Metronome
by Metronome (Stripe) HTTP API in Payment & monetisation platforms
Hosted
Stripe, LLC · metronome.com since 1998 · status page · who's behind it
Metronome is a hosted usage-based billing platform, part of Stripe. Its REST API ingests usage events, defines billable metrics, rate cards and contracts, and generates invoices, with official SDKs for Python, Node.js, Go, Ruby and Java.
Good for A company that meters usage and bills on contracts, credits and commits, with invoices delivered through Stripe, NetSuite or cloud marketplaces.
Is this your product? Claim this listing or verify it
Assessment. Metronome's API carries an Idempotency-Key on every POST, a public OpenAPI description of 142 operations, and agentic tokens whose writes wait for a person's approval. Prices for the Startup plan are public. Errors return only a message string, token scopes are set through support, and the status feed lists 13 incidents since 22 July 2026.
Facts
- Transport
- HTTP
- Endpoint
https://api.metronome.com- Auth
- API key
- Pricing
- Pay per use · 0.8% fee
- x402
- No
- Licence
- Proprietary service under the Stripe Services Agreement. The SDKs on GitHub are Apache-2.0
- Packages
npm@metronome/sdkpypimetronome-sdkgogithub.com/Metronome-Industries/metronome-go- llms.txt
- published
- Last release
- GitHub stars
- 7
- npm / week
- 363k
- API
- REST at https://api.metronome.com, OpenAPI 3.0.1 with 142 operations (127 under
/v1, 15 under/v2), 123 of them POST, and 509 schemas - Credentials
- Bearer tokens made in the web app, separate for sandbox and production, archivable. Scoping by access level, environment or endpoint through support. Agentic tokens queue writes for approval
- Rate limits
- Defaults in requests a second are 2,750 overall, 1,100 on
/v1/ingest, 220 on high-frequency reads, 55 on standard operations, 11 on contract, balance and invoice lists, 8 elsewhere. 429 carriesX-Metronome-Rate-Limit-Type - Idempotency
Idempotency-Keyon all POST endpoints (kept at least 24 hours),uniqueness_keyon contracts, alerts and customer commits and credits,transaction_idon events (34 days)- Pagination
limit(maximum 100) and anext_pagecursor on list endpoints- Errors
- JSON with a single
messagefield. Documented codes are 400, 401, 403, 404, 409, 429 and 5XX - Platform limits
- Defaults per environment are 5 active and 20 total contracts per customer, 20 subscriptions per contract, 5 active webhook destinations, 50 custom fields per object
- SDKs
- Python
metronome-sdk4.11.1 (28 August 2026), Node.js@metronome/sdk3.10.0 (23 July 2026), Go, Ruby and Java, generated by Stainless, Apache-2.0 - Audit
GET /v1/auditLogswith actor (user or token name), resource, action, request ID, IP address and user agent, filterable by date and resource- Integrations
- Invoicing through Stripe, NetSuite and the AWS, Azure and GCP marketplaces. Tax through Stripe Tax, Avalara and Anrok. Salesforce, Segment and Workato connectors
- Certifications
- SOC 2 Type 2 and SOC 1 Type 2 badges on the security page. The SOC 2 report is available from a Metronome representative
- Status
- status.metronome.com on incident.io, components API (Overall, Ingest), Usage Pipeline, Alerts, Dashboard, Data Export and Embeddable Dashboards
- Capabilities
- payments.metering accounting.invoices
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Public OpenAPI 3.0.1 description with 142 operations and 509 schemas, plus llms.txt and a Markdown twin of each docs page
Idempotency-Keyaccepted on every POST for at least 24 hours,uniqueness_keyon contracts and alerts, and eventtransaction_iddeduplication for 34 days- Agentic tokens get
403 AgenticMutationBlockedon writes and queue them at/v1/approval_requestsfor a person to approve or deny - Audit log readable at
/v1/auditLogs, naming the user or API token, the resource, the action, the IP address and the user agent - Startup plan prices are public (0.8 per cent of billing volume and $0.04 per 1,000 ingested events), with a self-serve sandbox sign-up
Weaknesses
- Errors are a single
messagestring with no machine-readable code, and the API description documents a 4xx response on 87 of 142 operations - Token scoping by access level, environment or endpoint is set by contacting support. By default a token has its creator's permissions
- The status feed lists 13 incidents between 22 July and 8 October 2026, among them two hours of elevated API and ingest errors on 3 September
- No SLA document is published. The pricing page names enhanced SLAs on the Custom plan only
- The governing terms are Stripe's Services Agreement, which does not name Metronome and grants Stripe a licence to use customer content to develop and improve its services
- No deprecation policy was found. SDK releases of 16 January and 2 March 2026 removed fields, announced in the changelog on the day
Before you call it notes for agents
- Send an
Idempotency-Keyheader on every POST and reuse it on retry. A cached error is returned for the same key, so use a new key after fixing the cause - Give each usage event a stable
transaction_id. Metronome ignores repeats for 34 days and accepts at most 100 events per/v1/ingestcall - On 429 read
X-Metronome-Rate-Limit-Type(clientorcustomer) and back off. Unlisted endpoints default to 8 requests a second - With an agentic token, expect
403 AgenticMutationBlockedon writes. Post the original method, path and body to/v1/approval_requestsand show the person theapproval_url - Use a sandbox token for testing. The token alone decides whether a call reaches sandbox or production data
Who's behind it provenance 85/100
- Legal entity namedStripe, LLC20/20
- Domain agemetronome.com, registered 1998-11-04 (27 years)15/15
- Endpoint on the vendor's domainapi.metronome.com15/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 1 clause that costs points7.1/10
- Privacy policyread, states 8 of the 8 things a reader expects, and has 1 clause that costs points8/10
- Status pagestatus.metronome.com10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2026-09-28, states 6 of 7, 3 to know
TL;DR Dated 2026-09-28. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.
Says the terms or the service can change without noticecosts points
Stripe may modify this Agreement (or any portion of it) at any time by posting a revised version of the modified portion(s) on the Stripe Legal Page or by notifying User.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
Termination for Convenience. Unless otherwise agreed in writing, Stripe may terminate this Agreement or close User’s Stripe Account at any time.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
Disputes between User and Stripe are subject to a class action waiver and will be resolved by individual binding arbitration, except as stated otherwise in this Agreement.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2026-09-28
Last modified: September 28, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
The laws of the state of California are the Governing Law.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the lesser of USD $1,000 and the fees paid in the 12 months before the claim
Stripe’s aggregate liability for Preview Services is limited to the lesser of the total Fees paid by User to Stripe (excluding all pass-through fees levied by Financial Providers) during the 12 month period before the first event giving rise to liability and USD $1,000.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Stripe may add or remove features of the Preview Services, or suspend or terminate User’s access to Preview Services at any time.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 30 days of notice before a change
Stripe may offer a Service without charge, or waive a Fee for that Service, and may start charging a Fee for that Service upon at least 30 days notice (or longer period if Law requires) to User.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Stripe may specify additional requirements or use restrictions that apply to User´s use of Preview Services in Preview Service Terms or Documentation.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
A user who uses an AI agent to access the services is solely responsible for each action initiated by or through the agent.
If User uses an AI Agent to access the Stripe Services, User is solely responsible for each action initiated by or through the AI Agent.
Noted by a second reader on 2026-10-08.
The user grants Stripe a perpetual, irrevocable licence to use its content to develop, improve and run the services and for Stripe's internal business purposes.
User grants to Stripe, on behalf of itself and its Affiliates, a perpetual, worldwide, non-exclusive, irrevocable, royalty-free license to use the Content to develop, improve, and provide Services and Stripe Technology and for Stripe’s internal business purposes.
Noted by a second reader on 2026-10-08.
Data returned by the services may be used only for the user's own internal business purposes and its intended purpose as described in the service terms or documentation.
User’s use of Stripe Output Data is limited to User’s own internal business purposes and for its intended purpose as may be described in the applicable Service Terms or Documentation.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 19,556 words
Privacy policy dated 2026-04-28, states 8 of 8, 2 to know
TL;DR Dated 2026-04-28. States all 8 things a reader expects. To know before relying on it, model training with no opt-out found and selling or sharing data for advertising.
Says it may use customer content to train or improve models, and no opt-out was foundcosts points
Training artificial intelligence models to power our Services and protect against fraud and other harm.
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Says it sells personal data or shares it for advertising
Because these third parties may use the data Stripe provides for their own purposes, Stripe's provision of data to these parties may be considered a data “sale” or “sharing” (for behavioral advertising) as those terms are defined under the CCPA and other applicable US privacy laws.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated Last updated 2026-04-28
Last updated: April 28, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This Privacy Policy (“Policy”) describes the Personal Data that we collect, how we use and share it, and how you can reach us with privacy-related inquiries.
The basic statement a privacy policy exists to make.
Says how long data is kept
We retain your Personal Data for as long as we continue to provide the Services to you or our Business Users, or for a period in which we reasonably foresee continuing to provide the Services.
Says when data sent to the service is deleted.
Says who else receives the data
Depending on the activity, Stripe assumes the role of a “data controller” and/or “data processor” (or “service provider”).
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising Says it does not sell personal data
Exercising the right to limit the use or sharing of Sensitive Personal Information: We do not sell or share (for behavioral advertising) Sensitive Personal Information as defined by US privacy laws and have not done so in the past 12 months.
A plain statement either way.
Says what rights people have over their data
The Policy also outlines your rights and choices as a data subject, including the right to object to certain uses of your Personal Data.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact dpo@stripe.com
The right to appeal any decision by Stripe relating to your rights by contacting Stripe’s Data Protection Officer (“DPO”) at dpo@stripe.com, and/or relevant regulatory agencies.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
EU Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum issued by the Information Commissioner’s Office.
The countries data goes to and the safeguard used.
The document · read 2026-10-08 · 12,244 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
Metronome's site says it is now part of Stripe. Its legal centre links two documents, Stripe's Services Agreement as terms of service and Stripe's privacy policy.
The Stripe Services Agreement (General Terms last modified 28 September 2026) names Stripe, LLC as the contracting entity for the United States, with other Stripe entities by country. It does not mention Metronome by name. Our request was redirected to the United Kingdom edition of the page.
The Stripe privacy policy was last updated on 28 April 2026 and covers services supplied under the Stripe Services Agreement. It does not mention Metronome by name.
The API answers at https://api.metronome.com per the OpenAPI description's server entry.
https://metronome.com/.well-known/security.txt returned 404. The SDK repositories' SECURITY.md gives dev-feedback@metronome.com for service security questions.
RDAP for metronome.com gives a registration date of 1998-11-04, which predates the company.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-10 00:51 UTC
Probed every five minutes at https://api.metronome.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 3 minutes ago
- github
Metronome-Industries/metronome-nodev3.10.0, released 2026-07-23 - npm
@metronome/sdk3.10.0 - pypi
metronome-sdk4.11.1, released 2026-08-28 - GitHub stars 7
- npm downloads a week 363k
- PyPI downloads a week 157k
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| docs.metronome.com/changelog | changelog | 6 hours ago · 200 | no change seen |
| metronome.com/pricing | pricing | 6 hours ago · 200 | no change seen |
| stripe.com/privacy | privacy | 6 hours ago · 200 | 30 hours ago |
| stripe.com/legal/ssa | terms | 6 hours ago · 200 | 30 hours ago |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/metronome.json
Notable
- Metronome's legal centre links Stripe's Services Agreement as its terms of service and Stripe's privacy policy as its privacy policy source
- The API description carries five approval-request operations for agentic tokens, whose writes return
403 AgenticMutationBlockeduntil a person approves them source - Default rate limits are published per tier, from 2,750 requests a second overall and 1,100 on
/v1/ingestdown to 8 on unlisted endpoints source - The changelog of 10 June 2026 says agents can provision a Metronome account and sandbox through the Stripe Projects CLI, and that of 15 June 2026 announces self-serve checkout to production with a credit card source
- Billing for LLM tokens entered public preview on 3 September 2026, with rates sourced from Stripe's
/v1/modelsAPI source - The status page runs on incident.io with seven components. Its feed lists 13 incidents and three maintenance windows between 22 July and 8 October 2026 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 13.6 | |
Hosted lines. status.metronome.com runs on incident.io with seven components (20). Its feed lists 13 incidents and three maintenance windows between 22 July and 8 October 2026. On 3 September a vendor's partial outage raised API and ingest error rates for two hours. API errors were also elevated on 22 July, 11 September (about 30 minutes) and 8 October (a two-minute burst), and most of the rest were data export or invoice delays. Durations were read on three incident pages only (10 of 30). Default rate limits are published per tier in requests a second (15). 429 responses carry X-Metronome-Rate-Limit-Type and the docs advise backoff, Idempotency-Key covers every POST and the SDKs retry twice by default. No Retry-After was found (13 of 15). The pricing page names enhanced SLAs on the Custom plan and no SLA document was found (0). The API is generally available (10). 68. | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 14.3 | |
A public OpenAPI 3.0.1 description with 142 operations and 509 schemas (25). llms.txt and a Markdown twin of each docs page (10). 131 of 142 operations carry a description longer than 80 characters and 76 have a section on when to use the call. Few say when not to (17 of 20). The description has 345 enums and 774 required lists, with 36 free-form maps (13 of 15). 118 operations carry a request example and 99 a response example. Errors are one message string, and only 87 operations document a 4xx response (10 of 15). Paths are versioned /v1 and /v2, and a dated changelog tags API and SDK entries. No dated API versions (13 of 15). 88. | |||
| Agent ergonomics | 13%16.2 | 12.2 | |
Graded on the REST API. List calls take limit up to 100 and some switches such as skip_zero_qty_line_items. No field selection was found and contract and invoice objects are large (13 of 25). Cursor pagination with next_page, and filters on status and dates. Many reads are POST calls with a body (17 of 20). Errors carry an HTTP status and a message string with no stable code, and the status-code page gives one remedy per status (11 of 20). Idempotency-Key on every POST, uniqueness_key on contracts and alerts, and 34-day transaction_id deduplication on events (20 of 20). Creating a customer has no required list in the description, ingest aliases stand in for IDs, and official SDKs cover five languages (14 of 15). 75. | |||
| Security & auth | 14%17.5 | 11.9 | |
Bearer tokens are created in the web app, shown once, separate for sandbox and production, and can be archived. Scoping by access level, environment or endpoint exists but is set by contacting support, and by default a token has its creator's permissions (22 of 30). The API description defines agentic tokens whose writes return 403 AgenticMutationBlocked and wait at /v1/approval_requests for a person. How to create such a token was not found in the docs index. Dashboard roles are documented on a page we did not read (15 of 20). The API returns customer-supplied names, custom fields and event properties, and no prompt-injection guidance was found (5 of 15). /v1/auditLogs records the user or token, resource, action, IP address and user agent (14 of 15). SOC 2 Type 2 and SOC 1 Type 2 badges, regular penetration tests per the security page, and a Vanta trust centre we could not read. security.txt returned 404 and no bounty or disclosure policy for the service was found (12 of 20). 68. | |||
| Payments & pricing | 10%12.5 | 4.9 | |
| Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found in the API description, the docs index or the pricing page (0). The Startup plan's prices are public at 0.8 per cent of billing volume and $0.04 per 1,000 ingested events. The Custom plan has no price (18 of 20). The pricing page says "Start free" and the quickstart links a self-serve sandbox sign-up, while production checkout needs a credit card. The sign-up page was not read, so whether the sandbox asks for a card is unconfirmed (15 of 20). A person signs up and creates the token in the web app. The changelog of 10 June 2026 says agents can provision an account through the Stripe Projects CLI, which we did not test and which needs a Stripe account (6 of 20). 39. | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.2 | |
| The changelog's latest entry is dated 29 September 2026, ten days before the check (30). It has 20 dated entries since 14 July 2026 (20). A support portal and a public changelog exist. The SDK issue queues (4 and 13 open items on the Node.js and Python repositories) were not read (9 of 15). Official SDKs in five languages. Python 4.11.1 was tagged on 28 August 2026 and Node.js 3.10.0 on 23 July, and both repositories were pushed to on 6 October (15). The repositories carry CI with lint, build and test jobs, lockfiles and automated releases. CI results were not read (8 of 10). 82. | |||
| Transparency & trusteditorial 45, provenance 85 | 7%8.8 | 5.7 | |
| The platform is closed. Metronome's legal centre links the Stripe Services Agreement, last modified 28 September 2026, which does not name Metronome. The SDKs are Apache-2.0 (15 of 30). Stripe's privacy policy of 28 April 2026 and the DPA the agreement incorporates cover data handling. The agreement says Stripe need not retain data after the term and grants Stripe a licence to use customer content to develop and improve its services. No Metronome retention period was found beyond 30 days of webhook delivery history (15 of 30). No deprecation policy was found. One operation is marked deprecated, v1 contract reads point new clients to v2, and SDK releases of 16 January and 2 March 2026 removed fields with changelog entries on the day (7 of 20). Stripe's privacy pages link a sub-processors list we did not read, and Metronome's trust centre is script-drawn. No hosting region was found (8 of 20). 45. | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 69.7 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 21 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Metronome, or have the agent fetch /fixes/metronome.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Metronome From Anchor Terminal's listing at https://www.anchorterminal.com/tools/metronome, the October 2026 research run, assessed 9 October 2026. Grade B, 69.7 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Metronome: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 39 out of 100, up to 7.6 more on the total Why it scored 39: Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found in the API description, the docs index or the pricing page (0). The Startup plan's prices are public at 0.8 per cent of billing volume and $0.04 per 1,000 ingested events. The Custom plan has no price (18 of 20). The pricing page says "Start free" and the quickstart links a self-serve sandbox sign-up, while production checkout needs a credit card. The sign-up page was not read, so whether the sandbox asks for a card is unconfirmed (15 of 20). A person signs up and creates the token in the web app. The changelog of 10 June 2026 says agents can provision an account through the Stripe Projects CLI, which we did not test and which needs a Stripe account (6 of 20). 39. The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Reliability, 68 out of 100, up to 6.4 more on the total Why it scored 68: Hosted lines. status.metronome.com runs on incident.io with seven components (20). Its feed lists 13 incidents and three maintenance windows between 22 July and 8 October 2026. On 3 September a vendor's partial outage raised API and ingest error rates for two hours. API errors were also elevated on 22 July, 11 September (about 30 minutes) and 8 October (a two-minute burst), and most of the rest were data export or invoice delays. Durations were read on three incident pages only (10 of 30). Default rate limits are published per tier in requests a second (15). 429 responses carry `X-Metronome-Rate-Limit-Type` and the docs advise backoff, `Idempotency-Key` covers every POST and the SDKs retry twice by default. No `Retry-After` was found (13 of 15). The pricing page names enhanced SLAs on the Custom plan and no SLA document was found (0). The API is generally available (10). 68. The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 3. Security & auth, 68 out of 100, up to 5.6 more on the total Why it scored 68: Bearer tokens are created in the web app, shown once, separate for sandbox and production, and can be archived. Scoping by access level, environment or endpoint exists but is set by contacting support, and by default a token has its creator's permissions (22 of 30). The API description defines agentic tokens whose writes return `403 AgenticMutationBlocked` and wait at `/v1/approval_requests` for a person. How to create such a token was not found in the docs index. Dashboard roles are documented on a page we did not read (15 of 20). The API returns customer-supplied names, custom fields and event properties, and no prompt-injection guidance was found (5 of 15). `/v1/auditLogs` records the user or token, resource, action, IP address and user agent (14 of 15). SOC 2 Type 2 and SOC 1 Type 2 badges, regular penetration tests per the security page, and a Vanta trust centre we could not read. security.txt returned 404 and no bounty or disclosure policy for the service was found (12 of 20). 68. The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Agent ergonomics, 75 out of 100, up to 4.1 more on the total Why it scored 75: Graded on the REST API. List calls take `limit` up to 100 and some switches such as `skip_zero_qty_line_items`. No field selection was found and contract and invoice objects are large (13 of 25). Cursor pagination with `next_page`, and filters on status and dates. Many reads are POST calls with a body (17 of 20). Errors carry an HTTP status and a `message` string with no stable code, and the status-code page gives one remedy per status (11 of 20). `Idempotency-Key` on every POST, `uniqueness_key` on contracts and alerts, and 34-day `transaction_id` deduplication on events (20 of 20). Creating a customer has no required list in the description, ingest aliases stand in for IDs, and official SDKs cover five languages (14 of 15). 75. The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 5. Transparency & trust, 65 out of 100, up to 3.1 more on the total Made of editorial 45, provenance 85. Why it scored 65: The platform is closed. Metronome's legal centre links the Stripe Services Agreement, last modified 28 September 2026, which does not name Metronome. The SDKs are Apache-2.0 (15 of 30). Stripe's privacy policy of 28 April 2026 and the DPA the agreement incorporates cover data handling. The agreement says Stripe need not retain data after the term and grants Stripe a licence to use customer content to develop and improve its services. No Metronome retention period was found beyond 30 days of webhook delivery history (15 of 30). No deprecation policy was found. One operation is marked deprecated, v1 contract reads point new clients to v2, and SDK releases of 16 January and 2 March 2026 removed fields with changelog entries on the day (7 of 20). Stripe's privacy pages link a sub-processors list we did not read, and Metronome's trust centre is script-drawn. No hosting region was found (8 of 20). 45. The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 6 of the 7 things a reader expects, and has 1 clause that costs points (7.1 of 10) - Privacy policy: read, states 8 of the 8 things a reader expects, and has 1 clause that costs points (8 of 10) - security.txt: not found (0 of 10) ## 6. Schema & documentation, 88 out of 100, up to 2 more on the total Why it scored 88: A public OpenAPI 3.0.1 description with 142 operations and 509 schemas (25). llms.txt and a Markdown twin of each docs page (10). 131 of 142 operations carry a description longer than 80 characters and 76 have a section on when to use the call. Few say when not to (17 of 20). The description has 345 enums and 774 required lists, with 36 free-form maps (13 of 15). 118 operations carry a request example and 99 a response example. Errors are one `message` string, and only 87 operations document a 4xx response (10 of 15). Paths are versioned `/v1` and `/v2`, and a dated changelog tags API and SDK entries. No dated API versions (13 of 15). 88. The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 7. Maintenance & community, 82 out of 100, up to 1.6 more on the total Why it scored 82: The changelog's latest entry is dated 29 September 2026, ten days before the check (30). It has 20 dated entries since 14 July 2026 (20). A support portal and a public changelog exist. The SDK issue queues (4 and 13 open items on the Node.js and Python repositories) were not read (9 of 15). Official SDKs in five languages. Python 4.11.1 was tagged on 28 August 2026 and Node.js 3.10.0 on 23 July, and both repositories were pushed to on 6 October (15). The repositories carry CI with lint, build and test jobs, lockfiles and automated releases. CI results were not read (8 of 10). 82. The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - The Stripe Services Agreement governs per Metronome's legal centre but never names Metronome. Whether service-specific terms or an order form add Metronome clauses was not established. - unchecked: trust.metronome.com is a script-drawn Vanta page, so sub-processors, policies and the full list of certifications were not read. - unchecked: signup.metronome.com was not read, so whether a sandbox account asks for a card is unconfirmed. - unchecked: the Stripe Projects CLI route for agents is the changelog's claim of 10 June 2026 and was not tested. No vendor software was run. - unchecked: how an agentic token is created. The approval operations are in the OpenAPI description and no guide page was found in llms.txt. - unchecked: the status feed gives no durations. Three incident pages were read, the other ten incidents were scored from their titles. - unchecked: the MCP registry did not answer a search for metronome. No MCP server was found in the docs index or the Node.js SDK repository. - unchecked: the RBAC, SSO and webhooks guides, Stripe's DPA and sub-processors list, and the SDK issue queues. - The 2 March 2026 SDK release removed the contract `priority` field in a minor version. Whether customers had notice before that day was not established, so no deduction was taken. - The docs tell Python users to run `pip install --pre metronome-sdk` although the repository's latest tag is 4.11.1, a stable version. - The lead named the docs' LLM token billing as a Stripe listing feature. Metronome has its own domain, API, SDKs, prices and status page, so it is graded apart. ## Weaknesses - Errors are a single `message` string with no machine-readable code, and the API description documents a 4xx response on 87 of 142 operations - Token scoping by access level, environment or endpoint is set by contacting support. By default a token has its creator's permissions - The status feed lists 13 incidents between 22 July and 8 October 2026, among them two hours of elevated API and ingest errors on 3 September - No SLA document is published. The pricing page names enhanced SLAs on the Custom plan only - The governing terms are Stripe's Services Agreement, which does not name Metronome and grants Stripe a licence to use customer content to develop and improve its services - No deprecation policy was found. SDK releases of 16 January and 2 March 2026 removed fields, announced in the changelog on the day ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Send an `Idempotency-Key` header on every POST and reuse it on retry. A cached error is returned for the same key, so use a new key after fixing the cause - Give each usage event a stable `transaction_id`. Metronome ignores repeats for 34 days and accepts at most 100 events per `/v1/ingest` call - On 429 read `X-Metronome-Rate-Limit-Type` (`client` or `customer`) and back off. Unlisted endpoints default to 8 requests a second - With an agentic token, expect `403 AgenticMutationBlocked` on writes. Post the original method, path and body to `/v1/approval_requests` and show the person the `approval_url` - Use a sandbox token for testing. The token alone decides whether a call reaches sandbox or production data ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- The Stripe Services Agreement governs per Metronome's legal centre but never names Metronome. Whether service-specific terms or an order form add Metronome clauses was not established.
- unchecked: trust.metronome.com is a script-drawn Vanta page, so sub-processors, policies and the full list of certifications were not read.
- unchecked: signup.metronome.com was not read, so whether a sandbox account asks for a card is unconfirmed.
- unchecked: the Stripe Projects CLI route for agents is the changelog's claim of 10 June 2026 and was not tested. No vendor software was run.
- unchecked: how an agentic token is created. The approval operations are in the OpenAPI description and no guide page was found in llms.txt.
- unchecked: the status feed gives no durations. Three incident pages were read, the other ten incidents were scored from their titles.
- unchecked: the MCP registry did not answer a search for metronome. No MCP server was found in the docs index or the Node.js SDK repository.
- unchecked: the RBAC, SSO and webhooks guides, Stripe's DPA and sub-processors list, and the SDK issue queues.
- The 2 March 2026 SDK release removed the contract
priorityfield in a minor version. Whether customers had notice before that day was not established, so no deduction was taken. - The docs tell Python users to run
pip install --pre metronome-sdkalthough the repository's latest tag is 4.11.1, a stable version. - The lead named the docs' LLM token billing as a Stripe listing feature. Metronome has its own domain, API, SDKs, prices and status page, so it is graded apart.
Sources 29
- home page, with the notice that Metronome is part of Stripe metronome.com · seen 2026-10-09
- pricing page metronome.com · seen 2026-10-09
- legal centre, linking Stripe's agreement and privacy policy metronome.com · seen 2026-10-09
- security page metronome.com · seen 2026-10-09
- post on the completed acquisition by Stripe metronome.com · seen 2026-10-09
- docs index for agents docs.metronome.com · seen 2026-10-09
- OpenAPI description, read as a file and counted by script docs.metronome.com · seen 2026-10-09
- authentication and token scoping docs.metronome.com · seen 2026-10-09
- rate limits and platform limits docs.metronome.com · seen 2026-10-09
- idempotency docs.metronome.com · seen 2026-10-09
- pagination docs.metronome.com · seen 2026-10-09
- status codes and the rate-limit header docs.metronome.com · seen 2026-10-09
- audit logs docs.metronome.com · seen 2026-10-09
- security principles docs.metronome.com · seen 2026-10-09
- Metronome's own pricing model for order forms docs.metronome.com · seen 2026-10-09
- API quickstart, sandbox sign-up link and first request docs.metronome.com · seen 2026-10-09
- SDK guide docs.metronome.com · seen 2026-10-09
- changelog docs.metronome.com · seen 2026-10-09
- status page status.metronome.com · seen 2026-10-09
- status feed the page links status.metronome.com · seen 2026-10-09
- incident of 3 September 2026 status.metronome.com · seen 2026-10-09
- incident of 11 September 2026 status.metronome.com · seen 2026-10-09
- incident of 8 October 2026 status.metronome.com · seen 2026-10-09
- Stripe Services Agreement, United Kingdom edition after redirect stripe.com · seen 2026-10-09
- Stripe privacy policy stripe.com · seen 2026-10-09
- Node.js SDK repository, shallow clone for tags, README, CI and SECURITY.md github.com · seen 2026-10-09
- Python SDK repository, shallow clone for tags and changelog github.com · seen 2026-10-09
- npm weekly downloads for @metronome/sdk api.npmjs.org · seen 2026-10-09
- RDAP record for metronome.com rdap.org · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Pay per use 0.8% fee The Startup plan costs 0.8 per cent of billing volume plus $0.04 per 1,000 ingested events, self-serve with a credit card for production. The pricing page says "Start free" and a sandbox account is self-serve. Custom plan prices are set by sales, and the docs describe an annual platform fee plus consumption charges on order forms (https://metronome.com/pricing, checked 2026-10-09).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Startup plan fee on billing volume | 0.8% | percentage fee | plus the event fee. Custom plan priced by sales |
| Ingested usage event on the Startup plan | $0. | per transaction | $0.04 per 1,000 ingest events |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/metronome.xml, or this listing's score history at history.json.
Connect
Install
npm install @metronome/sdk
First request
curl -X POST https://api.metronome.com/v1/billable-metrics/create \
-H "Authorization: Bearer $METRONOME_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "API Calls",
"aggregation_type": "count",
"event_type_filter": {
"in_values": ["api_call"]
}
}'
Through letme picks today, calling later
GET https://letme.dev/metronome
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Alternatives to Metronome
#4 of 14 in Best payment and monetisation platforms for AI agents · All 76 platforms comparisons
Stripe API + MCP ATempo BBNevermined API + MCP BBOrb BLago BPayPal MCP server C
Head to head ATXP vs Metronome · Lago vs Metronome · Metronome vs Nevermined API + MCP · Metronome vs Orb · Metronome vs Paid · Metronome vs Stripe API + MCP · Metronome vs Tempo · Metronome vs PayPal MCP server
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Stripe API + MCP Stripe | A | 82.4 | payments.metering | no |
| Tempo Tempo | BB | 76.6 | payments.metering | no |
| Apideck Accounting API + MCP Apideck | BB | 72.9 | accounting.invoices | no |
| Nevermined API + MCP Nevermined | BB | 70.8 | payments.metering | no |
| Merge Accounting API Merge | BB | 70 | accounting.invoices | no |
| Xero API + MCP Xero | B | 67.2 | accounting.invoices | no |
Machine-readable
- JSON
/api/v1/tools/metronome.json· historyhistory.json· badge/badges/metronome.svg· changes feed/feeds/tools/metronome.xml - Markdown
/tools/metronome.md· slim/tools/metronome.min.md(or sendAccept: text/markdown) - Fix list
/fixes/metronome.md·/fixes/metronome.json - From a terminal
anchor tool metronome --md(the CLI) · over MCPget_tool {"slug": "metronome"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/metronome"><img src="https://www.anchorterminal.com/badges/metronome.svg" alt="Metronome on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/metronome)<a href="https://www.anchorterminal.com/tools/metronome">Metronome on Anchor Terminal</a>It counts on a page on metronome.com or one of its subdomains, or the README of github.com/Metronome-Industries/metronome-node.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "metronome", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


