MPP Makes OUSD the Default While KERNEL and Laso Finance Join the Catalog

A primary-source review of MPP, Payment Auth, Tempo and HTTP 402 for the week ending October 4, 2026.

Last week was hygiene-only: no new services, no new terms, a spec fix and a pile of CI pins. This week has actual catalog movement — two new commercial services, a documentation default that changed which stablecoin gets shown first, and a health-check system that now watches the network’s own endpoints instead of waiting for someone to notice they’re broken.

OUSD becomes the thing the docs show you first

mpp PR #1029 and PR #1030 rewrite quickstarts, guides, SDK examples and protocol payloads to favor OUSD over USDC.e, with the accompanying commits fixing addresses and serialized credentials and ordered currency offers to match.

This is a documentation change, not a protocol change — MPP still supports whatever currencies a service offers. What moved is which one a new integrator sees first when they copy an example. That’s not a small thing for a protocol still building its developer base: the default in the quickstart tends to become the default in production, whether or not that was the intent. Worth verifying next is whether the OUSD examples are actually consistent everywhere they now claim to be, particularly in multi-currency discovery and fallback ordering — a docs PR that touches this many surfaces at once is exactly the kind that leaves one stale example behind.

Two new services, two different kinds of utility

mpp PR #1032 adds KERNEL, a paid stealth headful Chromium browser service charging $0.05 per 30-minute session, with idempotent payment support built in from the start. PR #1026 adds Laso Finance, which uses MPP-based USDC conversion to move value into prepaid cards, gift cards, and bank or push-to-card payouts, with direct MPP charge challenges handling the payment leg.

These sit at opposite ends of what “machine payments” can mean. KERNEL is an agent paying for compute access — a browser session, metered and billed per use. Laso Finance is an agent’s stablecoin balance turning into something a human bank account or a physical card can use. Both are catalog additions, not verified adoption: a service being listed in the directory means it’s reachable and documented, not that anyone is paying it yet. What’s worth checking in production is whether either service’s MPP challenge handling and idempotent-payment logic hold up under retries and partial failures, which is where idempotency claims usually get tested for real.

The catalog starts checking its own pulse

mpp PR #1038 adds a weekly unpaid service health-check system, running every Monday at 09:00 UTC, maintaining a bot-owned issue with findings tables plus JSON and Markdown reports.

A service directory is only as useful as its accuracy, and a directory this size can’t be kept accurate by someone periodically clicking through endpoints by hand. Automating that check is the kind of maintenance that doesn’t show up as a feature anyone announces but matters every time a developer trusts the catalog instead of re-verifying an endpoint themselves. Worth testing next: whether the report generation, the bot-owned issue updates, and the manual-dispatch path all behave the way the PR describes once they’ve run a few real cycles — a health check that silently stops updating is worse than no health check, because people keep trusting it.

Directory cleanup and a security patch, filed as routine

mpp PR #1040 repairs stale service documentation and endpoint listings, removing retired routes and updating 31 provider listings. PR #1037 removes unsupported proxy service listings, including AviationStack and Google Maps. Separately, PR #1028 patches Undici to resolve a WebSocket denial-of-service vulnerability, and PR #1027 pins GitHub Actions references for reproducibility.

None of this is adoption news, and none of it should be mistaken for it. It’s the same instinct that’s shown up in prior briefs — a directory that matches what’s actually live, and a dependency tree that doesn’t carry a known vulnerability longer than it has to. Worth verifying next: that the removed proxy listings actually stop appearing in discovery responses and client libraries, since a directory entry removed from the docs isn’t automatically removed from every cached client.

Two Hacker News signals, named and not folded in

This week’s source ledger also carries independent x402 commentary worth naming rather than treating as development: a Show HN post on an x402 configuration inspector, another describing pre- and post-payment checks for personal AI agents, and a piece reporting that the second-largest x402 seller on Base funded its own buyers. None of these touch MPP or the IETF spec directly, and none come with a transaction record I can verify independently. That last one in particular — a seller funding its own buyer side — is the kind of claim that would matter a great deal to anyone reading x402 volume as a demand signal, which is exactly why it stays a signal to watch rather than a verified development.

What I’m taking from this week

The headline is real but it’s a documentation default, not a protocol change: OUSD is now what new integrators see first, not the only thing they can use. The two new services are catalog additions with no usage data behind them yet. The health-check system is the most structurally interesting thing here, because it changes how the directory stays honest over time rather than adding to what it lists. Everything else — cleanup, a security patch, CI pins — is the maintenance layer doing its job quietly. Next week’s honest question is whether KERNEL or Laso Finance show any verifiable usage, and whether the health-check bot is still filing reports on schedule.

I built MPP Pulse to keep those layers separated instead of blurring them into one undifferentiated “things happened” feed. It’s an open-source AWS agent that collects primary evidence and drafts a cited weekly brief for human review.

Request the weekly brief or view the open-source engine.

← Field Notes