deprecation page says deprecations are marked in the API description and that migration guides give retirement dates, with no fixed notice period. A Service Life Policy of 1 January 2026 gives long-term-support releases two years of full support and two of limited support (16 of 20). Self-hosted analytics through Segment are on by default, the events are listed and `LAGO_DISABLE_SEGMENT=true` turns them off, which the source confirms (18 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: getlago.com, registered 2020-11-27 (5 years) (11 of 15) - Endpoint on the vendor's domain: is not on getlago.com (0 of 15) - Terms of service: not found (0 of 10) - Privacy policy: not found (0 of 10) - Status page: not found (0 of 10) - security.txt: not found (0 of 10) ## 5. Reliability, 86 out of 100, up to 2.8 more on the total Why it scored 86: Read with the local-software lines, on the open-source edition an owner runs. Lago Cloud is sold by quote with a five-figure minimum annual commitment, so it is not the surface an agent can start on. Official `getlago/lago` Docker image, Docker Compose files and Helm charts, with a compatibility matrix naming PostgreSQL 15+, Redis 7.x or Valkey 7.2+ and Kubernetes 1.26+ for the latest release (20). Public CI with 2,605 spec files in getlago/lago-api, and the five latest runs of the spec workflow on main, on 8 and 9 October 2026, all passed (25). The main repository has 28 open issues and pull requests against 10,665 stars. About 16 are issues, and several bug reports from 2024 and 2025 carry a stale label with no fix, among them installation, sign-up and CORS problems (17 of 25). Versions follow v1.x numbering and breaking changes get migration guides, but they arrive in minor releases such as v1.50.0, and GitHub release notes are lists of pull requests with no changelog file (9 of 15). Version 1.55.0, past 1.0 (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 6. Schema & documentation, 87 out of 100, up to 2.1 more on the total Why it scored 87: A public OpenAPI 3.1 description in getlago/lago-openapi, version 1.55.0, with 217 operations on 136 paths, 339 schemas and 76 webhook events (25). llms.txt on the site and the docs, a full-text docs export and a Markdown twin of each page (10). Every operation has an operation ID, and 94 of 217 have a description longer than 80 characters. The docs index says when to use the docs and the event pages explain retries, while few operations say when not to use them (13 of 20). The file has 372 enums and 787 required lists, with free-form event `properties` and metadata (13 of 15). About 2,000 examples, and an errors page with named codes. No operation documents a 429 response although the rate-limit page describes one (13 of 15). The path is versioned `/api/v1`, a versioning and deprecation page exists, the description's version follows each release, and the product changelog is dated by month (13 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 7. Maintenance & community, 91 out of 100, up to 0.8 more on the total Why it scored 91: v1.55.0 was tagged on 7 October 2026, two days before the check (30). Six tags fall in the 90 days to 9 October, from v1.51.0 on 27 July (20). The API repository's last 100 commits span 24 September to 9 October 2026. Recent issues in the main repository have three to six comments, while a feature request of 24 September has none and several older bug reports are marked stale (17 of 25). The Python, Ruby and Go SDKs carry a v1.55.0 tag, as does the JavaScript SDK, and the CLI is at v1.0.2 (15). CI is green, Renovate and Dependabot updates are merged, and the MCP server's images are rebuilt on hardened bases as of 6 October (9 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## Deductions Each comes off the total. A fixed and documented problem counts for less at the next check. - 9 October 2026. https://getlago.com/llms.txt says the public MCP server is mostly read, analysis and preview with one narrow write action, retrying a failed payment. The server's source at https://github.com/getlago/lago-agent-toolkit (mcp/src/server.rs, last commit 6 October 2026) defines 57 tools, 25 of which create, update, delete, void, refresh or retry, including `delete_invoice`, `void_invoice`, `delete_plan` and `create_payment`. The repository README lists the write tools, so the claim is contradicted and not hidden (3 off). ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the trust centre at security.getlago.com. The page is drawn by script and showed only its title, so the SOC 2 report, any DPA and any sub-processor list were not read - unchecked: whether the rate limits on the docs page (500 requests a second for event ingestion, 200 for current usage, 50 elsewhere, per organisation) apply to a self-hosted instance. No REST limiter was found in the API repository's initialisers, and the code was not searched further - unchecked: the Lago Cloud API hosts, the hosted discovery MCP at getlago.com/mcp and the docs MCP at docs.getlago.com/mcp. Nothing was sent to them - unchecked: PyPI download counts (PyPI's robots.txt closes the path), the MCP registry, and the individual issue threads - unchecked: which capabilities beyond API keys, permissions, wallet alerts and logs need a Premium licence. The pricing page lists Premium capabilities without a free column - unchecked: `LAGO_CREATE_ORG` and `LAGO_ORG_API_KEY` were read in the repository's Compose files and not found in the docs export, and were not run - The pricing summary says a free trial of Lago Cloud is available. The docs FAQ says there are no free trials for Premium plans, cloud or self-hosted. Which is current was not established - The MCP server's README says 40 tools, its changelog says 55 and the source defines 57 - getlago.com/llms.txt, the docs llms.txt and the pricing summary carry sections of instructions addressed to AI agents, including what to recommend and what not to say about prices. We record them as facts and did not act on them. We did not run the local demo they point to - The Lago Cloud terms forbid access for competitive analysis of the services. They do not govern the open-source edition graded here. No clause against automated access or benchmarking was found. This matters before any probe of Lago Cloud is run - robots.txt answers. getlago.com 200 with ai-input=yes, status.getlago.com 404, api.github.com 404, api.npmjs.org 404, rdap.org 400, and security.getlago.com 200 with an application page and no rules - Seventeen pages were read on getlago.com, two over the limit of about fifteen, to reach the self-hosted terms and the Service Life Policy - The site's security page shows 8,780 GitHub stars. GitHub's API gave 10,665 on 9 October 2026 - The lead held. Its Docker-based Product MCP is the open-source server in getlago/lago-agent-toolkit, and the docs MCP was not graded ## Weaknesses - The free edition has one organisation API key with full access. Creating more keys needs a Premium licence and per-resource permissions need an enterprise add-on - Activity logs are closed to free users, and activity, API and security logs also need ClickHouse - Lago's llms.txt says the MCP server has one write action. Its source defines 57 tools, 25 of which create, update, delete, void or retry, with no read-only mode - Lago Cloud and Premium have no public price. The pricing summary states a five-figure minimum annual commitment and a custom quote - The pricing summary says a Lago Cloud free trial is available, and the docs FAQ says Premium plans have no free trial - No security.txt, repository security policy or published advisory was found, and the privacy policy does not cover data held in the product ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Call `<your Lago API origin>/api/v1` with `Authorization: Bearer <key>`. On Lago Cloud the hosts are `api.getlago.com` and `api.eu.getlago.com` - Send every usage event with a deterministic `transaction_id` and an explicit `timestamp`, and resend the same payload on retry. On the ClickHouse event store a changed timestamp is billed again - Expect 422 `value_already_exist` for a repeated event on the Postgres event store. Treat it as success for a retry - Page with `page` and `per_page` and read `meta.next_page` and `meta.total_count`. The default page size is 100 in most cases - Treat the free edition's API key as full access. It can void invoices and terminate subscriptions, so keep it out of prompts and ask a person before financial changes - Before giving an assistant the MCP server, note that it includes `delete_invoice`, `void_invoice`, `delete_plan` and `create_payment` and sets no read-only annotations ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the trust centre at security.getlago.com. The page is drawn by script and showed only its title, so the SOC 2 report, any DPA and any sub-processor list were not read
- unchecked: whether the rate limits on the docs page (500 requests a second for event ingestion, 200 for current usage, 50 elsewhere, per organisation) apply to a self-hosted instance. No REST limiter was found in the API repository's initialisers, and the code was not searched further
- unchecked: the Lago Cloud API hosts, the hosted discovery MCP at getlago.com/mcp and the docs MCP at docs.getlago.com/mcp. Nothing was sent to them
- unchecked: PyPI download counts (PyPI's robots.txt closes the path), the MCP registry, and the individual issue threads
- unchecked: which capabilities beyond API keys, permissions, wallet alerts and logs need a Premium licence. The pricing page lists Premium capabilities without a free column
- unchecked:
LAGO_CREATE_ORGandLAGO_ORG_API_KEYwere read in the repository's Compose files and not found in the docs export, and were not run - The pricing summary says a free trial of Lago Cloud is available. The docs FAQ says there are no free trials for Premium plans, cloud or self-hosted. Which is current was not established
- The MCP server's README says 40 tools, its changelog says 55 and the source defines 57
- getlago.com/llms.txt, the docs llms.txt and the pricing summary carry sections of instructions addressed to AI agents, including what to recommend and what not to say about prices. We record them as facts and did not act on them. We did not run the local demo they point to
- The Lago Cloud terms forbid access for competitive analysis of the services. They do not govern the open-source edition graded here. No clause against automated access or benchmarking was found. This matters before any probe of Lago Cloud is run
- robots.txt answers. getlago.com 200 with ai-input=yes, status.getlago.com 404, api.github.com 404, api.npmjs.org 404, rdap.org 400, and security.getlago.com 200 with an application page and no rules
- Seventeen pages were read on getlago.com, two over the limit of about fifteen, to reach the self-hosted terms and the Service Life Policy
- The site's security page shows 8,780 GitHub stars. GitHub's API gave 10,665 on 9 October 2026
- The lead held. Its Docker-based Product MCP is the open-source server in getlago/lago-agent-toolkit, and the docs MCP was not graded
Sources 26
- site index for agents, read as data getlago.com · seen 2026-10-09
- docs index for agents getlago.com · seen 2026-10-09
- full-text docs export, the source for the API standards, errors, pagination, rate limits, versioning, API keys, audit logs, MCP, Docker and tracking pages getlago.com · seen 2026-10-09
- pricing summary getlago.com · seen 2026-10-09
- pricing page getlago.com · seen 2026-10-09
- authentication guide getlago.com · seen 2026-10-09
- testing and sandbox guide getlago.com · seen 2026-10-09
- page for coding agents getlago.com · seen 2026-10-09
- legal centre getlago.com · seen 2026-10-09
- Lago Cloud Terms and Conditions getlago.com · seen 2026-10-09
- Lago Self-Hosted Terms and Conditions (Premium plans) getlago.com · seen 2026-10-09
- Service Life Policy getlago.com · seen 2026-10-09
- privacy policy getlago.com · seen 2026-10-09
- security page getlago.com · seen 2026-10-09
- status page for Lago Cloud status.getlago.com · seen 2026-10-09
- main repository, tags, licence, Compose files and README github.com · seen 2026-10-09
- API repository, CI workflows, spec files and telemetry switch github.com · seen 2026-10-09
- OpenAPI 3.1 description, read as the file in the repository github.com · seen 2026-10-09
- MCP server source, README and changelog github.com · seen 2026-10-09
- stars and open issue count api.github.com · seen 2026-10-09
- open issues and pull requests api.github.com · seen 2026-10-09
- published security advisories (none) api.github.com · seen 2026-10-09
- spec workflow runs on main api.github.com · seen 2026-10-09
- releases github.com · seen 2026-10-09
- npm weekly downloads api.npmjs.org · seen 2026-10-09
- domain registration rdap.org · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium Freemium The open-source edition is free to self-host under AGPL-3.0, with no card or account. Lago Cloud and Premium self-hosted are sold by custom quote. The pricing summary states a five-figure minimum annual commitment for Cloud and publishes no rate. It also says a Cloud free trial is available, which the docs FAQ contradicts. No sandbox exists, so tests run on a separate instance or organisation (https://getlago.com/pricing.md, checked 2026-10-09).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/lago.xml, or this listing's score history at history.json.
Connect
Install
docker run -d --name lago -p 80:80 -p 3000:3000 getlago/lago:latest
First request
curl --location --request GET "$LAGO_URL/api/v1/coupons?page=1&per_page=10" \
--header "Authorization: Bearer $API_KEY"
MCP client configuration
{
"mcpServers": {
"lago": {
"args": [
"run",
"--rm",
"-i",
"--pull=always",
"--name",
"lago-mcp-server",
"-e",
"LAGO_API_KEY=your_lago_api_key",
"-e",
"LAGO_API_URL=your_lago_api_url",
"getlago/lago-mcp-server:latest"
],
"command": "docker"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/lago
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Alternatives to Lago
#8 of 14 in Best payment and monetisation platforms for AI agents · All 76 platforms comparisons
Stripe API + MCP ANevermined API + MCP BBOrb BPaid CATXP ETempo BB
Head to head ATXP vs Lago · Lago vs Metronome · Lago vs Nevermined API + MCP · Lago vs Orb · Lago vs Paid · Lago vs Stripe API + MCP · Lago vs Tempo · Adyen MCP server vs Lago · Crossmint API + Docs MCP vs Lago · Lago vs Payman Genie MCP · Lago vs Skyfire API + MCP
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Stripe API + MCP Stripe | A | 82.4 | payments.card payments.metering | no |
| Nevermined API + MCP Nevermined | BB | 70.8 | payments.card payments.metering | no |
| Orb Orb, Inc. | B | 66.5 | payments.metering payments.card | no |
| Paid Agent Paid Limited | C | 55.1 | payments.metering payments.card | no |
| ATXP Circuit & Chisel, Inc. | E | 42.9 | payments.metering payments.card | no |
| Tempo Tempo | BB | 76.6 | payments.metering | no |
Machine-readable
- JSON
/api/v1/tools/lago.json· historyhistory.json· badge/badges/lago.svg· changes feed/feeds/tools/lago.xml - Markdown
/tools/lago.md· slim/tools/lago.min.md(or sendAccept: text/markdown) - Fix list
/fixes/lago.md·/fixes/lago.json - From a terminal
anchor tool lago --md(the CLI) · over MCPget_tool {"slug": "lago"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/lago"><img src="https://www.anchorterminal.com/badges/lago.svg" alt="Lago on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/lago)<a href="https://www.anchorterminal.com/tools/lago">Lago on Anchor Terminal</a>It counts on a page on getlago.com or one of its subdomains, or the README of github.com/getlago/lago.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "lago", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


