Head to head · Spend transactions · October 2026 research run

BILL vs Brex

BILL and Brex score within a point of each other on agent readiness, 60.9 (C) and 60.7 (C). Brex leads on agent ergonomics, security & auth and maintenance & community. Both do spend transactions.

Which one, for what

BILL C

Good for A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.

Ahead on

  • Reliability, 81 against 60

Also in its favour

  • No incidents deducted, where Brex loses 3 points for them

Watch for

POST /v3/login takes a user's username and password with a developer key, and the session carries that user's role with no scopes

Brex C

Good for A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.

Ahead on

  • Agent ergonomics, 70 against 60
  • Security & auth, 72 against 56
  • Maintenance & community, 66 against 32

Watch for

The Expenses API update endpoint accepts only memo, so an outside agent can't set a category or custom field on an expense through it

Score by category

CategoryWeight this runBILLBrexEdge
Reliability16%208160BILL +21
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28380BILL +3
Agent ergonomics13%16.26070Brex +10
Security & auth14%17.55672Brex +16
Payments & pricing10%12.52525even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.83266Brex +34
Transparency & trust7%8.86667Brex +1
Negative events≤150-3
Total60.9 · C60.7 · C

Facts side by side

FactBILLBrex
KindHTTP APIHTTP API
VendorBILL Holdings, Inc.Brex LLC
Hosted endpointhttps://gateway.prod.bill.com/connecthttps://api.brex.com
TransportsHTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceProprietary service under the BILL Developer Terms and the BILL General Terms of ServiceProprietary service under the Brex Platform Agreement and the Brex Access Agreement
Tools exposednone43
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-05-212026-10-01
Terms last updated2026-03-03no date given
Privacy policy last updated2026-01-30no date given
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textyes

Verdicts

BILL

A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.

Brex

User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an Idempotency-Key, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.

Before you call either

BILL

  1. Sign in with POST /v3/login and send sessionId and devKey as headers on every AP and AR call. The session expires after 35 minutes idle
  2. Send the apiToken header alone on /v3/spend/ paths. Spend & Expense calls need no login and are limited to 60 a minute per token
  3. Complete the MFA challenge before POST /v3/payments. An untrusted session fails with BDC_1361
  4. Read back payments before retrying a failed POST /v3/payments. No idempotency key is accepted, so a blind retry can pay twice
  5. Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After BDC_1144, wait for the next hour

Brex

  1. Ask an account admin or card admin for a user token with only the scopes the task needs, and prefer the .readonly variants. A token unused for 90 days expires.
  2. Send a stored Idempotency-Key on every POST and PUT. Create transfer and Create card reject requests without one.
  3. Only settled transactions are returned. Poll card and cash transactions with posted_at_start and a lookback of at least one day.
  4. Keep under 1,000 requests in 60 seconds per client and account, and back off exponentially with jitter on 429.
  5. Send only ASCII in free-text fields, and quote the X-Brex-Trace-Id response header when reporting an error.

Questions

Which is better for AI agents, BILL or Brex?

BILL and Brex score within a point of each other on agent readiness, 60.9 (C) and 60.7 (C). Brex leads on agent ergonomics, security & auth and maintenance & community.

Do BILL and Brex need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call BILL and Brex without installing anything?

Yes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Brex at https://api.brex.com.

Other comparisons with BILL or Brex

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.