Head to head · Spend transactions · October 2026 research run

BILL vs Payhawk API + MCP

BILL scores 60.9 (C) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 4 of 7 scored categories. Payhawk API + MCP leads on security & auth, maintenance & community and transparency & trust. Both do spend transactions.

Which one, for what

BILL C

Good for A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.

Ahead on

  • Reliability, 81 against 58
  • Schema & documentation, 83 against 71
  • Agent ergonomics, 60 against 52
  • Payments & pricing, 25 against 13

Watch for

POST /v3/login takes a user's username and password with a developer key, and the session carries that user's role with no scopes

Payhawk API + MCP C

Good for A finance team already on Payhawk that wants an ERP or accounting sync, master data kept in step, purchase orders raised from another system, or an assistant that answers spend questions and prepares approvals.

Ahead on

  • Security & auth, 71 against 56
  • Maintenance & community, 53 against 32
  • Transparency & trust, 78 against 66

Watch for

No self-serve route. The API needs a Payhawk customer account, and a development sandbox is requested through a form

Score by category

CategoryWeight this runBILLPayhawk API + MCPEdge
Reliability16%208158BILL +23
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28371BILL +12
Agent ergonomics13%16.26052BILL +8
Security & auth14%17.55671Payhawk API + MCP +15
Payments & pricing10%12.52513BILL +12
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.83253Payhawk API + MCP +21
Transparency & trust7%8.86678Payhawk API + MCP +12
Negative events≤1500
Total60.9 · C57.1 · C

Facts side by side

FactBILLPayhawk API + MCP
KindHTTP APIHTTP API
VendorBILL Holdings, Inc.Payhawk Limited
Hosted endpointhttps://gateway.prod.bill.com/connecthttps://api.payhawk.com
TransportsHTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumPaid
x402nono
LicenceProprietary service under the BILL Developer Terms and the BILL General Terms of ServiceProprietary service under Payhawk's general terms and conditions
Tools exposednone82
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-05-212026-10-08
Terms last updated2026-03-032025-12-09
Privacy policy last updated2026-01-302026-06-29
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text

Verdicts

BILL

A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.

Payhawk API + MCP

The Developer API has a public OpenAPI 3.1 definition with 179 operations, read-only or full-access keys and a published limit of 15 requests a second. It needs a Payhawk customer account, no official SDK or API changelog was found, and the 82-tool MCP server is added by hand because it is not yet in the assistant directories.

Before you call either

BILL

  1. Sign in with POST /v3/login and send sessionId and devKey as headers on every AP and AR call. The session expires after 35 minutes idle
  2. Send the apiToken header alone on /v3/spend/ paths. Spend & Expense calls need no login and are limited to 60 a minute per token
  3. Complete the MFA challenge before POST /v3/payments. An untrusted session fails with BDC_1361
  4. Read back payments before retrying a failed POST /v3/payments. No idempotency key is accepted, so a blind retry can pay twice
  5. Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After BDC_1144, wait for the next hour

Payhawk API + MCP

  1. Send the key in X-Payhawk-ApiKey or as a Bearer token to https://api.payhawk.com/api/v3. A read-only key returns 403 on writes
  2. Page lists with $skip and $take. The help centre gives 1,000 a page and the definition a maximum of 10,000, so count what comes back
  3. Pass $filter as URL-encoded JSON, for example {"status":{"$equal":"draft"}}. Date filters compare the date part only
  4. Keep to 15 requests a second and wait for Retry-After on a 429. Do not send Idempotency-Key when creating a per diem expense, which returns 400
  5. Use a group-level key and the /groups/{groupId} paths for master data in a multi-entity group. Expenses and payments stay on account paths

Questions

Which is better for AI agents, BILL or Payhawk API + MCP?

BILL scores 60.9 (C) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 4 of 7 scored categories. Payhawk API + MCP leads on security & auth, maintenance & community and transparency & trust.

Do BILL and Payhawk API + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call BILL and Payhawk API + MCP without installing anything?

Yes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Payhawk API + MCP at https://api.payhawk.com.

Other comparisons with BILL or Payhawk API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.