Skip to content

LibraryStorage and networks2013Design paperCorpus record

Payment Protocol

BIP 70. Gavin Andresen.

BIP 70, Payment Protocol. A protocol for communication between a merchant and their customer, enabling both a better customer experience and better security against man-in-the-middle attacks on the payment process.

Status in the source: Deployed. A reading of the public specification, not a copy of it and not a certification.

Payment Protocol is worth reading for the rule it actually adds: A protocol for communication between a merchant and their customer, enabling both a better customer experience and better security against man-in-the-middle attacks on the payment process.

The five-minute read

The rule

A protocol for communication between a merchant and their customer, enabling both a better customer experience and better security against man-in-the-middle attacks on the payment process.

What was already failing

A node that cannot fetch, filter, or relay the data it is supposed to validate is not a peer of the network the paper describes.

What the number does not mean

The source marks this deployed. That is a statement about the text, not a promise that every wallet or node has shipped it.

What a builder should be able to point at

An implementation either constrains Payment Protocol or it is a different design.

One action, walked through

  1. Open BIP 70 and read the status line before the examples.
  2. Write down the rule in one sentence. A fair version of that sentence is: A protocol for communication between a merchant and their customer, enabling both a better customer experience and better security against man-in-the-middle attacks on the payment process.
  3. Name the object that changes: Payment Protocol.
  4. Ask what an old client, an old contract, or an offline counterparty does. If the document is silent, the silence is part of the design.

The argument, unpacked

What the text is allowed to settle

Bitcoin Improvement Proposal 70 can settle the shape of Payment Protocol. It cannot settle whether a later client, a later fork, or a later wallet still does this.

What this page will not pretend

There is no benchmark, no adoption number, and no claim that the mechanism is safe outside the assumptions written in the source.

What has to be true

  • You are implementing BIP 70 at the status the text itself states: Deployed.
  • The object that has to change is Payment Protocol. A neighbouring document with a similar name is not this one.
  • Measurements of delay in one year do not travel with the specification.

What happened after the paper

The source marks this deployed. That is a statement about the text, not a promise that every wallet or node has shipped it. Later documents can narrow, replace, or ignore this one. Cite the number you mean.

What to check before you use the idea

  • Which message does Payment Protocol add, and which old peer must still be answered?
  • What does a node do when the short form fails and the full object is required?
  • Which names are normative: Payment Protocol?

Terms

BIP 70
The public text titled Payment Protocol.
Deployed
The document's own label for how finished the text is. It is not a market fact.

The problem the paper names

A node that cannot fetch, filter, or relay the data it is supposed to validate is not a peer of the network the paper describes.

What the design proposes

  • A protocol for communication between a merchant and their customer, enabling both a better customer experience and better security against man-in-the-middle attacks on the payment process.
  • The current, minimal Bitcoin payment protocol operates as follows: # Customer adds items to an online shopping basket, and decides to pay using Bitcoin.
  • # Merchant generates a unique payment address, associates it with the customer's order, and asks the customer to pay.

How the mechanism is specified

  • Taken from the specification, the next constraint is: The current, minimal Bitcoin payment protocol operates as follows: # Customer adds items to an online shopping basket, and decides to pay using Bitcoin.
  • Locate Payment Protocol in BIP 70 and apply it to one transaction or call.
  • Then check the failure the class of rule always has: a node that did not upgrade, a reverted call, a replayed signature, or a peer that does not speak the message.

What this page does not treat as proven

  • A peer protocol is not a consensus rule. A peer can disconnect. A block is still valid or not on its own.
  • Measurements of delay in one year do not travel with the specification.
  • The source marks this deployed. That is a statement about the text, not a promise that every wallet or node has shipped it.

Why a venture studio still reads it

Use BIP 70 when a pitch says 'Payment Protocol' without saying whether the rule is consensus, policy, or an interface. The number is the citation. The pitch is not.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.