SANDBOX LABS AI · RESEARCH BRIEF

MPP Pulse

Weekly intelligence on the machine-payments layer: MPP, Tempo, x402, Payment Auth, HTTP 402, and the infrastructure making agent-to-agent commerce possible.

Subscription interest is reviewed manually. No spam, no automated enrollment.

01

Current Pulse

LATEST BRIEF · WEEK ENDING SEPTEMBER 27, 2026

MPP locks in deterministic HMAC challenge vectors while docs catch the IETF draft.

This week's pulse signal is flat: no verified new development, no new payment terms, no catalog changes. The one change that touches protocol behavior is a core-spec fix defining deterministic HMAC-SHA256 challenge-binding vectors for legacy, header-only, and header-plus-opaque inputs. Everything else is documentation aligning with the current IETF draft, a long-running CI pin-and-upgrade campaign across both repositories, and a doc sync tying MPPx session recording and memo handling to Tempo Session and Stripe PaymentIntent settlement.

Signal No verified new payment terms, integrations, or service-catalog changes. The substantive change is a core-spec fix defining deterministic HMAC-SHA256 challenge-binding vectors, closing an ambiguity in how Payment-Authorization headers get verified.

Evidence Explicit HMAC vectors for legacy, header-only, and header-plus-opaque inputs merged into the core spec; documentation corrected to match IETF draft `draft-httpauth-payment-01`; a long run of CI action pins and dependency upgrades across both repositories; a doc sync tying MPPx session recording and memo handling to Tempo Session and Stripe PaymentIntent settlement.

Watch next Whether MPP integrators' existing HMAC implementations actually match the new vectors, and whether `draft-httpauth-payment-01` is the currently published IETF Datatracker revision.

Read last week's report — IETF Payment Auth adds an XRP Ledger payment method.

02

What it watches

Protocols

MPP, Payment Auth, HTTP 402, x402, specifications, and revision-level changes.

Implementation

Repository activity, merged pull requests, releases, tags, and verifiable deployment evidence.

Adoption

Official announcements, integrations, payment rails, and machine-commerce infrastructure.

Evidence

Primary sources first. Community discussion is context, never proof by itself.

03

Why it exists

Machine payments are becoming an infrastructure layer for agents. The useful evidence is scattered across specifications, code, company announcements, and developer activity. MPP Pulse turns that movement into a short, cited weekly read.

Sources→Collection→Evidence gates→Human review→Weekly brief
04

Built in public

MPP Pulse began as an always-on AWS agent: EventBridge Scheduler triggers one Lambda; the agent collects, scores, and stores evidence; Amazon Bedrock prepares a cited report. The public project is open source, while the research workflow stays deliberately human-reviewed.

MPP Pulse is research and analysis, not investment, legal, or payment advice.