x402 vs MPP: Machine Payments Protocol and HTTP 402
By Shawn Michael Thomas II, Founder of Simple Easy Transactions · Published ·
What are x402 and MPP, and how do I accept both for pay-per-call agent payments? x402 and MPP (the Machine Payments Protocol) are two open protocols that let an AI agent pay for an API call inside the HTTP request itself: the server answers 402 Payment Required with its price, the agent pays and retries, and the server returns the result. x402, stewarded by the x402 Foundation, carries payments, today mostly USDC on chain, in PAYMENT-REQUIRED and PAYMENT-SIGNATURE headers. MPP, co-authored by Stripe and Tempo, uses WWW-Authenticate: Payment and also takes cards. With mppx, one endpoint can serve both.
AT A GLANCE
x402 vs MPP (Machine Payments Protocol).
| Question | x402 | MPP (Machine Payments Protocol) |
|---|---|---|
| Who stewards it | The x402 Foundation, a Linux Foundation project; Coinbase contributed the protocol | Co-authored by Stripe and Tempo; the core scheme is an IETF Internet-Draft |
| Status code | 402 Payment Required | 402 Payment Required, also when a credential fails |
| Price and terms | PAYMENT-REQUIRED header (base64 JSON) | WWW-Authenticate: Payment challenge |
| Proof of payment | PAYMENT-SIGNATURE header | Authorization: Payment (or Payment-Authorization) |
| Receipt | PAYMENT-RESPONSE header | Payment-Receipt header |
| Payment methods | Tokens on registered blockchain networks, most often USDC; its README says it aims to add fiat networks too | Stablecoins, cards through Stripe Shared Payment Tokens, Lightning and custom methods |
| Settlement | A facilitator verifies and settles on chain (Coinbase's CDP facilitator: Base, Polygon, Arbitrum, World, Solana) | Depends on the method; through Stripe, payments land in your Stripe balance |
| Fees | No protocol fee; CDP: first 1,000 on-chain settlements a month free, then $0.001 each | No protocol or licensing fee; on Stripe, SPT card charges start at 0.50 USD |
| Discovery | The Bazaar (indexed after a settled payment) and community directories | An OpenAPI document at /openapi.json; registries such as MPPscan |
| Client tooling | @x402/fetch and the x402 SDKs; Stripe's purl | mppx, pympp, mpp-rs, mpp-go; Stripe's link-cli for SPTs |
DEFINITIONS
x402, MPP and HTTP 402, one paragraph each.
HTTP 402 Payment Required is the status code a server sends when a resource costs money. Both protocols build on it. mpp.dev's rule is to answer 402 when payment is the main barrier, and 401 when the client simply isn't authenticated.
x402 is an open standard for internet-native payments over HTTP. Its README describes the flow: the server answers 402 with a PaymentRequired object in a PAYMENT-REQUIRED header, the client signs a PaymentPayload and retries with a PAYMENT-SIGNATURE header, a facilitator verifies and settles the payment on chain, and the server returns the resource with a PAYMENT-RESPONSE header. Its payment schemes are exact (a fixed price), upto (a capped, usage-based charge) and batch-settlement. On July 14, 2026 the Linux Foundation announced the operational launch of the x402 Foundation and the completed contribution of the protocol by Coinbase. Stripe, Coinbase, Google, Visa, Mastercard and Cloudflare are among its premier members.
MPP, the Machine Payments Protocol, is an open protocol for machine-to-machine payments over HTTP 402, co-authored by Stripe and Tempo. Its core is the Payment HTTP Authentication Scheme, an IETF Internet-Draft (draft-httpauth-payment-01, dated 5 October 2026, by authors from Tempo Labs and Stripe). A server sends a Challenge in WWW-Authenticate: Payment, the client pays and retries with a Credential in Authorization: Payment, and the server returns a Receipt in Payment-Receipt. mpp.dev calls it payment-method agnostic: Tempo stablecoins, cards through Stripe, and Lightning are in production, and anyone can write a new method.
A Stripe Shared Payment Token (SPT) is how an agent pays an MPP server by card. Stripe describes SPTs as scoped grants that let an agent use a customer's payment method through the seller's Stripe profile, each with usage and expiration limits, issued from the Link Agent Wallet.
An x402 facilitator is the server that checks a signed payment and submits it to the blockchain, so the API itself never handles gas or RPC calls. Coinbase's CDP facilitator also runs OFAC and Know Your Transaction screening. mppx is the TypeScript reference SDK for MPP, and it can serve x402 on the same route. Tempo is a blockchain built for stablecoin payments, and the network MPP's stablecoin examples use.
THE 402 FLOW
The 402 flow, step by step, with real headers.
This is the flow as my own endpoint runs it. Both protocols share the first and last steps; what differs is the header the price travels in and the header the proof comes back in.
The sample below is the real 402 that POST /api/agent/ai-visibility returned on October 11, 2026, shortened where the values run long. Notice that it carries two MPP challenges in one WWW-Authenticate header, and an x402 offer in PAYMENT-REQUIRED, all for the same $1.00.
- The agent sends the request with no payment: POST /api/agent/ai-visibility with {"url": "example.com"}.
- The server answers 402 Payment Required with a problem+json body and its terms: an MPP stripe challenge (card or Link, 100 cents), an MPP evm challenge (1,000,000 units of USDC on Base, chain 8453), and an x402 PAYMENT-REQUIRED offer (scheme exact, network eip155:8453).
- The agent picks one. An MPP client pays and retries with Authorization: Payment and a base64url credential; an x402 wallet signs an EIP-3009 transfer and retries with PAYMENT-SIGNATURE.
- The server verifies: for a card, Stripe charges the Shared Payment Token; for USDC, the facilitator verifies the signature and settles the transfer on Base.
- The server does the work and returns 200 with the result, plus Payment-Receipt for MPP or PAYMENT-RESPONSE for x402.
- A failed or expired credential gets a fresh 402 with a new challenge and an RFC 9457 Problem Details body, never a charge.
POST /api/agent/ai-visibility HTTP/1.1
Host: simpleeasytransactions.com
Content-Type: application/json
{"url":"example.com"}
HTTP/1.1 402 Payment Required
Content-Type: application/problem+json
Cache-Control: no-store
WWW-Authenticate: Payment id="1Fpf…", realm="simpleeasytransactions.com", method="stripe", intent="charge", request="eyJhbW91bnQiOiIxMDAi…", expires="…",
Payment id="TooS…", realm="simpleeasytransactions.com", method="evm", intent="charge", request="eyJhbW91bnQiOiIxMDAwMDAwIi…", expires="…"
PAYMENT-REQUIRED: eyJhY2NlcHRzIjpbeyJhbW91bnQiOiIxMDAwMDAw…
# method="stripe" request, decoded
{"amount":"100","currency":"usd","methodDetails":{"networkId":"profile_…","paymentMethodTypes":["card","link"]}}
# method="evm" request, decoded
{"amount":"1000000","currency":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","methodDetails":{"chainId":8453,"decimals":6},"recipient":"0x785d…26a4"}
# PAYMENT-REQUIRED, decoded (x402 v2)
{"x402Version":2,"accepts":[{"scheme":"exact","network":"eip155:8453","amount":"1000000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","payTo":"0x785d…26a4","maxTimeoutSeconds":300,"extra":{"name":"USD Coin","version":"2","assetTransferMethod":"eip3009"}}],"resource":{"url":"https://simpleeasytransactions.com/api/agent/ai-visibility"}}
# The retry carries one of
Authorization: Payment <base64url MPP credential>
PAYMENT-SIGNATURE: <base64 x402 PaymentPayload>
Authorization: Bearer <SET Agent Credits key>BOTH ON ONE ENDPOINT
How to accept x402 and MPP on one endpoint.
You don't have to choose. mpp.dev's own comparison says the x402 exact model maps onto MPP's charge intent, and that with mppx a route can emit both MPP and x402 challenges, accept either credential, call the facilitator to verify and settle x402 payments, and return the receipt header that matches the client's protocol. If you already run an x402 server, mppx ships wrappers for Express, Hono, Next.js and MCP that keep your x402 route table and add MPP around it.
Stripe covers both sides too. Its machine payments documentation says MPP is where Stripe works best, because MPP can take cards and stablecoins, and that Stripe also supports stablecoin payments over x402. Stripe's table lists MPP on Tempo (USDC.e) and Solana (USDC), and x402 on Base (USDC). For x402, Stripe's guide has you create a crypto deposit address on Base, settle through the CDP facilitator on mainnet, and record each settled transfer as a PaymentIntent, so it shows up in the Dashboard like any other payment.
Here is the setup this site runs in production, in the order a request meets it.
- One mppx server per request, with Stripe's SPT method first (card or Link, through the Stripe profile ID as the network ID) and mppx's EVM charge method second (USDC on Base).
- The EVM method is configured with an x402 facilitator, so the same 402 also carries a PAYMENT-REQUIRED header, and the route accepts PAYMENT-SIGNATURE (or the older X-PAYMENT). Route binding is set to resource, which mpp.dev says lets standard x402 wallets pay.
- In production the facilitator is Coinbase's CDP facilitator, each request signed with a short-lived JWT from a CDP API key; staging uses the public x402.org facilitator on Base Sepolia.
- USDC settles straight to the Stripe crypto deposit address for Base, found or created once and cached, and is recorded as a crypto PaymentIntent. The signed Stripe webhook then reconciles it by transaction hash, the same way it reconciles a card payment by PaymentIntent.
- The challenge doesn't depend on the request body, because mppx clients refuse a payment whose terms change between the probe and the paid retry. Each credential is single-use, and the replay markers live in the database, not in one server's memory.
- Paid-only work runs before the charge. The AI Visibility Check fetches the site first, and a check that fails is never charged, on any rail.
GETTING FOUND
How agents find paid APIs: OpenAPI, MPPscan, the Bazaar and the MCP Registry.
An agent can't pay for an API it can't find. MPP's discovery convention is an OpenAPI 3.1 document at /openapi.json with x-payment-info on each paid operation, which registries aggregate. MPPscan describes itself as an explorer for the MPP ecosystem that tracks AI agent payments and the servers that take them.
On the x402 side, Coinbase's Bazaar lists more than 23,000 x402 resources. Its documentation says the CDP facilitator indexes an endpoint after it settles a paid call for an endpoint that advertises Bazaar metadata, and that there is no registration form. The x402 README points to community directories such as x402scan.
For MCP clients, mpp.dev defines an MCP transport: an unpaid tool call answers JSON-RPC error -32042 with the challenge, and the credential travels in the request's _meta. An MCP server can then be listed in the official MCP Registry like any other.
FIELD NOTES
What I've learned building this.
- Two endpoints on this site take machine payments today: POST /api/agent/readiness (an agent payment readiness assessment) and POST /api/agent/ai-visibility (an AI Visibility Check of one public page). Each costs $1.00 a call, by card or Link through a Stripe Shared Payment Token, or in USDC on Base over x402 or MPP.
- One 402 carries everything: an MPP WWW-Authenticate header with a stripe challenge and an evm challenge, and an x402 v2 PAYMENT-REQUIRED header. npx mppx validate passed 30 checks against production on October 11, 2026 (the paid steps are skipped), and on staging it confirmed the PAYMENT-REQUIRED header carries a valid x402 v2 payload.
- No paid x402 call and no live card payment has gone through these endpoints yet. The challenges are validated; the first real payment on each rail is still ahead, and I'll update this guide when it happens.
- Agents that call often can skip per-call payment: prepaid SET Agent Credits are 25 calls for $20 or 100 calls for $70 (each lasting 12 months), or 50 calls a month for $29. GET /api/agent/credits lists the plans; a key in Authorization: Bearer spends one call instead of answering a 402.
- The same two checks are tools on a paid MCP server at POST /api/mcp: agent_payment_readiness_assessment and ai_visibility_check, plus the free list_paid_services. It is published in the official MCP Registry as com.simpleeasytransactions/agent-checks, the endpoints are registered on MPPscan, and a listing in the mpp.dev services catalog was submitted on October 11, 2026 and is not yet merged.
- I tried Coinbase's SDK first and dropped it: its bundled JWT library carries a private-key marker string that this site's publication check refuses to ship. Signing the CDP JWT with the Web Crypto API took a few lines and no dependency.
- Tempo stablecoin payments are built but switched off in production. On staging, the Tempo testnet RPC refused mppx's verification call, and a buyer would have seen an error after paying, so it stays off until a staging run passes.
HOW TO CHOOSE
How I'd choose.
- Offer MPP if your buyers include agents that pay by card. Stripe's Shared Payment Tokens are its card path for agents, and Stripe's x402 guide says to add MPP to accept cards.
- Offer x402 if your buyers hold USDC in wallets that already speak x402, or you want to appear where x402 clients look, such as the Bazaar.
- Offer both when you can. With mppx it is one route, one price and one result; what you add is a facilitator and somewhere for the stablecoin to land.
- Whatever you choose, run the paid-only work before you charge, make every credential single-use, and treat Stripe's signed webhook, not the 200 you returned, as the record of the payment.
QUESTIONS
Questions people ask.
What is x402?
x402 is an open standard for paying for an HTTP request. The server answers 402 Payment Required with a PAYMENT-REQUIRED header, the client signs a payment and retries with PAYMENT-SIGNATURE, and a facilitator verifies and settles it on chain. Coinbase contributed it to the x402 Foundation, which the Linux Foundation launched on July 14, 2026.
What is MPP, the Machine Payments Protocol?
MPP is an open protocol for machine-to-machine payments over HTTP 402, co-authored by Stripe and Tempo. The server sends a challenge in WWW-Authenticate: Payment, the client retries with Authorization: Payment, and the server returns a Payment-Receipt. It works with stablecoins, cards through Stripe, Lightning and custom methods, and its core is an IETF Internet-Draft.
What is the difference between x402 and MPP?
Both use HTTP 402. x402 focuses on on-chain payment schemes and uses PAYMENT-REQUIRED, PAYMENT-SIGNATURE and PAYMENT-RESPONSE headers. MPP is a payment-method-agnostic HTTP authentication scheme that uses WWW-Authenticate, Authorization and Payment-Receipt, and can carry card payments. mpp.dev says x402's exact scheme maps onto MPP's charge intent.
Can one API endpoint accept both x402 and MPP?
Yes. mppx can emit MPP and x402 challenges on the same 402, accept either credential, and return the matching receipt header. SET's two agent endpoints do this in production: one 402 offers card or Link through Stripe and USDC on Base, by MPP or x402.
What does HTTP 402 Payment Required mean?
It means the resource costs money and the response says how to pay. In MPP the 402 carries a WWW-Authenticate: Payment challenge; in x402 it carries a PAYMENT-REQUIRED header. MPP also answers 402, with a fresh challenge, when a payment credential fails.
Can an AI agent pay for an API with a card instead of crypto?
Yes, over MPP. Stripe's Shared Payment Tokens let an agent use a customer's card or Link through the seller's Stripe profile, with usage and expiration limits; Stripe says the minimum SPT charge is 0.50 USD. Stripe's x402 guide says to add MPP if you want to accept cards alongside stablecoins.
Does Stripe support x402?
Yes, for USDC on Base. Stripe's x402 guide has the server pay to a Stripe crypto deposit address, settle through Coinbase's CDP facilitator on mainnet, and record each settled transfer as a PaymentIntent. Stripe recommends adding MPP as well to accept cards.
What is an x402 facilitator, and what does Coinbase's cost?
A facilitator verifies a signed x402 payment and submits it to the blockchain for the server. Coinbase's CDP facilitator says the first 1,000 on-chain settlements each month are free, each one after that costs $0.001, and verification is always free. It also screens payments against OFAC and Know Your Transaction checks.
How do AI agents find paid APIs?
Through discovery documents and directories. MPP servers publish an OpenAPI document at /openapi.json with x-payment-info, which registries such as MPPscan read. Coinbase's Bazaar indexes x402 endpoints after a settled payment. MCP servers can be listed in the official MCP Registry.
Can MCP tool calls be paid with MPP?
Yes. mpp.dev's MCP transport answers an unpaid tool call with JSON-RPC error -32042 carrying the payment challenge, and the client sends its credential in the request's _meta. SET's MCP server at /api/mcp charges $1.00 per paid tool call this way, or accepts a SET Agent Credits key.
What does SET charge for its agent endpoints?
$1.00 per call for the agent payment readiness assessment and for the AI Visibility Check, by card or Link through a Stripe Shared Payment Token, or in USDC on Base over x402 or MPP. Prepaid SET Agent Credits cost $20 for 25 calls, $70 for 100 calls, or $29 a month for 50 calls.
Is MPP or x402 an official standard?
Not yet a finished one. MPP's core, the Payment HTTP Authentication Scheme, is an IETF Internet-Draft, which the IETF says is work in progress. x402 is specified by the x402 Foundation under the Linux Foundation.
SOURCES
Where these facts come from.
Sources checked on . Providers change their products and rules, so the linked pages are the final word.
- Stripe Docs: Machine payments
- Stripe Docs: MPP (Machine Payments Protocol)
- Stripe Docs: x402
- Stripe Docs: Shared payment tokens (sellers)
- mpp.dev: What is MPP? Machine-to-machine payments over HTTP 402
- mpp.dev: MPP vs x402
- mpp.dev: Use MPP with x402
- mpp.dev: HTTP 402
- mpp.dev: HTTP transport
- mpp.dev: MCP and JSON-RPC transport
- mpp.dev: Discovery
- mpp.dev: Frequently asked questions
- mpp.dev: llms.txt
- paymentauth.org: Machine Payments Protocol specifications
- IETF Internet-Draft: The "Payment" HTTP Authentication Scheme (draft-httpauth-payment-01, 5 October 2026)
- x402.org: x402, an open standard for internet-native payments
- x402.org: Linux Foundation announces operational launch of x402 Foundation (July 14, 2026)
- GitHub: x402-foundation/x402 (README and specification)
- Coinbase Developer Platform: x402 overview
- Coinbase Developer Platform: How x402 works
- Coinbase Developer Platform: CDP Facilitator (networks and pricing)
- Coinbase Developer Platform: Get discovered (Bazaar)
- Tempo: a purpose-built blockchain for stablecoin financial products
- MPPscan: Machine Payments Protocol Explorer
- Official MCP Registry: com.simpleeasytransactions/agent-checks