MPP
The Machine Payments Protocol on Tenzro: HTTP 402 challenges, signed credentials, receipts and capped sessions for streams of machine payments.
MPP, the Machine Payments Protocol, is an open protocol for machine-to-machine payments over HTTP. Like x402 it uses 402 Payment Required, but it is built around a session: a buyer opens a capped session once and then pays for many calls against it. That suits the way agents actually use services, such as a long conversation with a model, a stream of tool calls or a batch of storage writes.
On Tenzro Network 1, MPP is served by every node alongside x402, and it settles on the Tenzro ledger in TNZO or in stablecoins.
Challenge, credential, receipt
MPP has three messages:
| Message | Sent by | Carries |
|---|---|---|
| Challenge | The server, in the 402 response | Resource, amount, asset, payee, expiry and a challenge id |
| Credential | The client, on retry | The challenge id, the payer's identity and a signature from the paying account |
| Receipt | The server, with the response | Receipt id, amount settled and the settlement transaction |
The node checks that the credential answers a challenge it issued for this resource and payee, that the signature comes from the account being debited, and that the payer's delegation scope allows the payment. It then settles and returns the receipt. A receipt is issued only once the settlement has landed in a finalised block.
Sessions
A session lets a buyer authorise a spending cap once and then consume it call by call:
- The buyer answers the first challenge with a credential that opens a session up to a cap.
- Each later call draws down the session. The node meters each call, for example by tokens generated or bytes written.
- When the session closes or expires, the node settles what was used and the rest of the cap is released.
Sessions are the natural fit for metered, per-use settlement, which is the default for Machine Economy services. The cap is bounded by the payer's spending limits, so an agent can never open a session larger than its delegation allows.
List your sessions:
tenzro payment sessionsor call tenzro_listPaymentSessions.
Paying with MPP
From the CLI, pay a resource through a node with a ceiling:
tenzro payment pay https://rpc.tenzro.xyz/v1/chat/completions \
--protocol mpp \
--payer-did did:tenzro:machine:<agent> \
--max-amount 500000The output shows the amount paid, the receipt id and the session id.
From TypeScript, with npm install tenzro-sdk:
import { TenzroClient } from "tenzro-sdk";
const client = new TenzroClient({ endpoint: "https://rpc.tenzro.xyz" });
const receipt = await client.payment.payMpp(
"https://rpc.tenzro.xyz/v1/chat/completions",
"did:tenzro:machine:<agent>",
);
const again = await client.payment.getReceipt(receipt.receiptId);The payment call is an owner action: it must be signed by the paying account. Reading a receipt is open.
Charging with MPP
If you serve a resource, issue a challenge for it. The amount is in the asset's smallest unit:
tenzro payment challenge /v1/tenzro/forecasts \
--protocol mpp \
--amount 250000 \
--asset TNZO \
--recipient did:tenzro:machine:<you>The node returns a challenge id and a 402 body for your client. Paid routes on a Tenzro node, such as the OpenAI-compatible APIs, issue MPP and x402 challenges automatically when a request arrives without an API key.
Assets and settlement
MPP payments can be made in TNZO or in stablecoins. Stablecoin payments come from wallets provisioned through Bridge.xyz and settle on the Tenzro ledger, with TNZO paying the network fees underneath. The payer can also pay those fees in the same stablecoin. See Stablecoin payments.
Useful methods
| Method | Class | Purpose |
|---|---|---|
tenzro_payMpp | Owner | Pay a resource over MPP |
tenzro_createPaymentChallenge | Owner (signed by the payee) | Issue a challenge for a resource |
tenzro_verifyPayment | Open | Check a credential without settling |
tenzro_getPaymentReceipt | Open | Read a receipt |
tenzro_listPaymentSessions | Owner | List your sessions |
tenzro_paymentGatewayInfo | Open | Protocols, assets and settlement options on this node |
See Payments for identity binding and spending limits, and x402 for the stateless alternative.