{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "airwallex",
    "name": "Airwallex Spend and Issuing",
    "vendor": "Airwallex",
    "vendorUrl": "https://www.airwallex.com",
    "kind": "http-api",
    "category": "spend-management",
    "summary": "Airwallex is a multi-currency business account with company cards, expense management and bill pay. Its REST API issues and controls cards, reads card transactions and expenses, and creates vendors, purchase orders and bills. A CLI and MCP server use OAuth.",
    "url": "https://www.anchorterminal.com/tools/airwallex",
    "markdownUrl": "https://www.anchorterminal.com/tools/airwallex.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/airwallex.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/airwallex.json",
    "repo": "https://github.com/airwallex/airwallex-marketplace",
    "license": "Proprietary service under Airwallex's service agreement and API terms. The plugin and skills repository is Apache-2.0 and `@airwallex/node-sdk` is MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.airwallex.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@airwallex/node-sdk"
      }
    ],
    "auth": "mixed",
    "authNotes": "Access is self-serve in the sandbox and for an Airwallex customer in production. A user with the Owner, Admin or Developer role creates a key in the web app under Developer, then API keys. Scoped keys grant Read or Write per resource and can be tied to IP ranges, and admin keys are unrestricted. A key and client ID exchange at `POST /api/v1/authentication/login` for a bearer token that lasts 30 minutes. Spend resources need organisation-level permissions. The CLI, the MCP servers and partner apps use OAuth 2.0 with 64 scopes, and only Owner, Admin and Finance Admin users can consent. The service agreement says Airwallex must first approve API access, and the CLI guide says card and Issuing commands may need support to enable them.",
    "pricing": "freemium",
    "pricingNotes": "No separate API fee is published. The US pricing page lists Explore at $0 with up to 10 free Spend users, Grow at $12 per active Spend user a month up to 250 users, and Accelerate on request. It lists direct Spend API integration with an ERP under Accelerate and sends platform API and embedded finance use to sales. A sandbox account opens at once from a signup form with no payment card or contract, so an agent's owner can start there. Card, FX and transfer fees are on a separate fee schedule (checked 2026-10-08).",
    "priceSummary": "$12 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the API reference pages read or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 7,
      "npmWeekly": 44464,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.airwallex.com/docs/",
    "llmsTxt": "https://www.airwallex.com/docs/llms.txt",
    "capabilities": [
      "spend.transactions",
      "spend.cards",
      "spend.expenses",
      "spend.bills",
      "spend.procurement"
    ],
    "tags": [
      "hosted",
      "freemium",
      "api-key",
      "oauth",
      "mcp",
      "cli",
      "llms-txt",
      "webhooks",
      "sandbox",
      "multi-currency",
      "soc2",
      "pci-dss",
      "iso27001",
      "status-page",
      "security-txt",
      "bug-bounty"
    ],
    "lastRelease": "2026-09-30",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 68.3,
      "grade": "B",
      "agentReady": false,
      "rank": 187,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 1,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 69,
        "maintenance": 66,
        "payments": 25,
        "reliability": 77,
        "schema": 69,
        "security": 84,
        "transparency": 78
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 77,
          "points": 15.4,
          "reason": "Read with the hosted lines and scored on the REST API for Issuing and Spend. status.airwallex.com is a Statuspage site with 21 components in three groups, among them Spend, Issuing, API Gateway and Sandbox (20). Eleven incidents are listed since 27 April 2026 and none names Spend, Issuing or the API Gateway. Three marked major fall in the last 90 days on neighbouring products (Mastercard 3DS on 15 July, Mastercard payments on 15 August, USD deposits from 29 September to 5 October), each attributed to a third party, so 25 of 30. Limits are published, 100 requests a second per account, 20 per endpoint and 50 concurrent in production, and 20, 10 and 10 in the sandbox (15). The docs ask for exponential backoff with jitter on 429 and creates take a required `request_id`. No Retry-After header is documented (12 of 15). No SLA was found, and the service agreement supplies the services as is and as available (0). Issuing is generally available, but the four Spend endpoints we read are marked beta, as are the Node SDK and the AgentOS skills (5 of 10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 69,
          "points": 11.21,
          "reason": "No public OpenAPI spec was found. The paths we tried under /docs/api return the docs shell, and the CLI prints one endpoint's schema with `--api-schema-only`. Each endpoint has a structured Markdown reference page, which earns part credit (6 of 25). llms.txt at /docs/llms.txt and a Markdown twin of every guide and reference page (10). Endpoint and field descriptions state purpose, and deprecated endpoints name their replacement. Few say when not to call (14 of 20). Fields carry types, formats, required flags and possible values. Amounts are strings, and status filters warn that new values may appear (12 of 15). Every reference page has a cURL request and a response example, and Spend and Issuing each have an error code page. The create bill page lists 400, 404 and 500 but not 401 or 429 (12 of 15). Dated API versions (latest `2026-08-21`), an `x-api-version` override and a changelog of backwards-incompatible changes by version (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 69,
          "points": 11.21,
          "reason": "`page_size` runs from 1 to 100 and defaults to 100 on Spend lists. No field selection or expand parameter was found, and the CLI has a `--compact` flag (15 of 25). Spend lists and card transaction events page with a `page` bookmark and `page_after` and `page_before`, while cards and legacy transactions use `page_num` and `has_more`. Filters cover status, sync status, legal entity and created-at range, with a 30-day default window (16 of 20). Errors return `code`, `message`, `source` and `details`, and 429 responses carry a `trace_id`. The Spend error page lists three codes (15 of 20). `request_id` is required on create calls for cards, bills and purchase orders. Airwallex says the production MCP server annotates write tools, which we couldn't read without an account. The two tools on the keyless Docs MCP server carry readOnlyHint (16 of 20). Creating a bill needs eleven required fields. The only server SDK is `@airwallex/node-sdk` in beta, and the CLI has a dry-run flag (7 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 84,
          "points": 14.7,
          "reason": "Scoped API keys grant Read or Write per resource at organisation or account level, can be edited, regenerated, duplicated and deleted, and can be tied to IP ranges. Keys travel only in headers and exchange for a bearer token that lasts 30 minutes. Partner apps, the CLI and the MCP server use OAuth with 64 scopes (30). Read is separate from Write, the AgentOS tools don't start transfers, conversions or payouts by default, CLI writes ask for confirmation, and cards take limits, merchant category rules and remote authorisation. Unrestricted admin keys still exist, and API writes have no confirmation step (17 of 20). The AgentOS page warns about indirect prompt injection from documents and web pages, tool poisoning by other MCP servers and auto-approve modes. Expense descriptions, comments and merchant names are untrusted text (11 of 15). `GET /api/v1/audit_log/security_audit_logs` records logins, user management and key changes for selected accounts only, key changes trigger an email, and no per-call log was found (8 of 15). security.txt with contacts, a bug bounty that has been invite-only since 13 July 2021, SOC 1 and SOC 2 Type 2, ISO 27001 and PCI DSS Level 1 on the trust centre (18 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 25,
          "points": 3.13,
          "reason": "Read with the hosted rubric. No x402, MPP or L402 was found in the docs or on the pricing page (0). US plan prices are public, Explore at $0 with up to 10 free Spend users and Grow at $12 per active Spend user a month. The pricing page lists direct Spend API integration with an ERP under Accelerate, which is priced on request, and sends platform API use to sales, so half the plan-pricing credit (5 of 20). A sandbox account opens at once from a form asking for email, name, country and password, with no payment card and no contract, and the Explore plan is free (20). A person has to sign up in a browser and create a key in the web app or complete an OAuth sign-in. The Docs MCP server needs no account but answers docs questions only (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 66,
          "points": 5.78,
          "reason": "The airwallex-marketplace repository, which carries the AgentOS and developer plugins, tagged v0.2.11 on 30 September 2026. The newest API version is `2026-08-21` (30). Eight marketplace tags between 6 August and 30 September, and API versions on 17 July and 21 August (20). Closed service. The changelog lists backwards-incompatible changes only, support is a help centre ticket or developer.support@airwallex.com, and the marketplace repository shows one open issue. Response times couldn't be observed (9 of 15). `@airwallex/node-sdk` was last published on 31 December 2025 as 2.1.0-beta.5 and is the only server SDK. The official MCP registry has no Airwallex entry of the vendor's own, only a third party's (io.github.codespar/mcp-airwallex) (4 of 15). The marketplace repository has no CI workflow, and the CLI is a binary installed by script whose version we couldn't read (3 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 78,
          "points": 6.83,
          "note": "editorial 64, provenance 92",
          "reason": "Closed service with terms at stable URLs. The API terms are dated 20 June 2025, the service agreement took effect on 1 January 2026 and the Spend Management Terms are dated 6 December 2023. The plugin repository is Apache-2.0 and the Node SDK is MIT (16 of 30). The privacy policy describes retention by purpose and legal duty without fixed periods, names the countries where data is hosted, and says personal data may be processed to develop or improve Airwallex's AI and machine learning. A DPA is published as part of the customer agreement (18 of 30). Breaking changes ship as dated versions and an account stays on its version until it migrates. The API terms require a developer to implement an update within six months at most, give 30 days' notice of adverse changes to the terms, and let Airwallex discontinue services at its discretion. No retirement dates for old versions were found (12 of 20). A public list of processors and sub-processors, updated 7 October 2026, gives each one's category, role and region (18 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`page_size` runs from 1 to 100 and defaults to 100 on Spend lists. No field selection or expand parameter was found, and the CLI has a `--compact` flag (15 of 25). Spend lists and card transaction events page with a `page` bookmark and `page_after` and `page_before`, while cards and legacy transactions use `page_num` and `has_more`. Filters cover status, sync status, legal entity and created-at range, with a 30-day default window (16 of 20). Errors return `code`, `message`, `source` and `details`, and 429 responses carry a `trace_id`. The Spend error page lists three codes (15 of 20). `request_id` is required on create calls for cards, bills and purchase orders. Airwallex says the production MCP server annotates write tools, which we couldn't read without an account. The two tools on the keyless Docs MCP server carry readOnlyHint (16 of 20). Creating a bill needs eleven required fields. The only server SDK is `@airwallex/node-sdk` in beta, and the CLI has a dry-run flag (7 of 15).",
          "maintenance": "The airwallex-marketplace repository, which carries the AgentOS and developer plugins, tagged v0.2.11 on 30 September 2026. The newest API version is `2026-08-21` (30). Eight marketplace tags between 6 August and 30 September, and API versions on 17 July and 21 August (20). Closed service. The changelog lists backwards-incompatible changes only, support is a help centre ticket or developer.support@airwallex.com, and the marketplace repository shows one open issue. Response times couldn't be observed (9 of 15). `@airwallex/node-sdk` was last published on 31 December 2025 as 2.1.0-beta.5 and is the only server SDK. The official MCP registry has no Airwallex entry of the vendor's own, only a third party's (io.github.codespar/mcp-airwallex) (4 of 15). The marketplace repository has no CI workflow, and the CLI is a binary installed by script whose version we couldn't read (3 of 10).",
          "payments": "Read with the hosted rubric. No x402, MPP or L402 was found in the docs or on the pricing page (0). US plan prices are public, Explore at $0 with up to 10 free Spend users and Grow at $12 per active Spend user a month. The pricing page lists direct Spend API integration with an ERP under Accelerate, which is priced on request, and sends platform API use to sales, so half the plan-pricing credit (5 of 20). A sandbox account opens at once from a form asking for email, name, country and password, with no payment card and no contract, and the Explore plan is free (20). A person has to sign up in a browser and create a key in the web app or complete an OAuth sign-in. The Docs MCP server needs no account but answers docs questions only (0).",
          "reliability": "Read with the hosted lines and scored on the REST API for Issuing and Spend. status.airwallex.com is a Statuspage site with 21 components in three groups, among them Spend, Issuing, API Gateway and Sandbox (20). Eleven incidents are listed since 27 April 2026 and none names Spend, Issuing or the API Gateway. Three marked major fall in the last 90 days on neighbouring products (Mastercard 3DS on 15 July, Mastercard payments on 15 August, USD deposits from 29 September to 5 October), each attributed to a third party, so 25 of 30. Limits are published, 100 requests a second per account, 20 per endpoint and 50 concurrent in production, and 20, 10 and 10 in the sandbox (15). The docs ask for exponential backoff with jitter on 429 and creates take a required `request_id`. No Retry-After header is documented (12 of 15). No SLA was found, and the service agreement supplies the services as is and as available (0). Issuing is generally available, but the four Spend endpoints we read are marked beta, as are the Node SDK and the AgentOS skills (5 of 10).",
          "schema": "No public OpenAPI spec was found. The paths we tried under /docs/api return the docs shell, and the CLI prints one endpoint's schema with `--api-schema-only`. Each endpoint has a structured Markdown reference page, which earns part credit (6 of 25). llms.txt at /docs/llms.txt and a Markdown twin of every guide and reference page (10). Endpoint and field descriptions state purpose, and deprecated endpoints name their replacement. Few say when not to call (14 of 20). Fields carry types, formats, required flags and possible values. Amounts are strings, and status filters warn that new values may appear (12 of 15). Every reference page has a cURL request and a response example, and Spend and Issuing each have an error code page. The create bill page lists 400, 404 and 500 but not 401 or 429 (12 of 15). Dated API versions (latest `2026-08-21`), an `x-api-version` override and a changelog of backwards-incompatible changes by version (15).",
          "security": "Scoped API keys grant Read or Write per resource at organisation or account level, can be edited, regenerated, duplicated and deleted, and can be tied to IP ranges. Keys travel only in headers and exchange for a bearer token that lasts 30 minutes. Partner apps, the CLI and the MCP server use OAuth with 64 scopes (30). Read is separate from Write, the AgentOS tools don't start transfers, conversions or payouts by default, CLI writes ask for confirmation, and cards take limits, merchant category rules and remote authorisation. Unrestricted admin keys still exist, and API writes have no confirmation step (17 of 20). The AgentOS page warns about indirect prompt injection from documents and web pages, tool poisoning by other MCP servers and auto-approve modes. Expense descriptions, comments and merchant names are untrusted text (11 of 15). `GET /api/v1/audit_log/security_audit_logs` records logins, user management and key changes for selected accounts only, key changes trigger an email, and no per-call log was found (8 of 15). security.txt with contacts, a bug bounty that has been invite-only since 13 July 2021, SOC 1 and SOC 2 Type 2, ISO 27001 and PCI DSS Level 1 on the trust centre (18 of 20).",
          "transparency": "Closed service with terms at stable URLs. The API terms are dated 20 June 2025, the service agreement took effect on 1 January 2026 and the Spend Management Terms are dated 6 December 2023. The plugin repository is Apache-2.0 and the Node SDK is MIT (16 of 30). The privacy policy describes retention by purpose and legal duty without fixed periods, names the countries where data is hosted, and says personal data may be processed to develop or improve Airwallex's AI and machine learning. A DPA is published as part of the customer agreement (18 of 30). Breaking changes ship as dated versions and an account stays on its version until it migrates. The API terms require a developer to implement an update within six months at most, give 30 days' notice of adverse changes to the terms, and let Airwallex discontinue services at its discretion. No retirement dates for old versions were found (12 of 20). A public list of processors and sub-processors, updated 7 October 2026, gives each one's category, role and region (18 of 20)."
        },
        "sources": [
          {
            "what": "docs index for agents",
            "url": "https://www.airwallex.com/docs/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "how the Spend API works",
            "url": "https://www.airwallex.com/docs/spend/how-airwallex-spend-works.md",
            "seen": "2026-10-08"
          },
          {
            "what": "card expenses guide",
            "url": "https://www.airwallex.com/docs/spend/expenses/card-expenses-via-api.md",
            "seen": "2026-10-08"
          },
          {
            "what": "bills guide",
            "url": "https://www.airwallex.com/docs/spend/accounts-payable/bills-via-api.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Spend error codes",
            "url": "https://www.airwallex.com/docs/spend/troubleshooting/error-codes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "list expenses reference, marked beta",
            "url": "https://www.airwallex.com/docs/api/spend/expenses/list.md",
            "seen": "2026-10-08"
          },
          {
            "what": "create bill reference",
            "url": "https://www.airwallex.com/docs/api/spend/bills/create.md",
            "seen": "2026-10-08"
          },
          {
            "what": "create card reference",
            "url": "https://www.airwallex.com/docs/api/issuing/cards/create.md",
            "seen": "2026-10-08"
          },
          {
            "what": "card authorisation controls",
            "url": "https://www.airwallex.com/docs/issuing/card-controls/authorization-controls.md",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits",
            "url": "https://www.airwallex.com/docs/developer-tools/api/rate-limits.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API key management",
            "url": "https://www.airwallex.com/docs/developer-tools/api/manage-api-keys.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API key scopes",
            "url": "https://www.airwallex.com/docs/developer-tools/api/api-key-scopes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API key practices and IP allowlisting",
            "url": "https://www.airwallex.com/docs/developer-tools/api/api-key-best-practices.md",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth scopes",
            "url": "https://www.airwallex.com/docs/developer-tools/partner-connections/oauth-scopes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "security audit logs",
            "url": "https://www.airwallex.com/docs/developer-tools/security/security-audit-logs.md",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox overview",
            "url": "https://www.airwallex.com/docs/developer-tools/sandbox-environment.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API versioning",
            "url": "https://www.airwallex.com/docs/api/versioning.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API changelog",
            "url": "https://www.airwallex.com/docs/api/changelog.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API errors",
            "url": "https://www.airwallex.com/docs/api/errors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "AgentOS and the production MCP server",
            "url": "https://www.airwallex.com/docs/developer-tools/ai/agentos.md",
            "seen": "2026-10-08"
          },
          {
            "what": "developer and docs MCP servers",
            "url": "https://www.airwallex.com/docs/developer-tools/ai/developer-connector.md",
            "seen": "2026-10-08"
          },
          {
            "what": "CLI guide",
            "url": "https://www.airwallex.com/docs/developer-tools/cli.md",
            "seen": "2026-10-08"
          },
          {
            "what": "server-side SDK guide",
            "url": "https://www.airwallex.com/docs/developer-tools/sdks/server-side-sdks-(beta).md",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks overview",
            "url": "https://www.airwallex.com/docs/developer-tools/webhooks/webhooks-overview.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP protected resource metadata, 35 scopes",
            "url": "https://mcp.airwallex.com/.well-known/oauth-protected-resource/mcp/",
            "seen": "2026-10-08"
          },
          {
            "what": "Docs MCP server, tools/list",
            "url": "https://mcp.sandbox.airwallex.com/docs",
            "seen": "2026-10-08"
          },
          {
            "what": "plugin repository, tags and licence",
            "url": "https://github.com/airwallex/airwallex-marketplace",
            "seen": "2026-10-08"
          },
          {
            "what": "Node SDK on npm",
            "url": "https://registry.npmjs.org/@airwallex/node-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.airwallex.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status components",
            "url": "https://status.airwallex.com/api/v2/summary.json",
            "seen": "2026-10-08"
          },
          {
            "what": "US pricing",
            "url": "https://www.airwallex.com/us/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "API terms",
            "url": "https://www.airwallex.com/us/terms/application-programming-interface-terms",
            "seen": "2026-10-08"
          },
          {
            "what": "service agreement",
            "url": "https://www.airwallex.com/us/terms/airwallex-service-agreement",
            "seen": "2026-10-08"
          },
          {
            "what": "Spend Management Terms",
            "url": "https://www.airwallex.com/us/terms/spend-management-terms",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.airwallex.com/us/terms/privacy-policy-airwallex",
            "seen": "2026-10-08"
          },
          {
            "what": "processors and sub-processors",
            "url": "https://www.airwallex.com/terms/sub-processors-list",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre",
            "url": "https://security.airwallex.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.airwallex.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "bug bounty rules",
            "url": "https://help.airwallex.com/hc/en-gb/articles/900004502526-Bug-Bounty-Program-Rules",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=airwallex",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for airwallex.com",
            "url": "https://rdap.verisign.com/com/v1/domain/airwallex.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the production MCP server's tool list, input schemas and annotations at https://mcp.airwallex.com/mcp, which need an OAuth sign-in to an Airwallex account. `toolCount` is left empty",
          "unchecked: the CLI's version and release history. static.airwallex.com didn't answer our requests for the install script",
          "unchecked: whether a sandbox or Explore account can call the Spend endpoints. The pricing page lists direct Spend API integration under Accelerate, and the docs state no plan requirement",
          "unchecked: whether Issuing API access needs approval on every account. The CLI guide says card and Issuing commands may return 403 until support enables access, and the service agreement says API access must first be approved",
          "unchecked: whether 429 responses carry a Retry-After header. None is documented",
          "unchecked: whether an OpenAPI spec is published somewhere we didn't look. None is linked from llms.txt or the API introduction",
          "unchecked: the date of the US privacy policy, which shows no last-updated line in the text we read. The global policy is dated 26 February 2026",
          "unchecked: whether an SLA exists in Accelerate or platform contracts. None was found in the service agreement or the API terms",
          "The lead described a plain REST API with a sandbox. It left out that the Spend endpoints are beta and that the vendor also runs a CLI and three MCP servers",
          "The docs carry two pages titled Instructions for AI agents and an install prompt that asks an assistant to fetch and follow the AgentOS guide. We recorded them as facts and didn't act on them",
          "The pricing page is the US one in USD. Plans and fees differ by region, and the terms and privacy policy cited are those of Airwallex US, LLC",
          "security.txt gives its expiry as `2030-06-30 T00:00:00.000Z` with a space inside the timestamp, which isn't the RFC 9116 format. We recorded it as valid because the contacts and a future expiry are present"
        ]
      },
      "negative": 0,
      "verdict": "Scoped API keys split read from write per resource, tokens last 30 minutes, and the sandbox opens at once with no contract. No OpenAPI spec was found, every Spend endpoint read is marked beta, the pricing page lists direct Spend API integration under the custom-priced Accelerate plan, and no SLA was found.",
      "bestFor": "A company already banking with Airwallex in several currencies that wants an agent to issue cards with limits, read card transactions and expenses, load vendors, purchase orders and bills, and sync status to an ERP.",
      "strengths": [
        "Scoped API keys grant Read or Write per resource, can be limited to listed IP ranges, and exchange for bearer tokens that last 30 minutes",
        "A sandbox account opens at once from a signup form, with the full API except Connected Accounts and simulation endpoints for card transactions",
        "Rate limits are published with numbers, 100 requests a second per account and 20 per endpoint in production, with backoff guidance for 429",
        "Create calls such as `POST /api/v1/issuing/cards/create` and `POST /api/v1/spend/bills/create` require a `request_id`, so a retried request isn't applied twice",
        "status.airwallex.com has separate Spend, Issuing, API Gateway and Sandbox components, and none was named in an incident between 27 April and 8 October 2026"
      ],
      "weaknesses": [
        "No OpenAPI spec was found. The reference is a Markdown page per endpoint, and the CLI prints one endpoint's schema at a time",
        "Each Spend endpoint we read (expenses, vendors, bills, purchase orders) is marked beta, and the pricing page lists direct Spend API integration under the custom-priced Accelerate plan",
        "The Spend API reads expenses and sets sync status. No endpoint was found to attach a receipt, code a card expense or approve one",
        "The only server SDK is `@airwallex/node-sdk`, still in beta and last published on 31 December 2025",
        "No SLA was found, and the Security Audit Logs API is open to selected accounts only and covers logins, user changes and key changes, not API calls"
      ],
      "agentNotes": [
        "Exchange `x-client-id` and `x-api-key` at `POST /api/v1/authentication/login` once, then reuse the bearer token for 30 minutes. The login endpoint allows 100 requests a minute per key",
        "Create Spend keys with organisation-level permissions. With a key linked to several accounts, send `x-login-as` at login or the token carries no account permissions",
        "Send a fresh UUID as `request_id` on every create call and reuse the same value when retrying after a timeout",
        "Expect two pagination styles. Spend and card transaction events use the `page` bookmark with `page_after` and `page_before`. Cards and legacy transactions use `page_num` and `has_more`",
        "Card and expense lists default to the last 30 days. Pass both created-at bounds to read further back, and fetch a card singly to see its `authorization_controls`"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 68.3
        }
      ],
      "editorialScores": {
        "ergonomics": 69,
        "maintenance": 66,
        "payments": 25,
        "reliability": 77,
        "schema": 69,
        "security": 84,
        "transparency": 64
      },
      "provenanceScore": 92
    },
    "connect": {
      "install": "curl -fsSL https://static.airwallex.com/developer-tools/airwallex-cli/install.sh | sh",
      "http": "curl -X POST https://api.sandbox.airwallex.com/api/v1/authentication/login \\\n  -H 'Content-Type: application/json' \\\n  -H 'x-api-key: {{YOUR_API_KEY}}' \\\n  -H 'x-client-id: {{YOUR_CLIENT_ID}}'",
      "claudeCode": "claude mcp add-json airwallex '{ \"type\": \"http\", \"url\": \"https://mcp.airwallex.com/mcp\" }'",
      "config": {
        "mcpServers": {
          "airwallex": {
            "type": "http",
            "url": "https://mcp.airwallex.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/spend.transactions",
      "tool": "https://letme.dev/airwallex"
    },
    "notable": [
      "The four Spend reference pages we read (list expenses, list vendors, create bill, create purchase order) are headed Status beta (https://www.airwallex.com/docs/api/spend/expenses/list.md)",
      "The Spend API is built for ERP sync. It reads card expenses and reimbursements and sets their sync status, and creates vendors, purchase orders and bills (https://www.airwallex.com/docs/spend/how-airwallex-spend-works.md)",
      "The AgentOS MCP server at https://mcp.airwallex.com/mcp acts on a production account over OAuth, and Airwallex says its tools don't start transfers, conversions or payouts by default (https://www.airwallex.com/docs/developer-tools/ai/agentos.md)",
      "Scoped API keys grant Read or Write per resource and can be restricted to listed IP ranges (https://www.airwallex.com/docs/developer-tools/api/api-key-best-practices.md)",
      "Production limits are 100 requests a second per account, 20 per endpoint and 50 concurrent requests (https://www.airwallex.com/docs/developer-tools/api/rate-limits.md)",
      "The US pricing page lists direct Spend API integration with an ERP under the Accelerate plan, which is priced on request (https://www.airwallex.com/us/pricing)",
      "The docs carry two pages of instructions addressed to AI agents and an install prompt that asks an assistant to fetch and follow the AgentOS guide (https://www.airwallex.com/docs/developer-tools/ai-agent-instructions.md)",
      "The privacy policy says personal data may be processed to develop or improve Airwallex's AI and machine learning technologies (https://www.airwallex.com/us/terms/privacy-policy-airwallex)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "API",
        "value": "REST at https://api.airwallex.com (sandbox https://api.sandbox.airwallex.com), dated versions with `2026-08-21` the latest. The scope catalogue links 34 Issuing and 24 Spend reference pages. No OpenAPI spec found"
      },
      {
        "label": "Spend endpoints",
        "value": "Card expenses and reimbursement reports (list, get, set sync status, mark paid externally), vendors, purchase orders and bills (create, list, get, set sync status). Each page we read is marked beta"
      },
      {
        "label": "Issuing endpoints",
        "value": "Cardholders, cards (create, activate, update, sensitive details, remaining limits), authorisations, card transaction events, card transactions and lifecycles, disputes, digital wallet tokens and issuing config"
      },
      {
        "label": "MCP servers",
        "value": "AgentOS MCP at https://mcp.airwallex.com/mcp (production, OAuth, 35 scopes advertised). Developer MCP at https://mcp.sandbox.airwallex.com/developer (sandbox, OAuth). Docs MCP at https://mcp.sandbox.airwallex.com/docs (no sign-in, 2 read-only tools)"
      },
      {
        "label": "CLI",
        "value": "`airwallex`, macOS and Linux, installed by script, OAuth sign-in, sandbox by default and `--prod` for production. `--dry-run`, `--compact`, `--api-schema-only`, and confirmation on writes unless `--confirm` is passed. Telemetry is on by default with an opt-out"
      },
      {
        "label": "Credentials",
        "value": "Scoped API keys (Read or Write per resource, optional IP allowlist) or admin keys, exchanged for a 30-minute bearer token. OAuth 2.0 with 64 scopes for partner apps, the CLI and MCP"
      },
      {
        "label": "Rate limits",
        "value": "Production 100 requests a second per account, 20 per endpoint, 50 concurrent. Sandbox 20, 10 and 10. Login endpoint 100 a minute per key"
      },
      {
        "label": "Pagination",
        "value": "`page` bookmark with `page_after` and `page_before` on Spend and card transaction events. `page_num` and `has_more` on cards and legacy transactions. `page_size` 1 to 100"
      },
      {
        "label": "Errors",
        "value": "JSON with `code`, `message`, `source` and `details`. 429 returns `too_many_requests` with a `trace_id`"
      },
      {
        "label": "Card controls",
        "value": "Single or multiple use, allowed currencies, merchant category codes, active period, transaction limits by amount and interval, blocked transaction types, alert thresholds and remote authorisation"
      },
      {
        "label": "Webhooks",
        "value": "Signed with HMAC over timestamp and body, retried with exponential backoff for about three days. Spend events for bills, expenses and reimbursements"
      },
      {
        "label": "SDK",
        "value": "`@airwallex/node-sdk` 2.1.0-beta.5 (31 December 2025), MIT, Node only"
      },
      {
        "label": "Certifications",
        "value": "SOC 1 Type 2, SOC 2 Type 2, ISO/IEC 27001 and PCI DSS Level 1 per security.airwallex.com. Bug bounty by invitation since 13 July 2021"
      },
      {
        "label": "Status",
        "value": "status.airwallex.com on Statuspage, 21 components including Spend, Issuing, API Gateway and Sandbox"
      },
      {
        "label": "Sub-processors",
        "value": "Public list updated 7 October 2026 with category, role and region. Google Cloud Platform is the primary host"
      }
    ],
    "unitPrices": [
      {
        "item": "Explore plan",
        "unit": "seat-month",
        "usd": 0,
        "note": "Up to 10 free Spend users. No separate API fee is published"
      },
      {
        "item": "Grow plan",
        "unit": "seat-month",
        "usd": 12,
        "note": "Per active Spend user, up to 250. Accelerate, which lists direct Spend API integration, is priced on request"
      }
    ],
    "provenance": {
      "legalEntity": "Airwallex US, LLC",
      "domain": "airwallex.com",
      "domainRegistered": "2015-11-08",
      "endpointOnVendorDomain": true,
      "terms": "https://www.airwallex.com/us/terms/application-programming-interface-terms",
      "privacy": "https://www.airwallex.com/us/terms/privacy-policy-airwallex",
      "statusPage": "https://status.airwallex.com",
      "changelog": "https://www.airwallex.com/docs/api/changelog",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The terms and privacy policy cited are the US ones. The US privacy policy names Airwallex US, LLC among the entities responsible, and the site footer gives Airwallex US, LLC (NMLS #1928093) as the licensed money transmitter. Other regions have their own entities and documents.",
        "The API terms (API Developer Terms and Conditions) are dated 20 June 2025. The service agreement was last updated on 2 December 2025 and took effect on 1 January 2026. The Spend Management Terms are dated 6 December 2023.",
        "The API answers at api.airwallex.com and api.sandbox.airwallex.com, and the MCP servers at mcp.airwallex.com and mcp.sandbox.airwallex.com.",
        "www.airwallex.com/.well-known/security.txt lists bugbounty@airwallex.com and security@airwallex.com and an expiry of 30 June 2030. The timestamp has a space inside it, which isn't the RFC 9116 format.",
        "The US privacy policy shows no last-updated line in the text we read. The global policy at /terms/privacy-policy is dated 26 February 2026.",
        "RDAP for airwallex.com gives a registration date of 2015-11-08."
      ],
      "score": 92,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Airwallex US, LLC",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "airwallex.com, registered 2015-11-08 (10 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.airwallex.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects, and has 1 clause that costs points",
          "points": 7.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.airwallex.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.airwallex.com/us/terms/application-programming-interface-terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-06-20",
          "words": 5487,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: 20 June 2025",
              "says": "Last updated 2025-06-20"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "If any provision of these API Terms is determined to be invalid or unenforceable by a court of law, the remaining provisions of these API Terms will remain in full force and effect."
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "To the maximum extent permitted by Applicable Laws, Airwallex’s liability to Developer in relation to these API Terms, whether in contract, negligence, liability, tort or other legal or equitable theory, for losses or damages shall not exceed USD $1,000 (or local currency equivalent).",
              "says": "Capped at USD $1,000"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "The Developer may terminate these API Terms at any time by ceasing all use of the Developer platform, servers, or systems and notifying Airwallex."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Airwallex may terminate these API Terms for any reason upon providing 10 days notice to the Developer.",
              "says": "Gives 10 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If the Developer uses the Airwallex Platform and provides a financial service or product (as described in Airwallex’s Acceptable Use Policy), the Developer is prohibited from using the Airwallex Platform without Airwallex’s prior written consent (“Airwallex Approval”)."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "(d) download, scrape, post or transmit any part of the other Party’s website or content;",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "(j) access the other Party’s platform for competitive purposes or publicly disseminate performance information or analysis relating to the other Party’s APIs.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Airwallex may terminate these API Terms for any reason upon providing 10 days notice to the Developer."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Airwallex's liability to the developer under the API Terms is capped at 1,000 US dollars or the local currency equivalent.",
              "quote": "Airwallex’s liability to Developer in relation to these API Terms, whether in contract, negligence, liability, tort or other legal or equitable theory, for losses or damages shall not exceed USD $1,000 (or local currency equivalent)."
            },
            {
              "date": "2026-10-08",
              "text": "Airwallex may publish the developer's marks on its websites, in press releases and in promotional materials without prior consent.",
              "quote": "Airwallex may also publish the Developer’s Marks (with or without a link to the Developer’s website or content) on our websites, in press releases, and in promotional materials without your prior consent."
            },
            {
              "date": "2026-10-08",
              "text": "The developer must implement any update within the time Airwallex specifies, and no later than six months after Airwallex issues it.",
              "quote": "The Developer agrees to implement any Update within a reasonable time, as specified by Airwallex, and in any case no longer than six (6) months of Airwallex issuing the Update."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.airwallex.com/us/terms/privacy-policy-airwallex",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 8347,
          "points": 7.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy (the “Policy”) describes the personal data (sometimes also referred to as personal information) we collect as a data controller from you and how that information is used and shared by us."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "When a relevant retention period has passed, Airwallex will destroy personal information or, where applicable, sufficiently anonymize the personal information."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Our affiliates and select third parties support the operation of the Services and will necessarily receive and/or transfer personal information in order to facilitate the Services and services provided by third parties at your request and/or with your consent where legally required."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "To learn more about behavioral advertising and online tracking, visit the Network Advertising Initiative."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "to verify your identity or authenticate your right to access an account or other information;"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you want to reach out to our Data Protection Officer, please contact [email protected].",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "…security requirements, as well as the standards described in this Policy, including the use of mandated Standard Contractual Clauses (for the European Union and Brazil) and International Data Transfer Agreement (for the United Kingdom) or any equivalent standard contracts issued by relevant authorities into its agreem…",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "We may also process personal data to develop or improve our AI or ML technologies as described in section 4 of this Policy in accordance with applicable law and internal standards.",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Airwallex may keep personal information after an account is closed or after a deletion request.",
              "quote": "We may retain your personal information even after you close your Airwallex account or request deletion of your personal information."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/airwallex.json",
    "live": {
      "slug": "airwallex",
      "probe": {
        "target": "https://api.airwallex.com",
        "method": "get",
        "lastAt": "2026-10-08T21:12:03.204142811Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 37,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 44,
        "p95ms24h": 75,
        "samples24h": 21,
        "samples30d": 21,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 21,
            "ok": 21
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.airwallex.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T21:05:50.696967861Z"
      },
      "updatedAt": "2026-10-08T21:12:03.204142811Z"
    }
  }
}
