{
  "data": {
    "category": {
      "area": "domain-data",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "spend.procurement"
      ],
      "description": "Company cards, expenses, bills and purchasing, with an interface an agent can use to read transactions, match receipts, code expenses and raise purchase requests. Compared on API coverage, write access, approval controls and how access is granted.",
      "json": "https://www.anchorterminal.com/categories/spend-management.json",
      "name": "Spend management \u0026 procurement",
      "slug": "spend-management",
      "test": "One test company with a fixed set of card transactions in each listing's sandbox. The same tasks run through its API (list transactions, attach a receipt, code an expense, create a spending limit, read a bill). We check scopes, approval points and the audit record. In this run listings are graded from public evidence against the published checklist.",
      "title": "Spend management and procurement platforms for AI agents",
      "toolCount": 5,
      "tools": [
        "pleo",
        "spendesk",
        "brex",
        "ramp",
        "expensify"
      ],
      "url": "https://www.anchorterminal.com/categories/spend-management"
    },
    "tools": [
      {
        "slug": "pleo",
        "name": "Pleo API + MCP",
        "vendor": "Pleo Technologies A/S",
        "vendorUrl": "https://www.pleo.io/en",
        "kind": "http-api",
        "category": "spend-management",
        "summary": "Spend management platform from Pleo Technologies A/S in Copenhagen, covering company cards, expenses, reimbursements, invoices and accounting exports. Outside agents reach it through a hosted MCP server for expense work and a REST API built for accounting integrations.",
        "url": "https://www.anchorterminal.com/tools/pleo",
        "markdownUrl": "https://www.anchorterminal.com/tools/pleo.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/pleo.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/pleo.json",
        "license": "Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://external.pleo.io",
        "packages": [],
        "auth": "mixed",
        "authNotes": "A person signs in for every route. The MCP server uses OAuth 2.0 in a browser (authorisation code with PKCE, dynamic client registration, no keys to configure) and acts with the connecting user's Pleo role, once a company admin has enabled MCP access for that entity. The External API accepts OAuth 2.0 bearer tokens with resource scopes for partner integrations, whose client ID and secret Pleo issues after review in its Early Access Programme. A single company can use a Standalone API Key with chosen scopes and an expiry, sent as the Basic auth username, but only after Pleo support or a Customer Success Manager enables keys for the organisation.",
        "pricing": "paid",
        "pricingNotes": "Per-user plans, with no separate charge for the API or the MCP server. The pricing page shown to a UK visitor lists Start at £8 per user per month, Build at £14 and Optimise at £18, the last two cheaper billed yearly and with a three-user minimum. MCP is listed on Optimise only, which is sold through a demo. Start and Build have a Try for free button and the signup form states 21 days free. Whether the trial needs a payment card isn't stated. A staging environment with test data exists for customers with API keys enabled and for approved partners. Fees for payments and foreign exchange are extra (checked 2026-10-08).",
        "priceSummary": "Paid",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": null,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://developers.pleo.io/",
        "llmsTxt": "https://developers.pleo.io/llms.txt",
        "openapi": "https://developers.pleo.io/reference/Export%20API.json",
        "capabilities": [
          "spend.transactions",
          "spend.expenses",
          "spend.bills"
        ],
        "tags": [
          "official",
          "hosted",
          "mcp",
          "oauth",
          "api-key",
          "openapi",
          "llms-txt",
          "webhooks",
          "closed-source",
          "status-page",
          "bug-bounty",
          "sandbox"
        ],
        "lastRelease": "2026-10-02",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 62.9,
          "grade": "B",
          "agentReady": false,
          "rank": 293,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 1,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 55,
            "maintenance": 64,
            "payments": 15,
            "reliability": 71,
            "schema": 82,
            "security": 71,
            "transparency": 75
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.",
          "bestFor": "An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.",
          "strengths": [
            "MCP server at mcp.pleo.io/mcp uses OAuth with PKCE and dynamic client registration, and acts with the connecting user's Pleo permissions",
            "Payments, card changes and spending-limit changes are blocked through the MCP by design, per the AI Access Terms",
            "Eleven current OpenAPI 3.0.1 specs with 162 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page",
            "One documented rate limit of 600 requests a minute per credential, with written 429 and Retry-After guidance",
            "Staging hosts for both the API (external.staging.pleo.io) and the MCP server (mcp.staging.pleo.io/mcp)",
            "Sub-processor list with locations, customer data in AWS Ireland, and 30 days' notice of new sub-processors in the DPA"
          ],
          "weaknesses": [
            "The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)",
            "MCP tool names, schemas and count aren't published, so they can't be read without a customer sign-in",
            "Standalone API keys aren't self-service. Pleo support or a Customer Success Manager enables them, and partner OAuth clients go through a reviewed programme",
            "No Idempotency-Key header, no official SDK and no entry in the official MCP registry",
            "The API terms call the API a beta version that Pleo may discontinue at any time, and no SLA was found",
            "No end-of-life date is published for the deprecated Legacy API, and its Q3 2026 replacements for employee writes and wallet balance aren't in the docs"
          ],
          "agentNotes": [
            "Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default",
            "Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist",
            "Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side",
            "Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there",
            "Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second",
            "Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 62.9
            }
          ],
          "editorialScores": {
            "ergonomics": 55,
            "maintenance": 64,
            "payments": 15,
            "reliability": 71,
            "schema": 82,
            "security": 71,
            "transparency": 63
          },
          "provenanceScore": 87
        },
        "connect": {
          "http": "curl --request GET \\\n-u \"YOUR-API-KEY:\" \\\n-H \"Accept: application/json;charset=UTF-8\" \\\n\"https://external.staging.pleo.io/v2/employees\"",
          "claudeCode": "claude mcp add --transport http pleo-mcp-staging https://mcp.staging.pleo.io/mcp",
          "config": {
            "mcpServers": {
              "pleo": {
                "url": "https://mcp.pleo.io/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/spend.transactions",
          "tool": "https://letme.dev/pleo"
        },
        "area": "domain-data",
        "provenance": {
          "legalEntity": "Pleo Technologies A/S",
          "domain": "pleo.io",
          "domainRegistered": "2015-10-07",
          "endpointOnVendorDomain": true,
          "terms": "https://developers.pleo.io/page/terms-of-service",
          "privacy": "https://www.pleo.io/legal-documents/pleo-privacy-policy-en.pdf",
          "statusPage": "https://status.pleo.io",
          "changelog": "https://developers.pleo.io/changelog",
          "securityTxt": "none",
          "checked": "2026-10-08",
          "notes": [
            "The website footer names Pleo Technologies A/S (36538686), Ravnsborg Tværgade 5C, 2200 København N, Denmark. UK payment services come from Pleo Financial Services UK Ltd, FCA firm reference 1020730, company number 15842283.",
            "The API Terms of Service on the developer portal name Pleo Technologies A/S, carry no date, and describe the API as a beta version. The UK Master Service Agreement has an effective date of 7 September 2026 and is governed by the laws of England and Wales.",
            "The API answers at external.pleo.io and the MCP server at mcp.pleo.io, both pleo.io subdomains. The MCP host publishes its OAuth metadata at https://mcp.pleo.io/.well-known/oauth-authorization-server",
            "www.pleo.io/.well-known/security.txt and pleo.io/.well-known/security.txt both return 403 with an AccessDenied body. The vulnerability disclosure policy gives security-vd@pleo.io as the reporting address.",
            "The privacy notice is dated June 2026 and the Data Processing Agreement 14 October 2025. An AI Access Terms document covers the MCP server.",
            "RDAP from the .io registry gives a registration date of 2015-10-07 for pleo.io."
          ],
          "score": 87
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/pleo.json",
        "live": {
          "slug": "pleo",
          "probe": {
            "target": "https://external.pleo.io",
            "method": "get",
            "lastAt": "2026-10-08T18:20:37.689130608Z",
            "lastOk": true,
            "lastStatus": 403,
            "lastMs": 107,
            "lastNote": "asks for credentials",
            "authRequired": true,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 94,
            "p95ms24h": 163,
            "samples24h": 33,
            "samples30d": 33,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 33,
                "ok": 33
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.pleo.io",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-08T18:22:15.952094673Z"
          },
          "securityTxt": {
            "url": "https://pleo.io/.well-known/security.txt",
            "state": "unknown",
            "checkedAt": "2026-10-08T15:38:57.657849973Z"
          },
          "pages": [
            {
              "url": "https://developers.pleo.io/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-08T18:17:58.324737763Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "7369dd13eb7c"
            },
            {
              "url": "https://developers.pleo.io/page/terms-of-service",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-08T18:18:00.641635735Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "5da670693385"
            }
          ],
          "updatedAt": "2026-10-08T18:22:15.952094673Z"
        }
      },
      {
        "slug": "spendesk",
        "name": "Spendesk API + MCP",
        "vendor": "Spendesk SAS",
        "vendorUrl": "https://www.spendesk.com",
        "kind": "http-api",
        "category": "spend-management",
        "summary": "Spend management platform from Spendesk SAS in Paris, covering company cards, expense claims, supplier invoices, purchase orders and accounting exports. Outside agents reach it through a REST API with scoped keys or OAuth, and a hosted MCP server.",
        "url": "https://www.anchorterminal.com/tools/spendesk",
        "markdownUrl": "https://www.anchorterminal.com/tools/spendesk.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/spendesk.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/spendesk.json",
        "license": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://public-api.spendesk.com",
        "packages": [],
        "auth": "mixed",
        "authNotes": "Access is granted by Spendesk, not self-serve. A customer asks its Spendesk representative for API access, then an Account Owner or Admin creates an API key (client ID and secret) with chosen scopes and an expiry of up to one year. The key is exchanged at POST /v1/auth/token with HTTP Basic for a Bearer token that lasts 60 minutes and can carry fewer scopes than the key. Partner integrations use OAuth 2.0 authorisation code with PKCE after approval by the partnerships team. The MCP server accepts only OAuth user tokens, refuses API keys, and limits use to Controllers and Account Owners. Experimental scopes are added on request.",
        "pricing": "paid",
        "pricingNotes": "No public prices. The pricing page describes a fixed monthly platform fee plus variable fees per transaction (card purchases, invoice payments and expense claims) and asks for a quote. It lists the open API and the MCP connection in the base package. No free tier, trial or self-serve sandbox was found. A demo environment exists at public-api.demo.spendesk.com, with credentials requested alongside API access (checked 2026-10-08).",
        "priceSummary": "Paid",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI definition or the pricing page (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 62,
        "popularity": {
          "githubStars": null,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://developer.spendesk.com",
        "llmsTxt": "https://developer.spendesk.com/llms.txt",
        "openapi": "https://developer.spendesk.com/openapi/spendesk-public-api.json",
        "capabilities": [
          "spend.transactions",
          "spend.expenses",
          "spend.cards",
          "spend.bills",
          "spend.procurement"
        ],
        "tags": [
          "hosted",
          "enterprise",
          "api-key",
          "oauth",
          "mcp",
          "openapi",
          "llms-txt",
          "webhooks",
          "sales-led",
          "status-page",
          "iso27001",
          "bug-bounty"
        ],
        "lastRelease": "2026-09-29",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 62.3,
          "grade": "B",
          "agentReady": false,
          "rank": 306,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 2,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 62,
            "maintenance": 57,
            "payments": 0,
            "reliability": 55,
            "schema": 87,
            "security": 86,
            "transparency": 80
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.",
          "bestFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
          "strengths": [
            "OpenAPI 3.1 definition with 106 operations, llms.txt and a Markdown copy of every docs page, all public without sign-in",
            "37 documented scopes split by resource and by read or write. A token can carry fewer scopes than its key, and keys expire within one year",
            "MCP write permissions are off by default, enabled per connection by an admin with a second factor, then ticked by each user",
            "Every MCP tool call is recorded in an action log with date, tool, status, user, company and correlation ID",
            "Rate limits are published (1,000 requests a minute per company and credential) with x-ratelimit headers on every response"
          ],
          "weaknesses": [
            "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative",
            "Cards, transactions, invoices, purchase orders, webhooks and most writes sit behind experimental scopes granted on request, and may change",
            "No official SDK found on npm or PyPI, and the MCP server isn't in the official MCP registry",
            "status.spendesk.com has no API component and lists three critical and three major incidents opened between 2 and 29 September 2026",
            "An Idempotency-Key is documented only for creating an intake. A repeated purchase order or supplier request creates a second record"
          ],
          "agentNotes": [
            "Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401",
            "Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list",
            "With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400",
            "The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission",
            "After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 62.3
            }
          ],
          "editorialScores": {
            "ergonomics": 62,
            "maintenance": 57,
            "payments": 0,
            "reliability": 55,
            "schema": 87,
            "security": 86,
            "transparency": 64
          },
          "provenanceScore": 96
        },
        "connect": {
          "http": "curl -X POST https://public-api.demo.spendesk.com/v1/auth/token \\\n  -u \"YOUR_CLIENT_ID:YOUR_CLIENT_SECRET\"\n\ncurl https://public-api.demo.spendesk.com/v1/wallet-summary \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\""
        },
        "letme": {
          "capability": "https://letme.dev/spend.transactions",
          "tool": "https://letme.dev/spendesk"
        },
        "area": "domain-data",
        "provenance": {
          "legalEntity": "Spendesk SAS",
          "domain": "spendesk.com",
          "domainRegistered": "2015-10-30",
          "endpointOnVendorDomain": true,
          "terms": "https://www.spendesk.com/legals/terms/",
          "privacy": "https://www.spendesk.com/legals/privacy/",
          "statusPage": "https://status.spendesk.com",
          "changelog": "https://developer.spendesk.com/changelog",
          "securityTxt": "valid",
          "checked": "2026-10-08",
          "notes": [
            "The legal notice names Spendesk SAS, 7 Rue de Madrid, 75008 Paris, registration 821 893 286 R.C.S. Paris. The privacy policy (March 2025, version 0.5) gives the registered office as 51 rue de Londres, 75008 Paris.",
            "Payment services are supplied by Spendesk Financial Services (a French payment institution licensed by the ACPR, number 17518) in the EEA, Adyen in the UK and Sutton Bank in the US, per the site footer.",
            "The API and the MCP server answer at public-api.spendesk.com. An unauthenticated POST to /v1/mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata.",
            "www.spendesk.com/.well-known/security.txt is present with a contact and an expiry of 31 December 2026. developer.spendesk.com/.well-known/security.txt returns 404.",
            "The terms page lists the customer terms, a DORA addendum, a Spendesk API agreement and partner programme terms. The document links are drawn by JavaScript and we couldn't open them.",
            "RDAP for spendesk.com gives a registration date of 2015-10-30."
          ],
          "score": 96
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/spendesk.json",
        "live": {
          "slug": "spendesk",
          "probe": {
            "target": "https://public-api.spendesk.com",
            "method": "get",
            "lastAt": "2026-10-08T18:20:40.801700324Z",
            "lastOk": true,
            "lastStatus": 403,
            "lastMs": 67,
            "lastNote": "asks for credentials",
            "authRequired": true,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 67,
            "p95ms24h": 103,
            "samples24h": 33,
            "samples30d": 33,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 33,
                "ok": 33
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.spendesk.com",
            "indicator": "minor",
            "summary": "Partially Degraded Service",
            "checkedAt": "2026-10-08T18:22:20.323763159Z"
          },
          "securityTxt": {
            "url": "https://spendesk.com/.well-known/security.txt",
            "state": "valid",
            "expires": "2026-12-31T22:00:00.000Z",
            "checkedAt": "2026-10-08T15:38:39.004780879Z"
          },
          "pages": [
            {
              "url": "https://developer.spendesk.com/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-08T18:17:18.275650963Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "0a7493461e82"
            }
          ],
          "updatedAt": "2026-10-08T18:22:20.323763159Z"
        }
      },
      {
        "slug": "brex",
        "name": "Brex",
        "vendor": "Brex LLC",
        "vendorUrl": "https://www.brex.com",
        "kind": "http-api",
        "category": "spend-management",
        "summary": "Brex is a spend platform with corporate cards, expense management, bill pay, travel and business accounts. Its REST Developer API reads and writes cards, expenses, spend limits, vendors and transfers, and a hosted MCP server is in beta.",
        "url": "https://www.anchorterminal.com/tools/brex",
        "markdownUrl": "https://www.anchorterminal.com/tools/brex.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/brex.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/brex.json",
        "license": "Proprietary service under the Brex Platform Agreement and the Brex Access Agreement",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://api.brex.com",
        "packages": [],
        "auth": "mixed",
        "authNotes": "Access is self-serve for a Brex customer. An account admin or card admin accepts the Developer API agreement in the dashboard, then creates a user token with chosen scopes at Settings \u003e Developer. The token is sent as a Bearer header, is shown once, can be revoked, and expires after 90 days without a call. Partners acting for other Brex accounts apply to Brex for a client ID and secret and use the OAuth 2.0 authorisation code grant, with one-hour access tokens and refresh tokens. The MCP server takes OAuth with dynamic client registration, where each employee signs in with their own permissions, or an admin's user token.",
        "pricing": "freemium",
        "pricingNotes": "No separate API fee. brex.com/pricing lists Brex API access under Essentials at $0 per user per month, with Premium at $12 per user per month and Enterprise priced on request. Access needs an approved Brex business account, so an agent can't start without one. There is no customer sandbox, and the staging server is for approved partners only. The Access Agreement lets Brex introduce API fees on 30 days' notice (checked 2026-10-08).",
        "priceSummary": "$12 / seat-mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": 43,
        "popularity": {
          "githubStars": null,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://developer.brex.com",
        "llmsTxt": "https://developer.brex.com/llms.txt",
        "openapi": "https://developer.brex.com/_bundle/openapi/team_api.yaml",
        "capabilities": [
          "spend.transactions",
          "spend.expenses",
          "spend.cards",
          "spend.bills"
        ],
        "tags": [
          "hosted",
          "freemium",
          "api-key",
          "oauth",
          "mcp",
          "openapi",
          "llms-txt",
          "webhooks",
          "status-page",
          "soc2",
          "pci-dss"
        ],
        "lastRelease": "2026-10-01",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 60.7,
          "grade": "C",
          "agentReady": false,
          "rank": 345,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 3,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 70,
            "maintenance": 66,
            "payments": 25,
            "reliability": 60,
            "schema": 80,
            "security": 72,
            "transparency": 67
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": -3,
          "negativeNotes": [
            "2026-02 and 2026-09. The changelog records the List expenses maximum `limit` cut from 1,000 to 100 in February 2026, and `GET /v2/users/{id}/limit` removed from the Team API in September 2026 without a deprecated label in the entry. The Team API is at version 1.0, and the launch-stages page says breaking changes to generally available APIs come as new versions with deprecation timelines. Both changes are documented in the month they shipped, and notice by email couldn't be checked, so the smallest deduction applies (https://developer.brex.com/changelog)."
          ],
          "verdict": "User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.",
          "bestFor": "A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.",
          "strengths": [
            "Ten public OpenAPI 3 specs covering 115 operations, plus llms.txt and a Markdown twin of every docs page",
            "User tokens take scopes chosen at creation, most with a read-only variant, and card numbers need the separate `cards.pan` scope",
            "Every POST and PUT accepts an `Idempotency-Key`, and Create transfer and Create card require one",
            "API access is listed on the Essentials plan at $0 per user per month",
            "The hosted MCP server uses OAuth with dynamic client registration and each employee's own Brex permissions"
          ],
          "weaknesses": [
            "The Expenses API update endpoint accepts only `memo`, so an outside agent can't set a category or custom field on an expense through it",
            "No customer sandbox. The docs say staging isn't a sandbox and won't accept customer tokens",
            "No official SDK. The docs list three community libraries that Brex doesn't support",
            "status.brex.com logs API request errors from 16:01 to 20:34 UTC on 4 August 2026 and invalidated developer tokens on 21 September 2026",
            "The MCP server is beta with 43 tools, and approvals and card management aren't available through it"
          ],
          "agentNotes": [
            "Ask an account admin or card admin for a user token with only the scopes the task needs, and prefer the `.readonly` variants. A token unused for 90 days expires.",
            "Send a stored `Idempotency-Key` on every POST and PUT. Create transfer and Create card reject requests without one.",
            "Only settled transactions are returned. Poll card and cash transactions with `posted_at_start` and a lookback of at least one day.",
            "Keep under 1,000 requests in 60 seconds per client and account, and back off exponentially with jitter on 429.",
            "Send only ASCII in free-text fields, and quote the `X-Brex-Trace-Id` response header when reporting an error."
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 60.7
            }
          ],
          "editorialScores": {
            "ergonomics": 70,
            "maintenance": 66,
            "payments": 25,
            "reliability": 60,
            "schema": 80,
            "security": 72,
            "transparency": 47
          },
          "provenanceScore": 86
        },
        "connect": {
          "http": "curl -i -X GET \\\n  https://api.brex.com/v2/users/me \\\n  -H 'Authorization: Bearer \u003cYOUR_TOKEN_FROM_STEP_1_HERE\u003e'",
          "claudeCode": "claude mcp add --transport http brex https://api.brex.com/mcp",
          "config": {
            "mcpServers": {
              "brex": {
                "headers": {
                  "Authorization": "Bearer YOUR_BREX_ACCESS_TOKEN"
                },
                "type": "http",
                "url": "https://api.brex.com/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/spend.transactions",
          "tool": "https://letme.dev/brex"
        },
        "area": "domain-data",
        "unitPrices": [
          {
            "item": "Essentials plan",
            "unit": "seat-month",
            "usd": 0,
            "note": "Brex API access listed on this plan"
          },
          {
            "item": "Premium plan",
            "unit": "seat-month",
            "usd": 12,
            "note": "Enterprise is priced on request"
          }
        ],
        "provenance": {
          "legalEntity": "Brex LLC",
          "domain": "brex.com",
          "domainRegistered": "1998-10-22",
          "endpointOnVendorDomain": true,
          "terms": "https://www.brex.com/legal/platform-agreement",
          "privacy": "https://www.brex.com/legal/privacy",
          "statusPage": "https://status.brex.com",
          "changelog": "https://developer.brex.com/changelog",
          "securityTxt": "none",
          "checked": "2026-10-08",
          "notes": [
            "The Platform Agreement defines Brex as Brex LLC, a wholly owned subsidiary of Capital One, N.A., and the pricing page footer gives addresses in San Francisco and Salt Lake City.",
            "API use is also governed by the Brex Access Agreement at https://www.brex.com/legal/developer-portal, which an admin accepts in the dashboard before creating a token.",
            "The API and the MCP server answer at api.brex.com and the authorisation server at accounts-api.brex.com, both brex.com subdomains. The former host platform.brexapis.com still works per the docs.",
            "www.brex.com/.well-known/security.txt returns 404. brex.com/trust/responsible-disclosure has a disclosure policy and a form run with Bugcrowd.",
            "RDAP for brex.com gives a registration date of 1998-10-22."
          ],
          "score": 86
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/brex.json",
        "live": {
          "slug": "brex",
          "probe": {
            "target": "https://api.brex.com",
            "method": "get",
            "lastAt": "2026-10-08T18:20:26.579313312Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 355,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 434,
            "p95ms24h": 526,
            "samples24h": 33,
            "samples30d": 33,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 33,
                "ok": 33
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.brex.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-08T18:21:50.939179332Z"
          },
          "securityTxt": {
            "url": "https://brex.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-08T15:38:43.637271768Z"
          },
          "pages": [
            {
              "url": "https://developer.brex.com/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-08T18:17:07.265606865Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "953aa59e7531"
            }
          ],
          "updatedAt": "2026-10-08T18:21:50.939179332Z"
        }
      },
      {
        "slug": "ramp",
        "name": "Ramp",
        "vendor": "Ramp Business Corporation",
        "vendorUrl": "https://ramp.com",
        "kind": "http-api",
        "category": "spend-management",
        "summary": "Ramp is a finance platform with company cards, expense management, bill pay, procurement and travel. Its Developer API reads and writes transactions, receipts, funds, bills and purchase orders. A hosted MCP server and CLI work with the signed-in user's permissions.",
        "url": "https://www.anchorterminal.com/tools/ramp",
        "markdownUrl": "https://www.anchorterminal.com/tools/ramp.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ramp.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ramp.json",
        "repo": "https://github.com/ramp-public/ramp-cli",
        "license": "Proprietary service under the Ramp Platform Agreement and the API Agreement. The ramp-cli repository is MIT",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://api.ramp.com",
        "packages": [],
        "auth": "oauth",
        "authNotes": "Access is self-serve for a Ramp customer. An admin creates an app at Company \u003e Developer, accepts the terms, and picks grant types and scopes. Client credentials tokens are requested from `/developer/v1/token` with HTTP Basic auth, last 10 days and act with the app creator's permissions. The authorisation code grant is for apps acting for other businesses, with one-hour access tokens by default, optional refresh tokens, and consent limited to Admin and Business Owner users. Scopes follow `resource:read` and `resource:write`, and `cards:read_vault` needs a production review by Ramp. The MCP server and CLI use OAuth and work with the signed-in user's permissions, and custom MCP clients need their redirect URI allowlisted by Ramp.",
        "pricing": "freemium",
        "pricingNotes": "No separate API fee is published. ramp.com/pricing lists Free at $0 per user per month, Plus at $15 per user per month plus a platform fee by team size, and Enterprise on request, with a 30-day Plus trial. The OpenAPI spec marks 51 of 260 operations as needing Plus. Access needs an approved Ramp business account, so an agent can't start without one. A sandbox at demo-api.ramp.com is available on request through a form. The API Agreement reserves the right to charge API fees (checked 2026-10-08).",
        "priceSummary": "$15 / seat-mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "Ramp's own API isn't paid for by x402, MPP or L402. Ramp lets a connected agent pay other sellers by x402 from a funded wallet, or by Stripe MPP, per the agentic payments guide (https://docs.ramp.com/llms-guides/agent-payments.txt, checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 53,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://docs.ramp.com",
        "llmsTxt": "https://docs.ramp.com/llms.txt",
        "openapi": "https://docs.ramp.com/openapi/developer-api.json",
        "capabilities": [
          "spend.transactions",
          "spend.expenses",
          "spend.cards",
          "spend.bills",
          "spend.procurement"
        ],
        "tags": [
          "hosted",
          "freemium",
          "oauth",
          "mcp",
          "cli",
          "openapi",
          "llms-txt",
          "webhooks",
          "sandbox",
          "soc2",
          "pci-dss",
          "security-txt"
        ],
        "lastRelease": "2026-10-07",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 57.3,
          "grade": "C",
          "agentReady": false,
          "rank": 423,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 4,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 66,
            "maintenance": 74,
            "payments": 25,
            "reliability": 30,
            "schema": 86,
            "security": 79,
            "transparency": 70
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": -3,
          "negativeNotes": [
            "2026-06-25 and 2026-02-11. The changelog records the webhook event type `transactions.all_requirements_met_and_approved` removed on 25 June 2026, three days after the 22 June entry marked it a deprecated alias, and `functional_currency_amount` dropped from default transaction responses on 11 February 2026. Both are documented on the day they shipped and the first names a replacement. Notice by email couldn't be checked, so the smallest deduction applies (https://docs.ramp.com/developer-api/v1/changelog)."
          ],
          "verdict": "OAuth 2.0 scopes split read from write across about 40 resources, a 260-operation OpenAPI spec is public, and an audit log endpoint records actions by user and agent. No public status page was found, 89 operations are marked beta, the API Agreement allows changes without notice, and idempotency keys cover only eight write operations.",
          "bestFor": "A finance team already on Ramp that wants an agent to read transactions, upload receipts, code and split expenses, issue funds with limits, create bills and work with purchase orders and procurement requests.",
          "strengths": [
            "Public OpenAPI 3.0.2 spec with 260 operations, plus llms.txt and a plain-text export of every guide and the API reference",
            "OAuth 2.0 scopes follow `resource:read` and `resource:write`, tokens are bound to scopes at issue, and `POST /developer/v1/token/revoke` invalidates them",
            "`GET /developer/v1/audit-logs/events` filters events by user, date, event type and actor type, including Ramp's own agents",
            "A sandbox at demo-api.ramp.com and demo.ramp.com moves no real money and has demo actions that create test transactions",
            "The changelog is dated to the day, with 26 dated entries between 15 July and 7 October 2026 and an RSS feed"
          ],
          "weaknesses": [
            "No public status page was found. status.ramp.com doesn't resolve, and no status link appears in the docs, help centre or trust centre pages read",
            "89 of 260 operations carry `x-beta`, among them creating a fund and splitting a transaction, and the MCP guide says the server is subject to change",
            "`X-Idempotency-Key` is accepted on 8 of 155 write operations. Creating a bill, a purchase order or a vendor has none",
            "The API Agreement says Ramp may change or discontinue the APIs at any time with or without notice",
            "No official SDK was found in the docs, and 51 operations (custom records, purchase orders, the audit log) need the paid Plus plan"
          ],
          "agentNotes": [
            "Send `scope` on the client credentials token request. Without it Ramp issues a token with no scopes and every resource call fails with 403",
            "Follow the full URL in `next` to page. `page_size` defaults to 20 and stops at 100, and the cursor is opaque",
            "Stay under 200 requests in any 10 seconds per source IP and back off 1, 2 then 4 seconds on 429. No Retry-After header is documented",
            "Don't use `synced_after` or `from_created_at` to find changed records. Bills and transactions have no updated-at filter, so subscribe to webhooks",
            "Send `X-Idempotency-Key` when creating funds or procurement requests. Elsewhere a retried POST can create a duplicate, so read back before retrying"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 57.3
            }
          ],
          "editorialScores": {
            "ergonomics": 66,
            "maintenance": 74,
            "payments": 25,
            "reliability": 30,
            "schema": 86,
            "security": 79,
            "transparency": 55
          },
          "provenanceScore": 84
        },
        "connect": {
          "install": "curl -fsSL https://agents.ramp.com/install.sh | sh",
          "http": "curl https://api.ramp.com/developer/v1/transactions \\\n  -H \"Authorization: Bearer $RAMP_ACCESS_TOKEN\""
        },
        "letme": {
          "capability": "https://letme.dev/spend.transactions",
          "tool": "https://letme.dev/ramp"
        },
        "area": "domain-data",
        "unitPrices": [
          {
            "item": "Free plan",
            "unit": "seat-month",
            "usd": 0,
            "note": "No separate API fee is published"
          },
          {
            "item": "Plus plan",
            "unit": "seat-month",
            "usd": 15,
            "note": "Plus a platform fee by team size, not stated. Enterprise is priced on request"
          }
        ],
        "provenance": {
          "legalEntity": "Ramp Business Corporation",
          "domain": "ramp.com",
          "domainRegistered": "1994-03-14",
          "endpointOnVendorDomain": true,
          "terms": "https://ramp.com/legal/developer-terms/developer-terms/api-agreement",
          "privacy": "https://ramp.com/legal/privacy-policy",
          "statusPage": "",
          "changelog": "https://docs.ramp.com/developer-api/v1/changelog",
          "securityTxt": "valid",
          "checked": "2026-10-08",
          "notes": [
            "The API Agreement (last updated 26 March 2026) names Ramp Business Corporation, 28 West 23rd Street, Floor 2, New York, NY 10010.",
            "The API answers at api.ramp.com and demo-api.ramp.com, and the MCP servers at mcp.ramp.com and demo-mcp.ramp.com.",
            "No status page was found. status.ramp.com doesn't resolve, and no status link appears in the docs, help centre, trust centre, home or pricing pages read on 8 October 2026.",
            "ramp.com/.well-known/security.txt gives security-external@ramp.com as the contact and expires on 18 March 2027.",
            "The Platform Agreement was last updated on 22 September 2026, the privacy policy on 21 August 2026 and the DPA on 10 July 2026. The legal pages render with JavaScript, and we read the published documents from the site's own script files.",
            "RDAP for ramp.com gives a registration date of 1994-03-14 and Cloudflare, Inc. as registrar."
          ],
          "score": 84
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/ramp.json",
        "live": {
          "slug": "ramp",
          "probe": {
            "target": "https://api.ramp.com",
            "method": "get",
            "lastAt": "2026-10-08T18:20:38.384448827Z",
            "lastOk": true,
            "lastStatus": 401,
            "lastMs": 139,
            "lastNote": "asks for credentials",
            "authRequired": true,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 137,
            "p95ms24h": 194,
            "samples24h": 33,
            "samples30d": 33,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 33,
                "ok": 33
              }
            ]
          },
          "versions": [
            {
              "registry": "github",
              "name": "ramp-public/ramp-cli",
              "version": "v0.2.54",
              "released": "2026-10-06",
              "seenAt": "2026-10-08T16:26:56.585492266Z"
            }
          ],
          "githubStars": 53,
          "securityTxt": {
            "url": "https://ramp.com/.well-known/security.txt",
            "state": "valid",
            "expires": "2027-03-18T19:00:00.000Z",
            "checkedAt": "2026-10-08T15:38:51.088112552Z"
          },
          "pages": [
            {
              "url": "https://docs.ramp.com/developer-api/v1/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-08T18:19:18.141617922Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "df9c69ecf0f3"
            },
            {
              "url": "https://ramp.com/legal/privacy-policy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-08T18:23:38.570721399Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "e3b0c44298fc"
            },
            {
              "url": "https://ramp.com/legal/developer-terms/developer-terms/api-agreement",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-08T18:23:36.289237573Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "e3b0c44298fc"
            }
          ],
          "updatedAt": "2026-10-08T18:23:38.570721399Z"
        }
      },
      {
        "slug": "expensify",
        "name": "Expensify",
        "vendor": "Expensify, Inc.",
        "vendorUrl": "https://www.expensify.com",
        "kind": "http-api",
        "category": "spend-management",
        "summary": "Expensify is an expense management service with receipt scanning, expense reports, approvals, reimbursement and company cards. Its Integration Server API exports report and card data and creates expenses, reports and workspace settings. A hosted MCP server gives read-only search.",
        "url": "https://www.anchorterminal.com/tools/expensify",
        "markdownUrl": "https://www.anchorterminal.com/tools/expensify.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/expensify.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/expensify.json",
        "license": "Proprietary service under the Expensify Terms of Service. The Expensify app client and help articles on GitHub (Expensify/App) are MIT",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://integrations.expensify.com/Integration-Server/ExpensifyIntegrations",
        "packages": [],
        "auth": "mixed",
        "authNotes": "Access is self-serve for anyone with an Expensify account. Signing in at https://www.expensify.com/tools/integrations/ generates a partnerUserID and partnerUserSecret pair, shown once and replaceable on the same page. The pair travels inside the `requestJobDescription` form field and acts with the account's own rights, so domain and workspace admin jobs need an admin's credentials. Creating reports or expenses in other users' accounts needs Expensify to enable it for the domain by email to Concierge. OAuth2 for the API (authorisation code grant, scope `integrations:api`, two-hour access tokens, rotating refresh tokens) is in private beta by request form. The MCP server uses OAuth 2.1 with PKCE and the `mcp:tools` scope.",
        "pricing": "freemium",
        "pricingNotes": "No separate API fee is published. Collect is $5 per unique member a month, pay-per-use. Control is $18 per member a month on an annual subscription or $36 per active member pay-per-use, and as low as $9 with Expensify Card spend. A workspace starts a 30-day free trial, with a payment card asked for when it ends, and a free Submit workspace exists for individuals. An agent can start on the trial without a contract. No sandbox was found, and whether the API works without a paid plan wasn't established (checked 2026-10-08).",
        "priceSummary": "$5 / seat-mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the Integration Server reference, the help articles or the pricing article (checked 2026-10-08).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": null,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-08"
        },
        "docsUrl": "https://integrations.expensify.com/Integration-Server/doc/",
        "capabilities": [
          "spend.transactions",
          "spend.expenses"
        ],
        "tags": [
          "hosted",
          "freemium",
          "api-key",
          "oauth",
          "mcp",
          "soc2",
          "pci-dss"
        ],
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 41.1,
          "grade": "E",
          "agentReady": false,
          "rank": 593,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 5,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 45,
            "maintenance": 23,
            "payments": 30,
            "reliability": 62,
            "schema": 28,
            "security": 34,
            "transparency": 58
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-08"
          },
          "negative": 0,
          "verdict": "One endpoint exports reports through caller-written templates and creates expenses, reports, rules and workspace settings, with limits of 5 requests per 10 seconds published and a status page that tracks the API separately. There is no OpenAPI spec, changelog, SDK, pagination or idempotency key, and one credential pair carries the whole account's rights.",
          "bestFor": "A finance team already on Expensify that wants an agent to export approved reports to an accounting system, create expenses and reports, keep categories, tags and employees in step with an HR system, or mark reports reimbursed.",
          "strengths": [
            "Export templates written in Freemarker let the caller choose every output field, in CSV, XLS, XLSX, TXT, PDF, JSON or XML, filtered by date, state, workspace and report ID",
            "Rate limits are published as 5 requests per 10 seconds and 20 per 60 seconds, with status 429 when exceeded",
            "The status page lists Integration APIs as its own component, and no incident in the 90 days to 8 October 2026 names it",
            "The hosted MCP server at https://www.expensify.com/mcp is read-only and uses OAuth 2.1 with PKCE, the `mcp:tools` scope and a revocation endpoint",
            "Every job in the reference has a curl example, a parameter table with valid values and a sample error response"
          ],
          "weaknesses": [
            "No OpenAPI spec, llms.txt, version number or changelog was found for the Integration Server API",
            "The partnerUserID and partnerUserSecret pair acts with all of the account's rights. No scopes or read-only credential were found for the API",
            "No idempotency key or pagination is documented, and no official SDK was found",
            "Errors arrive as `responseCode` in the body. An invalid credential returned HTTP 200 with `responseCode` 404 when we tried it on 8 October 2026",
            "The Terms of Service allow Expensify to modify or discontinue the service at any time without prior notice, and no SLA was found"
          ],
          "agentNotes": [
            "POST `requestJobDescription` as a form field to the single endpoint. Keep it out of the URL query string, because it carries the secret",
            "Read `responseCode` in the body on every reply. HTTP status can be 200 on failure, and validation errors use 410",
            "Stay under 5 requests per 10 seconds and 20 per 60 seconds. No Retry-After header is documented, so space retries yourself",
            "Export in two calls. A `file` job returns a filename, then a `download` job fetches it. Amounts are in cents",
            "Don't retry a create job blindly. No idempotency key exists, so export and check before resending. Set `dry-run` to true when testing the Advanced Employee Updater"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "E",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 41.1
            }
          ],
          "editorialScores": {
            "ergonomics": 45,
            "maintenance": 23,
            "payments": 30,
            "reliability": 62,
            "schema": 28,
            "security": 34,
            "transparency": 41
          },
          "provenanceScore": 75
        },
        "connect": {
          "http": "curl -X POST 'https://integrations.expensify.com/Integration-Server/ExpensifyIntegrations' \\\n  -d 'requestJobDescription={\"type\":\"get\",\"credentials\":{\"partnerUserID\":\"_REPLACE_\",\"partnerUserSecret\":\"_REPLACE_\"},\"inputSettings\":{\"type\":\"policyList\"}}'"
        },
        "letme": {
          "capability": "https://letme.dev/spend.transactions",
          "tool": "https://letme.dev/expensify"
        },
        "area": "domain-data",
        "unitPrices": [
          {
            "item": "Collect plan, pay-per-use",
            "unit": "seat-month",
            "usd": 5,
            "note": "Per unique member. No separate API fee is published"
          },
          {
            "item": "Control plan, annual subscription",
            "unit": "seat-month",
            "usd": 18,
            "note": "As low as $9 with Expensify Card spend. Active members above the subscription size are $36"
          },
          {
            "item": "Control plan, pay-per-use",
            "unit": "seat-month",
            "usd": 36,
            "note": "Per active member"
          }
        ],
        "provenance": {
          "legalEntity": "Expensify, Inc.",
          "domain": "expensify.com",
          "domainRegistered": "2007-10-26",
          "endpointOnVendorDomain": true,
          "terms": "https://www.expensify.com/terms",
          "privacy": "https://www.expensify.com/privacy",
          "statusPage": "https://status.expensify.com",
          "changelog": "",
          "securityTxt": "none",
          "checked": "2026-10-08",
          "notes": [
            "The Terms of Service (last updated 10 September 2026) name Expensify, Inc., 401 SW 5th Ave, Portland, OR 97204, and govern the Expensify Service including related software and tools. No separate API agreement was found.",
            "The privacy policy (last updated 1 April 2026) is issued for the Expensify group and names Expensify, Inc. as controller.",
            "The API answers at integrations.expensify.com and the MCP server at www.expensify.com/mcp.",
            "https://www.expensify.com/.well-known/security.txt returned 404 on 8 October 2026.",
            "No changelog was found for the Integration Server API.",
            "RDAP for expensify.com gives a registration date of 2007-10-26."
          ],
          "score": 75
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/expensify.json",
        "live": {
          "slug": "expensify",
          "probe": {
            "target": "https://integrations.expensify.com/Integration-Server/ExpensifyIntegrations",
            "method": "get",
            "lastAt": "2026-10-08T18:20:29.928594883Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 466,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 281,
            "p95ms24h": 522,
            "samples24h": 10,
            "samples30d": 10,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 10,
                "ok": 10
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.expensify.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-08T18:22:00.245241397Z"
          },
          "updatedAt": "2026-10-08T18:22:00.245241397Z"
        }
      }
    ]
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/categories/spend-management",
    "json": "https://www.anchorterminal.com/categories/spend-management.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/categories/spend-management.md",
    "slim": "https://www.anchorterminal.com/categories/spend-management.min.md"
  },
  "markdown": "Company cards, expenses, bills and purchasing, with an interface an agent can use to read transactions, match receipts, code expenses and raise purchase requests. Compared on API coverage, write access, approval controls and how access is granted.\n\n- Tools ranked: 5 · agent-ready (BB or better): 0 · accept x402: 0 · hosted endpoints: 5 · desk reviews by the panel: 0\n- JSON: https://www.anchorterminal.com/api/v1/tools.json (list) · https://www.anchorterminal.com/api/v1/rankings.json (ranked) · https://www.anchorterminal.com/api/v1/x402.json (payable) · https://www.anchorterminal.com/api/v1/capabilities.json (by capability)\n- Grades run AA, A, BB, B, C, D, E, F · methodology: https://www.anchorterminal.com/benchmark/\n\n- Capabilities in this category: spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement\n- https://letme.dev/spend.transactions picks the top-graded tool in this list and says how to call it direct; calling through letme comes later (https://www.anchorterminal.com/letme/index.md)\n\n## Ranking\n\n| # | Tool | Vendor | Kind | Category | Grade | Score | Confidence | x402 | Auth | Where | Reviews | Page |\n| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |\n| 293 | Pleo API + MCP | Pleo Technologies A/S | HTTP API | Spend | B | 62.9 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/pleo.md |\n| 306 | Spendesk API + MCP | Spendesk SAS | HTTP API | Spend | B | 62.3 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/spendesk.md |\n| 345 | Brex | Brex LLC | HTTP API | Spend | C | 60.7 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/brex.md |\n| 423 | Ramp | Ramp Business Corporation | HTTP API | Spend | C | 57.3 | medium | no | OAuth | hosted | none | https://www.anchorterminal.com/tools/ramp.md |\n| 593 | Expensify | Expensify, Inc. | HTTP API | Spend | E | 41.1 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/expensify.md |\n\nScores are from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/), with Performance and Task success pending. p95 latency and context cost come from our probes, which haven't run yet.\n\n## Summaries\n\n### 293. Pleo API + MCP, B (62.9)\n\nSpend management platform from Pleo Technologies A/S in Copenhagen, covering company cards, expenses, reimbursements, invoices and accounting exports. Outside agents reach it through a hosted MCP server for expense work and a REST API built for accounting integrations. The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.\n\n- Page: https://www.anchorterminal.com/tools/pleo · Markdown: https://www.anchorterminal.com/tools/pleo.md · JSON: https://www.anchorterminal.com/api/v1/tools/pleo.json\n- Capabilities: spend.transactions, spend.expenses, spend.bills · endpoint: `https://external.pleo.io`\n\n### 306. Spendesk API + MCP, B (62.3)\n\nSpend management platform from Spendesk SAS in Paris, covering company cards, expense claims, supplier invoices, purchase orders and accounting exports. Outside agents reach it through a REST API with scoped keys or OAuth, and a hosted MCP server. Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.\n\n- Page: https://www.anchorterminal.com/tools/spendesk · Markdown: https://www.anchorterminal.com/tools/spendesk.md · JSON: https://www.anchorterminal.com/api/v1/tools/spendesk.json\n- Capabilities: spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement · endpoint: `https://public-api.spendesk.com`\n\n### 345. Brex, C (60.7)\n\nBrex is a spend platform with corporate cards, expense management, bill pay, travel and business accounts. Its REST Developer API reads and writes cards, expenses, spend limits, vendors and transfers, and a hosted MCP server is in beta. User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.\n\n- Page: https://www.anchorterminal.com/tools/brex · Markdown: https://www.anchorterminal.com/tools/brex.md · JSON: https://www.anchorterminal.com/api/v1/tools/brex.json\n- Capabilities: spend.transactions, spend.expenses, spend.cards, spend.bills · endpoint: `https://api.brex.com`\n\n### 423. Ramp, C (57.3)\n\nRamp is a finance platform with company cards, expense management, bill pay, procurement and travel. Its Developer API reads and writes transactions, receipts, funds, bills and purchase orders. A hosted MCP server and CLI work with the signed-in user's permissions. OAuth 2.0 scopes split read from write across about 40 resources, a 260-operation OpenAPI spec is public, and an audit log endpoint records actions by user and agent. No public status page was found, 89 operations are marked beta, the API Agreement allows changes without notice, and idempotency keys cover only eight write operations.\n\n- Page: https://www.anchorterminal.com/tools/ramp · Markdown: https://www.anchorterminal.com/tools/ramp.md · JSON: https://www.anchorterminal.com/api/v1/tools/ramp.json\n- Capabilities: spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement · endpoint: `https://api.ramp.com`\n\n### 593. Expensify, E (41.1)\n\nExpensify is an expense management service with receipt scanning, expense reports, approvals, reimbursement and company cards. Its Integration Server API exports report and card data and creates expenses, reports and workspace settings. A hosted MCP server gives read-only search. One endpoint exports reports through caller-written templates and creates expenses, reports, rules and workspace settings, with limits of 5 requests per 10 seconds published and a status page that tracks the API separately. There is no OpenAPI spec, changelog, SDK, pagination or idempotency key, and one credential pair carries the whole account's rights.\n\n- Page: https://www.anchorterminal.com/tools/expensify · Markdown: https://www.anchorterminal.com/tools/expensify.md · JSON: https://www.anchorterminal.com/api/v1/tools/expensify.json\n- Capabilities: spend.transactions, spend.expenses · endpoint: `https://integrations.expensify.com/Integration-Server/ExpensifyIntegrations`\n\n## How we test this category\n\nOne test company with a fixed set of card transactions in each listing's sandbox. The same tasks run through its API (list transactions, attach a receipt, code an expense, create a spending limit, read a bill). We check scopes, approval points and the audit record. In this run listings are graded from public evidence against the published checklist. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence.\n\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Spend management \u0026 procurement",
        "url": ""
      }
    ],
    "description": "5 spend management \u0026 procurement listings ranked by the Anchor benchmark. Leader Pleo API + MCP (B). Company cards, expenses, bills and purchasing, with an interface an agent can use to read transactions, match receipts, code expenses and raise purchase requests. Compared on API coverage, write access, approval controls and how access is granted.",
    "facts": [
      "Pleo API + MCP B",
      "Spendesk API + MCP B",
      "Brex C"
    ],
    "h1": "Spend management and procurement platforms for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/categories-spend-management.png",
    "path": "/categories/spend-management",
    "published": "",
    "section": "tools",
    "title": "Spend management and procurement platforms for AI agents, ranked",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/categories/spend-management"
  },
  "tokens": {
    "markdown": 2050,
    "slim": 380
  },
  "version": 1
}
