Skip to main content
machine payments protocol (mpp) is an open protocol co-authored by stripe and tempo. it uses an http 402 challenge so an agent can pay for an api request without a checkout page. KERNEL accepts mpp payments for browser sessions: an agent pays with a stripe shared payment token, then connects to the browser over cdp. this route doesn’t require a KERNEL account or api key. the mpp price is $0.50 for one stealth, headful browser for 30 minutes. read the 402 challenge to confirm the current price and duration before paying.

How the mpp payment flow works

  1. link-cli mpp pay sends POST /mpp/browsers without a payment credential. KERNEL returns 402 Payment Required with the offer in WWW-Authenticate: Payment.
  2. the link cli gives you an approval url. after you approve the payment through link, it retries the request with Authorization: Payment <credential>.
  3. KERNEL verifies and charges the credential, creates the browser, and returns its connection urls in a 200 response. the Payment-Receipt header contains the mpp receipt.
link through the link cli is the only supported payment flow for now. after approval, the cli sends a credential containing a stripe shared payment token (spt_...) to KERNEL. you can’t send card details or a standalone card credential to this endpoint, and stablecoin payments aren’t offered. the payment challenge expires after 30 minutes by default; that is the time available to approve the offer, not the browser’s lifetime. run stripe’s link cli to pay through link. the command reads the 402 challenge, gives you an approval link, and completes the payment after you approve it. you don’t need to create a spend request separately.
to inspect the offer without paying, send an unauthenticated request:
you can send an optional {"email":"agent@example.com"} json body if you want the stripe receipt sent to that address. otherwise KERNEL uses the billing email shared by the payment token, if available. the paid response includes session_id, cdp_ws_url, webdriver_ws_url, browser_live_view_url when available, and expires_at. payment.amount is in us cents, and access.type is session_urls. treat the connection urls as credentials; anyone with them can access the browser while it is active. connect playwright to the returned cdp_ws_url. set CDP_WS_URL to that value from the paid response:

Retry and expiration

a challenge buys one browser. if the paid request times out or you lose its response, retry with the same payment credential. KERNEL returns the same browser without another charge while it is active. don’t create a new payment to recover an uncertain purchase. the paid time starts when the charge succeeds; use expires_at in the response as the access deadline. after expiration, a retry returns a new 402 challenge with code: session_expired; paying that challenge buys a new browser. if KERNEL charges you but can’t create the browser, it attempts a refund. a successful refund returns a 503 error with a refund_id.

When to use mpp

mpp is a payment protocol, not a browser feature. when a merchant exposes an mpp endpoint, an agent can pay that merchant directly without opening a checkout page. a browser is still useful when the task requires a site’s interface, login, or checkout and the site doesn’t expose the needed action through mpp. KERNEL’s mpp endpoint handles a different purchase: the agent pays KERNEL for browser access. it lets an agent using the link cli acquire one browser without account setup. the purchase returns connection urls only; it doesn’t provision a vault or merchant payment credential. for merchant checkout with KERNEL’s wallet integrations, use payments for browser agents with an account-based browser. for projects, api keys, and ongoing browser management, use account-based browser access.