Skip to content
Tenzro
Documentation menu
Payments

MPP

The Machine Payments Protocol on Tenzro: HTTP 402 challenges, signed credentials, receipts and capped sessions for streams of machine payments.

MPP, the Machine Payments Protocol, is an open protocol for machine-to-machine payments over HTTP. Like x402 it uses 402 Payment Required, but it is built around a session: a buyer opens a capped session once and then pays for many calls against it. That suits the way agents actually use services, such as a long conversation with a model, a stream of tool calls or a batch of storage writes.

On Tenzro Network 1, MPP is served by every node alongside x402, and it settles on the Tenzro ledger in TNZO or in stablecoins.

Challenge, credential, receipt

MPP has three messages:

MessageSent byCarries
ChallengeThe server, in the 402 responseResource, amount, asset, payee, expiry and a challenge id
CredentialThe client, on retryThe challenge id, the payer's identity and a signature from the paying account
ReceiptThe server, with the responseReceipt id, amount settled and the settlement transaction

The node checks that the credential answers a challenge it issued for this resource and payee, that the signature comes from the account being debited, and that the payer's delegation scope allows the payment. It then settles and returns the receipt. A receipt is issued only once the settlement has landed in a finalised block.

Sessions

A session lets a buyer authorise a spending cap once and then consume it call by call:

  1. The buyer answers the first challenge with a credential that opens a session up to a cap.
  2. Each later call draws down the session. The node meters each call, for example by tokens generated or bytes written.
  3. When the session closes or expires, the node settles what was used and the rest of the cap is released.

Sessions are the natural fit for metered, per-use settlement, which is the default for Machine Economy services. The cap is bounded by the payer's spending limits, so an agent can never open a session larger than its delegation allows.

List your sessions:

bash
tenzro payment sessions

or call tenzro_listPaymentSessions.

Paying with MPP

From the CLI, pay a resource through a node with a ceiling:

bash
tenzro payment pay https://rpc.tenzro.xyz/v1/chat/completions \
  --protocol mpp \
  --payer-did did:tenzro:machine:<agent> \
  --max-amount 500000

The output shows the amount paid, the receipt id and the session id.

From TypeScript, with npm install tenzro-sdk:

ts
import { TenzroClient } from "tenzro-sdk";

const client = new TenzroClient({ endpoint: "https://rpc.tenzro.xyz" });

const receipt = await client.payment.payMpp(
  "https://rpc.tenzro.xyz/v1/chat/completions",
  "did:tenzro:machine:<agent>",
);

const again = await client.payment.getReceipt(receipt.receiptId);

The payment call is an owner action: it must be signed by the paying account. Reading a receipt is open.

Charging with MPP

If you serve a resource, issue a challenge for it. The amount is in the asset's smallest unit:

bash
tenzro payment challenge /v1/tenzro/forecasts \
  --protocol mpp \
  --amount 250000 \
  --asset TNZO \
  --recipient did:tenzro:machine:<you>

The node returns a challenge id and a 402 body for your client. Paid routes on a Tenzro node, such as the OpenAI-compatible APIs, issue MPP and x402 challenges automatically when a request arrives without an API key.

Assets and settlement

MPP payments can be made in TNZO or in stablecoins. Stablecoin payments come from wallets provisioned through Bridge.xyz and settle on the Tenzro ledger, with TNZO paying the network fees underneath. The payer can also pay those fees in the same stablecoin. See Stablecoin payments.

Useful methods

MethodClassPurpose
tenzro_payMppOwnerPay a resource over MPP
tenzro_createPaymentChallengeOwner (signed by the payee)Issue a challenge for a resource
tenzro_verifyPaymentOpenCheck a credential without settling
tenzro_getPaymentReceiptOpenRead a receipt
tenzro_listPaymentSessionsOwnerList your sessions
tenzro_paymentGatewayInfoOpenProtocols, assets and settlement options on this node

See Payments for identity binding and spending limits, and x402 for the stateless alternative.