{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "brex",
    "name": "Brex",
    "vendor": "Brex LLC",
    "vendorUrl": "https://www.brex.com",
    "kind": "http-api",
    "category": "spend-management",
    "summary": "Brex is a spend platform with corporate cards, expense management, bill pay, travel and business accounts. Its REST Developer API reads and writes cards, expenses, spend limits, vendors and transfers, and a hosted MCP server is in beta.",
    "url": "https://www.anchorterminal.com/tools/brex",
    "markdownUrl": "https://www.anchorterminal.com/tools/brex.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/brex.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/brex.json",
    "license": "Proprietary service under the Brex Platform Agreement and the Brex Access Agreement",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.brex.com",
    "packages": [],
    "auth": "mixed",
    "authNotes": "Access is self-serve for a Brex customer. An account admin or card admin accepts the Developer API agreement in the dashboard, then creates a user token with chosen scopes at Settings \u003e Developer. The token is sent as a Bearer header, is shown once, can be revoked, and expires after 90 days without a call. Partners acting for other Brex accounts apply to Brex for a client ID and secret and use the OAuth 2.0 authorisation code grant, with one-hour access tokens and refresh tokens. The MCP server takes OAuth with dynamic client registration, where each employee signs in with their own permissions, or an admin's user token.",
    "pricing": "freemium",
    "pricingNotes": "No separate API fee. brex.com/pricing lists Brex API access under Essentials at $0 per user per month, with Premium at $12 per user per month and Enterprise priced on request. Access needs an approved Brex business account, so an agent can't start without one. There is no customer sandbox, and the staging server is for approved partners only. The Access Agreement lets Brex introduce API fees on 30 days' notice (checked 2026-10-08).",
    "priceSummary": "$12 / seat-mo",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 43,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.brex.com",
    "llmsTxt": "https://developer.brex.com/llms.txt",
    "openapi": "https://developer.brex.com/_bundle/openapi/team_api.yaml",
    "capabilities": [
      "spend.transactions",
      "spend.expenses",
      "spend.cards",
      "spend.bills"
    ],
    "tags": [
      "hosted",
      "freemium",
      "api-key",
      "oauth",
      "mcp",
      "openapi",
      "llms-txt",
      "webhooks",
      "status-page",
      "soc2",
      "pci-dss"
    ],
    "lastRelease": "2026-10-01",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 60.7,
      "grade": "C",
      "agentReady": false,
      "rank": 345,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 3,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 70,
        "maintenance": 66,
        "payments": 25,
        "reliability": 60,
        "schema": 80,
        "security": 72,
        "transparency": 67
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 60,
          "points": 12,
          "reason": "Read with the hosted lines and scored on the REST Developer API, the surface an outside agent calls with a token. status.brex.com on Atlassian Statuspage has 12 components, among them Partner API and Authentication, with incident history (20). Thirteen entries between 12 July and 8 October 2026, seven marked critical. Errors affecting API requests ran from 16:01 to 20:34 UTC on 4 August, with a fix in place at 17:50. An entry on 21 September reports developer API tokens invalidated unexpectedly, with affected customers told to create new ones. Maintenance took the dashboard and external APIs down for about nine minutes on 12 July. One API outage of over an hour plus the token invalidation, read as between one major and several (5). Limits with numbers, 1,000 requests in 60 seconds per client and account, plus daily caps on transfers, wires and cards (15). The docs recommend exponential backoff with jitter on 429, and every POST and PUT accepts an `Idempotency-Key`, required on transfers and cards. A Retry-After header isn't documented (13 of 15). No SLA found in the Platform Agreement or the Access Agreement (0). Team, Budgets, Payments, Transactions, Travel and Onboarding are at version 1.0, while Fields is beta, Accounting alpha, Expenses and Webhooks are numbered 0.1 and the MCP server is beta (7 of 10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 80,
          "points": 13,
          "reason": "Ten public OpenAPI 3 specs, 115 operations, each downloadable from the reference page (25). llms.txt and a Markdown twin of every docs and reference page (10). Operation descriptions state the purpose and which role may call them, and some carry constraints, such as the ten physical cards a user may hold. Many filter parameters have no description, and none says when not to use an endpoint (12 of 20). Enums on status and type fields, date-time formats and required bodies. `expand[]` takes free strings (12 of 15). An examples page per API and an error guide with the body shape and a table of common errors. The Team API spec documents only 200 responses for its 35 operations, and no spec lists 429 (9 of 15). Path versions v1 and v2, launch-stage suffixes on spec versions and a public changelog, dated to the month only (12 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 70,
          "points": 11.38,
          "reason": "`limit` sizes a page, related objects arrive only through `expand[]`, and custom fields only with `load_custom_fields`. No field selection (18 of 25). Cursor pagination with `next_cursor` on every list endpoint and 15 filters on List expenses. The FAQ says card transactions can't be filtered to a time range beyond a start date, and pending transactions aren't returned (17 of 20). Errors carry `type`, `message` and an optional `code`, with an `X-Brex-Trace-Id` header and a short table of fixes. No full list of codes (12 of 20). `Idempotency-Key` on all POST and PUT requests, required where a duplicate would move money or issue a card. MCP tool annotations couldn't be read without an account (17 of 20). List calls need no parameters. No official SDK, three community libraries the docs say Brex doesn't support, and a Postman guide (6 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 72,
          "points": 12.6,
          "reason": "User tokens with scopes chosen at creation, shown once, revocable in the dashboard and expired after 90 days unused. Partners use the OAuth 2.0 authorisation code grant with scopes, optional PKCE and one-hour access tokens. All credentials travel in the `Authorization` header (30). Most resources have a read-only scope, card numbers need the separate `cards.pan` scope, and MCP users act with their own Brex permissions, with approvals and card management left out of the MCP. No approval step was found for transfers or card creation made with a token that holds the write scope (13 of 20). Expense memos, merchant and vendor names and receipts are untrusted text. The MCP page advises requiring human approval before actions, with no guidance on injected content (5 of 15). The MCP page points to API logs in the dashboard and a list of connected integrations that can be revoked, and responses carry a trace ID. Log contents and retention aren't documented publicly (9 of 15). SOC 1 Type II, SOC 2 Type II and PCI DSS per the trust page, and a disclosure policy with a form run with Bugcrowd. No bounty is stated and there is no security.txt (15 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 25,
          "points": 3.13,
          "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public, $0 per user per month for Essentials, which lists API access, and $12 for Premium, with Enterprise on request. The API has no per-call price (10). The $0 plan needs no payment card, but it needs an approved Brex business account, and there is no customer sandbox, so partial credit (15 of 20). A person creates each token in the dashboard or completes an OAuth sign-in (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 66,
          "points": 5.78,
          "reason": "The changelog's latest entry is October 2026 (30). Entries for July, August, September and October 2026, with nine items in September alone (20). Closed service with a dated changelog, a developer support address and a Slack community. Response times couldn't be observed (10 of 15). No official SDK, and no entry for the Brex MCP server in the official MCP registry (3 of 15). No packages to assess. The OpenAPI bundles match the changelog's October additions (3 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 67,
          "points": 5.86,
          "note": "editorial 47, provenance 86",
          "reason": "Closed service with terms published at stable URLs and as Markdown, the Platform Agreement and the Brex Access Agreement for API use (15 of 30). A privacy policy and a DPA with breach notice within 72 hours and deletion within 30 days of a written request after termination. Retention periods aren't stated, and the Access Agreement lets Brex monitor API use for any business purpose (17 of 30). A launch-stages page promises 15 days' notice of breaking changes in alpha and 60 in beta, and new versions with deprecation timelines once generally available. Deprecated endpoints are marked in the specs. Removal dates aren't published, and the versioning page promises only sufficient lead time (11 of 20). The DPA points to a sub-processor list on trust-portal.brex.com, which returned 403 to our reader, and says data may be transferred globally. The trust page names AWS storage services (4 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`limit` sizes a page, related objects arrive only through `expand[]`, and custom fields only with `load_custom_fields`. No field selection (18 of 25). Cursor pagination with `next_cursor` on every list endpoint and 15 filters on List expenses. The FAQ says card transactions can't be filtered to a time range beyond a start date, and pending transactions aren't returned (17 of 20). Errors carry `type`, `message` and an optional `code`, with an `X-Brex-Trace-Id` header and a short table of fixes. No full list of codes (12 of 20). `Idempotency-Key` on all POST and PUT requests, required where a duplicate would move money or issue a card. MCP tool annotations couldn't be read without an account (17 of 20). List calls need no parameters. No official SDK, three community libraries the docs say Brex doesn't support, and a Postman guide (6 of 15).",
          "maintenance": "The changelog's latest entry is October 2026 (30). Entries for July, August, September and October 2026, with nine items in September alone (20). Closed service with a dated changelog, a developer support address and a Slack community. Response times couldn't be observed (10 of 15). No official SDK, and no entry for the Brex MCP server in the official MCP registry (3 of 15). No packages to assess. The OpenAPI bundles match the changelog's October additions (3 of 10).",
          "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). Plan prices are public, $0 per user per month for Essentials, which lists API access, and $12 for Premium, with Enterprise on request. The API has no per-call price (10). The $0 plan needs no payment card, but it needs an approved Brex business account, and there is no customer sandbox, so partial credit (15 of 20). A person creates each token in the dashboard or completes an OAuth sign-in (0).",
          "reliability": "Read with the hosted lines and scored on the REST Developer API, the surface an outside agent calls with a token. status.brex.com on Atlassian Statuspage has 12 components, among them Partner API and Authentication, with incident history (20). Thirteen entries between 12 July and 8 October 2026, seven marked critical. Errors affecting API requests ran from 16:01 to 20:34 UTC on 4 August, with a fix in place at 17:50. An entry on 21 September reports developer API tokens invalidated unexpectedly, with affected customers told to create new ones. Maintenance took the dashboard and external APIs down for about nine minutes on 12 July. One API outage of over an hour plus the token invalidation, read as between one major and several (5). Limits with numbers, 1,000 requests in 60 seconds per client and account, plus daily caps on transfers, wires and cards (15). The docs recommend exponential backoff with jitter on 429, and every POST and PUT accepts an `Idempotency-Key`, required on transfers and cards. A Retry-After header isn't documented (13 of 15). No SLA found in the Platform Agreement or the Access Agreement (0). Team, Budgets, Payments, Transactions, Travel and Onboarding are at version 1.0, while Fields is beta, Accounting alpha, Expenses and Webhooks are numbered 0.1 and the MCP server is beta (7 of 10).",
          "schema": "Ten public OpenAPI 3 specs, 115 operations, each downloadable from the reference page (25). llms.txt and a Markdown twin of every docs and reference page (10). Operation descriptions state the purpose and which role may call them, and some carry constraints, such as the ten physical cards a user may hold. Many filter parameters have no description, and none says when not to use an endpoint (12 of 20). Enums on status and type fields, date-time formats and required bodies. `expand[]` takes free strings (12 of 15). An examples page per API and an error guide with the body shape and a table of common errors. The Team API spec documents only 200 responses for its 35 operations, and no spec lists 429 (9 of 15). Path versions v1 and v2, launch-stage suffixes on spec versions and a public changelog, dated to the month only (12 of 15).",
          "security": "User tokens with scopes chosen at creation, shown once, revocable in the dashboard and expired after 90 days unused. Partners use the OAuth 2.0 authorisation code grant with scopes, optional PKCE and one-hour access tokens. All credentials travel in the `Authorization` header (30). Most resources have a read-only scope, card numbers need the separate `cards.pan` scope, and MCP users act with their own Brex permissions, with approvals and card management left out of the MCP. No approval step was found for transfers or card creation made with a token that holds the write scope (13 of 20). Expense memos, merchant and vendor names and receipts are untrusted text. The MCP page advises requiring human approval before actions, with no guidance on injected content (5 of 15). The MCP page points to API logs in the dashboard and a list of connected integrations that can be revoked, and responses carry a trace ID. Log contents and retention aren't documented publicly (9 of 15). SOC 1 Type II, SOC 2 Type II and PCI DSS per the trust page, and a disclosure policy with a form run with Bugcrowd. No bounty is stated and there is no security.txt (15 of 20).",
          "transparency": "Closed service with terms published at stable URLs and as Markdown, the Platform Agreement and the Brex Access Agreement for API use (15 of 30). A privacy policy and a DPA with breach notice within 72 hours and deletion within 30 days of a written request after termination. Retention periods aren't stated, and the Access Agreement lets Brex monitor API use for any business purpose (17 of 30). A launch-stages page promises 15 days' notice of breaking changes in alpha and 60 in beta, and new versions with deprecation timelines once generally available. Deprecated endpoints are marked in the specs. Removal dates aren't published, and the versioning page promises only sufficient lead time (11 of 20). The DPA points to a sub-processor list on trust-portal.brex.com, which returned 403 to our reader, and says data may be transferred globally. The trust page names AWS storage services (4 of 20)."
        },
        "sources": [
          {
            "what": "llms.txt and docs index",
            "url": "https://developer.brex.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server, tools, authentication and beta status",
            "url": "https://developer.brex.com/docs/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "user tokens, revocation and expiry",
            "url": "https://developer.brex.com/guides/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "scopes and roles",
            "url": "https://developer.brex.com/guides/roles_permissions_scopes",
            "seen": "2026-10-08"
          },
          {
            "what": "partner OAuth, staging server",
            "url": "https://developer.brex.com/guides/partner_authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits and 429 guidance",
            "url": "https://developer.brex.com/guides/rate_limits",
            "seen": "2026-10-08"
          },
          {
            "what": "idempotency",
            "url": "https://developer.brex.com/guides/idempotency",
            "seen": "2026-10-08"
          },
          {
            "what": "pagination",
            "url": "https://developer.brex.com/guides/pagination",
            "seen": "2026-10-08"
          },
          {
            "what": "error codes",
            "url": "https://developer.brex.com/guides/error_codes",
            "seen": "2026-10-08"
          },
          {
            "what": "versioning",
            "url": "https://developer.brex.com/guides/versioning",
            "seen": "2026-10-08"
          },
          {
            "what": "launch stages and notice periods",
            "url": "https://developer.brex.com/guides/api-launch-stages",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://developer.brex.com/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "FAQ, settled transactions only",
            "url": "https://developer.brex.com/docs/faq",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI specs, ten files",
            "url": "https://developer.brex.com/_bundle/openapi/team_api.yaml",
            "seen": "2026-10-08"
          },
          {
            "what": "Expenses API reference and spec",
            "url": "https://developer.brex.com/openapi/expenses_api",
            "seen": "2026-10-08"
          },
          {
            "what": "community libraries",
            "url": "https://developer.brex.com/docs/community_supported_libraries",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.brex.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status components",
            "url": "https://status.brex.com/api/v2/components.json",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.brex.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "trust page and certifications",
            "url": "https://www.brex.com/trust",
            "seen": "2026-10-08"
          },
          {
            "what": "responsible disclosure policy",
            "url": "https://www.brex.com/trust/responsible-disclosure",
            "seen": "2026-10-08"
          },
          {
            "what": "Brex Access Agreement",
            "url": "https://www.brex.com/legal/developer-portal",
            "seen": "2026-10-08"
          },
          {
            "what": "Platform Agreement",
            "url": "https://www.brex.com/legal/platform-agreement",
            "seen": "2026-10-08"
          },
          {
            "what": "DPA",
            "url": "https://www.brex.com/legal/dpa",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.brex.com/legal/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP protected resource metadata",
            "url": "https://api.brex.com/.well-known/oauth-protected-resource/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=brex",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for brex.com",
            "url": "https://rdap.verisign.com/com/v1/domain/brex.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the sub-processor list and security documents on trust-portal.brex.com, which returned 403 to our reader",
          "unchecked: MCP tool input schemas and the readOnlyHint and destructiveHint annotations, which need a signed-in Brex account",
          "unchecked: whether customers were told by email before the February 2026 limit cut and the September 2026 endpoint removal",
          "unchecked: whether 429 responses carry a Retry-After header",
          "unchecked: what the dashboard's API logs record and how long they are kept",
          "The changelog is dated to the month, so `lastRelease` is recorded as 2026-10-01 for an entry labelled October 2026",
          "The 4 August 2026 API incident and the 21 September token incident have no published cause or count of affected customers",
          "Bills appear only as read-only MCP tools (`list_bills`, `get_bill_by_id`). The REST API has vendors and transfers but no bill endpoints in the public specs",
          "No purchase request or procurement endpoint was found in the public specs",
          "The last-updated dates of the privacy policy and the Access Agreement weren't visible in the pages we read"
        ]
      },
      "negative": -3,
      "negativeNotes": [
        "2026-02 and 2026-09. The changelog records the List expenses maximum `limit` cut from 1,000 to 100 in February 2026, and `GET /v2/users/{id}/limit` removed from the Team API in September 2026 without a deprecated label in the entry. The Team API is at version 1.0, and the launch-stages page says breaking changes to generally available APIs come as new versions with deprecation timelines. Both changes are documented in the month they shipped, and notice by email couldn't be checked, so the smallest deduction applies (https://developer.brex.com/changelog)."
      ],
      "verdict": "User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.",
      "bestFor": "A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.",
      "strengths": [
        "Ten public OpenAPI 3 specs covering 115 operations, plus llms.txt and a Markdown twin of every docs page",
        "User tokens take scopes chosen at creation, most with a read-only variant, and card numbers need the separate `cards.pan` scope",
        "Every POST and PUT accepts an `Idempotency-Key`, and Create transfer and Create card require one",
        "API access is listed on the Essentials plan at $0 per user per month",
        "The hosted MCP server uses OAuth with dynamic client registration and each employee's own Brex permissions"
      ],
      "weaknesses": [
        "The Expenses API update endpoint accepts only `memo`, so an outside agent can't set a category or custom field on an expense through it",
        "No customer sandbox. The docs say staging isn't a sandbox and won't accept customer tokens",
        "No official SDK. The docs list three community libraries that Brex doesn't support",
        "status.brex.com logs API request errors from 16:01 to 20:34 UTC on 4 August 2026 and invalidated developer tokens on 21 September 2026",
        "The MCP server is beta with 43 tools, and approvals and card management aren't available through it"
      ],
      "agentNotes": [
        "Ask an account admin or card admin for a user token with only the scopes the task needs, and prefer the `.readonly` variants. A token unused for 90 days expires.",
        "Send a stored `Idempotency-Key` on every POST and PUT. Create transfer and Create card reject requests without one.",
        "Only settled transactions are returned. Poll card and cash transactions with `posted_at_start` and a lookback of at least one day.",
        "Keep under 1,000 requests in 60 seconds per client and account, and back off exponentially with jitter on 429.",
        "Send only ASCII in free-text fields, and quote the `X-Brex-Trace-Id` response header when reporting an error."
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 60.7
        }
      ],
      "editorialScores": {
        "ergonomics": 70,
        "maintenance": 66,
        "payments": 25,
        "reliability": 60,
        "schema": 80,
        "security": 72,
        "transparency": 47
      },
      "provenanceScore": 86
    },
    "connect": {
      "http": "curl -i -X GET \\\n  https://api.brex.com/v2/users/me \\\n  -H 'Authorization: Bearer \u003cYOUR_TOKEN_FROM_STEP_1_HERE\u003e'",
      "claudeCode": "claude mcp add --transport http brex https://api.brex.com/mcp",
      "config": {
        "mcpServers": {
          "brex": {
            "headers": {
              "Authorization": "Bearer YOUR_BREX_ACCESS_TOKEN"
            },
            "type": "http",
            "url": "https://api.brex.com/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/spend.transactions",
      "tool": "https://letme.dev/brex"
    },
    "notable": [
      "The Developer API is ten REST APIs with public OpenAPI specs (Team, Expenses, Budgets, Payments, Transactions, Travel, Fields, Accounting, Webhooks, Onboarding), 115 operations in the specs read on 8 October 2026 (https://developer.brex.com/llms.txt)",
      "The Brex MCP server is hosted at https://api.brex.com/mcp, launched in April 2026 and still labelled beta, with 43 tools listed and approvals and card management not yet available (https://developer.brex.com/docs/mcp)",
      "Rate limits are per client ID and account. 1,000 requests in 60 seconds, 1,000 transfers, 100 international wires and 5,000 card creations in 24 hours (https://developer.brex.com/guides/rate_limits)",
      "All POST and PUT requests accept an `Idempotency-Key` header, required on Create transfer and Create card (https://developer.brex.com/guides/idempotency)",
      "The API returns only settled transactions, and the September 2026 changelog removed `GET /v2/users/{id}/limit` from the Team API (https://developer.brex.com/docs/faq, https://developer.brex.com/changelog)",
      "The pricing page lists Brex API access under the Essentials plan at $0 per user per month, with Premium at $12 (https://www.brex.com/pricing)",
      "The Platform Agreement names Brex LLC as a wholly owned subsidiary of Capital One, N.A. (https://www.brex.com/legal/platform-agreement)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "APIs",
        "value": "Team (35 operations), Budgets (17), Webhooks (13), Payments (10), Fields (10, beta), Transactions (8), Expenses (7), Accounting (6, alpha), Onboarding (5), Travel (4), all OpenAPI 3 at https://developer.brex.com/_bundle/openapi/\u003cname\u003e_api.yaml and served from https://api.brex.com"
      },
      {
        "label": "Write access",
        "value": "Create, update, lock, unlock and terminate cards. Create and update spend limits and budgets. Create vendors and ACH, wire, cheque and book transfers. Upload and match receipts. Expense updates accept `memo` only"
      },
      {
        "label": "MCP server",
        "value": "Hosted at https://api.brex.com/mcp, beta, 43 tools, mostly reads plus memo, receipt, attendee and limit-assignment updates on expenses. An admin accepts the Developer API agreement and enables the Brex in AI assistants beta first"
      },
      {
        "label": "Credentials",
        "value": "User token (prefix `bxt_`) created by an account admin or card admin with chosen scopes, shown once, revocable, expires after 90 days unused. Partners use OAuth 2.0 authorisation code (PKCE optional) with one-hour access tokens. MCP uses OAuth with dynamic client registration or a user token"
      },
      {
        "label": "Scopes",
        "value": "41 documented scopes across nine APIs, most split into a view scope and a view-and-manage scope, with `cards.pan` separate for card numbers"
      },
      {
        "label": "Rate limits",
        "value": "1,000 requests in 60 seconds per client ID and account. 1,000 transfers, 100 international wires and 5,000 cards created in 24 hours"
      },
      {
        "label": "Pagination",
        "value": "Cursor and limit on list endpoints, default 100. The pagination guide gives a maximum of 1,000, while List expenses was cut to 100 in February 2026"
      },
      {
        "label": "Errors",
        "value": "JSON body with `type`, `message` and optional `code`. `X-Brex-Trace-Id` on responses. The docs recommend exponential backoff with jitter on 429"
      },
      {
        "label": "Sandbox",
        "value": "None for customers. Staging at https://api-staging.brex.com is for approved partners, with data that can be purged at any time"
      },
      {
        "label": "Webhooks",
        "value": "HMAC SHA-256 signatures in `Webhook-Signature`, signing secrets from GET /v1/webhooks/secrets with two keys during rotation, 20 event types in the spec"
      },
      {
        "label": "Launch stages",
        "value": "Alpha (at least 15 days' notice of breaking changes), beta (at least 60 days, opt-in) and general availability (new versions with deprecation timelines)"
      },
      {
        "label": "Certifications",
        "value": "SOC 1 Type II, SOC 2 Type II and PCI DSS per brex.com/trust. Vulnerability reports go through a form run with Bugcrowd"
      },
      {
        "label": "Status",
        "value": "status.brex.com on Atlassian Statuspage, 12 components among them Partner API, Authentication, Spend Management and Bill Pay"
      }
    ],
    "unitPrices": [
      {
        "item": "Essentials plan",
        "unit": "seat-month",
        "usd": 0,
        "note": "Brex API access listed on this plan"
      },
      {
        "item": "Premium plan",
        "unit": "seat-month",
        "usd": 12,
        "note": "Enterprise is priced on request"
      }
    ],
    "provenance": {
      "legalEntity": "Brex LLC",
      "domain": "brex.com",
      "domainRegistered": "1998-10-22",
      "endpointOnVendorDomain": true,
      "terms": "https://www.brex.com/legal/platform-agreement",
      "privacy": "https://www.brex.com/legal/privacy",
      "statusPage": "https://status.brex.com",
      "changelog": "https://developer.brex.com/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Platform Agreement defines Brex as Brex LLC, a wholly owned subsidiary of Capital One, N.A., and the pricing page footer gives addresses in San Francisco and Salt Lake City.",
        "API use is also governed by the Brex Access Agreement at https://www.brex.com/legal/developer-portal, which an admin accepts in the dashboard before creating a token.",
        "The API and the MCP server answer at api.brex.com and the authorisation server at accounts-api.brex.com, both brex.com subdomains. The former host platform.brexapis.com still works per the docs.",
        "www.brex.com/.well-known/security.txt returns 404. brex.com/trust/responsible-disclosure has a disclosure policy and a form run with Bugcrowd.",
        "RDAP for brex.com gives a registration date of 1998-10-22."
      ],
      "score": 86,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Brex LLC",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "brex.com, registered 1998-10-22 (27 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.brex.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 6.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.brex.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.brex.com/legal/platform-agreement",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 12100,
          "points": 6.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "This Platform Agreement will be construed, applied, and governed by the laws of the State of Utah exclusive of its conflict or choice of law rules except to the extent that U.S.",
              "says": "The law of the State of Utah"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Our maximum liability to you arising from or related to (i)-(iv) above is limited to the total amount of Fees actually paid by you to Brex in the twelve months preceding the event that is the basis of your claim.",
              "says": "Capped at the fees paid in the 12 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If Brex receives reports of any such behavior, we may contact your Administrator, suspend or limit access to Company’s Brex Account or the Services, or close your Brex Account, in Brex’s sole discretion."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We may add new Fees or increase existing Fees upon 30 days' Notice to you, or earlier as provided by applicable Service-Specific Terms.",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "- Company is not engaged and will not engage in any [Prohibited Activities](https://www.brex.com/legal/prohibited-restricted-activities)"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "(h) accessed or used for purposes of comparison with or benchmarking against third party products or services or in order to build similar services or competitive services;",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "In addition to the termination rights provided for in Section 3.9 below, Brex has the right to terminate this Platform Agreement at any time and for any reason with thirty (30) days notice to you."
            },
            {
              "key": "terms.arbitration",
              "label": "Requires arbitration or waives class actions",
              "found": true,
              "quote": "Section 4 of this Platform Agreement includes an agreement to resolve any Disputes through binding arbitration on an individual basis and includes a waiver of any representative, consolidated, mass, or class actions, along with important disclaimers and limitations of liability."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The customer grants Brex a worldwide, irrevocable licence over Company Data for the purposes named in the agreement.",
              "quote": "You grant Brex a worldwide, irrevocable license to use, modify, distribute, copy, and create derivative works from Company Data for the purposes identified in this Platform Agreement."
            },
            {
              "date": "2026-10-08",
              "text": "Brex may name the customer publicly as a Brex customer during the term of the agreement.",
              "quote": "We may publicly reference you as a Brex customer on our website or in other communications during the term of this Platform Agreement."
            },
            {
              "date": "2026-10-08",
              "text": "Each user must hold their own credentials and must not share them with any other person or third party.",
              "quote": "You will ensure that each User has their own unique set of Credentials, keeps those Credentials secure, does not share those Credentials with any other person or third party, and does not reuse Credentials for other services."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.brex.com/legal/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 8183,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy applies to the personal information we collect and process, when you:"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We keep your personal information for as long as it is required in order to fulfill the relevant purposes described in this Privacy Policy, or for other essential purposes such as complying with our legal obligations, resolving disputes and enforcing our agreements.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "- **Third Party Service Partners and Providers (“Service Providers”).** Any products, services, websites or content that are offered by third parties through integrations with Brex Services, which are governed by their own respective privacy policies."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "The third parties we share with include vendors engaged in cross-context targeted advertising."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Note that if you are a California resident, you may exercise your right to opt-out of sales or sharing through preference signals."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you experience any difficulties accessing the information in this Privacy Policy, please contact us at privacy@brex.com.",
              "says": "privacy@brex.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "For personal information transferred from the European Economic Area, Switzerland or the United Kingdom, we will provide appropriate safeguards, such as through the use of the relevant standard contractual clauses.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We disclose information to vendors, platforms, analytics providers and other parties for marketing and advertising related purposes."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "If a company connects its email service, Brex may receive the user's email communications and attachments for processing.",
              "quote": "Other third party services, like your company's HRIS, may disclose your Authorized User Data, and if your company connects its email service, we may receive your email communications and attachments for processing."
            },
            {
              "date": "2026-10-08",
              "text": "Brex says it may keep personal information after a person stops being an authorised user or the company's account has closed.",
              "quote": "Please note that our retention obligations may require us to retain your Personal Information after you are no longer an Authorized User or your Company’s Brex Account has closed."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/brex.json",
    "live": {
      "slug": "brex",
      "probe": {
        "target": "https://api.brex.com",
        "method": "get",
        "lastAt": "2026-10-08T17:36:32.349215047Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 435,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 427,
        "p95ms24h": 526,
        "samples24h": 25,
        "samples30d": 25,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 25,
            "ok": 25
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.brex.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T17:38:12.310656901Z"
      },
      "securityTxt": {
        "url": "https://brex.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:43.637271768Z"
      },
      "updatedAt": "2026-10-08T17:38:12.310656901Z"
    }
  }
}
