△Partial evidenceTHIRD-PARTY REPORTED1/4Reviewed 5 Sep 2026 · Source → official site
LAST CHECKED2026-08-27
LAST UPDATED2026-09-05
Specs
DOCUMENT CHECKNone recorded
IDENTITY EXPOSURELevel 0/4
KYC TRIGGERSNo KYC of any kind. You run the server. You control the keys.
FEEFree
CATEGORIESMerchants, Privacy Tools, Agent Money
COMMON USESMerchants accepting BTC, Self-sovereign payments, No-fee transactions
FEATURESSelf-hosted, Open source, Lightning, No processor fees, No software KYC, Non-custodial, Merchant payments, WooCommerce plugin
TORNot listed
REGIONSGlobal availability
Review analysis, source material, related services, and history
Agent payments
Spend controls and data exposure
Useful as a self-hosted invoice and merchant-payment rail for agent workflows. It avoids platform custody and KYC, but wallet funding, network history, server logs, and merchant order records still need separate controls.
The safer pattern is agent-drafts, operator-or-policy-signs. Do not put seed material or broad wallet keys in the same runtime that browses, prompts, or receives untrusted task input.
Self-hosted open-source Bitcoin and Lightning payment processor that is non-custodial and charges no fees.
Analysis
OVERVIEW
A self-hosted payment processor: merchants accept Bitcoin and Lightning directly to their own keys, with no fees, no intermediary, and no KYC anywhere in the architecture.
LIMITS
Self-hosting is the cost: server operations, key management, and uptime fall on the merchant, and using a third-party host reintroduces exactly the intermediary the software removes.
USEFUL FOR
Merchants who want direct crypto acceptance and are prepared to run infrastructure for it.
No identity verification is recorded for typical use. No KYC of any kind. You run the server. You control the keys.
Which payment methods are accepted?
Please check the provider site for accepted payment methods.
Where is it available?
Recorded availability: GLOBAL.
Is the operator based in a Five Eyes country?
The jurisdiction is not publicly confirmed. Check the provider site for incorporation details.
How are identity, operator, and evidence fields reported?
Identity exposure is level 0 of 4. A hosted operator is recorded. Jurisdiction is shown as context, not a safety verdict. Source coverage is partial evidence, last reviewed 2026-09-05, and recorded risk is caution.
Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.
Service history
Latest meaningful changes to the facts shown on this provider page.
Review overdue providers against current sources
Features, Jurisdiction, Jurisdiction confidence, KYC last checked, and 4 more
Apply full-service rereview and score 4.0
Privacy warning, Recorded risk, Score assessment
Corporate registry information updated
Corporate / Entity type
Full service history
updated
Review overdue providers against current sources
Features
Self-hosted, Open source, Lightning, No fees, No KYC, Non-custodial, Merchant payments, WooCommerce plugin, Shopify plugin → Self-hosted, Open source, Lightning, No processor fees, No software KYC, Non-custodial, Merchant payments, WooCommerce plugin
Jurisdiction
JP → not set
Jurisdiction confidence
inferred → unknown
KYC last checked
2026-03-13 → 2026-09-05
Last reviewed
2026-07-05 → 2026-09-05
Privacy warning
Self-hosted and non-custodial, but all versions before 2.4.2 exposed LND admin macaroon credentials; attackers exploited the flaw and stole funds. LND operators must update to current BTCPay Server/LND, rotate or regenerate credentials, and review node activity. → BTCPay Server versions before 2.4.2 exposed LND macaroon credentials to unauthenticated remote access, and attackers exploited the flaw to steal funds. Only LND deployments were exposed; built-in on-chain wallets were not affected. Update to a current release, regenerate or rotate credentials, and inspect node activity. Separately managed LND exposure paths need manual credential rotation.
Source reviewed
older source, not independently verified → https://blog.btcpayserver.org/security-advisory-btcpay-server-2-4-2/
not set → Outcome: HOLD; Checked at: 2026-08-27; Inputs: Operator data exposure: none; Control model: local-self-custody; Source model: open-reproducible; Audit: Score eligible: no; Reason: Security policy exists, but no current complete independent audit report with date/scope was established.
not set → Self-hosted and non-custodial, but all versions before 2.4.2 exposed LND admin macaroon credentials; attackers exploited the flaw and stole funds. LND operators must update to current BTCPay Server/LND, rotate or regenerate credentials, and review node activity.
Recorded risk
standard → caution
Score assessment
not set → Operator data exposure: limited; Control model: local-self-custody; Source model: open
Self-hosted, open source Bitcoin and Lightning payment processor. Free, no fees, no KYC, non-custodial. Run on your own server or use a third-party host. → Self-hosted open-source Bitcoin and Lightning payment processor that is non-custodial and charges no fees.
not set → human-approval, policy-engine, wallet-grant
Agent money / Autonomy level
not set → 1
Agent money / Custody model
not set → self-custody
Agent money / Protocol privacy notes
not set → The safer pattern is agent-drafts, operator-or-policy-signs. Do not put seed material or broad wallet keys in the same runtime that browses, prompts, or receives untrusted task input.
not set → Compatible: yes; Control surfaces: api, dashboard, manual; Spend limits: no; Merchant lock: yes; Category lock: no; Pause close: yes; Transaction webhooks: yes; Funding source: self-hosted; Identity surface: none; Data path: AI agent, approval wallet or operator, BTCPay Greenfield API invoice, self-hosted BTCPay server, Bitcoin or Lightning network, merchant order record; Notes: Useful as a self-hosted invoice and merchant-payment rail for agent workflows. It avoids platform custody and KYC, but wallet funding, network history, server logs, and merchant order records still need separate controls.