402 challenge so an agent can pay for an api request without a checkout page. KERNEL accepts mpp payments for browser sessions: an agent pays with a stripe shared payment token, then connects to the browser over cdp. this route doesn’t require a KERNEL account or api key.
the mpp price is $0.50 for one stealth, headful browser for 30 minutes. read the 402 challenge to confirm the current price and duration before paying.
How the mpp payment flow works
link-cli mpp paysendsPOST /mpp/browserswithout a payment credential. KERNEL returns402 Payment Requiredwith the offer inWWW-Authenticate: Payment.- the link cli gives you an approval url. after you approve the payment through link, it retries the request with
Authorization: Payment <credential>. - KERNEL verifies and charges the credential, creates the browser, and returns its connection urls in a
200response. thePayment-Receiptheader contains the mpp receipt.
spt_...) to KERNEL.
you can’t send card details or a standalone card credential to this endpoint, and stablecoin payments aren’t offered. the payment challenge expires after 30 minutes by default; that is the time available to approve the offer, not the browser’s lifetime.
Pay with link
run stripe’s link cli to pay through link. the command reads the402 challenge, gives you an approval link, and completes the payment after you approve it. you don’t need to create a spend request separately.
{"email":"agent@example.com"} json body if you want the stripe receipt sent to that address. otherwise KERNEL uses the billing email shared by the payment token, if available.
the paid response includes session_id, cdp_ws_url, webdriver_ws_url, browser_live_view_url when available, and expires_at. payment.amount is in us cents, and access.type is session_urls. treat the connection urls as credentials; anyone with them can access the browser while it is active.
connect playwright to the returned cdp_ws_url. set CDP_WS_URL to that value from the paid response:
- TypeScript
- Python
Retry and expiration
a challenge buys one browser. if the paid request times out or you lose its response, retry with the same payment credential. KERNEL returns the same browser without another charge while it is active. don’t create a new payment to recover an uncertain purchase. the paid time starts when the charge succeeds; useexpires_at in the response as the access deadline. after expiration, a retry returns a new 402 challenge with code: session_expired; paying that challenge buys a new browser. if KERNEL charges you but can’t create the browser, it attempts a refund. a successful refund returns a 503 error with a refund_id.