Paid
by Agent Paid Limited HTTP API in Payment & monetisation platforms
Hosted
Agent Paid Limited · paid.ai since 2017 · who's behind it
Paid is a billing and metering platform for companies that sell AI agents. It records usage signals and model costs and runs credits, plans, invoices and checkout, through a REST API, five SDKs, a CLI and a hosted MCP server.
Good for A team selling an AI agent that needs usage metering, credit balances, cost and margin tracking and invoicing in one service, with Stripe as the payment rail.
Is this your product? Claim this listing or verify it
Assessment. Paid suits a builder who wants usage metering, credits and invoicing behind one API, with restricted and customer-bound keys, OAuth on the MCP server and a free plan that needs no card. No status page, SLA figure, API changelog or rate-limit numbers were found, both advertised OpenAPI links returned 404, and card payments need the builder's own Stripe account.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://api.agentpaid.io/api/v2- Auth
- OAuth or key
- Pricing
- Freemium · $300 / mo
- x402
- No
- Licence
- Proprietary service under Paid's Master Subscription Agreement. The Node and Python SDKs on GitHub are MIT
- Packages
npm@paid-ai/paid-nodepypipaid-pythongogithub.com/paid-ai/paid-gonpm@paid-ai/cli- Docs
- docs.paid.ai
- llms.txt
- published
- Last release
- npm / week
- 24k
- API
- REST at
https://api.agentpaid.io/api/v2, 178 operations in the v2 reference index across customers, signals, costs, credits, orders, invoices, plans, products, pricing, checkouts, payments, value receipts, analytics and webhooks. A v1 reference with 59 operations is still published - MCP server
- Hosted at
https://mcp.agentpaid.io/mcpover HTTP. OAuth 2.1 with PKCE through auth.paid.ai with scopesmcp:toolsandoffline_access, or a Paid API key as a bearer token. The tool list is not published and the source is closed - Credentials
- Organisation API keys, full-access or restricted with scopes such as
write:api-keys,write:usageandread:analytics. Customer API keys (paid_ck_live_,paid_ck_test_) bound to one customer, with optional expiry and revocation, enabled on request - Rate limits
- A token bucket per organisation on signal ingestion, counted per signal, with separate live and test buckets. No bucket size or refill rate is published. Other endpoints are not yet limited per organisation. Maximum 500 signals a request
- Errors
- JSON body with
error,codeanddetails. 429 withRetry-Afterin seconds forRATE_LIMIT_EXCEEDED, and a second 429 code,CONCURRENCY_LIMIT_EXCEEDED, for analytics queries - Pagination
limit(default 10) andoffseton list calls, withtotalandhasMorein the response and filters by name, status, creation date and external ID on customers- SDKs
- Node
@paid-ai/paid-node1.8.0 (11 September 2026), Pythonpaid-python1.12.0 (10 September 2026), Gopaid-gov1.1.0 (5 August 2026), Ruby and Java, generated by Fern. CLI@paid-ai/cli1.2.0 (15 September 2026) - Webhooks
- Ten billing events, signed with HMAC-SHA256 in
x-webhook-signatureover the timestamp and raw body, one signing secret per organisation with a rotate call, five-minute replay window advised - Payment rails
- Hosted checkout, cards and US virtual bank accounts for ACH and wire, all through the builder's connected Stripe account. Test-mode organisations use a Stripe sandbox
- Plans
- Free up to $100,000 of billings a year, Grow $300 a month up to $200,000, Scale $600 up to $500,000, Accelerate $1,000 up to $1 million, Enterprise custom with five-year data retention. Annual billing takes 20 per cent off. 14-day trial on paid plans
- Data handling
- DPA last updated 13 March 2026. Hosting on AWS US-East-1, breach notice within 72 hours where feasible, data retrievable as JSON for 30 days after termination and deleted from backups within 90 days, 30 days' notice of new sub-processors
- Terms
- The Master Subscription Agreement bars access for monitoring availability or performance and for benchmarking. The website terms bar automated access at scale to the site, dashboards, APIs and documentation
- Capabilities
- payments.metering payments.checkout payments.card
Facts verified 2026-10-09 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Free plan at $0 for up to $100,000 of billings a year, and the pricing page says no credit card is required
- The hosted MCP server signs in through OAuth 2.1 with PKCE and client registration, and tools run with the user's role, so viewers stay read-only
- Customer API keys are bound to one customer, can only send that customer's signals, take an optional expiry and are stored as a hash
- Rate-limited requests answer 429 with
Retry-After, and anidempotencyKeyon each signal makes a whole-batch retry safe - The agreement says customer data is not used to train general-purpose models, and the DPA names AWS US-East-1 and a 30-day retrieval window
Weaknesses
- The docs index advertises an OpenAPI 3.1 file at two addresses, and both returned 404 on 9 October 2026
- No status page, uptime figure or SLA percentage was found. The agreement promises commercially reasonable efforts only
- Rate limits are described as a token bucket per organisation with no published bucket size or refill rate
- No API changelog or deprecation policy was found. Six operations are marked deprecated with no removal date
- The API and MCP server run on agentpaid.io, a second domain, and collecting card or bank payments needs the builder's own connected Stripe account
Before you call it notes for agents
- Call
https://api.agentpaid.io/api/v2withAuthorization: Bearer <key>. A person creates the first key at app.paid.ai. No programmatic signup was found - Give every signal a stable
idempotencyKeyand resend the same key on retry. Signals without one are not deduplicated - Send at most 500 signals a request. A 429 rejects the whole batch, so wait for
Retry-Afterand resend it all - Read the
codefield on a 429.CONCURRENCY_LIMIT_EXCEEDEDcarries noRetry-Afterand clears when an analytics query finishes - Install the Python SDK as
paid-python, the name in its README andpyproject.toml. The quickstart'spip install paidnames a package we could not check
Who's behind it provenance 47/100
- Legal entity namedAgent Paid Limited20/20
- Domain agepaid.ai, registered 2017-12-16 (8 years)11/15
- Endpoint on the vendor's domainapi.agentpaid.io is not on paid.ai0/15
- Terms of serviceread, states 5 of the 7 things a reader expects, and has 1 clause that costs points6.3/10
- Privacy policyread, states 7 of the 8 things a reader expects9.3/10
- Status pagenot found0/10
- Changelognot found0/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service gives no date, states 5 of 7, 2 to know
TL;DR Gives no date. States 5 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on benchmarking and cut-off without notice or for any reason.
Restricts benchmarking or competitive usecosts points
In addition, the Services may not be accessed for purposes of monitoring their availability, performance, or functionality, or for any other benchmarking or competitive purposes.
A clause against publishing test results or using the service to build something that competes.
Says access can be ended without notice or for any reason
Customer agrees that the Company, in its sole discretion and for any or no reason, may terminate Customer's access to the Free Services or any part thereof.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of England and Wales
This Agreement and any dispute arising out of or in connection with it (including non-contractual disputes or claims) shall be governed by and construed in accordance with the laws of England and Wales, without regard to its conflicts of laws rules.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at $1,000.00
…UNDER APPLICABLE LAW IN WHICH CASE COMPANY'S LIABILITY WITH RESPECT TO THE SERVICES PROVIDED SHALL NOT EXCEED $1,000.00.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Customer agrees that the Company, in its sole discretion and for any or no reason, may terminate Customer's access to the Free Services or any part thereof.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 30 days of notice before a change
…by credit card or direct debit whose payment has been declined, the Company will give Customer at least 10 days' prior notice that its account is overdue, in accordance with the “Manner of Giving Notice” section below for billing notices, before suspending services to Customer.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Unless otherwise expressly agreed in writing by the parties (including any additional safeguards required by applicable Data Protection Laws), Customer will not submit to the Services any special category Personal Data or Personal Data relating to criminal convictions and offences.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Paid may adjust per-unit pricing for any renewal term of a subscription.
The per-unit pricing during any renewal term may be adjusted by Company.
Noted by a second reader on 2026-10-08.
After the agreement ends, customer data is available for retrieval for up to 30 days.
Upon termination or expiration of this Agreement, and in accordance with the Documentation and applicable Data Protection Laws, the Company will make Customer Data available for retrieval for up to thirty (30) days.
Noted by a second reader on 2026-10-08.
Paid may name the customer and show its logo in customer lists, presentations and marketing materials, and the customer may opt out by written notice.
Company may identify Customer by name and/or logo as a user of the Services in Company's customer lists, presentations, and marketing materials, provided that such usage does not imply any endorsement by Customer. Customer may opt out at any time by written notice.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 7,746 words
Privacy policy gives no date, states 7 of 8
TL;DR Gives no date. States 7 of the 8 things a reader expects. The rules found no clause to flag.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
We're committed to protecting your privacy and being transparent about how we collect, use, and safeguard your personal data in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and other privacy regulations.
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 24 months
Business contact and marketing lead data is generally retained for up to 24 months after our last meaningful interaction with you, unless you opt out earlier, object to the processing, or a longer period is reasonably necessary to establish, exercise or defend legal claims.
Says when data sent to the service is deleted.
Says who else receives the data
Where we process personal information on behalf of our business customers in connection with the Services, we do so as a processor or service provider under the applicable customer contract and data processing agreement.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Depending on where you live, you may have the right to opt out of certain processing for targeted advertising or similar advertising purposes.
A plain statement either way.
Says what rights people have over their data
Depending on where you live, you may have the right to opt out of certain processing for targeted advertising or similar advertising purposes.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact hello@paid.ai
If you have any questions about our privacy practices or this Privacy Policy, or to exercise your rights, please contact us at hello@paid.ai or write to us at 161 Farringdon Road, London, EC1R 3AL, United Kingdom.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
Where we transfer personal information outside the UK or EEA, we use appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum (or other lawful transfer mechanism) in accordance with applicable data protection laws.
The countries data goes to and the safeguard used.
Paid says it does not use customer prompts or outputs to train third-party foundation models, and shares them with model providers only as needed to generate the requested output.
We do not use customer prompts or outputs to train third-party foundation models, and we do not share prompts or outputs with model providers except as necessary to generate the requested output as part of providing the Services.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-09 · 2,934 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The Master Subscription Agreement names Agent Paid Limited, company number 16113498, registered in England and Wales at 161 Farringdon Road, London, EC1R 3AL. It governs the service, free plan included, and carries no date.
The privacy policy names the same company as controller and says processing done for business customers is governed by the customer contract and the DPA at https://paid.ai/legal/dpa (last updated 13 March 2026).
The API answers at api.agentpaid.io and the MCP server at mcp.agentpaid.io. The MCP server's OAuth metadata names auth.paid.ai as its authorisation server.
paid.ai/.well-known/security.txt returned 404. The DPA gives security@paid.ai for reporting suspected incidents.
RDAP for paid.ai gives a registration date of 2017-12-16 and a transfer on 2025-02-13. Agent Paid Limited's SDK licence files are dated 2025.
No status page or API changelog was found in the pricing page footer, the docs index or the pages read. trust.paid.ai was not read.
Checked 2026-10-09 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-10 00:51 UTC
Probed every five minutes at https://api.agentpaid.io/api/v2. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- github
paid-ai/paid-node1.8.0, released 2026-09-11 - npm
@paid-ai/cli1.2.0 - npm
@paid-ai/paid-node1.8.0 - pypi
paid-python1.12.0, released 2026-09-10 - GitHub stars 8
- npm downloads a week 24k
- PyPI downloads a week 25k
Pages we watch
| Page | Kind | Last checked | Last changed |
|---|---|---|---|
| paid.ai/pricing | pricing | 6 hours ago · 200 | no change seen |
| paid.ai/legal/privacy | privacy | 6 hours ago · 200 | no change seen |
| paid.ai/legal/msa | terms | 6 hours ago · 200 | no change seen |
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/paid.json
Notable
- The rate-limit page says a rejected signals request ingests nothing and that a stable
idempotencyKeyon each signal makes the retry safe source - MCP tools run with the signed-in user's organisation role, so viewers keep read-only access, and each change is recorded in the audit log under that user's name source
- A customer API key can send signals for one customer through
POST /api/v2/signals/bulkand every other route refuses it. Paid keeps only the key's hash source - The docs index lists an OpenAPI 3.1 file at /v-2/openapi.json and /v-2/openapi.yaml. Both answered 404 on 9 October 2026 source
- The Master Subscription Agreement says the services may not be accessed to monitor availability, performance or functionality, or for benchmarking, and that customer data is not used to train general-purpose models source
- The website terms define the Website to include dashboards, APIs and documentation portals and forbid scraping, crawling or automated access at scale source
- The pricing page draws plan prices as animated digit columns. We read $300, $600 and $1,000 a month from the page's markup source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 9 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 7.0 | |
Hosted lines. No status page was found in the pricing page footer, the docs index or the pages read, and trust.paid.ai was not read (0). With no history to read, the incident line takes 5. Rate limits are described as a token bucket per organisation on signal ingestion, counted per signal, with a 500-signal cap a request, but no bucket size or refill rate is published and other endpoints are not yet limited (7 of 15). A 429 carries Retry-After, the docs ask for exponential backoff with jitter, a per-signal idempotencyKey makes batch retries safe and the SDKs retry twice by default. No idempotency key was found on orders or payments (13 of 15). The agreement promises commercially reasonable efforts at 24-hour availability and 48 hours' notice of planned downtime, with no percentage or credit (0). The v2 API is the default version with no beta label, and custom views are marked experimental (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 10.4 | |
The docs index says an OpenAPI 3.1 file is at /v-2/openapi.json and /v-2/openapi.yaml, and both returned 404 on 9 October 2026. Each reference page has a typed Markdown twin and the SDKs are generated from the specification, so 10 of 25. llms.txt per version and Markdown for every page (10). The pages read state purpose and limits well on signals and customer keys and tersely on list calls (15 of 20). Inputs carry enums, defaults and required flags, with free-form maps for data and metadata (12 of 15). Examples use placeholder values, and errors share one error, code, details shape with named codes in the guides (10 of 15). Docs and paths are versioned v1 and v2. No API changelog was found (7 of 15). | |||
| Agent ergonomics | 13%16.2 | 11.4 | |
Graded on the REST API. List calls take limit and offset and return total and hasMore, with no field selection, and the MCP server's tool count could not be read (12 of 25). Customers filter by name, status, creation state, dates and external ID (17 of 20). Errors return a stable code, and the two kinds of 429 are told apart by it (15 of 20). Signals take an idempotencyKey, many resources have upsert or external-ID routes and order amendments have a preview call. MCP annotations were not checked (12 of 20). Official SDKs in five languages and a CLI, with short required lists on the calls read (14 of 15). | |||
| Security & auth | 14%17.5 | 11.4 | |
The MCP server uses OAuth 2.1 with PKCE and client registration, and tools run with the user's role. API keys are full-access or restricted by scope, and customer keys are bound to one customer and one route, expire on request, can be revoked and are stored as a hash. No full scope list was found (27 of 30). Viewers are read-only through MCP and restricted keys limit a workload. No confirmation step for deletes was found (14 of 20). The API returns customer-supplied names and metadata, and the MCP page warns about answers the tools did not produce, with no prompt-injection guidance (7 of 15). An audit log names the user or the key's creator, and keys show lastUsedAt (11 of 15). security.txt returned 404, the DPA gives a reporting address and lists TLS 1.2 and AES-256, and no certification or bounty was found in the pages read. trust.paid.ai was not read (6 of 20). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
| Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found on Paid's own API or for its merchants, whose customers pay by card or bank transfer through a connected Stripe account (0). Plan prices are public at $0, $300, $600 and $1,000 a month by billings tier, with no per-unit price (10). The Free plan covers up to $100,000 of billings a year and the page says no credit card is required (20). A person signs up at app.paid.ai and creates the first key in the dashboard (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.7 | |
The CLI @paid-ai/cli 1.2.0 was published on 15 September 2026, 24 days before the check (30). Five releases in 90 days, CLI 1.1.0 and 1.2.0, Node SDK 1.8.0, Python SDK 1.12.0 and Go SDK v1.1.0 (20). No public API changelog was found. Support is by email, with Slack on paid plans, and the issue queues were not read (5 of 15). Current official SDKs in five languages (15). The SDK repositories carry CI workflows and lockfiles. CI results were not read, and the Go module still declares go 1.13 (7 of 10). | |||
| Transparency & trusteditorial 55, provenance 47 | 7%8.8 | 4.5 | |
| The platform is closed under a published Master Subscription Agreement, and the Node and Python SDKs are MIT. The Go SDK repository has no licence file (17 of 30). The agreement, privacy policy and DPA agree with each other on a 30-day retrieval window, deletion from backups within 90 days, hosting on AWS US-East-1 and no training of general-purpose models on customer data. The agreement is undated (22 of 30). Six operations are marked deprecated with a named replacement and no removal date, and no deprecation policy was found (6 of 20). The DPA names AWS and its region and points to trust.paid.ai for the full sub-processor list, which was not read (10 of 20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 55.1 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 24 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Paid, or have the agent fetch /fixes/paid.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Paid From Anchor Terminal's listing at https://www.anchorterminal.com/tools/paid, the October 2026 research run, assessed 9 October 2026. Grade C, 55.1 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Paid: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 35 out of 100, up to 13 more on the total Why it scored 35: Hosted lines. No status page was found in the pricing page footer, the docs index or the pages read, and trust.paid.ai was not read (0). With no history to read, the incident line takes 5. Rate limits are described as a token bucket per organisation on signal ingestion, counted per signal, with a 500-signal cap a request, but no bucket size or refill rate is published and other endpoints are not yet limited (7 of 15). A 429 carries `Retry-After`, the docs ask for exponential backoff with jitter, a per-signal `idempotencyKey` makes batch retries safe and the SDKs retry twice by default. No idempotency key was found on orders or payments (13 of 15). The agreement promises commercially reasonable efforts at 24-hour availability and 48 hours' notice of planned downtime, with no percentage or credit (0). The v2 API is the default version with no beta label, and custom views are marked experimental (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: Payment platforms take the highest step that applies on the 40-point protocol line. No x402, MPP or L402 was found on Paid's own API or for its merchants, whose customers pay by card or bank transfer through a connected Stripe account (0). Plan prices are public at $0, $300, $600 and $1,000 a month by billings tier, with no per-unit price (10). The Free plan covers up to $100,000 of billings a year and the page says no credit card is required (20). A person signs up at app.paid.ai and creates the first key in the dashboard (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Security & auth, 65 out of 100, up to 6.1 more on the total Why it scored 65: The MCP server uses OAuth 2.1 with PKCE and client registration, and tools run with the user's role. API keys are full-access or restricted by scope, and customer keys are bound to one customer and one route, expire on request, can be revoked and are stored as a hash. No full scope list was found (27 of 30). Viewers are read-only through MCP and restricted keys limit a workload. No confirmation step for deletes was found (14 of 20). The API returns customer-supplied names and metadata, and the MCP page warns about answers the tools did not produce, with no prompt-injection guidance (7 of 15). An audit log names the user or the key's creator, and keys show `lastUsedAt` (11 of 15). security.txt returned 404, the DPA gives a reporting address and lists TLS 1.2 and AES-256, and no certification or bounty was found in the pages read. trust.paid.ai was not read (6 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Schema & documentation, 64 out of 100, up to 5.9 more on the total Why it scored 64: The docs index says an OpenAPI 3.1 file is at /v-2/openapi.json and /v-2/openapi.yaml, and both returned 404 on 9 October 2026. Each reference page has a typed Markdown twin and the SDKs are generated from the specification, so 10 of 25. llms.txt per version and Markdown for every page (10). The pages read state purpose and limits well on signals and customer keys and tersely on list calls (15 of 20). Inputs carry enums, defaults and required flags, with free-form maps for `data` and `metadata` (12 of 15). Examples use placeholder values, and errors share one `error`, `code`, `details` shape with named codes in the guides (10 of 15). Docs and paths are versioned v1 and v2. No API changelog was found (7 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 5. Agent ergonomics, 70 out of 100, up to 4.9 more on the total Why it scored 70: Graded on the REST API. List calls take `limit` and `offset` and return `total` and `hasMore`, with no field selection, and the MCP server's tool count could not be read (12 of 25). Customers filter by name, status, creation state, dates and external ID (17 of 20). Errors return a stable `code`, and the two kinds of 429 are told apart by it (15 of 20). Signals take an `idempotencyKey`, many resources have upsert or external-ID routes and order amendments have a preview call. MCP annotations were not checked (12 of 20). Official SDKs in five languages and a CLI, with short required lists on the calls read (14 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 6. Transparency & trust, 51 out of 100, up to 4.3 more on the total Made of editorial 55, provenance 47. Why it scored 51: The platform is closed under a published Master Subscription Agreement, and the Node and Python SDKs are MIT. The Go SDK repository has no licence file (17 of 30). The agreement, privacy policy and DPA agree with each other on a 30-day retrieval window, deletion from backups within 90 days, hosting on AWS US-East-1 and no training of general-purpose models on customer data. The agreement is undated (22 of 30). Six operations are marked deprecated with a named replacement and no removal date, and no deprecation policy was found (6 of 20). The DPA names AWS and its region and points to trust.paid.ai for the full sub-processor list, which was not read (10 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: paid.ai, registered 2017-12-16 (8 years) (11 of 15) - Endpoint on the vendor's domain: api.agentpaid.io is not on paid.ai (0 of 15) - Terms of service: read, states 5 of the 7 things a reader expects, and has 1 clause that costs points (6.3 of 10) - Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10) - Status page: not found (0 of 10) - Changelog: not found (0 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 77 out of 100, up to 2 more on the total Why it scored 77: The CLI `@paid-ai/cli` 1.2.0 was published on 15 September 2026, 24 days before the check (30). Five releases in 90 days, CLI 1.1.0 and 1.2.0, Node SDK 1.8.0, Python SDK 1.12.0 and Go SDK v1.1.0 (20). No public API changelog was found. Support is by email, with Slack on paid plans, and the issue queues were not read (5 of 15). Current official SDKs in five languages (15). The SDK repositories carry CI workflows and lockfiles. CI results were not read, and the Go module still declares go 1.13 (7 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: trust.paid.ai (the sub-processor list and any certifications). The website terms forbid automated access at scale to Paid's sites, so we stopped at the pages already fetched and the docs' published agent files - unchecked: the paid.ai home page and product pages, for the same reason. A status page link may sit on a page we did not read. None is in the pricing page footer or the docs index - unchecked: the OpenAPI document. Both addresses in the docs index returned 404, so operation counts come from the reference index and schema quality from six reference pages - unchecked: the MCP server's tool names, count, schemas and annotations. The server needs a sign-in and its source is not public - unchecked: who publishes the `paid` package on PyPI that the quickstart tells users to install. The PyPI project page answered with a client challenge. The SDK's README and `pyproject.toml` name `paid-python` - unchecked: GitHub stars, issue queues and CI results for the SDK repositories, and PyPI download counts - unchecked: the registration date of agentpaid.io. RDAP returned no events - unchecked: the list of API key scopes. Three scope names appear in the pages read and no page listing them all was found - The lead named the Python package `paid`. The SDK repository names it `paid-python`. The lead also listed only a docs MCP server, and Paid runs a product MCP server at mcp.agentpaid.io, a CLI, and Ruby and Java SDKs - The plan prices were decoded from the transform values of the pricing page's digit columns, not read as plain text ## Weaknesses - The docs index advertises an OpenAPI 3.1 file at two addresses, and both returned 404 on 9 October 2026 - No status page, uptime figure or SLA percentage was found. The agreement promises commercially reasonable efforts only - Rate limits are described as a token bucket per organisation with no published bucket size or refill rate - No API changelog or deprecation policy was found. Six operations are marked deprecated with no removal date - The API and MCP server run on agentpaid.io, a second domain, and collecting card or bank payments needs the builder's own connected Stripe account ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Call `https://api.agentpaid.io/api/v2` with `Authorization: Bearer <key>`. A person creates the first key at app.paid.ai. No programmatic signup was found - Give every signal a stable `idempotencyKey` and resend the same key on retry. Signals without one are not deduplicated - Send at most 500 signals a request. A 429 rejects the whole batch, so wait for `Retry-After` and resend it all - Read the `code` field on a 429. `CONCURRENCY_LIMIT_EXCEEDED` carries no `Retry-After` and clears when an analytics query finishes - Install the Python SDK as `paid-python`, the name in its README and `pyproject.toml`. The quickstart's `pip install paid` names a package we could not check ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: trust.paid.ai (the sub-processor list and any certifications). The website terms forbid automated access at scale to Paid's sites, so we stopped at the pages already fetched and the docs' published agent files
- unchecked: the paid.ai home page and product pages, for the same reason. A status page link may sit on a page we did not read. None is in the pricing page footer or the docs index
- unchecked: the OpenAPI document. Both addresses in the docs index returned 404, so operation counts come from the reference index and schema quality from six reference pages
- unchecked: the MCP server's tool names, count, schemas and annotations. The server needs a sign-in and its source is not public
- unchecked: who publishes the
paidpackage on PyPI that the quickstart tells users to install. The PyPI project page answered with a client challenge. The SDK's README andpyproject.tomlnamepaid-python - unchecked: GitHub stars, issue queues and CI results for the SDK repositories, and PyPI download counts
- unchecked: the registration date of agentpaid.io. RDAP returned no events
- unchecked: the list of API key scopes. Three scope names appear in the pages read and no page listing them all was found
- The lead named the Python package
paid. The SDK repository names itpaid-python. The lead also listed only a docs MCP server, and Paid runs a product MCP server at mcp.agentpaid.io, a CLI, and Ruby and Java SDKs - The plan prices were decoded from the transform values of the pricing page's digit columns, not read as plain text
Sources 23
- Master Subscription Agreement paid.ai · seen 2026-10-09
- website terms paid.ai · seen 2026-10-09
- privacy policy paid.ai · seen 2026-10-09
- data processing agreement paid.ai · seen 2026-10-09
- fair usage policy paid.ai · seen 2026-10-09
- pricing paid.ai · seen 2026-10-09
- docs index for agents docs.paid.ai · seen 2026-10-09
- API overview and SDK list docs.paid.ai · seen 2026-10-09
- rate limits and 429 handling docs.paid.ai · seen 2026-10-09
- MCP quickstart docs.paid.ai · seen 2026-10-09
- MCP OAuth resource metadata mcp.agentpaid.io · seen 2026-10-09
- CLI command reference docs.paid.ai · seen 2026-10-09
- customer API keys docs.paid.ai · seen 2026-10-09
- webhooks docs.paid.ai · seen 2026-10-09
- bank transfers through Stripe docs.paid.ai · seen 2026-10-09
- checkout guide docs.paid.ai · seen 2026-10-09
- list customers reference docs.paid.ai · seen 2026-10-09
- Node SDK repository, tags and README github.com · seen 2026-10-09
- Python SDK repository and tags github.com · seen 2026-10-09
- Go SDK repository and tags github.com · seen 2026-10-09
- CLI release dates registry.npmjs.org · seen 2026-10-09
- npm weekly downloads api.npmjs.org · seen 2026-10-09
- domain registration rdap.org · seen 2026-10-09
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $300 / mo Free plan at $0 for up to $100,000 of billings a year, with no card required per the pricing page. Paid plans are $300, $600 and $1,000 a month by billings tier, with a 14-day trial and 20 per cent off for annual billing, and Enterprise is priced on request. No per-call price or percentage fee is published. Test-mode organisations work as a sandbox (https://paid.ai/pricing, checked 2026-10-09).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Grow plan | $300 | per month (plan) | up to $200,000 of billings a year, billed monthly |
| Scale plan | $600 | per month (plan) | up to $500,000 of billings a year, billed monthly |
| Accelerate plan | $1000 | per month (plan) | up to $1 million of billings a year, billed monthly |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/paid.xml, or this listing's score history at history.json.
Connect
Install
npm install @paid-ai/paid-node
First request
curl -X POST https://api.agentpaid.io/api/v2/customers/external/customer_123/api-keys \
-H "Authorization: Bearer $PAID_API_KEY" \
-H "Content-Type: application/json" \
-d '{"name": "Tenant runtime (production)"}'
Claude Code
claude mcp add --transport http paid https://mcp.agentpaid.io/mcp
MCP client configuration
{
"mcpServers": {
"paid": {
"type": "http",
"url": "https://mcp.agentpaid.io/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/paid
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Alternatives to Paid
#11 of 14 in Best payment and monetisation platforms for AI agents · All 76 platforms comparisons
Stripe API + MCP ANevermined API + MCP BBCrossmint API + Docs MCP BOrb BLago BAdyen MCP server C
Head to head ATXP vs Paid · Lago vs Paid · Metronome vs Paid · Nevermined API + MCP vs Paid · Orb vs Paid · Paid vs Stripe API + MCP · Paid vs Tempo · Crossmint API + Docs MCP vs Paid · Paid vs Payman Genie MCP · Adyen MCP server vs Paid · Paid vs PayPal MCP server · Paid vs Skyfire API + MCP
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Stripe API + MCP Stripe | A | 82.4 | payments.card payments.metering payments.checkout | no |
| Nevermined API + MCP Nevermined | BB | 70.8 | payments.card payments.metering payments.checkout | no |
| Square Block, Inc. | B | 69.2 | payments.card payments.checkout | no |
| Crossmint API + Docs MCP Crossmint | B | 67.1 | payments.card payments.checkout | no |
| Orb Orb, Inc. | B | 66.5 | payments.metering payments.card | no |
| Lago Get Lago Corp. | B | 65.7 | payments.metering payments.card | no |
Machine-readable
- JSON
/api/v1/tools/paid.json· historyhistory.json· badge/badges/paid.svg· changes feed/feeds/tools/paid.xml - Markdown
/tools/paid.md· slim/tools/paid.min.md(or sendAccept: text/markdown) - Fix list
/fixes/paid.md·/fixes/paid.json - From a terminal
anchor tool paid --md(the CLI) · over MCPget_tool {"slug": "paid"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/paid"><img src="https://www.anchorterminal.com/badges/paid.svg" alt="Paid on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/paid)<a href="https://www.anchorterminal.com/tools/paid">Paid on Anchor Terminal</a>It counts on a page on paid.ai or one of its subdomains, or the README of github.com/paid-ai/paid-node.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "paid", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


