L402 Lightning Payments
Real-time Lightning Network payment processing for Kevros endpoints
L402 Protocol
Rail Status
Active
/.well-known/l402
Invoice Capability
Enabled
BOLT11 challenge flow
Network
Lightning
mainnet invoices only
Pricing
Live
from discovery
L402 Flow
Fail closed
1. Challenge
GET or HEAD a paid endpoint for non-executing discovery
No actuation
Discovery
2. Pay
Pay the BOLT11 invoice and retain the preimage
Signed token
Settlement
3. Retry
Send Authorization: L402 macaroon plus preimage
Metered call
Authorized
Protected Endpoints
Priced live
/shield/scan
Discovery
$0.01
/governance/verify
Discovery
$0.01
/governance/attest
Discovery
$0.02
Fetch /.well-known/l402 for current sats pricing.
Settlement Signals
Private backend
Challenge
Paid endpoints emit L402 challenges before protected work runs.
Live
Verify
Preimages are checked before the request is metered.
Per call
Replay
Verified preimages are single-use.
Fail closed
Internal node, webhook, and channel details are not public metadata.
L402 Configuration
Edit
Settlement Backend
Managed LND backend (private)
Provider Callback
Private settlement callback
Invoice Expiry
120 seconds
Pricing Source
/.well-known/l402 and /payment/discovery
Protocol Header
WWW-Authenticate: L402 token="{token}", invoice="{bolt11}"
Discovery Document
/.well-known/l402