Head to head · Spend transactions · October 2026 research run
BILL vs Brex
BILL and Brex score within a point of each other on agent readiness, 60.9 (C) and 60.7 (C). Brex leads on agent ergonomics, security & auth and maintenance & community. Both do spend transactions.
Which one, for what
BILL C
Good for A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.
Ahead on
- Reliability, 81 against 60
Also in its favour
- No incidents deducted, where Brex loses 3 points for them
Watch for
POST /v3/login takes a user's username and password with a developer key, and the session carries that user's role with no scopes
Brex C
Good for A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.
Ahead on
- Agent ergonomics, 70 against 60
- Security & auth, 72 against 56
- Maintenance & community, 66 against 32
Watch for
The Expenses API update endpoint accepts only memo, so an outside agent can't set a category or custom field on an expense through it
Score by category
| Category | Weight this run | BILL | Brex | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 81 | 60 | BILL +21 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 83 | 80 | BILL +3 |
| Agent ergonomics | 13%16.2 | 60 | 70 | Brex +10 |
| Security & auth | 14%17.5 | 56 | 72 | Brex +16 |
| Payments & pricing | 10%12.5 | 25 | 25 | even |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 32 | 66 | Brex +34 |
| Transparency & trust | 7%8.8 | 66 | 67 | Brex +1 |
| Negative events | ≤15 | 0 | -3 | |
| Total | 60.9 · C | 60.7 · C |
Facts side by side
| Fact | BILL | Brex |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | BILL Holdings, Inc. | Brex LLC |
| Hosted endpoint | https://gateway.prod.bill.com/connect | https://api.brex.com |
| Transports | HTTP | HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | Proprietary service under the BILL Developer Terms and the BILL General Terms of Service | Proprietary service under the Brex Platform Agreement and the Brex Access Agreement |
| Tools exposed | none | 43 |
| Read-only variant documented | no | yes |
| llms.txt | yes | yes |
| Last release | 2026-05-21 | 2026-10-01 |
| Terms last updated | 2026-03-03 | no date given |
| Privacy policy last updated | 2026-01-30 | no date given |
| Customer content may train models | not found in the text | not found in the text |
| Terms restrict automated access | not found in the text | not found in the text |
| Terms restrict benchmarking | not found in the text | yes |
| Terms or service can change without notice | not found in the text | not found in the text |
| Arbitration or class-action waiver | not found in the text | yes |
Verdicts
BILL
A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.
Brex
User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an Idempotency-Key, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.
Before you call either
BILL
- Sign in with
POST /v3/loginand sendsessionIdanddevKeyas headers on every AP and AR call. The session expires after 35 minutes idle - Send the
apiTokenheader alone on/v3/spend/paths. Spend & Expense calls need no login and are limited to 60 a minute per token - Complete the MFA challenge before
POST /v3/payments. An untrusted session fails withBDC_1361 - Read back payments before retrying a failed
POST /v3/payments. No idempotency key is accepted, so a blind retry can pay twice - Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After
BDC_1144, wait for the next hour
Brex
- Ask an account admin or card admin for a user token with only the scopes the task needs, and prefer the
.readonlyvariants. A token unused for 90 days expires. - Send a stored
Idempotency-Keyon every POST and PUT. Create transfer and Create card reject requests without one. - Only settled transactions are returned. Poll card and cash transactions with
posted_at_startand a lookback of at least one day. - Keep under 1,000 requests in 60 seconds per client and account, and back off exponentially with jitter on 429.
- Send only ASCII in free-text fields, and quote the
X-Brex-Trace-Idresponse header when reporting an error.
Questions
Which is better for AI agents, BILL or Brex?
BILL and Brex score within a point of each other on agent readiness, 60.9 (C) and 60.7 (C). Brex leads on agent ergonomics, security & auth and maintenance & community.
Do BILL and Brex need an API key?
Both take an API key or an OAuth sign-in.
Can an agent call BILL and Brex without installing anything?
Yes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Brex at https://api.brex.com.
Other comparisons with BILL or Brex
Machine-readable
- This page as Markdown
/compare/bill-vs-brex.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/bill.json·/api/v1/tools/brex.json - From a terminal
anchor compare bill brex(the CLI) - Over MCP
compare_tools {"a": "bill", "b": "brex"}at/mcp, no key