
Product
Socket Now Protects the Firefox Extension Ecosystem
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.
@bolthub/agent
Advanced tools
L402 client for AI agents — pay Lightning invoices automatically to access paywalled APIs
L402 client for AI agents. Automatically handles 402 Payment Required challenges, pays Lightning invoices, and retries requests with proof of payment.
npm install @bolthub/agent
import { L402Client, LndWallet } from "@bolthub/agent";
const wallet = new LndWallet({
host: "https://your-lnd-node:8080",
macaroon: "0201036c6e...",
});
const client = new L402Client({
wallet,
maxPerRequestSats: 100,
budgetSats: 10_000,
});
const resp = await client.get(
"https://acme.gw.bolthub.ai/v1/weather",
{ params: { city: "berlin" } }
);
const data = await resp.json();
import { LndWallet } from "@bolthub/agent";
const wallet = new LndWallet({
host: "https://your-lnd-node:8080",
macaroon: "admin-macaroon-hex",
timeoutSeconds: 30,
});
import { LnbitsWallet } from "@bolthub/agent";
const wallet = new LnbitsWallet({
url: "https://lnbits.example.com",
adminKey: "your-admin-key",
});
import { NwcWallet } from "@bolthub/agent";
const wallet = new NwcWallet(nwcConnection);
Implement the WalletAdapter interface:
import type { WalletAdapter } from "@bolthub/agent";
const myWallet: WalletAdapter = {
async payInvoice(bolt11: string) {
const preimage = await myPaymentLogic(bolt11);
return { preimage };
},
};
const client = new L402Client({
wallet,
maxPerRequestSats: 100, // reject invoices over 100 sats
budgetSats: 10_000, // total spending cap
});
console.log(client.totalSpent); // sats spent so far
console.log(client.remainingBudget); // sats remaining
The price of each invoice is determined from the response body (amountSats),
the BOLT11 invoice itself, or an optional priceHeader. If it still cannot be
determined, onUnknownAmount controls what happens — by default ("cap") the
client pays only up to maxPerRequestSats and refuses outright if no ceiling is
set, so a price-less challenge is never paid blind. Use "refuse" to always
refuse, or "allow" for the legacy pay-blind behaviour. Budget accounting is
also concurrency-safe: requests issued together (e.g. via Promise.all) can
never overspend.
By default sessions are kept in memory. Use FileSessionStore to persist
tokens across process restarts (stored in ~/.bolthub/sessions.json):
import { L402Client, LndWallet, FileSessionStore } from "@bolthub/agent";
const client = new L402Client({
wallet: new LndWallet({ host, macaroon }),
sessionStore: new FileSessionStore(),
});
A real L402 macaroon can be narrowed offline and handed to a sub-agent, so a parent agent that paid for access can delegate a restricted credential without re-paying or calling bolthub:
import { attenuate } from "@bolthub/agent";
// `macaroon` is the value from `Authorization: L402 <macaroon>:<preimage>`.
const restricted = attenuate(macaroon, {
method: "GET", // only GET requests
validUntil: Date.now() + 60_000, // expires in 60s, tighter than the original
});
// Give `restricted` plus the SAME preimage to the sub-agent, which sends
// Authorization: L402 <restricted>:<preimage>
The gateway enforces every caveat down the chain (most restrictive wins).
| Export | Description |
|---|---|
L402Client | HTTP client with automatic L402 challenge handling |
LndWallet | Wallet adapter for LND REST API |
LnbitsWallet | Wallet adapter for LNbits |
PhoenixdWallet | Wallet adapter for Phoenixd |
NwcWallet | Wallet adapter for Nostr Wallet Connect |
WebLnWallet | Browser-only wallet via the WebLN provider |
isWebLnAvailable() | Check if a WebLN provider exists |
FileSessionStore | Disk-backed session token persistence |
createL402Client() | Shorthand factory for L402Client |
attenuate() | Narrow a macaroon offline to delegate a restricted credential |
WalletAdapter | Interface to implement for custom wallets |
L402Error | Base error class for L402 failures |
L402BudgetError | Thrown when budget limits are exceeded |
L402PaymentError | Thrown when the wallet fails to pay |
L402TimeoutError | Thrown when a request times out |
MIT
FAQs
L402 client for AI agents — pay Lightning invoices automatically to access paywalled APIs
The npm package @bolthub/agent receives a total of 9 weekly downloads. As such, @bolthub/agent popularity was classified as not popular.
We found that @bolthub/agent demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.

Research
/Security News
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.