{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "payhawk",
    "name": "Payhawk API + MCP",
    "vendor": "Payhawk Limited",
    "vendorUrl": "https://payhawk.com",
    "kind": "http-api",
    "category": "spend-management",
    "summary": "Spend management platform from Payhawk Limited in London, covering company cards, expenses, bills, purchase orders and travel. Outside agents reach it through a REST Developer API with read-only or full-access keys, and a hosted MCP server.",
    "url": "https://www.anchorterminal.com/tools/payhawk",
    "markdownUrl": "https://www.anchorterminal.com/tools/payhawk.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payhawk.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payhawk.json",
    "license": "Proprietary service under Payhawk's general terms and conditions",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.payhawk.com",
    "packages": [],
    "auth": "mixed",
    "authNotes": "Access needs a Payhawk customer account. An Administrator, an IT Administrator or a user with a custom role creates an API key in the portal under Settings, Integrations, choosing read-only or full access, and can regenerate it. The key goes in the `X-Payhawk-ApiKey` header or as a Bearer token. Two system-generated keys per account cannot be deleted by users. Group-level keys reach the group endpoints. If the key is not active, the API page says to write to partners@payhawk.com. The MCP server accepts OAuth 2 authorisation code with PKCE, where each user signs in with a Payhawk login and the assistant acts with that user's role.",
    "pricing": "paid",
    "pricingNotes": "Sold by quote per module (Travel, Cards and Expenses, Accounts Payable, Procurement) on annual or multi-year contracts, with unit-based charges for extra cards, reimbursements, purchase orders and invoices. The one published price is the Growth programme at 149 pounds a month for single-entity firms in the UK or EEA with fewer than 20 employees, with an optional 7-day trial for eligible customers. The API page says the API is free for all Payhawk accounts, and the pricing page lists Developer API access and the MCP server in the modules. A development sandbox is requested through a form on the API page (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the OpenAPI definition, the help centre or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 82,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developers.payhawk.com",
    "llmsTxt": "https://payhawk.com/llms.txt",
    "openapi": "https://api.payhawk.com/api/v3/docs.json",
    "capabilities": [
      "spend.transactions",
      "spend.expenses",
      "spend.cards",
      "spend.bills",
      "spend.procurement"
    ],
    "tags": [
      "hosted",
      "enterprise",
      "api-key",
      "oauth",
      "mcp",
      "openapi",
      "llms-txt",
      "webhooks",
      "sales-led",
      "status-page",
      "soc2",
      "iso27001"
    ],
    "lastRelease": "2026-10-08",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 57.1,
      "grade": "C",
      "agentReady": false,
      "rank": 561,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 8,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 52,
        "maintenance": 53,
        "payments": 13,
        "reliability": 58,
        "schema": 71,
        "security": 71,
        "transparency": 78
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 58,
          "points": 11.6,
          "reason": "Read with the hosted lines and scored on the Developer API, with the MCP server as a second surface. status.payhawk.com, a PagerDuty status page created on 22 October 2025, lists five services, one of them the Developer API (20). The page is drawn by script and its feeds returned the same shell, so the incident history went unread (5). The limit of 15 requests a second is stated on the API page, in the help centre and on every operation (15). Every operation declares a 429 with Retry-After and RateLimit-Remaining headers, and an unauthenticated call returned ratelimit headers. An Idempotency-Key header is mentioned only for creating an expense and is not declared as a parameter (10). The API page claims 99.9 per cent uptime, while section 16.3.3 of the terms disclaims service levels and no figure is published, so this is a claim and not an SLA (0). API v3 carries no beta label. The MCP docs refer to a beta period and the server is not yet in the Claude or ChatGPT directories (8)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 71,
          "points": 11.54,
          "reason": "A public OpenAPI 3.1 definition at api.payhawk.com/api/v3/docs.json with 105 paths and 179 operations, shown in a Swagger UI at developers.payhawk.com (25). payhawk.com/llms.txt and the help centre's index link Markdown copies of the help articles, the API overview and the MCP pages among them. The developer portal has no llms.txt and the reference exists only as the definition (8). 173 of 179 operations carry a description but only 34 run past 80 characters. Those that do state preconditions, such as which expense states allow an update. The MCP tool reference gives when to use and when not for five tools and names only for the rest (11). The definition has 167 enums, 18 patterns, required lists and closed objects. Filters are JSON passed as a query string, typed by a schema, and no header parameter is declared (12). 400, 401, 403 and 429 are declared on nearly every operation with one error model of a code and a message. Examples are sparse, 50 in a file of 1.4 MB (9). The version is in the path. No API changelog was found, and the help articles still cite api.payhawk.io and a v2 path (6)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 52,
          "points": 8.45,
          "reason": "The API has no field selection. Lists take `$take` up to 10,000 and two operations take `$include`. The MCP server has 82 tools, the lowest band, with the list filtered by the user's role and long analyses run as background jobs (12). `$skip` and `$take` appear on 7 operations, `$filter` on 11 and `$orderBy` on 2 of 75 GET operations. Paging is by offset, and the help centre and the definition disagree on the page limit (14). Errors are a code and a message, and many 400 responses are described case by case in the definition. No list of codes was found, and the 401 we received had an empty message (11). An Idempotency-Key is accepted when creating an expense other than a per diem, and PUT operations replace whole lists. MCP writes show a preview and wait for confirmation. Tool annotations could not be listed without a customer sign-in (9). Few parameters are required beyond the account ID. No official SDK was found (6)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 71,
          "points": 12.43,
          "reason": "API keys are created as read-only or full access, can be regenerated, travel in the `X-Payhawk-ApiKey` or Authorization header, and are managed by administrators or a custom role. Two system keys per account cannot be deleted by users. The MCP server uses OAuth 2 authorisation code with PKCE (S256), refresh tokens and a revocation endpoint, with no scopes published (24). Read-only keys exist. Each MCP call runs with the signed-in user's role, every write is previewed and waits for confirmation according to the docs, and payments and transfers are excluded from the MCP server (16). Supplier names, invoice text and comments reach the model, and no guidance on prompt injection was found. The MCP docs say card numbers are cut to four digits and personal details are removed from lists (4). An activity tab records changes to expenses and requests and the MCP server has a `list_audit_logs` tool. No log of calls per API key was found (9). security.txt is valid and points to a disclosure policy with no paid bounty. The trust page links SOC 1 and SOC 2 Type 2, ISO 27001, PCI DSS Level 1 and penetration test documents (18)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 13,
          "points": 1.63,
          "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). Pricing is by quote for each module, with one published plan, the Growth programme at 149 pounds a month for single-entity firms in the UK or EEA with under 20 employees. The API page says the API is free for all Payhawk accounts (8). The Growth programme has an optional 7-day trial for eligible customers, and a development sandbox is requested through a form. Neither is open to anyone without contact (5). A person signs up as a customer, creates the key in the portal or signs in to the MCP connector (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 53,
          "points": 4.64,
          "reason": "The OpenAPI definition was last modified on 8 October 2026 by its response header and the newest release note is dated 7 October 2026 (30). The release notes have more than three dated entries since late September 2026, but they cover the product and none we read concerns the API, so partial credit (15). Closed service with public release notes, support and partner addresses and partner solution consultants. No public forum or issue tracker was found (8). No official SDK on npm or PyPI and no entry in the official MCP registry (0). Nothing is packaged to assess (0)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 78,
          "points": 6.83,
          "note": "editorial 55, provenance 100",
          "reason": "Closed service with public terms, last updated on 9 December 2025, which name the contracting entities and list developer APIs among the software services (15). The privacy policy (29 June 2026) and the Data Processing Addendum (26 June 2026) agree on roles. The addendum sets deletion at 90 days after termination and bars using customer personal data, prompts included, to train general models. The privacy policy gives no retention periods, and the addendum lists SOC 1 Type 1 where the trust page says Type 2 (21). No deprecation policy for the API was found. Fields are marked deprecated in descriptions without dates, and the terms give two business days' notice of scheduled maintenance (4). The addendum's schedule lists Payhawk EOOD in Belgium and Germany and two optional sub-processors, with 30 days' notice of changes. The trust page names AWS and Google Cloud and storage in Belgium and Frankfurt, but the schedule does not list the hosting providers (15)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The API has no field selection. Lists take `$take` up to 10,000 and two operations take `$include`. The MCP server has 82 tools, the lowest band, with the list filtered by the user's role and long analyses run as background jobs (12). `$skip` and `$take` appear on 7 operations, `$filter` on 11 and `$orderBy` on 2 of 75 GET operations. Paging is by offset, and the help centre and the definition disagree on the page limit (14). Errors are a code and a message, and many 400 responses are described case by case in the definition. No list of codes was found, and the 401 we received had an empty message (11). An Idempotency-Key is accepted when creating an expense other than a per diem, and PUT operations replace whole lists. MCP writes show a preview and wait for confirmation. Tool annotations could not be listed without a customer sign-in (9). Few parameters are required beyond the account ID. No official SDK was found (6).",
          "maintenance": "The OpenAPI definition was last modified on 8 October 2026 by its response header and the newest release note is dated 7 October 2026 (30). The release notes have more than three dated entries since late September 2026, but they cover the product and none we read concerns the API, so partial credit (15). Closed service with public release notes, support and partner addresses and partner solution consultants. No public forum or issue tracker was found (8). No official SDK on npm or PyPI and no entry in the official MCP registry (0). Nothing is packaged to assess (0).",
          "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). Pricing is by quote for each module, with one published plan, the Growth programme at 149 pounds a month for single-entity firms in the UK or EEA with under 20 employees. The API page says the API is free for all Payhawk accounts (8). The Growth programme has an optional 7-day trial for eligible customers, and a development sandbox is requested through a form. Neither is open to anyone without contact (5). A person signs up as a customer, creates the key in the portal or signs in to the MCP connector (0).",
          "reliability": "Read with the hosted lines and scored on the Developer API, with the MCP server as a second surface. status.payhawk.com, a PagerDuty status page created on 22 October 2025, lists five services, one of them the Developer API (20). The page is drawn by script and its feeds returned the same shell, so the incident history went unread (5). The limit of 15 requests a second is stated on the API page, in the help centre and on every operation (15). Every operation declares a 429 with Retry-After and RateLimit-Remaining headers, and an unauthenticated call returned ratelimit headers. An Idempotency-Key header is mentioned only for creating an expense and is not declared as a parameter (10). The API page claims 99.9 per cent uptime, while section 16.3.3 of the terms disclaims service levels and no figure is published, so this is a claim and not an SLA (0). API v3 carries no beta label. The MCP docs refer to a beta period and the server is not yet in the Claude or ChatGPT directories (8).",
          "schema": "A public OpenAPI 3.1 definition at api.payhawk.com/api/v3/docs.json with 105 paths and 179 operations, shown in a Swagger UI at developers.payhawk.com (25). payhawk.com/llms.txt and the help centre's index link Markdown copies of the help articles, the API overview and the MCP pages among them. The developer portal has no llms.txt and the reference exists only as the definition (8). 173 of 179 operations carry a description but only 34 run past 80 characters. Those that do state preconditions, such as which expense states allow an update. The MCP tool reference gives when to use and when not for five tools and names only for the rest (11). The definition has 167 enums, 18 patterns, required lists and closed objects. Filters are JSON passed as a query string, typed by a schema, and no header parameter is declared (12). 400, 401, 403 and 429 are declared on nearly every operation with one error model of a code and a message. Examples are sparse, 50 in a file of 1.4 MB (9). The version is in the path. No API changelog was found, and the help articles still cite api.payhawk.io and a v2 path (6).",
          "security": "API keys are created as read-only or full access, can be regenerated, travel in the `X-Payhawk-ApiKey` or Authorization header, and are managed by administrators or a custom role. Two system keys per account cannot be deleted by users. The MCP server uses OAuth 2 authorisation code with PKCE (S256), refresh tokens and a revocation endpoint, with no scopes published (24). Read-only keys exist. Each MCP call runs with the signed-in user's role, every write is previewed and waits for confirmation according to the docs, and payments and transfers are excluded from the MCP server (16). Supplier names, invoice text and comments reach the model, and no guidance on prompt injection was found. The MCP docs say card numbers are cut to four digits and personal details are removed from lists (4). An activity tab records changes to expenses and requests and the MCP server has a `list_audit_logs` tool. No log of calls per API key was found (9). security.txt is valid and points to a disclosure policy with no paid bounty. The trust page links SOC 1 and SOC 2 Type 2, ISO 27001, PCI DSS Level 1 and penetration test documents (18).",
          "transparency": "Closed service with public terms, last updated on 9 December 2025, which name the contracting entities and list developer APIs among the software services (15). The privacy policy (29 June 2026) and the Data Processing Addendum (26 June 2026) agree on roles. The addendum sets deletion at 90 days after termination and bars using customer personal data, prompts included, to train general models. The privacy policy gives no retention periods, and the addendum lists SOC 1 Type 1 where the trust page says Type 2 (21). No deprecation policy for the API was found. Fields are marked deprecated in descriptions without dates, and the terms give two business days' notice of scheduled maintenance (4). The addendum's schedule lists Payhawk EOOD in Belgium and Germany and two optional sub-processors, with 30 days' notice of changes. The trust page names AWS and Google Cloud and storage in Belgium and Frankfurt, but the schedule does not list the hosting providers (15)."
        },
        "sources": [
          {
            "what": "OpenAPI definition (API v3)",
            "url": "https://api.payhawk.com/api/v3/docs.json",
            "seen": "2026-10-08"
          },
          {
            "what": "developer portal (Swagger UI) and its config file",
            "url": "https://developers.payhawk.com/config/config.yml",
            "seen": "2026-10-08"
          },
          {
            "what": "Developer API page and FAQ",
            "url": "https://payhawk.com/integration/api",
            "seen": "2026-10-08"
          },
          {
            "what": "help centre, overview of the Developer API",
            "url": "https://payhawk.com/help/overview-of-the-payhawk-developer-api",
            "seen": "2026-10-08"
          },
          {
            "what": "help centre, FAQ on the Developer API",
            "url": "https://payhawk.com/help/faq-on-payhawk-developer-api",
            "seen": "2026-10-08"
          },
          {
            "what": "help centre, API returns only 999 results",
            "url": "https://payhawk.com/help/api-returns-only-999-results",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt",
            "url": "https://payhawk.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "help centre index for agents",
            "url": "https://payhawk.document360.io/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "about the Payhawk MCP",
            "url": "https://payhawk.com/help/payhawk-mcp-overview.md",
            "seen": "2026-10-08"
          },
          {
            "what": "connecting the Payhawk MCP",
            "url": "https://payhawk.com/help/connecting-payhawk-mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tool reference",
            "url": "https://payhawk.com/help/payhawk-mcp-tool-reference.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP troubleshooting",
            "url": "https://payhawk.com/help/troubleshooting-the-payhawk-mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP authorisation server metadata",
            "url": "https://mcp.payhawk.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "Fall '26 edition",
            "url": "https://payhawk.com/help/fall-26-edition.md",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox accounts",
            "url": "https://payhawk.com/help/activating-beta-features-in-sandbox-account.md",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page",
            "url": "https://payhawk.com/pricing-and-plans",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://payhawk.com/release-notes",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.payhawk.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre",
            "url": "https://payhawk.com/trust",
            "seen": "2026-10-08"
          },
          {
            "what": "vulnerability disclosure policy",
            "url": "https://payhawk.com/security/disclosure",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://payhawk.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "general terms and conditions",
            "url": "https://payhawk.com/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://payhawk.com/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Processing Addendum",
            "url": "https://payhawk.com/dpa",
            "seen": "2026-10-08"
          },
          {
            "what": "legal index",
            "url": "https://payhawk.com/legal",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=payhawk",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry (no package)",
            "url": "https://registry.npmjs.org/payhawk",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP record for payhawk.com",
            "url": "https://rdap.org/domain/payhawk.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the incident history on status.payhawk.com, which is drawn by script. Its feeds returned the same page shell",
          "unchecked: MCP tool input schemas and readOnlyHint or destructiveHint annotations, which need a customer sign-in to list",
          "unchecked: the SOC, ISO 27001 and penetration test PDFs linked from the trust page were not opened",
          "unchecked: the fee schedules and the partner terms linked from the legal index",
          "Whether the MCP server enforces confirmation of writes itself or relies on the assistant. The docs say every write waits for confirmation",
          "Whether api.payhawk.io, cited in the help centre and the API page FAQ, still answers alongside api.payhawk.com",
          "Whether the Growth programme includes Developer API access and whether its 7-day trial needs a card",
          "The page limit. The help centre gives 1,000 records a page and the definition a maximum of 10,000",
          "Whether an API changelog exists behind sign-in. None is linked from the developer portal or the help centre",
          "The lead was right on the header, the OpenAPI 3.1 definition and the 105 paths. It did not mention the MCP server at mcp.payhawk.com, launched with the Fall '26 edition in September 2026",
          "No search for security incidents was made beyond the vendor's own pages. The trust page states no material breaches in the last 12 months"
        ]
      },
      "negative": 0,
      "verdict": "The Developer API has a public OpenAPI 3.1 definition with 179 operations, read-only or full-access keys and a published limit of 15 requests a second. It needs a Payhawk customer account, no official SDK or API changelog was found, and the 82-tool MCP server is added by hand because it is not yet in the assistant directories.",
      "bestFor": "A finance team already on Payhawk that wants an ERP or accounting sync, master data kept in step, purchase orders raised from another system, or an assistant that answers spend questions and prepares approvals.",
      "strengths": [
        "Public OpenAPI 3.1 definition with 105 paths and 179 operations, covering expenses, cards, fund accounts, suppliers, purchase orders and 24 webhook event types",
        "API keys are created as read-only or full access, sent in a header, and managed by administrators or a custom role",
        "The limit of 15 requests a second is stated on every operation, and responses carry RateLimit headers with Retry-After on a 429",
        "The MCP server acts with the signed-in user's own role, previews every write for confirmation, and never starts a payment or transfer",
        "SOC 1 and SOC 2 Type 2, ISO 27001, PCI DSS Level 1 and a penetration test attestation are downloadable from the trust page"
      ],
      "weaknesses": [
        "No self-serve route. The API needs a Payhawk customer account, and a development sandbox is requested through a form",
        "No official SDK on npm or PyPI, no API changelog and no deprecation policy were found. Release notes cover the product only",
        "The API page's FAQ contradicts the definition on the host name, the page size and whether expenses can be created or reviewed",
        "The status page is drawn by script, so its incident history could not be read. The terms disclaim service levels",
        "The MCP server has 82 tools, is not in the official MCP registry, and no guidance on prompt injection was found"
      ],
      "agentNotes": [
        "Send the key in `X-Payhawk-ApiKey` or as a Bearer token to `https://api.payhawk.com/api/v3`. A read-only key returns 403 on writes",
        "Page lists with `$skip` and `$take`. The help centre gives 1,000 a page and the definition a maximum of 10,000, so count what comes back",
        "Pass `$filter` as URL-encoded JSON, for example `{\"status\":{\"$equal\":\"draft\"}}`. Date filters compare the date part only",
        "Keep to 15 requests a second and wait for `Retry-After` on a 429. Do not send `Idempotency-Key` when creating a per diem expense, which returns 400",
        "Use a group-level key and the `/groups/{groupId}` paths for master data in a multi-entity group. Expenses and payments stay on account paths"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 57.1
        }
      ],
      "editorialScores": {
        "ergonomics": 52,
        "maintenance": 53,
        "payments": 13,
        "reliability": 58,
        "schema": 71,
        "security": 71,
        "transparency": 55
      },
      "provenanceScore": 100
    },
    "connect": {
      "http": "curl https://api.payhawk.com/api/v3/accounts/YOUR_ACCOUNT_ID/fund-accounts \\\n  -H \"X-Payhawk-ApiKey: YOUR_API_KEY\""
    },
    "letme": {
      "capability": "https://letme.dev/spend.transactions",
      "tool": "https://letme.dev/payhawk"
    },
    "notable": [
      "The MCP server at https://mcp.payhawk.com/mcp lists 82 tools in its public reference, filtered by the user's role, and never starts a payment or transfer (https://payhawk.com/help/payhawk-mcp-tool-reference)",
      "The MCP server is not yet listed in the Claude or ChatGPT directories and is added by hand as a custom connector. ChatGPT and Codex need Developer Mode (https://payhawk.com/help/connecting-payhawk-mcp)",
      "The FAQ on the API page says expenses cannot be created or reviewed through the API and gives https://api.payhawk.io/api/v3 as the address, while the definition at api.payhawk.com has operations for both (https://payhawk.com/integration/api)",
      "Webhooks cover 24 event types and are signed with RSA and SHA256 in an X-Payhawk-Signature header, checked against the key at `/api/v3/rsa-public-key` (https://payhawk.com/help/overview-of-the-payhawk-developer-api)",
      "The API page claims 99.9 per cent uptime. Section 16.3.3 of the terms says Payhawk does not guarantee any service levels (https://payhawk.com/terms)",
      "The Data Processing Addendum bars using customer personal data, including prompts and conversation histories, to train general-purpose models (https://payhawk.com/dpa)",
      "The disclosure policy says Payhawk cannot run a paid bug bounty and gives a non-cash reward for qualifying reports (https://payhawk.com/security/disclosure)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "API",
        "value": "REST, OpenAPI 3.1, version v3, 105 paths and 179 operations at https://api.payhawk.com/api/v3. 75 GET, 38 POST, 28 PATCH, 24 DELETE, 14 PUT"
      },
      {
        "label": "Coverage",
        "value": "Expenses and files, expense reports, cards (issue, update, change status), fund accounts, deposits and bank statements, suppliers, purchase orders and goods received notes, spend policies, users, teams, custom fields, expense categories, tax rates, account codes and webhooks, at account and group level"
      },
      {
        "label": "MCP server",
        "value": "Hosted at https://mcp.payhawk.com/mcp. 82 tools in the public reference, read and write, filtered by role. Works with Claude, ChatGPT and Codex as a custom connector. Launched with the Fall '26 edition in September 2026"
      },
      {
        "label": "Credentials",
        "value": "API key with read-only or full access in `X-Payhawk-ApiKey` or as a Bearer token. MCP uses OAuth 2 authorisation code with PKCE (S256), refresh tokens, a revocation endpoint and dynamic client registration"
      },
      {
        "label": "Access",
        "value": "Payhawk customers only. Keys are created in the portal under Settings, Integrations by an Administrator, an IT Administrator or a custom role. A development sandbox is requested by form"
      },
      {
        "label": "Rate limits",
        "value": "15 requests a second on a one-second sliding window. Responses carry ratelimit-limit, ratelimit-remaining and ratelimit-reset headers, and a 429 carries Retry-After"
      },
      {
        "label": "Pagination",
        "value": "Offset paging with `$skip` and `$take` on 7 list operations, `$filter` as URL-encoded JSON on 11 and `$orderBy` on 2. The help centre gives 1,000 records a page, the definition a maximum of 10,000"
      },
      {
        "label": "Errors",
        "value": "JSON with a `code` and a `message`. 400, 401, 403 and 429 are declared on nearly every operation and 404 on 134"
      },
      {
        "label": "Webhooks",
        "value": "24 event types for expenses, payments, deposits, suppliers, purchase orders and expense reports. Signed with RSA and SHA256, retried on 408, 409, 429 and 5xx responses"
      },
      {
        "label": "Idempotency",
        "value": "An Idempotency-Key header is accepted when creating an expense, except a per diem, per the operation's description. It is not declared as a parameter"
      },
      {
        "label": "Certifications",
        "value": "SOC 1 Type 2, SOC 2 Type 2, ISO 27001, PCI DSS Level 1, CSA STAR Level 1 and IDW PS 880 per the trust page. Electronic money institution licences in the UK and the EEA"
      },
      {
        "label": "Status",
        "value": "status.payhawk.com on PagerDuty, with services for Card Authorisation, Bank transfers, Web Portal, Core API and Developer API"
      },
      {
        "label": "Data location",
        "value": "AWS and Google Cloud. EU and US customer data in Belgium, German customers' data in Frankfurt, per the trust page"
      },
      {
        "label": "Sub-processors",
        "value": "Schedule 2 of the Data Processing Addendum lists Payhawk EOOD (Belgium and Germany, language models hosted on Google Cloud), Merge API for HR integrations and Duffel for travel, with 30 days' notice of changes"
      }
    ],
    "provenance": {
      "legalEntity": "Payhawk Limited",
      "domain": "payhawk.com",
      "domainRegistered": "2003-07-06",
      "endpointOnVendorDomain": true,
      "terms": "https://payhawk.com/terms",
      "privacy": "https://payhawk.com/privacy",
      "statusPage": "https://status.payhawk.com",
      "changelog": "https://payhawk.com/release-notes",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The terms name Payhawk Limited (company number 11747263, Chancery House, 53-64 Chancery Lane, London WC2A 1QS) as the contracting entity worldwide and Payhawk Inc., a Delaware corporation, in the US. Payhawk EOOD in Sofia owns the platform.",
        "Cards are issued by Payhawk Financial Services UAB in the EEA, Payhawk Financial Services Limited in the UK and Cross River Bank in the US, per the site footer.",
        "The API answers at api.payhawk.com and the MCP server at mcp.payhawk.com. An unauthenticated POST to /mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata.",
        "payhawk.com/.well-known/security.txt has a contact, a policy link and an expiry of 1 January 2030.",
        "The terms were last updated on 9 December 2025, the privacy policy on 29 June 2026 and the Data Processing Addendum on 26 June 2026.",
        "The release notes cover the product. No changelog for the API was found.",
        "RDAP for payhawk.com gives a registration date of 2003-07-06. The terms' company number dates the company later, so the domain predates the vendor."
      ],
      "score": 100,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Payhawk Limited",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "payhawk.com, registered 2003-07-06 (23 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.payhawk.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 7 of the 7 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.payhawk.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://payhawk.com/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-12-09",
          "words": 21533,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated on 9 Dec 2025",
              "says": "Last updated 2025-12-09"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "The Framework Agreement and any Dispute or non-contractual disputes or claims arising out of or in connection with it or its subject matter or formation shall be governed by and construed in accordance with the law of England and Wales.",
              "says": "The law of England and Wales"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…under Applicable Law, Payhawk's maximum aggregate liability to Company under this Framework Agreement is limited to the total amount of Fees for Payhawk Software Services actually paid by Company to Payhawk Limited or, as the case may be, Payhawk Inc, in the three months preceding the event that is the basis of Compan…",
              "says": "Capped at the fees paid in the 3 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "In the case of inaccuracies, Company shall immediately rectify them and the respective Payment Services Provider may elect, at its sole discretion, to limit, suspend or deny access to certain or, as the case may be, all Payment Services until the Company has complied with any such requirement."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Subject always to Section 8 of these General Terms, where we intend to make material changes to these Terms, we will provide at least 30 days’ Notice before their proposed date of application, unless we are otherwise prohibited by Applicable Law.",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "You will not be compensated or credited for any Feedback provided."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "To the maximum extent legally permitted, any Payhawk Beta Services are provided AS IS and as available and without warranty and are not subject to any service level terms."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Payhawk's total liability is limited to the software service fees paid in the three months before the event behind the claim, except for intent or gross negligence.",
              "quote": "maximum aggregate liability to Company under this Framework Agreement is limited to the total amount of Fees for Payhawk Software Services actually paid by Company to Payhawk Limited or, as the case may be, Payhawk Inc, in the three months preceding the event that is the basis of Company's claim."
            },
            {
              "date": "2026-10-08",
              "text": "Accepting the terms gives Payhawk permission to name the company publicly as a customer on its website or in communications during the agreement.",
              "quote": "By accepting these Terms, Company gives Payhawk permission to publicly reference Company as a Payhawk customer on the Payhawk Website or in communications during the term of the Framework Agreement."
            },
            {
              "date": "2026-10-08",
              "text": "If Payhawk suspends or terminates for unpaid fees, the company is liable for all fees for the remaining duration of the current subscription period.",
              "quote": "Company will be liable to the relevant Payhawk provider for the aggregate amount of all Fees to be paid for the remaining duration of the-then current Subscription Period."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://payhawk.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-06-29",
          "words": 5157,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated on 29 Jun 2026",
              "says": "Last updated 2026-06-29"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy will help you understand what types of information we collect, how we use it, and what choices you have."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain Personal Data for as long as needed to provide our Payhawk Services and to comply with our legal obligations, resolve disputes and enforce our agreements (unless we are instructed otherwise).",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Registration for the Payhawk Services can also be completed via our third-party login service providers, such as Google’s Single Sign On (SSO)."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not rent or sell any Personal Data.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You have the right to withdraw consent at any time where we are relying on consent to process your Personal Data."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you wish to exercise any of the above-mentioned rights or raise any concern, please contact our DPO at dpo@payhawk.com or use the postal addresses mentioned at the bottom of this Privacy Policy.",
              "says": "dpo@payhawk.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Where those providers engage sub-processors located in the United States to deliver email notifications as part of the referral program, such processing takes place subject to appropriate safeguards under the EU-US Data Privacy Framework or standard contractual clauses.",
              "says": "Relies on standard contractual clauses and the Data Privacy Framework"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Payhawk uses Google reCAPTCHA, which evaluates behavioural data and device information to tell human users from automated bots.",
              "quote": "This service evaluates behavioral data (such as mouse movements and typing patterns) and technical device information to distinguish human users from automated bots."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/payhawk.json",
    "live": {
      "slug": "payhawk",
      "probe": {
        "target": "https://api.payhawk.com",
        "method": "get",
        "lastAt": "2026-10-09T09:27:00.11605886Z",
        "lastOk": true,
        "lastStatus": 404,
        "lastMs": 123,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 53,
        "p95ms24h": 123,
        "samples24h": 20,
        "samples30d": 20,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 20,
            "ok": 20
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.payhawk.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-09T07:58:24.812233514Z"
      },
      "updatedAt": "2026-10-09T09:27:00.11605886Z"
    }
  }
}
