{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "pleo",
    "name": "Pleo API + MCP",
    "vendor": "Pleo Technologies A/S",
    "vendorUrl": "https://www.pleo.io/en",
    "kind": "http-api",
    "category": "spend-management",
    "summary": "Spend management platform from Pleo Technologies A/S in Copenhagen, covering company cards, expenses, reimbursements, invoices and accounting exports. Outside agents reach it through a hosted MCP server for expense work and a REST API built for accounting integrations.",
    "url": "https://www.anchorterminal.com/tools/pleo",
    "markdownUrl": "https://www.anchorterminal.com/tools/pleo.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/pleo.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/pleo.json",
    "license": "Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms",
    "transports": [
      "http",
      "streamable-http"
    ],
    "remoteUrl": "https://external.pleo.io",
    "packages": [],
    "auth": "mixed",
    "authNotes": "A person signs in for every route. The MCP server uses OAuth 2.0 in a browser (authorisation code with PKCE, dynamic client registration, no keys to configure) and acts with the connecting user's Pleo role, once a company admin has enabled MCP access for that entity. The External API accepts OAuth 2.0 bearer tokens with resource scopes for partner integrations, whose client ID and secret Pleo issues after review in its Early Access Programme. A single company can use a Standalone API Key with chosen scopes and an expiry, sent as the Basic auth username, but only after Pleo support or a Customer Success Manager enables keys for the organisation.",
    "pricing": "paid",
    "pricingNotes": "Per-user plans, with no separate charge for the API or the MCP server. The pricing page shown to a UK visitor lists Start at £8 per user per month, Build at £14 and Optimise at £18, the last two cheaper billed yearly and with a three-user minimum. MCP is listed on Optimise only, which is sold through a demo. Start and Build have a Try for free button and the signup form states 21 days free. Whether the trial needs a payment card isn't stated. A staging environment with test data exists for customers with API keys enabled and for approved partners. Fees for payments and foreign exchange are extra (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developers.pleo.io/",
    "llmsTxt": "https://developers.pleo.io/llms.txt",
    "openapi": "https://developers.pleo.io/reference/Export%20API.json",
    "capabilities": [
      "spend.transactions",
      "spend.expenses",
      "spend.bills"
    ],
    "tags": [
      "official",
      "hosted",
      "mcp",
      "oauth",
      "api-key",
      "openapi",
      "llms-txt",
      "webhooks",
      "closed-source",
      "status-page",
      "bug-bounty",
      "sandbox"
    ],
    "lastRelease": "2026-10-02",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 62.9,
      "grade": "B",
      "agentReady": false,
      "rank": 325,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 3,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 55,
        "maintenance": 64,
        "payments": 15,
        "reliability": 71,
        "schema": 82,
        "security": 71,
        "transparency": 75
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 71,
          "points": 14.2,
          "reason": "Read with the hosted lines and scored on the MCP server and the External API together. status.pleo.io on incident.io has 25 components with incident history, among them Pleo API (20). From 10 July to 8 October 2026 the page lists two incidents, both marked minor and neither on the Pleo API component. Card transactions failed intermittently for about 2 hours 30 minutes on 15 July during a Mastercard authentication fault, and instant top-up in Sweden was impaired from 10 to 15 September (20). One limit is published, 600 requests a minute per credential across all endpoints. No limit is documented for the MCP server (15). The docs tell clients to wait for Retry-After when present, otherwise back off from one second, and say which steps are unsafe to repeat after a 429. There is no Idempotency-Key header, and the OpenAPI specs don't declare 429 (11 of 15). No SLA found in the API terms or the UK Master Service Agreement (0). The API terms describe the API as a beta version, and the specs include /v0 and /v1-beta paths. The MCP server carries no beta label (5 of 10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 82,
          "points": 13.33,
          "reason": "Eleven current OpenAPI 3.0.1 specs with 162 operations, linked from llms.txt, plus a spec for the deprecated Legacy API (25). llms.txt, llms-full.txt and a Markdown copy of every docs page at the same URL with .md (10). 107 of 162 operations carry a description, and long guides explain when each export and sync step applies. The MCP server has no public tool reference, only prose on what it can do, so its tool descriptions couldn't be read without a customer sign-in. Three specs carry internal titles (Gjoll, Oberon, Triton) (11 of 20). The specs hold 86 enums and required lists, and search endpoints take typed filter bodies. MCP input schemas are unread (11 of 15). 463 examples across the specs and typed error examples such as MISSING_CONTRA_ACCOUNTS and INVALID_TARGET_SYSTEM. 77 operations declare only a default error response and none declares 429 (11 of 15). Path versions, with Export API v1 to v3 documented side by side, and a public changelog of 56 dated entries back to November 2024. The current API has no written versioning policy (14 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 55,
          "points": 8.94,
          "reason": "The MCP tool count and definitions aren't published, so context cost couldn't be measured. On the API, `limit` sizes a page and aggregated endpoints return tag groups and category groups in one call, with no field selection (13 of 25). Cursor and offset pagination with sorting keys, and search endpoints with filters for accounting entries, receipts, tags, vendors and employees. Two pagination styles are in use (17 of 20). Errors carry a `type` code and a message, and every response has a request-Id header. The general error page lists seven statuses with generic fixes and leaves out 409, 422 and 429 (13 of 20). No Idempotency-Key. The docs ask integrators to make their own processing idempotent, and export jobs can be resumed. MCP readOnlyHint and destructiveHint annotations couldn't be read (7 of 20). List calls need few parameters. No official SDK was found, only a Postman collection and two community libraries named for the Legacy API (5 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 71,
          "points": 12.43,
          "reason": "The MCP server uses OAuth authorisation code with PKCE (S256), refresh tokens and dynamic client registration, with a single scope and the connecting user's Pleo role as the real boundary. The API uses OAuth 2.0 with resource scopes and rotating refresh tokens, or API keys with chosen scopes and an expiry, sent in the Authorization header (28 of 30). Read and write are separate API scopes. MCP access is off until an admin enables it per entity, can't be limited to named users yet, and has no read-only mode. Payments, card changes and limit changes are blocked through the MCP by design. Confirmation before a write is left to the AI client (15 of 20). Merchant names, notes and receipts are untrusted text. The docs say to review significant output and recommend approval for write tools, with no guidance on injected content (5 of 15). Changes made through the MCP appear in Pleo's activity and audit logs, and users can list and revoke MCP connections. No call log for API keys was found (10 of 15). A disclosure policy with safe harbour, a HackerOne bug bounty, PCI-DSS and Google's CASA per the trust page. No SOC 2 or ISO 27001 is claimed, reports are shared under NDA, and security.txt returns 403 (13 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 15,
          "points": 1.88,
          "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). Per-user plan prices are public (£8, £14 and £18 a month as shown to a UK visitor), with no per-call price for the API or MCP (10). The signup form states 21 days free on Start and Build, but the pricing page lists MCP on Optimise only, which is sold through a demo, and API keys need enabling by Pleo support. Whether the trial needs a card isn't stated. Partial credit (5 of 20). A person signs in with OAuth in a browser or creates a key in the web app, and Pleo issues partner OAuth clients after review (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 64,
          "points": 5.6,
          "reason": "The newest changelog entry is 2 October 2026, a new Teams API (30). Sixteen dated entries between 15 July and 2 October 2026, among them the MCP documentation on 17 August and Export API v3 additions (20). Closed service with a dated changelog, api@pleo.io for partners and Pleo support for customers. The docs say custom implementation support is generally not given, and response times couldn't be observed (9 of 15). No official SDK was found, the MCP server isn't in the official MCP registry, and the docs say Pleo isn't in Claude's connector directory yet (0). No packages to assess. The published specs carry current version numbers and match the changelog (5 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "note": "editorial 63, provenance 87",
          "reason": "Closed service with public API terms naming Pleo Technologies A/S, a Master Service Agreement and separate AI Access Terms for the MCP. The API terms carry no date and let Pleo discontinue the API at any time (14 of 30). A privacy notice dated June 2026, a DPA of 14 October 2025 and a trust page placing customer data in AWS Ireland agree with each other. Pleo's MCP page says it doesn't use customer data to train AI models. Retention for customer data is stated only as long as there is a valid purpose or legal requirement, with no periods (20 of 30). The Legacy API is deprecated with migration guides, but no end-of-life date is published, and replacements listed for Q3 2026 (a SCIM API and wallet balance) weren't in the docs index on 8 October. Changes to the API terms take effect no sooner than 30 days after posting (9 of 20). A public sub-processor list with each provider's role and location, and 30 days' notice of new sub-processors in the DPA (20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The MCP tool count and definitions aren't published, so context cost couldn't be measured. On the API, `limit` sizes a page and aggregated endpoints return tag groups and category groups in one call, with no field selection (13 of 25). Cursor and offset pagination with sorting keys, and search endpoints with filters for accounting entries, receipts, tags, vendors and employees. Two pagination styles are in use (17 of 20). Errors carry a `type` code and a message, and every response has a request-Id header. The general error page lists seven statuses with generic fixes and leaves out 409, 422 and 429 (13 of 20). No Idempotency-Key. The docs ask integrators to make their own processing idempotent, and export jobs can be resumed. MCP readOnlyHint and destructiveHint annotations couldn't be read (7 of 20). List calls need few parameters. No official SDK was found, only a Postman collection and two community libraries named for the Legacy API (5 of 15).",
          "maintenance": "The newest changelog entry is 2 October 2026, a new Teams API (30). Sixteen dated entries between 15 July and 2 October 2026, among them the MCP documentation on 17 August and Export API v3 additions (20). Closed service with a dated changelog, api@pleo.io for partners and Pleo support for customers. The docs say custom implementation support is generally not given, and response times couldn't be observed (9 of 15). No official SDK was found, the MCP server isn't in the official MCP registry, and the docs say Pleo isn't in Claude's connector directory yet (0). No packages to assess. The published specs carry current version numbers and match the changelog (5 of 10).",
          "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). Per-user plan prices are public (£8, £14 and £18 a month as shown to a UK visitor), with no per-call price for the API or MCP (10). The signup form states 21 days free on Start and Build, but the pricing page lists MCP on Optimise only, which is sold through a demo, and API keys need enabling by Pleo support. Whether the trial needs a card isn't stated. Partial credit (5 of 20). A person signs in with OAuth in a browser or creates a key in the web app, and Pleo issues partner OAuth clients after review (0).",
          "reliability": "Read with the hosted lines and scored on the MCP server and the External API together. status.pleo.io on incident.io has 25 components with incident history, among them Pleo API (20). From 10 July to 8 October 2026 the page lists two incidents, both marked minor and neither on the Pleo API component. Card transactions failed intermittently for about 2 hours 30 minutes on 15 July during a Mastercard authentication fault, and instant top-up in Sweden was impaired from 10 to 15 September (20). One limit is published, 600 requests a minute per credential across all endpoints. No limit is documented for the MCP server (15). The docs tell clients to wait for Retry-After when present, otherwise back off from one second, and say which steps are unsafe to repeat after a 429. There is no Idempotency-Key header, and the OpenAPI specs don't declare 429 (11 of 15). No SLA found in the API terms or the UK Master Service Agreement (0). The API terms describe the API as a beta version, and the specs include /v0 and /v1-beta paths. The MCP server carries no beta label (5 of 10).",
          "schema": "Eleven current OpenAPI 3.0.1 specs with 162 operations, linked from llms.txt, plus a spec for the deprecated Legacy API (25). llms.txt, llms-full.txt and a Markdown copy of every docs page at the same URL with .md (10). 107 of 162 operations carry a description, and long guides explain when each export and sync step applies. The MCP server has no public tool reference, only prose on what it can do, so its tool descriptions couldn't be read without a customer sign-in. Three specs carry internal titles (Gjoll, Oberon, Triton) (11 of 20). The specs hold 86 enums and required lists, and search endpoints take typed filter bodies. MCP input schemas are unread (11 of 15). 463 examples across the specs and typed error examples such as MISSING_CONTRA_ACCOUNTS and INVALID_TARGET_SYSTEM. 77 operations declare only a default error response and none declares 429 (11 of 15). Path versions, with Export API v1 to v3 documented side by side, and a public changelog of 56 dated entries back to November 2024. The current API has no written versioning policy (14 of 15).",
          "security": "The MCP server uses OAuth authorisation code with PKCE (S256), refresh tokens and dynamic client registration, with a single scope and the connecting user's Pleo role as the real boundary. The API uses OAuth 2.0 with resource scopes and rotating refresh tokens, or API keys with chosen scopes and an expiry, sent in the Authorization header (28 of 30). Read and write are separate API scopes. MCP access is off until an admin enables it per entity, can't be limited to named users yet, and has no read-only mode. Payments, card changes and limit changes are blocked through the MCP by design. Confirmation before a write is left to the AI client (15 of 20). Merchant names, notes and receipts are untrusted text. The docs say to review significant output and recommend approval for write tools, with no guidance on injected content (5 of 15). Changes made through the MCP appear in Pleo's activity and audit logs, and users can list and revoke MCP connections. No call log for API keys was found (10 of 15). A disclosure policy with safe harbour, a HackerOne bug bounty, PCI-DSS and Google's CASA per the trust page. No SOC 2 or ISO 27001 is claimed, reports are shared under NDA, and security.txt returns 403 (13 of 20).",
          "transparency": "Closed service with public API terms naming Pleo Technologies A/S, a Master Service Agreement and separate AI Access Terms for the MCP. The API terms carry no date and let Pleo discontinue the API at any time (14 of 30). A privacy notice dated June 2026, a DPA of 14 October 2025 and a trust page placing customer data in AWS Ireland agree with each other. Pleo's MCP page says it doesn't use customer data to train AI models. Retention for customer data is stated only as long as there is a valid purpose or legal requirement, with no periods (20 of 30). The Legacy API is deprecated with migration guides, but no end-of-life date is published, and replacements listed for Q3 2026 (a SCIM API and wallet balance) weren't in the docs index on 8 October. Changes to the API terms take effect no sooner than 30 days after posting (9 of 20). A public sub-processor list with each provider's role and location, and 30 days' notice of new sub-processors in the DPA (20)."
        },
        "sources": [
          {
            "what": "developer docs index (llms.txt)",
            "url": "https://developers.pleo.io/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Pleo MCP overview",
            "url": "https://developers.pleo.io/docs/current/pleo-mcp/get-started/pleo-mcp-overview",
            "seen": "2026-10-08"
          },
          {
            "what": "Pleo MCP capabilities",
            "url": "https://developers.pleo.io/docs/current/pleo-mcp/get-started/pleo-mcp-capabilities",
            "seen": "2026-10-08"
          },
          {
            "what": "Pleo MCP access and permissions",
            "url": "https://developers.pleo.io/docs/current/pleo-mcp/get-started/access-and-permissions",
            "seen": "2026-10-08"
          },
          {
            "what": "Pleo MCP FAQs",
            "url": "https://developers.pleo.io/docs/current/pleo-mcp/get-started/faq",
            "seen": "2026-10-08"
          },
          {
            "what": "custom MCP install, URLs and transport",
            "url": "https://developers.pleo.io/docs/current/pleo-mcp/how-tos/installation/custom-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP OAuth metadata",
            "url": "https://mcp.pleo.io/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "API base URLs, authentication and rate limits",
            "url": "https://developers.pleo.io/docs/current/authentication/api-base-urls",
            "seen": "2026-10-08"
          },
          {
            "what": "Standalone API Keys overview",
            "url": "https://developers.pleo.io/docs/current/authentication/standalone-api-keys-overview",
            "seen": "2026-10-08"
          },
          {
            "what": "Early Access Programme",
            "url": "https://developers.pleo.io/docs/current/getting-started/developer-partnership-programme",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth tokens overview",
            "url": "https://developers.pleo.io/docs/current/integration-design/auth/oauth/token-lifecycle/integration-design-auth-oauth-token-overview",
            "seen": "2026-10-08"
          },
          {
            "what": "pagination",
            "url": "https://developers.pleo.io/reference/pagination",
            "seen": "2026-10-08"
          },
          {
            "what": "API response codes and errors",
            "url": "https://developers.pleo.io/reference/api-response-codes-errors-1",
            "seen": "2026-10-08"
          },
          {
            "what": "Export API OpenAPI spec",
            "url": "https://developers.pleo.io/reference/Export%20API.json",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://developers.pleo.io/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "API deprecation notice",
            "url": "https://developers.pleo.io/deprecation/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "API Terms of Service",
            "url": "https://developers.pleo.io/page/terms-of-service",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.pleo.io/en/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP product page and FAQ",
            "url": "https://www.pleo.io/en/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "AI Access Terms",
            "url": "https://www.pleo.io/legal-documents/pleo-ai-access-terms-en.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "trust and security",
            "url": "https://www.pleo.io/en/trust-and-security",
            "seen": "2026-10-08"
          },
          {
            "what": "vulnerability disclosure policy",
            "url": "https://www.pleo.io/en/vulnerability-disclosure-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://www.pleo.io/en/sub-processors",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy notice",
            "url": "https://www.pleo.io/legal-documents/pleo-privacy-policy-en.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Processing Agreement",
            "url": "https://www.pleo.io/legal-documents/pleo-data-processing-addendum-en.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "UK Master Service Agreement",
            "url": "https://www.pleo.io/legal-documents/pleo-master-service-agreement-uk-pfs.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.pleo.io/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status history feed",
            "url": "https://status.pleo.io/history.rss",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=pleo",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.identitydigital.services/rdap/domain/pleo.io",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: MCP tool names, input schemas, annotations and count. tools/list needs a signed-in Pleo customer and we didn't register a client",
          "unchecked: whether the 21-day trial needs a payment card, and whether a trial company can use the MCP server or API keys",
          "unchecked: prices in USD. The pricing page showed GBP to our UK fetch, so unitPrices is empty",
          "Whether Standalone API Keys are tied to a plan. The pricing page lists MCP by plan but doesn't mention the API",
          "Whether the SCIM API and the wallet balance replacement, both listed for Q3 2026, have shipped",
          "Whether a rate limit applies to the MCP server, and what its errors look like",
          "unchecked: the HackerOne programme's scope and rewards. The trust page states the programme exists and we didn't read the HackerOne page",
          "Whether an SLA exists in order forms for larger customers"
        ]
      },
      "negative": 0,
      "verdict": "The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.",
      "bestFor": "An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.",
      "strengths": [
        "MCP server at mcp.pleo.io/mcp uses OAuth with PKCE and dynamic client registration, and acts with the connecting user's Pleo permissions",
        "Payments, card changes and spending-limit changes are blocked through the MCP by design, per the AI Access Terms",
        "Eleven current OpenAPI 3.0.1 specs with 162 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page",
        "One documented rate limit of 600 requests a minute per credential, with written 429 and Retry-After guidance",
        "Staging hosts for both the API (external.staging.pleo.io) and the MCP server (mcp.staging.pleo.io/mcp)",
        "Sub-processor list with locations, customer data in AWS Ireland, and 30 days' notice of new sub-processors in the DPA"
      ],
      "weaknesses": [
        "The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)",
        "MCP tool names, schemas and count aren't published, so they can't be read without a customer sign-in",
        "Standalone API keys aren't self-service. Pleo support or a Customer Success Manager enables them, and partner OAuth clients go through a reviewed programme",
        "No Idempotency-Key header, no official SDK and no entry in the official MCP registry",
        "The API terms call the API a beta version that Pleo may discontinue at any time, and no SLA was found",
        "No end-of-life date is published for the deprecated Legacy API, and its Q3 2026 replacements for employee writes and wallet balance aren't in the docs"
      ],
      "agentNotes": [
        "Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default",
        "Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist",
        "Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side",
        "Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there",
        "Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second",
        "Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 62.9
        }
      ],
      "editorialScores": {
        "ergonomics": 55,
        "maintenance": 64,
        "payments": 15,
        "reliability": 71,
        "schema": 82,
        "security": 71,
        "transparency": 63
      },
      "provenanceScore": 87
    },
    "connect": {
      "http": "curl --request GET \\\n-u \"YOUR-API-KEY:\" \\\n-H \"Accept: application/json;charset=UTF-8\" \\\n\"https://external.staging.pleo.io/v2/employees\"",
      "claudeCode": "claude mcp add --transport http pleo-mcp-staging https://mcp.staging.pleo.io/mcp",
      "config": {
        "mcpServers": {
          "pleo": {
            "url": "https://mcp.pleo.io/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/spend.transactions",
      "tool": "https://letme.dev/pleo"
    },
    "notable": [
      "The Pleo MCP server is a remote Streamable HTTP endpoint at https://mcp.pleo.io/mcp with a staging twin at https://mcp.staging.pleo.io/mcp, and signs users in with OAuth in a browser (https://developers.pleo.io/docs/current/pleo-mcp/how-tos/installation/custom-mcp)",
      "MCP access is off by default and enabled per entity by a company admin. Per-user enablement is not available yet, per the FAQ (https://developers.pleo.io/docs/current/pleo-mcp/get-started/faq)",
      "The AI Access Terms say no agent can initiate payments or move money, issue, freeze or change cards, or change spending limits through the MCP (https://www.pleo.io/legal-documents/pleo-ai-access-terms-en.pdf)",
      "The pricing page lists MCP as included on Optimise and not included on Start or Build (https://www.pleo.io/en/pricing)",
      "Standalone API Keys are not self-service. A Customer Success Manager or Pleo Support enables them, and partner integrations register through the Early Access Programme with OAuth 2.0 (https://developers.pleo.io/docs/current/authentication/standalone-api-keys-overview)",
      "All Pleo APIs share one limit of 600 requests a minute per credential, across endpoints and methods (https://developers.pleo.io/docs/current/authentication/api-base-urls)",
      "The Legacy API at openapi.pleo.io is deprecated with no end-of-life date published. Replacements for adding or removing users (a SCIM API) and for the wallet balance are listed for Q3 2026 (https://developers.pleo.io/deprecation/overview)",
      "Pleo lists Anthropic among its sub-processors for AI-product enablement, with processing in the US (https://www.pleo.io/en/sub-processors)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "Surfaces",
        "value": "Pleo MCP server (https://mcp.pleo.io/mcp, Streamable HTTP) for expense work by a signed-in user, and the External API (https://external.pleo.io) for accounting integrations. The Legacy API at openapi.pleo.io is deprecated"
      },
      {
        "label": "MCP scope",
        "value": "Search and read expenses, set categories, tags and tax codes, split an expense, add notes and attendees, attach receipts, review and approve, and add expenses to the export queue. No company configuration, payments, card changes or limit changes"
      },
      {
        "label": "External API",
        "value": "Eleven current OpenAPI 3.0.1 specs, 162 operations. Accounting entries and receipts (read), enrichment (attach a receipt), export jobs and items (v1 to v3), tags, tax codes, chart of accounts, bookkeeping categories, vendors, employees and companies (read), teams, webhook subscriptions and app marketplace installations"
      },
      {
        "label": "Access",
        "value": "MCP needs the Optimise plan per the pricing page and an admin opt-in per entity. Standalone API keys are enabled on request by Pleo support. Partner OAuth clients are issued after review in the Early Access Programme, staging first"
      },
      {
        "label": "Credentials",
        "value": "MCP uses OAuth authorisation code with PKCE (S256), refresh tokens and dynamic client registration, with one scope named authenticated. API uses OAuth 2.0 bearer tokens with resource scopes such as export-jobs:read, or a scoped API key with an expiry sent as the Basic auth username"
      },
      {
        "label": "Token lifetimes",
        "value": "Access token lifetime is given in expires_in. Refresh tokens last at least 60 days and rotate on use. Reusing an expired refresh token invalidates every refresh token for that authorisation"
      },
      {
        "label": "Rate limits",
        "value": "600 requests a minute per credential, shared across all endpoints and methods. The docs suggest targeting 500. No separate limit is documented for the MCP server"
      },
      {
        "label": "Pagination",
        "value": "Cursor (`before`, `after`, `limit`) and offset (`offset`, `limit`) styles, with `sorting_keys` and `sorting_order`. Responses carry `hasNextPage`, `startCursor` and `endCursor`"
      },
      {
        "label": "Errors",
        "value": "JSON body with a `type` code and a `message`, such as MISSING_CONTRA_ACCOUNTS (400) or EXPORT_ALREADY_IN_PROGRESS (409). Every response carries a request-Id header for support"
      },
      {
        "label": "Webhooks",
        "value": "Subscriptions API with two documented events, export job created and vendor created, signed with webhook-id, webhook-timestamp and webhook-signature headers"
      },
      {
        "label": "Sandbox",
        "value": "Staging at https://external.staging.pleo.io and https://mcp.staging.pleo.io/mcp with test data. Customers with keys enabled can create a staging key directly. Partners get staging through the Early Access Programme"
      },
      {
        "label": "Plans",
        "value": "Start £8 per user per month, billed monthly. Build £14 monthly or £12 billed yearly. Optimise £18 monthly or £16 billed yearly. Build and Optimise have a three-user minimum. GBP prices as shown to a UK visitor on 8 October 2026"
      },
      {
        "label": "Audit",
        "value": "Changes made through the MCP appear in Pleo's activity and audit logs and in the Activity tab of the expense. Users see and revoke connected clients under My Account, Security and Devices, MCP Connections"
      },
      {
        "label": "Security programme",
        "value": "Vulnerability disclosure policy with safe harbour (security-vd@pleo.io), a bug bounty on HackerOne, PCI-DSS and Google's CASA per the trust page. Compliance reports are shared under NDA on request"
      },
      {
        "label": "Data location",
        "value": "Customer data is stored and processed in AWS Ireland (eu-west-1) per the trust page. The sub-processor list names each provider's location"
      },
      {
        "label": "Status",
        "value": "status.pleo.io on incident.io, 25 components, among them Pleo API, Transactions, Card, E-money Account and 15 accounting integrations"
      }
    ],
    "provenance": {
      "legalEntity": "Pleo Technologies A/S",
      "domain": "pleo.io",
      "domainRegistered": "2015-10-07",
      "endpointOnVendorDomain": true,
      "terms": "https://developers.pleo.io/page/terms-of-service",
      "privacy": "https://www.pleo.io/legal-documents/pleo-privacy-policy-en.pdf",
      "statusPage": "https://status.pleo.io",
      "changelog": "https://developers.pleo.io/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The website footer names Pleo Technologies A/S (36538686), Ravnsborg Tværgade 5C, 2200 København N, Denmark. UK payment services come from Pleo Financial Services UK Ltd, FCA firm reference 1020730, company number 15842283.",
        "The API Terms of Service on the developer portal name Pleo Technologies A/S, carry no date, and describe the API as a beta version. The UK Master Service Agreement has an effective date of 7 September 2026 and is governed by the laws of England and Wales.",
        "The API answers at external.pleo.io and the MCP server at mcp.pleo.io, both pleo.io subdomains. The MCP host publishes its OAuth metadata at https://mcp.pleo.io/.well-known/oauth-authorization-server",
        "www.pleo.io/.well-known/security.txt and pleo.io/.well-known/security.txt both return 403 with an AccessDenied body. The vulnerability disclosure policy gives security-vd@pleo.io as the reporting address.",
        "The privacy notice is dated June 2026 and the Data Processing Agreement 14 October 2025. An AI Access Terms document covers the MCP server.",
        "RDAP from the .io registry gives a registration date of 2015-10-07 for pleo.io."
      ],
      "score": 87,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Pleo Technologies A/S",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "pleo.io, registered 2015-10-07 (11 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "external.pleo.io",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 4 of the 7 things a reader expects",
          "points": 7.4,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.pleo.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://developers.pleo.io/page/terms-of-service",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 1188,
          "points": 7.4,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "To the extent permitted by law, Pleo are not liable for failure or delay in performance to the extent caused by circumstances beyond our reasonable control."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Pleo Technologies A/S may suspend access to the APIs without notice if we reasonably believe that you are in violation of the Terms."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We’ll post notice of modifications to the Terms within the API documentation.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "The Customer will not use the API to encourage or promote illegal activity, violation of third party rights or violate any legal terms which govern the services offered by Pleo Technologies A/S and Pleo Financial Services A/S, respectively."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Pleo reserves the right to discontinue the API or any portion or feature or the access thereto for any reason and at any time without liability or other obligation to you."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The API is described as a beta version still in development, supplied as is with no commitment on reliability or availability.",
              "quote": "THE API IS A BETA VERSION AND IS STILL BEING DEVELOPED, TESTED AND EVALUATED."
            },
            {
              "date": "2026-10-08",
              "text": "Pleo reserves the right to introduce fees and payment terms for any use of the API.",
              "quote": "Pleo reserves the right to implement fees and payment terms with respect to any use of the Pleo API."
            },
            {
              "date": "2026-10-08",
              "text": "The customer agrees that Pleo may monitor API use to check quality, improve its products and verify compliance with the terms.",
              "quote": "THE CUSTOMER AGREES THAT PLEO TECHNOLOGIES A/S MAY MONITOR USE OF THE API TO ENSURE QUALITY, IMPROVE PLEO TECHNOLOGIES A/S (AND ITS AFFILIATES’) PRODUCTS AND SERVICES, AND VERIFY YOUR COMPLIANCE WITH THE TERMS."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.pleo.io/legal-documents/pleo-privacy-policy-en.pdf",
          "state": "not-read",
          "points": 10,
          "max": 10
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/pleo.json",
    "live": {
      "slug": "pleo",
      "probe": {
        "target": "https://external.pleo.io",
        "method": "get",
        "lastAt": "2026-10-08T19:52:59.235241456Z",
        "lastOk": true,
        "lastStatus": 403,
        "lastMs": 56,
        "lastNote": "asks for credentials",
        "authRequired": true,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 88,
        "p95ms24h": 164,
        "samples24h": 50,
        "samples30d": 50,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 50,
            "ok": 50
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.pleo.io",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T19:50:58.828625898Z"
      },
      "securityTxt": {
        "url": "https://pleo.io/.well-known/security.txt",
        "state": "unknown",
        "checkedAt": "2026-10-08T15:38:57.657849973Z"
      },
      "pages": [
        {
          "url": "https://developers.pleo.io/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:17:58.324737763Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "7369dd13eb7c"
        },
        {
          "url": "https://developers.pleo.io/page/terms-of-service",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:18:00.641635735Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "5da670693385"
        }
      ],
      "updatedAt": "2026-10-08T19:52:59.235241456Z"
    }
  }
}
