Most API monetization stacks are built around accounts, subscriptions, and human checkout flows. Agent and machine clients need a protocol-native way to pay per request without custom billing infrastructure.
Product
Open SourcePaygate
Payment infrastructure for machine-native APIs
Paygate gives services and machine clients both sides of an HTTP 402 payment flow: Spring Boot APIs issue L402 or MPP challenges, the Rust client applies local spend policy and pays over Lightning, and the request is retried with a scoped credential.
Paygate auto-configures Spring Boot filters, protocol handlers, Lightning backends, credential validation, and observability. Developers add `@PaymentRequired`, configure LNbits or LND, and unpaid requests receive a 402 challenge instead of protected content.
As agents consume more APIs directly, payment and authorization need to become programmable, metered, and machine-readable. Paygate gives Java teams a concrete path to sell API access over Lightning without building the payment protocol layer from scratch.
Ecosystem
A complete payment loop
Use the projects independently or together: protect an API, pay from a machine client under explicit policy, and inspect the flow against a live service.
Paygate Spring Boot Starter
Annotation-driven payment gating for Spring Boot 4 APIs with L402 and MPP, Lightning backends, Spring Security, and fail-closed defaults.
- Protect an endpoint with `@PaymentRequired`
- Bind credentials to the exact request boundary
- Run with LNbits or LND settlement backends
Paygate Client
A Rust CLI that validates payment challenges, enforces host and spend policy, pays through a configured backend, caches scoped credentials, and retries the request.
- MPP-first with optional L402 support
- Per-request limits, fee caps, and daily budgets
- Isolated profiles for manager and worker agents
Paygate Agent Trust
A public service that sells signed agent trust reports and demonstrates the full challenge, Lightning settlement, paid retry, and receipt flow.
- Free catalog and quote discovery
- Real LNbits-backed settlement
- Ed25519-signed reports with payment receipts
Who it is for
- Backend engineers
- Spring Boot teams
- API developers
- Agent platform builders
- AI infrastructure teams
- Lightning application builders
Use cases
- Protect premium API endpoints behind Lightning payments
- Add pay-per-use pricing with `@PaymentRequired` annotations
- Serve L402 and Payment challenges from the same endpoint
- Use dynamic pricing for expensive AI or data operations
- Integrate payment validation into Spring Security filter chains
Quickstart
Add payment gating to a Spring Boot endpoint
Paygate is publicly available as a Spring Boot starter for payment-gated APIs. The examples below show the released developer experience.
Gradle first, Maven compatible
dependencies {
implementation("com.greenharborlabs:paygate-spring-boot-starter:0.1.6")
}<dependency>
<groupId>com.greenharborlabs</groupId>
<artifactId>paygate-spring-boot-starter</artifactId>
<version>0.1.6</version>
</dependency>@GetMapping("/trust/report")
@PaymentRequired(priceSats = 30)
TrustReport report(@RequestParam String domain) {
return trustReports.generate(domain);
}HTTP/1.1 402 Payment Required
WWW-Authenticate: L402 invoice="<bolt11>", macaroon="<token>"
WWW-Authenticate: Payment invoice="<bolt11>", amount="30sat"
{
"error": "payment_required",
"retry": "pay invoice and repeat the request"
}paygate:
backend: lnbits
default-price-sats: 30
lnbits:
url: ${LNBITS_URL}
api-key: ${LNBITS_API_KEY}
# backend: lnd is supported for node-direct deploymentsExplore all 11 technical features
- Spring Boot 4 starter with annotation-driven `@PaymentRequired` endpoint protection
- Dual-protocol L402 and MPP challenges through multiple `WWW-Authenticate` headers
- Rust payer client with local request limits, fee caps, daily budgets, and host allowlists
- Credential caching and isolated client profiles for manager and worker agents
- LNbits and LND Lightning settlement backends
- Credentials bound to HTTP method, registered path, raw query, and bounded request body
- Authenticated MPP expiry and `Payment-Receipt` proof after successful validation
- Dynamic pricing through `PaygatePricingStrategy` with replayable bounded request bodies
- Spring Security integration with authenticated, verifier-approved attributes
- Micrometer metrics, Actuator health and status, challenge rate limiting, and trusted-proxy controls
- Fail-closed outages and strict canonical credential parsing with Macaroon V2 interoperability
Build with the lab
Build with Paygate
Have a focused use case for Paygate? Green Harbor Labs can help shape the integration, workflow, or prototype.