{
  "data": {
    "a": {
      "slug": "bill",
      "name": "BILL",
      "vendor": "BILL Holdings, Inc.",
      "vendorUrl": "https://www.bill.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "BILL is a US financial operations platform for accounts payable, accounts receivable and company card spend. Its v3 REST API reads and writes bills, payments, invoices, budgets, cards, transactions and reimbursements, and an MCP server in beta gives read-only access.",
      "url": "https://www.anchorterminal.com/tools/bill",
      "markdownUrl": "https://www.anchorterminal.com/tools/bill.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/bill.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/bill.json",
      "license": "Proprietary service under the BILL Developer Terms and the BILL General Terms of Service",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://gateway.prod.bill.com/connect",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is self-serve. A person signs up for a sandbox or production account in a browser and generates a developer key under Settings \u003e Sync \u0026 Integrations \u003e Manage Developer Keys after accepting the Developer Terms. The AP and AR API signs in with `POST /v3/login` using a username, password, organisation ID and `devKey`, and returns a `sessionId` that expires after 35 minutes idle and carries the user's role, with no scopes. Payments and bank account changes need a session trusted by multi-factor authentication. The Spend \u0026 Expense API takes an `apiToken` header that an ADMIN user generates, with no login. App partners request their developer key by email and use customer sync tokens that can't make payments. The MCP server uses OAuth through auth.bill.com with PKCE, and clients other than Claude and ChatGPT need approval by email.",
      "pricing": "freemium",
      "pricingNotes": "No separate API fee is published. bill.com/product/pricing lists API access on every plan. AP and AR plans are Essentials at $49, Team at $65 and Corporate at $89 per user per month, with Enterprise on request, and Spend \u0026 Expense at $0 per user per month, which needs an approved credit application. Payment types such as cheques, ACH and international transfers carry per-transaction fees. The sandbox is self-serve and free, and production has a 30-day trial. The Developer Terms mention API licence and development fees set on the developer site or an order form (checked 2026-10-08).",
      "priceSummary": "$49 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI files or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.bill.com/docs/home",
      "llmsTxt": "https://developer.bill.com/llms.txt",
      "openapi": "https://developer.bill.com/openapi/bill-v3-api.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "accounting.invoices"
      ],
      "tags": [
        "hosted",
        "freemium",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-05-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.9,
        "grade": "C",
        "agentReady": false,
        "rank": 380,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 32,
          "payments": 25,
          "reliability": 81,
          "schema": 83,
          "security": 56,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.",
        "bestFor": "A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.",
        "strengths": [
          "Two public OpenAPI 3.0.1 files cover 326 operations, with llms.txt, a Markdown copy of every docs page and a docs MCP server at `https://developer.bill.com/mcp`",
          "Creating a payment, adding a funding bank account and enabling vendor auto-pay need an API session trusted by multi-factor authentication",
          "The sandbox is self-serve through a sign-up form, charges no subscription fee and moves no real money",
          "www.billcomstatus.com lists an API Servers component and shows no incident after 15 April 2026",
          "The Developer Terms commit BILL to commercially reasonable efforts at 30 days' notice of deprecations and breaking changes"
        ],
        "weaknesses": [
          "`POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes",
          "No idempotency key is accepted on the 203 write operations of the v3 API, payments included. `X-Idempotent-Key` exists only on two webhook subscription calls",
          "The MCP server is beta, read-only and limited to US organisations, and MCP clients other than Claude and ChatGPT need BILL's approval by email",
          "The changelog's latest entry is dated 21 May 2026, and the MCP server has no entry there",
          "No official SDK, sub-processor list, data processing agreement or security.txt was found, and the audit trail endpoint covers vendors only"
        ],
        "agentNotes": [
          "Sign in with `POST /v3/login` and send `sessionId` and `devKey` as headers on every AP and AR call. The session expires after 35 minutes idle",
          "Send the `apiToken` header alone on `/v3/spend/` paths. Spend \u0026 Expense calls need no login and are limited to 60 a minute per token",
          "Complete the MFA challenge before `POST /v3/payments`. An untrusted session fails with `BDC_1361`",
          "Read back payments before retrying a failed `POST /v3/payments`. No idempotency key is accepted, so a blind retry can pay twice",
          "Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After `BDC_1144`, wait for the next hour"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.9
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 32,
          "payments": 25,
          "reliability": 81,
          "schema": 83,
          "security": 56,
          "transparency": 44
        },
        "provenanceScore": 88
      },
      "connect": {
        "http": "curl --request POST \\\n--url 'https://gateway.stage.bill.com/connect/v3/login' \\\n--header 'content-type: application/json' \\\n--data '{\n  \"username\": \"{username}\", \n  \"password\": \"{password}\",\n  \"organizationId\": \"{organization_id}\", \n  \"devKey\": \"{developer_key}\"\n}'"
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/bill"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Spend \u0026 Expense",
          "unit": "seat-month",
          "usd": 0,
          "note": "API access listed. Needs an approved credit application"
        },
        {
          "item": "AP and AR Essentials",
          "unit": "seat-month",
          "usd": 49,
          "note": "API access listed. Per-transaction payment fees apply"
        },
        {
          "item": "AP and AR Team",
          "unit": "seat-month",
          "usd": 65,
          "note": "API access listed"
        },
        {
          "item": "AP and AR Corporate",
          "unit": "seat-month",
          "usd": 89,
          "note": "Enterprise is priced on request"
        }
      ],
      "provenance": {
        "legalEntity": "Bill.com, LLC",
        "domain": "bill.com",
        "domainRegistered": "1994-11-03",
        "endpointOnVendorDomain": true,
        "terms": "https://developer.bill.com/docs/bill-developer-terms",
        "privacy": "https://www.bill.com/privacy",
        "statusPage": "https://www.billcomstatus.com",
        "changelog": "https://developer.bill.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Developer Terms (effective 3 March 2026) are between the developer and Bill.com, LLC and its affiliates, and are accepted when a developer key is generated. The parent company named in the privacy notice is BILL Holdings, Inc.",
          "The BILL Privacy Notice (effective 30 January 2026) names BILL Holdings, Inc. and its subsidiaries Bill.com, LLC, DivvyPay, LLC and Invoice2go, LLC, of San Jose, California.",
          "The API answers at gateway.prod.bill.com and gateway.stage.bill.com, and OAuth for the MCP server at auth.bill.com. The docs send card number decoding to api.divvy.co, a second domain of the vendor's.",
          "The status page is on a separate domain, www.billcomstatus.com, linked from the developer docs. status.bill.com and trust.bill.com didn't answer.",
          "www.bill.com/.well-known/security.txt and www.bill.com/security.txt return 404. The security page sends reports to a HackerOne vulnerability disclosure programme.",
          "The BILL General Terms of Service (last updated 10 February 2025) and separate Spend \u0026 Expense terms govern a customer's account. No data processing agreement or sub-processor list was found on the legal index.",
          "RDAP for bill.com gives a registration date of 1994-11-03 and GoDaddy Corporate Domains, LLC as registrar."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/bill.json",
      "live": {
        "slug": "bill",
        "probe": {
          "target": "https://gateway.prod.bill.com/connect",
          "method": "get",
          "lastAt": "2026-10-08T21:53:17.219430668Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 522,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 449,
          "p95ms24h": 522,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.billcomstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:57:43.262829057Z"
        },
        "updatedAt": "2026-10-08T21:57:43.262829057Z"
      }
    },
    "answer": "BILL and Brex score within a point of each other on agent readiness, 60.9 (C) and 60.7 (C). Brex leads on agent ergonomics, security \u0026 auth and maintenance \u0026 community.",
    "b": {
      "slug": "brex",
      "name": "Brex",
      "vendor": "Brex LLC",
      "vendorUrl": "https://www.brex.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Brex is a spend platform with corporate cards, expense management, bill pay, travel and business accounts. Its REST Developer API reads and writes cards, expenses, spend limits, vendors and transfers, and a hosted MCP server is in beta.",
      "url": "https://www.anchorterminal.com/tools/brex",
      "markdownUrl": "https://www.anchorterminal.com/tools/brex.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/brex.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/brex.json",
      "license": "Proprietary service under the Brex Platform Agreement and the Brex Access Agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.brex.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is self-serve for a Brex customer. An account admin or card admin accepts the Developer API agreement in the dashboard, then creates a user token with chosen scopes at Settings \u003e Developer. The token is sent as a Bearer header, is shown once, can be revoked, and expires after 90 days without a call. Partners acting for other Brex accounts apply to Brex for a client ID and secret and use the OAuth 2.0 authorisation code grant, with one-hour access tokens and refresh tokens. The MCP server takes OAuth with dynamic client registration, where each employee signs in with their own permissions, or an admin's user token.",
      "pricing": "freemium",
      "pricingNotes": "No separate API fee. brex.com/pricing lists Brex API access under Essentials at $0 per user per month, with Premium at $12 per user per month and Enterprise priced on request. Access needs an approved Brex business account, so an agent can't start without one. There is no customer sandbox, and the staging server is for approved partners only. The Access Agreement lets Brex introduce API fees on 30 days' notice (checked 2026-10-08).",
      "priceSummary": "$12 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 43,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.brex.com",
      "llmsTxt": "https://developer.brex.com/llms.txt",
      "openapi": "https://developer.brex.com/_bundle/openapi/team_api.yaml",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills"
      ],
      "tags": [
        "hosted",
        "freemium",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "status-page",
        "soc2",
        "pci-dss"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.7,
        "grade": "C",
        "agentReady": false,
        "rank": 391,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 66,
          "payments": 25,
          "reliability": 60,
          "schema": 80,
          "security": 72,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-02 and 2026-09. The changelog records the List expenses maximum `limit` cut from 1,000 to 100 in February 2026, and `GET /v2/users/{id}/limit` removed from the Team API in September 2026 without a deprecated label in the entry. The Team API is at version 1.0, and the launch-stages page says breaking changes to generally available APIs come as new versions with deprecation timelines. Both changes are documented in the month they shipped, and notice by email couldn't be checked, so the smallest deduction applies (https://developer.brex.com/changelog)."
        ],
        "verdict": "User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.",
        "bestFor": "A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.",
        "strengths": [
          "Ten public OpenAPI 3 specs covering 115 operations, plus llms.txt and a Markdown twin of every docs page",
          "User tokens take scopes chosen at creation, most with a read-only variant, and card numbers need the separate `cards.pan` scope",
          "Every POST and PUT accepts an `Idempotency-Key`, and Create transfer and Create card require one",
          "API access is listed on the Essentials plan at $0 per user per month",
          "The hosted MCP server uses OAuth with dynamic client registration and each employee's own Brex permissions"
        ],
        "weaknesses": [
          "The Expenses API update endpoint accepts only `memo`, so an outside agent can't set a category or custom field on an expense through it",
          "No customer sandbox. The docs say staging isn't a sandbox and won't accept customer tokens",
          "No official SDK. The docs list three community libraries that Brex doesn't support",
          "status.brex.com logs API request errors from 16:01 to 20:34 UTC on 4 August 2026 and invalidated developer tokens on 21 September 2026",
          "The MCP server is beta with 43 tools, and approvals and card management aren't available through it"
        ],
        "agentNotes": [
          "Ask an account admin or card admin for a user token with only the scopes the task needs, and prefer the `.readonly` variants. A token unused for 90 days expires.",
          "Send a stored `Idempotency-Key` on every POST and PUT. Create transfer and Create card reject requests without one.",
          "Only settled transactions are returned. Poll card and cash transactions with `posted_at_start` and a lookback of at least one day.",
          "Keep under 1,000 requests in 60 seconds per client and account, and back off exponentially with jitter on 429.",
          "Send only ASCII in free-text fields, and quote the `X-Brex-Trace-Id` response header when reporting an error."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.7
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 66,
          "payments": 25,
          "reliability": 60,
          "schema": 80,
          "security": 72,
          "transparency": 47
        },
        "provenanceScore": 86
      },
      "connect": {
        "http": "curl -i -X GET \\\n  https://api.brex.com/v2/users/me \\\n  -H 'Authorization: Bearer \u003cYOUR_TOKEN_FROM_STEP_1_HERE\u003e'",
        "claudeCode": "claude mcp add --transport http brex https://api.brex.com/mcp",
        "config": {
          "mcpServers": {
            "brex": {
              "headers": {
                "Authorization": "Bearer YOUR_BREX_ACCESS_TOKEN"
              },
              "type": "http",
              "url": "https://api.brex.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/brex"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Essentials plan",
          "unit": "seat-month",
          "usd": 0,
          "note": "Brex API access listed on this plan"
        },
        {
          "item": "Premium plan",
          "unit": "seat-month",
          "usd": 12,
          "note": "Enterprise is priced on request"
        }
      ],
      "provenance": {
        "legalEntity": "Brex LLC",
        "domain": "brex.com",
        "domainRegistered": "1998-10-22",
        "endpointOnVendorDomain": true,
        "terms": "https://www.brex.com/legal/platform-agreement",
        "privacy": "https://www.brex.com/legal/privacy",
        "statusPage": "https://status.brex.com",
        "changelog": "https://developer.brex.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Platform Agreement defines Brex as Brex LLC, a wholly owned subsidiary of Capital One, N.A., and the pricing page footer gives addresses in San Francisco and Salt Lake City.",
          "API use is also governed by the Brex Access Agreement at https://www.brex.com/legal/developer-portal, which an admin accepts in the dashboard before creating a token.",
          "The API and the MCP server answer at api.brex.com and the authorisation server at accounts-api.brex.com, both brex.com subdomains. The former host platform.brexapis.com still works per the docs.",
          "www.brex.com/.well-known/security.txt returns 404. brex.com/trust/responsible-disclosure has a disclosure policy and a form run with Bugcrowd.",
          "RDAP for brex.com gives a registration date of 1998-10-22."
        ],
        "score": 86
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/brex.json",
      "live": {
        "slug": "brex",
        "probe": {
          "target": "https://api.brex.com",
          "method": "get",
          "lastAt": "2026-10-08T21:53:18.122029765Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 442,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 434,
          "p95ms24h": 523,
          "samples24h": 71,
          "samples30d": 71,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 71,
              "ok": 71
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.brex.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:57:43.963870022Z"
        },
        "securityTxt": {
          "url": "https://brex.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:43.637271768Z"
        },
        "pages": [
          {
            "url": "https://developer.brex.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:07.265606865Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "953aa59e7531"
          },
          {
            "url": "https://www.brex.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:48.465771046Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b6066f1a37fc"
          },
          {
            "url": "https://www.brex.com/legal/platform-agreement",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:45.950905207Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "86931ef51c0f"
          }
        ],
        "updatedAt": "2026-10-08T21:57:43.963870022Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "BILL Holdings, Inc.",
        "b": "Brex LLC",
        "name": "Vendor"
      },
      {
        "a": "https://gateway.prod.bill.com/connect",
        "b": "https://api.brex.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the BILL Developer Terms and the BILL General Terms of Service",
        "b": "Proprietary service under the Brex Platform Agreement and the Brex Access Agreement",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "43",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-05-21",
        "b": "2026-10-01",
        "name": "Last release"
      },
      {
        "a": "2026-03-03",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-01-30",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      }
    ],
    "faq": [
      {
        "answer": "BILL and Brex score within a point of each other on agent readiness, 60.9 (C) and 60.7 (C). Brex leads on agent ergonomics, security \u0026 auth and maintenance \u0026 community.",
        "question": "Which is better for AI agents, BILL or Brex?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do BILL and Brex need an API key?"
      },
      {
        "answer": "Yes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Brex at https://api.brex.com.",
        "question": "Can an agent call BILL and Brex without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 81 against 60"
        ],
        "also": [
          "No incidents deducted, where Brex loses 3 points for them"
        ],
        "goodFor": "A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.",
        "slug": "bill",
        "watchFor": "`POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes"
      },
      {
        "aheadOn": [
          "Agent ergonomics, 70 against 60",
          "Security \u0026 auth, 72 against 56",
          "Maintenance \u0026 community, 66 against 32"
        ],
        "also": null,
        "goodFor": "A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.",
        "slug": "brex",
        "watchFor": "The Expenses API update endpoint accepts only `memo`, so an outside agent can't set a category or custom field on an expense through it"
      }
    ],
    "job": {
      "capability": "spend.transactions",
      "name": "Spend transactions"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/airwallex-vs-bill.json",
        "title": "Airwallex Spend and Issuing vs BILL",
        "url": "https://www.anchorterminal.com/compare/airwallex-vs-bill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airwallex-vs-brex.json",
        "title": "Airwallex Spend and Issuing vs Brex",
        "url": "https://www.anchorterminal.com/compare/airwallex-vs-brex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-expensify.json",
        "title": "BILL vs Expensify",
        "url": "https://www.anchorterminal.com/compare/bill-vs-expensify"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-mercury.json",
        "title": "BILL vs Mercury API",
        "url": "https://www.anchorterminal.com/compare/bill-vs-mercury"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-pleo.json",
        "title": "BILL vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/bill-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-ramp.json",
        "title": "BILL vs Ramp",
        "url": "https://www.anchorterminal.com/compare/bill-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-spendesk.json",
        "title": "BILL vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/bill-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-expensify.json",
        "title": "Brex vs Expensify",
        "url": "https://www.anchorterminal.com/compare/brex-vs-expensify"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-mercury.json",
        "title": "Brex vs Mercury API",
        "url": "https://www.anchorterminal.com/compare/brex-vs-mercury"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-pleo.json",
        "title": "Brex vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-ramp.json",
        "title": "Brex vs Ramp",
        "url": "https://www.anchorterminal.com/compare/brex-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-spendesk.json",
        "title": "Brex vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-spendesk"
      }
    ],
    "scores": [
      {
        "bill": 81,
        "brex": 60,
        "by": 21,
        "edge": "bill",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "bill": 83,
        "brex": 80,
        "by": 3,
        "edge": "bill",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "bill": 60,
        "brex": 70,
        "by": 10,
        "edge": "brex",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "bill": 56,
        "brex": 72,
        "by": 16,
        "edge": "brex",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "bill": 25,
        "brex": 25,
        "by": 0,
        "edge": "",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "bill": 32,
        "brex": 66,
        "by": 34,
        "edge": "brex",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "bill": 66,
        "brex": 67,
        "by": 1,
        "edge": "brex",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "BILL and Brex score within a point of each other on agent readiness, 60.9 (C) and 60.7 (C). Brex leads on agent ergonomics, security \u0026 auth and maintenance \u0026 community. Both do spend transactions.",
    "verdicts": {
      "bill": "A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.",
      "brex": "User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/bill-vs-brex",
    "json": "https://www.anchorterminal.com/compare/bill-vs-brex.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/bill-vs-brex.md",
    "slim": "https://www.anchorterminal.com/compare/bill-vs-brex.min.md"
  },
  "markdown": "BILL and Brex score within a point of each other on agent readiness, 60.9 (C) and 60.7 (C). Brex leads on agent ergonomics, security \u0026 auth and maintenance \u0026 community. Both do spend transactions.\n\n- BILL: grade C, 60.9/100, rank #380 of 722. Markdown https://www.anchorterminal.com/tools/bill.md · JSON https://www.anchorterminal.com/api/v1/tools/bill.json\n- Brex: grade C, 60.7/100, rank #391 of 722. Markdown https://www.anchorterminal.com/tools/brex.md · JSON https://www.anchorterminal.com/api/v1/tools/brex.json\n\n## Which one, for what\n\n### BILL (C)\n\nGood for: A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.\n\nAhead on:\n- Reliability, 81 against 60\n\nAlso in its favour:\n- No incidents deducted, where Brex loses 3 points for them\n\nWatch for: `POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes\n\n### Brex (C)\n\nGood for: A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.\n\nAhead on:\n- Agent ergonomics, 70 against 60\n- Security \u0026 auth, 72 against 56\n- Maintenance \u0026 community, 66 against 32\n\nWatch for: The Expenses API update endpoint accepts only `memo`, so an outside agent can't set a category or custom field on an expense through it\n\n\n## Score by category\n\n| Category | Weight | BILL | Brex | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 81 | 60 | BILL +21 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 83 | 80 | BILL +3 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 70 | Brex +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 72 | Brex +16 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 25 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 32 | 66 | Brex +34 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 66 | 67 | Brex +1 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **60.9 · C** | **60.7 · C** | |\n\n## Facts side by side\n\n| Fact | BILL | Brex |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | BILL Holdings, Inc. | Brex LLC |\n| Hosted endpoint | `https://gateway.prod.bill.com/connect` | `https://api.brex.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under the BILL Developer Terms and the BILL General Terms of Service | Proprietary service under the Brex Platform Agreement and the Brex Access Agreement |\n| Tools exposed | none | 43 |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| Last release | 2026-05-21 | 2026-10-01 |\n| Terms last updated | 2026-03-03 | no date given |\n| Privacy policy last updated | 2026-01-30 | no date given |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | yes |\n\n## Verdicts\n\n**BILL.** A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.\n\n**Brex.** User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.\n\n## Before you call either\n\n### BILL\n\n1. Sign in with `POST /v3/login` and send `sessionId` and `devKey` as headers on every AP and AR call. The session expires after 35 minutes idle\n2. Send the `apiToken` header alone on `/v3/spend/` paths. Spend \u0026 Expense calls need no login and are limited to 60 a minute per token\n3. Complete the MFA challenge before `POST /v3/payments`. An untrusted session fails with `BDC_1361`\n4. Read back payments before retrying a failed `POST /v3/payments`. No idempotency key is accepted, so a blind retry can pay twice\n5. Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After `BDC_1144`, wait for the next hour\n\n### Brex\n\n1. Ask an account admin or card admin for a user token with only the scopes the task needs, and prefer the `.readonly` variants. A token unused for 90 days expires.\n2. Send a stored `Idempotency-Key` on every POST and PUT. Create transfer and Create card reject requests without one.\n3. Only settled transactions are returned. Poll card and cash transactions with `posted_at_start` and a lookback of at least one day.\n4. Keep under 1,000 requests in 60 seconds per client and account, and back off exponentially with jitter on 429.\n5. Send only ASCII in free-text fields, and quote the `X-Brex-Trace-Id` response header when reporting an error.\n\n## Questions\n\n### Which is better for AI agents, BILL or Brex?\n\nBILL and Brex score within a point of each other on agent readiness, 60.9 (C) and 60.7 (C). Brex leads on agent ergonomics, security \u0026 auth and maintenance \u0026 community.\n\n### Do BILL and Brex need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call BILL and Brex without installing anything?\n\nYes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Brex at https://api.brex.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/bill-vs-brex.json, and with the fewest tokens: https://www.anchorterminal.com/compare/bill-vs-brex.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"bill\", \"b\": \"brex\"}`. From a terminal: `anchor compare bill brex`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/bill.json and https://www.anchorterminal.com/api/v1/tools/brex.json\n\n## Other comparisons with BILL or Brex\n\n- [Airwallex Spend and Issuing vs BILL](https://www.anchorterminal.com/compare/airwallex-vs-bill.md)\n- [Airwallex Spend and Issuing vs Brex](https://www.anchorterminal.com/compare/airwallex-vs-brex.md)\n- [BILL vs Expensify](https://www.anchorterminal.com/compare/bill-vs-expensify.md)\n- [BILL vs Mercury API](https://www.anchorterminal.com/compare/bill-vs-mercury.md)\n- [BILL vs Pleo API + MCP](https://www.anchorterminal.com/compare/bill-vs-pleo.md)\n- [BILL vs Ramp](https://www.anchorterminal.com/compare/bill-vs-ramp.md)\n- [BILL vs Spendesk API + MCP](https://www.anchorterminal.com/compare/bill-vs-spendesk.md)\n- [Brex vs Expensify](https://www.anchorterminal.com/compare/brex-vs-expensify.md)\n- [Brex vs Mercury API](https://www.anchorterminal.com/compare/brex-vs-mercury.md)\n- [Brex vs Pleo API + MCP](https://www.anchorterminal.com/compare/brex-vs-pleo.md)\n- [Brex vs Ramp](https://www.anchorterminal.com/compare/brex-vs-ramp.md)\n- [Brex vs Spendesk API + MCP](https://www.anchorterminal.com/compare/brex-vs-spendesk.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "BILL vs Brex",
        "url": ""
      }
    ],
    "description": "BILL and Brex score within a point of each other on agent readiness, 60.9 (C) and 60.7 (C). Brex leads on agent ergonomics, security \u0026 auth and maintenance \u0026 community. Both do spend transactions. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "BILL C 60.9",
      "Brex C 60.7",
      "scores"
    ],
    "h1": "BILL vs Brex",
    "image": "https://www.anchorterminal.com/assets/og/compare-bill-vs-brex.png",
    "path": "/compare/bill-vs-brex",
    "published": "2026-10-01",
    "section": "tools",
    "title": "BILL vs Brex for AI agents, C 60.9 vs C 60.7 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/bill-vs-brex"
  },
  "tokens": {
    "markdown": 2050,
    "slim": 630
  },
  "version": 1
}
