> ## Documentation Index
> Fetch the complete documentation index at: https://tbd-6fc993ce-hypeship-docs-ia-v2.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Buy a browser session with a machine payment

> Buys a stealth headful browser for the duration in the offer with a Machine Payments Protocol (MPP) payment, without a Kernel account. A request without an `Authorization: Payment` credential gets a 402 challenge; the paid retry returns the browser and a `Payment-Receipt` header. A challenge can be paid until its `expires` time, 30 minutes after it is issued by default. A challenge buys one browser. Resending the same paid credential is intentional and safe: it returns the same browser without charging again until the session expires, even after the challenge has expired, so an agent can retry after a timeout. After the session expires it gets a 402 with a fresh challenge and `code: session_expired`. A different payment for a challenge that was already charged is rejected with a 402 before any charge.



## OpenAPI

````yaml https://api.onkernel.com/spec.json post /mpp/browsers
openapi: 3.1.0
info:
  description: Developer tools and cloud infrastructure for AI agents to use web browsers
  title: Kernel API
  version: 0.1.0
servers:
  - description: API Server
    url: https://api.onkernel.com
security:
  - bearerAuth: []
tags:
  - description: Search the web and retrieve content for selected results.
    name: Search
  - description: Create and manage browser sessions.
    name: Browsers
  - description: Control mouse, keyboard, and screen on the browser instance.
    name: Browser Computer Controls
  - description: Execute Playwright code against the browser instance.
    name: Browser Playwright
  - description: Execute JavaScript in the browser instance's persistent Browser REPL.
    name: Browser REPL
  - description: Discover and invoke native page tools across the browser instance.
    name: Browser WebMCP
  - description: Read, write, and manage files on the browser instance.
    name: Browser Filesystem
  - description: Execute and manage processes on the browser instance.
    name: Browser Processes
  - description: Record and manage browser session video replays.
    name: Browser Replays
  - description: Stream logs from the browser instance.
    name: Browser Logs
  - description: >-
      Stream live telemetry events from a browser session, and manage the
      destinations sessions export them to.
    name: Browser Telemetry
  - description: Create, list, retrieve, and delete browser profiles.
    name: Profiles
  - description: Create and manage proxy configurations for routing browser traffic.
    name: Proxies
  - description: Create, list, retrieve, and delete browser extensions.
    name: Extensions
  - description: Create and manage browser pools for acquiring and releasing browsers.
    name: Browser Pools
  - description: Inspect the identity and authorization context for the current request.
    name: Authentication
  - description: >-
      Create and manage auth connections for automated credential capture and
      login.
    name: Managed Auth
  - description: Create and manage credentials for authentication.
    name: Credentials
  - description: Configure external credential providers like 1Password.
    name: Credential Providers
  - description: List applications and versions.
    name: Apps
  - description: Create and manage app deployments and stream deployment events.
    name: Deployments
  - description: Invoke actions and stream or query invocation status and events.
    name: Invocations
  - description: Read and manage organization-level limits.
    name: Organization
  - description: |
      Create and manage projects for resource isolation within an organization.
      When projects are disabled for the organization, project operations return
      `404` with code `projects_disabled`.
    name: Projects
  - description: Create and manage API keys for organization and project-scoped access.
    name: API Keys
  - description: Read audit log records for the authenticated organization.
    name: Audit Logs
  - description: Resolve browser and proxy recommendations for bot-protected sites.
    name: Config Registry
paths:
  /mpp/browsers:
    post:
      tags:
        - Browsers
      summary: Buy a browser session with a machine payment
      description: >-
        Buys a stealth headful browser for the duration in the offer with a
        Machine Payments Protocol (MPP) payment, without a Kernel account. A
        request without an `Authorization: Payment` credential gets a 402
        challenge; the paid retry returns the browser and a `Payment-Receipt`
        header. A challenge can be paid until its `expires` time, 30 minutes
        after it is issued by default. A challenge buys one browser. Resending
        the same paid credential is intentional and safe: it returns the same
        browser without charging again until the session expires, even after the
        challenge has expired, so an agent can retry after a timeout. After the
        session expires it gets a 402 with a fresh challenge and `code:
        session_expired`. A different payment for a challenge that was already
        charged is rejected with a 402 before any charge.
      operationId: postMppBrowsers
      requestBody:
        content:
          application/json:
            schema:
              properties:
                email:
                  description: >-
                    Optional address for the Stripe receipt. When omitted, the
                    billing email shared with the payment token is used, if any.
                    A malformed address is rejected with a 400 before any
                    challenge or charge.
                  format: email
                  type: string
              type: object
        required: false
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  access:
                    properties:
                      type:
                        enum:
                          - session_urls
                        type: string
                    required:
                      - type
                    type: object
                  browser_live_view_url:
                    type: string
                  cdp_ws_url:
                    type: string
                  created_at:
                    format: date-time
                    type: string
                  duration_minutes:
                    type: integer
                  expires_at:
                    format: date-time
                    type: string
                  headless:
                    type: boolean
                  payment:
                    properties:
                      amount:
                        description: Amount in cents
                        type: integer
                      currency:
                        type: string
                      reference:
                        description: Stripe PaymentIntent ID
                        type: string
                    required:
                      - reference
                      - amount
                      - currency
                    type: object
                  session_id:
                    type: string
                  stealth:
                    type: boolean
                  webdriver_ws_url:
                    type: string
                required:
                  - session_id
                  - cdp_ws_url
                  - webdriver_ws_url
                  - headless
                  - stealth
                  - duration_minutes
                  - created_at
                  - expires_at
                  - payment
                  - access
                type: object
          description: The purchased browser session.
          headers:
            Payment-Receipt:
              description: Base64url-encoded MPP receipt.
              schema:
                type: string
        '400':
          content:
            application/problem+json:
              schema:
                type: object
          description: The request body is not a JSON object, or `email` is malformed.
        '402':
          content:
            application/problem+json:
              schema:
                properties:
                  challengeId:
                    type: string
                  code:
                    enum:
                      - session_expired
                    type: string
                  detail:
                    type: string
                  expires_at:
                    format: date-time
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: >-
            Payment required. The `WWW-Authenticate` header carries a fresh
            Payment challenge; the body is RFC 9457 problem details. When the
            session this credential bought has expired, the problem type is
            `invalid-challenge` with `code: session_expired` and `expires_at`.
          headers:
            WWW-Authenticate:
              description: MPP Payment challenge.
              schema:
                type: string
        '429':
          description: Too many requests from this client.
        '503':
          content:
            application/problem+json:
              schema:
                type: object
          description: >-
            Paid browsers are unavailable, at capacity, or the browser could not
            be created (payment refunded).
      security: []
components:
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.