{
  "data": {
    "a": {
      "slug": "bill",
      "name": "BILL",
      "vendor": "BILL Holdings, Inc.",
      "vendorUrl": "https://www.bill.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "BILL is a US financial operations platform for accounts payable, accounts receivable and company card spend. Its v3 REST API reads and writes bills, payments, invoices, budgets, cards, transactions and reimbursements, and an MCP server in beta gives read-only access.",
      "url": "https://www.anchorterminal.com/tools/bill",
      "markdownUrl": "https://www.anchorterminal.com/tools/bill.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/bill.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/bill.json",
      "license": "Proprietary service under the BILL Developer Terms and the BILL General Terms of Service",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://gateway.prod.bill.com/connect",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is self-serve. A person signs up for a sandbox or production account in a browser and generates a developer key under Settings \u003e Sync \u0026 Integrations \u003e Manage Developer Keys after accepting the Developer Terms. The AP and AR API signs in with `POST /v3/login` using a username, password, organisation ID and `devKey`, and returns a `sessionId` that expires after 35 minutes idle and carries the user's role, with no scopes. Payments and bank account changes need a session trusted by multi-factor authentication. The Spend \u0026 Expense API takes an `apiToken` header that an ADMIN user generates, with no login. App partners request their developer key by email and use customer sync tokens that can't make payments. The MCP server uses OAuth through auth.bill.com with PKCE, and clients other than Claude and ChatGPT need approval by email.",
      "pricing": "freemium",
      "pricingNotes": "No separate API fee is published. bill.com/product/pricing lists API access on every plan. AP and AR plans are Essentials at $49, Team at $65 and Corporate at $89 per user per month, with Enterprise on request, and Spend \u0026 Expense at $0 per user per month, which needs an approved credit application. Payment types such as cheques, ACH and international transfers carry per-transaction fees. The sandbox is self-serve and free, and production has a 30-day trial. The Developer Terms mention API licence and development fees set on the developer site or an order form (checked 2026-10-08).",
      "priceSummary": "$49 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI files or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.bill.com/docs/home",
      "llmsTxt": "https://developer.bill.com/llms.txt",
      "openapi": "https://developer.bill.com/openapi/bill-v3-api.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "accounting.invoices"
      ],
      "tags": [
        "hosted",
        "freemium",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-05-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.9,
        "grade": "C",
        "agentReady": false,
        "rank": 441,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 32,
          "payments": 25,
          "reliability": 81,
          "schema": 83,
          "security": 56,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.",
        "bestFor": "A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.",
        "strengths": [
          "Two public OpenAPI 3.0.1 files cover 326 operations, with llms.txt, a Markdown copy of every docs page and a docs MCP server at `https://developer.bill.com/mcp`",
          "Creating a payment, adding a funding bank account and enabling vendor auto-pay need an API session trusted by multi-factor authentication",
          "The sandbox is self-serve through a sign-up form, charges no subscription fee and moves no real money",
          "www.billcomstatus.com lists an API Servers component and shows no incident after 15 April 2026",
          "The Developer Terms commit BILL to commercially reasonable efforts at 30 days' notice of deprecations and breaking changes"
        ],
        "weaknesses": [
          "`POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes",
          "No idempotency key is accepted on the 203 write operations of the v3 API, payments included. `X-Idempotent-Key` exists only on two webhook subscription calls",
          "The MCP server is beta, read-only and limited to US organisations, and MCP clients other than Claude and ChatGPT need BILL's approval by email",
          "The changelog's latest entry is dated 21 May 2026, and the MCP server has no entry there",
          "No official SDK, sub-processor list, data processing agreement or security.txt was found, and the audit trail endpoint covers vendors only"
        ],
        "agentNotes": [
          "Sign in with `POST /v3/login` and send `sessionId` and `devKey` as headers on every AP and AR call. The session expires after 35 minutes idle",
          "Send the `apiToken` header alone on `/v3/spend/` paths. Spend \u0026 Expense calls need no login and are limited to 60 a minute per token",
          "Complete the MFA challenge before `POST /v3/payments`. An untrusted session fails with `BDC_1361`",
          "Read back payments before retrying a failed `POST /v3/payments`. No idempotency key is accepted, so a blind retry can pay twice",
          "Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After `BDC_1144`, wait for the next hour"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.9
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 32,
          "payments": 25,
          "reliability": 81,
          "schema": 83,
          "security": 56,
          "transparency": 44
        },
        "provenanceScore": 88
      },
      "connect": {
        "http": "curl --request POST \\\n--url 'https://gateway.stage.bill.com/connect/v3/login' \\\n--header 'content-type: application/json' \\\n--data '{\n  \"username\": \"{username}\", \n  \"password\": \"{password}\",\n  \"organizationId\": \"{organization_id}\", \n  \"devKey\": \"{developer_key}\"\n}'"
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/bill"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Spend \u0026 Expense",
          "unit": "seat-month",
          "usd": 0,
          "note": "API access listed. Needs an approved credit application"
        },
        {
          "item": "AP and AR Essentials",
          "unit": "seat-month",
          "usd": 49,
          "note": "API access listed. Per-transaction payment fees apply"
        },
        {
          "item": "AP and AR Team",
          "unit": "seat-month",
          "usd": 65,
          "note": "API access listed"
        },
        {
          "item": "AP and AR Corporate",
          "unit": "seat-month",
          "usd": 89,
          "note": "Enterprise is priced on request"
        }
      ],
      "provenance": {
        "legalEntity": "Bill.com, LLC",
        "domain": "bill.com",
        "domainRegistered": "1994-11-03",
        "endpointOnVendorDomain": true,
        "terms": "https://developer.bill.com/docs/bill-developer-terms",
        "privacy": "https://www.bill.com/privacy",
        "statusPage": "https://www.billcomstatus.com",
        "changelog": "https://developer.bill.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Developer Terms (effective 3 March 2026) are between the developer and Bill.com, LLC and its affiliates, and are accepted when a developer key is generated. The parent company named in the privacy notice is BILL Holdings, Inc.",
          "The BILL Privacy Notice (effective 30 January 2026) names BILL Holdings, Inc. and its subsidiaries Bill.com, LLC, DivvyPay, LLC and Invoice2go, LLC, of San Jose, California.",
          "The API answers at gateway.prod.bill.com and gateway.stage.bill.com, and OAuth for the MCP server at auth.bill.com. The docs send card number decoding to api.divvy.co, a second domain of the vendor's.",
          "The status page is on a separate domain, www.billcomstatus.com, linked from the developer docs. status.bill.com and trust.bill.com didn't answer.",
          "www.bill.com/.well-known/security.txt and www.bill.com/security.txt return 404. The security page sends reports to a HackerOne vulnerability disclosure programme.",
          "The BILL General Terms of Service (last updated 10 February 2025) and separate Spend \u0026 Expense terms govern a customer's account. No data processing agreement or sub-processor list was found on the legal index.",
          "RDAP for bill.com gives a registration date of 1994-11-03 and GoDaddy Corporate Domains, LLC as registrar."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/bill.json",
      "live": {
        "slug": "bill",
        "probe": {
          "target": "https://gateway.prod.bill.com/connect",
          "method": "get",
          "lastAt": "2026-10-09T11:28:55.292087407Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 448,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 449,
          "p95ms24h": 483,
          "samples24h": 172,
          "samples30d": 172,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 50,
              "ok": 50
            },
            {
              "date": "2026-10-09",
              "probes": 122,
              "ok": 122
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.billcomstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T11:25:59.564241535Z"
        },
        "updatedAt": "2026-10-09T11:28:55.292087407Z"
      }
    },
    "answer": "BILL scores 60.9 (C) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 4 of 7 scored categories. Payhawk API + MCP leads on security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust.",
    "b": {
      "slug": "payhawk",
      "name": "Payhawk API + MCP",
      "vendor": "Payhawk Limited",
      "vendorUrl": "https://payhawk.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Spend management platform from Payhawk Limited in London, covering company cards, expenses, bills, purchase orders and travel. Outside agents reach it through a REST Developer API with read-only or full-access keys, and a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/payhawk",
      "markdownUrl": "https://www.anchorterminal.com/tools/payhawk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payhawk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payhawk.json",
      "license": "Proprietary service under Payhawk's general terms and conditions",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.payhawk.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access needs a Payhawk customer account. An Administrator, an IT Administrator or a user with a custom role creates an API key in the portal under Settings, Integrations, choosing read-only or full access, and can regenerate it. The key goes in the `X-Payhawk-ApiKey` header or as a Bearer token. Two system-generated keys per account cannot be deleted by users. Group-level keys reach the group endpoints. If the key is not active, the API page says to write to partners@payhawk.com. The MCP server accepts OAuth 2 authorisation code with PKCE, where each user signs in with a Payhawk login and the assistant acts with that user's role.",
      "pricing": "paid",
      "pricingNotes": "Sold by quote per module (Travel, Cards and Expenses, Accounts Payable, Procurement) on annual or multi-year contracts, with unit-based charges for extra cards, reimbursements, purchase orders and invoices. The one published price is the Growth programme at 149 pounds a month for single-entity firms in the UK or EEA with fewer than 20 employees, with an optional 7-day trial for eligible customers. The API page says the API is free for all Payhawk accounts, and the pricing page lists Developer API access and the MCP server in the modules. A development sandbox is requested through a form on the API page (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the OpenAPI definition, the help centre or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 82,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.payhawk.com",
      "llmsTxt": "https://payhawk.com/llms.txt",
      "openapi": "https://api.payhawk.com/api/v3/docs.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "spend.procurement"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sales-led",
        "status-page",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.1,
        "grade": "C",
        "agentReady": false,
        "rank": 561,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 52,
          "maintenance": 53,
          "payments": 13,
          "reliability": 58,
          "schema": 71,
          "security": 71,
          "transparency": 78
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The Developer API has a public OpenAPI 3.1 definition with 179 operations, read-only or full-access keys and a published limit of 15 requests a second. It needs a Payhawk customer account, no official SDK or API changelog was found, and the 82-tool MCP server is added by hand because it is not yet in the assistant directories.",
        "bestFor": "A finance team already on Payhawk that wants an ERP or accounting sync, master data kept in step, purchase orders raised from another system, or an assistant that answers spend questions and prepares approvals.",
        "strengths": [
          "Public OpenAPI 3.1 definition with 105 paths and 179 operations, covering expenses, cards, fund accounts, suppliers, purchase orders and 24 webhook event types",
          "API keys are created as read-only or full access, sent in a header, and managed by administrators or a custom role",
          "The limit of 15 requests a second is stated on every operation, and responses carry RateLimit headers with Retry-After on a 429",
          "The MCP server acts with the signed-in user's own role, previews every write for confirmation, and never starts a payment or transfer",
          "SOC 1 and SOC 2 Type 2, ISO 27001, PCI DSS Level 1 and a penetration test attestation are downloadable from the trust page"
        ],
        "weaknesses": [
          "No self-serve route. The API needs a Payhawk customer account, and a development sandbox is requested through a form",
          "No official SDK on npm or PyPI, no API changelog and no deprecation policy were found. Release notes cover the product only",
          "The API page's FAQ contradicts the definition on the host name, the page size and whether expenses can be created or reviewed",
          "The status page is drawn by script, so its incident history could not be read. The terms disclaim service levels",
          "The MCP server has 82 tools, is not in the official MCP registry, and no guidance on prompt injection was found"
        ],
        "agentNotes": [
          "Send the key in `X-Payhawk-ApiKey` or as a Bearer token to `https://api.payhawk.com/api/v3`. A read-only key returns 403 on writes",
          "Page lists with `$skip` and `$take`. The help centre gives 1,000 a page and the definition a maximum of 10,000, so count what comes back",
          "Pass `$filter` as URL-encoded JSON, for example `{\"status\":{\"$equal\":\"draft\"}}`. Date filters compare the date part only",
          "Keep to 15 requests a second and wait for `Retry-After` on a 429. Do not send `Idempotency-Key` when creating a per diem expense, which returns 400",
          "Use a group-level key and the `/groups/{groupId}` paths for master data in a multi-entity group. Expenses and payments stay on account paths"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.1
          }
        ],
        "editorialScores": {
          "ergonomics": 52,
          "maintenance": 53,
          "payments": 13,
          "reliability": 58,
          "schema": 71,
          "security": 71,
          "transparency": 55
        },
        "provenanceScore": 100
      },
      "connect": {
        "http": "curl https://api.payhawk.com/api/v3/accounts/YOUR_ACCOUNT_ID/fund-accounts \\\n  -H \"X-Payhawk-ApiKey: YOUR_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/payhawk"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Payhawk Limited",
        "domain": "payhawk.com",
        "domainRegistered": "2003-07-06",
        "endpointOnVendorDomain": true,
        "terms": "https://payhawk.com/terms",
        "privacy": "https://payhawk.com/privacy",
        "statusPage": "https://status.payhawk.com",
        "changelog": "https://payhawk.com/release-notes",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms name Payhawk Limited (company number 11747263, Chancery House, 53-64 Chancery Lane, London WC2A 1QS) as the contracting entity worldwide and Payhawk Inc., a Delaware corporation, in the US. Payhawk EOOD in Sofia owns the platform.",
          "Cards are issued by Payhawk Financial Services UAB in the EEA, Payhawk Financial Services Limited in the UK and Cross River Bank in the US, per the site footer.",
          "The API answers at api.payhawk.com and the MCP server at mcp.payhawk.com. An unauthenticated POST to /mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata.",
          "payhawk.com/.well-known/security.txt has a contact, a policy link and an expiry of 1 January 2030.",
          "The terms were last updated on 9 December 2025, the privacy policy on 29 June 2026 and the Data Processing Addendum on 26 June 2026.",
          "The release notes cover the product. No changelog for the API was found.",
          "RDAP for payhawk.com gives a registration date of 2003-07-06. The terms' company number dates the company later, so the domain predates the vendor."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payhawk.json",
      "live": {
        "slug": "payhawk",
        "probe": {
          "target": "https://api.payhawk.com",
          "method": "get",
          "lastAt": "2026-10-09T11:29:09.063638464Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 48,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 55,
          "p95ms24h": 123,
          "samples24h": 41,
          "samples30d": 41,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 41,
              "ok": 41
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.payhawk.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:24.812233514Z"
        },
        "updatedAt": "2026-10-09T11:29:09.063638464Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "BILL Holdings, Inc.",
        "b": "Payhawk Limited",
        "name": "Vendor"
      },
      {
        "a": "https://gateway.prod.bill.com/connect",
        "b": "https://api.payhawk.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the BILL Developer Terms and the BILL General Terms of Service",
        "b": "Proprietary service under Payhawk's general terms and conditions",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "82",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-05-21",
        "b": "2026-10-08",
        "name": "Last release"
      },
      {
        "a": "2026-03-03",
        "b": "2025-12-09",
        "name": "Terms last updated"
      },
      {
        "a": "2026-01-30",
        "b": "2026-06-29",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      }
    ],
    "faq": [
      {
        "answer": "BILL scores 60.9 (C) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 4 of 7 scored categories. Payhawk API + MCP leads on security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust.",
        "question": "Which is better for AI agents, BILL or Payhawk API + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do BILL and Payhawk API + MCP need an API key?"
      },
      {
        "answer": "Yes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Payhawk API + MCP at https://api.payhawk.com.",
        "question": "Can an agent call BILL and Payhawk API + MCP without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 81 against 58",
          "Schema \u0026 documentation, 83 against 71",
          "Agent ergonomics, 60 against 52",
          "Payments \u0026 pricing, 25 against 13"
        ],
        "also": null,
        "goodFor": "A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.",
        "slug": "bill",
        "watchFor": "`POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 71 against 56",
          "Maintenance \u0026 community, 53 against 32",
          "Transparency \u0026 trust, 78 against 66"
        ],
        "also": null,
        "goodFor": "A finance team already on Payhawk that wants an ERP or accounting sync, master data kept in step, purchase orders raised from another system, or an assistant that answers spend questions and prepares approvals.",
        "slug": "payhawk",
        "watchFor": "No self-serve route. The API needs a Payhawk customer account, and a development sandbox is requested through a form"
      }
    ],
    "job": {
      "capability": "spend.transactions",
      "name": "Spend transactions"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/airwallex-vs-bill.json",
        "title": "Airwallex Spend and Issuing vs BILL",
        "url": "https://www.anchorterminal.com/compare/airwallex-vs-bill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airwallex-vs-payhawk.json",
        "title": "Airwallex Spend and Issuing vs Payhawk API + MCP",
        "url": "https://www.anchorterminal.com/compare/airwallex-vs-payhawk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-brex.json",
        "title": "BILL vs Brex",
        "url": "https://www.anchorterminal.com/compare/bill-vs-brex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-expensify.json",
        "title": "BILL vs Expensify",
        "url": "https://www.anchorterminal.com/compare/bill-vs-expensify"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-mercury.json",
        "title": "BILL vs Mercury API",
        "url": "https://www.anchorterminal.com/compare/bill-vs-mercury"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-pleo.json",
        "title": "BILL vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/bill-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-ramp.json",
        "title": "BILL vs Ramp",
        "url": "https://www.anchorterminal.com/compare/bill-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-spendesk.json",
        "title": "BILL vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/bill-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-payhawk.json",
        "title": "Brex vs Payhawk API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-payhawk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expensify-vs-payhawk.json",
        "title": "Expensify vs Payhawk API + MCP",
        "url": "https://www.anchorterminal.com/compare/expensify-vs-payhawk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mercury-vs-payhawk.json",
        "title": "Mercury API vs Payhawk API + MCP",
        "url": "https://www.anchorterminal.com/compare/mercury-vs-payhawk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payhawk-vs-pleo.json",
        "title": "Payhawk API + MCP vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/payhawk-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payhawk-vs-ramp.json",
        "title": "Payhawk API + MCP vs Ramp",
        "url": "https://www.anchorterminal.com/compare/payhawk-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payhawk-vs-spendesk.json",
        "title": "Payhawk API + MCP vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/payhawk-vs-spendesk"
      }
    ],
    "scores": [
      {
        "bill": 81,
        "by": 23,
        "edge": "bill",
        "key": "reliability",
        "name": "Reliability",
        "payhawk": 58,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "bill": 83,
        "by": 12,
        "edge": "bill",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payhawk": 71,
        "weight": 13
      },
      {
        "bill": 60,
        "by": 8,
        "edge": "bill",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payhawk": 52,
        "weight": 13
      },
      {
        "bill": 56,
        "by": 15,
        "edge": "payhawk",
        "key": "security",
        "name": "Security \u0026 auth",
        "payhawk": 71,
        "weight": 14
      },
      {
        "bill": 25,
        "by": 12,
        "edge": "bill",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payhawk": 13,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "bill": 32,
        "by": 21,
        "edge": "payhawk",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payhawk": 53,
        "weight": 7
      },
      {
        "bill": 66,
        "by": 12,
        "edge": "payhawk",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payhawk": 78,
        "weight": 7
      }
    ],
    "summary": "BILL scores 60.9 (C) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 4 of 7 scored categories. Payhawk API + MCP leads on security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust. Both do spend transactions.",
    "verdicts": {
      "bill": "A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.",
      "payhawk": "The Developer API has a public OpenAPI 3.1 definition with 179 operations, read-only or full-access keys and a published limit of 15 requests a second. It needs a Payhawk customer account, no official SDK or API changelog was found, and the 82-tool MCP server is added by hand because it is not yet in the assistant directories."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/bill-vs-payhawk",
    "json": "https://www.anchorterminal.com/compare/bill-vs-payhawk.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/bill-vs-payhawk.md",
    "slim": "https://www.anchorterminal.com/compare/bill-vs-payhawk.min.md"
  },
  "markdown": "BILL scores 60.9 (C) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 4 of 7 scored categories. Payhawk API + MCP leads on security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust. Both do spend transactions.\n\n- BILL: grade C, 60.9/100, rank #441 of 842. Markdown https://www.anchorterminal.com/tools/bill.md · JSON https://www.anchorterminal.com/api/v1/tools/bill.json\n- Payhawk API + MCP: grade C, 57.1/100, rank #561 of 842. Markdown https://www.anchorterminal.com/tools/payhawk.md · JSON https://www.anchorterminal.com/api/v1/tools/payhawk.json\n\n## Which one, for what\n\n### BILL (C)\n\nGood for: A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.\n\nAhead on:\n- Reliability, 81 against 58\n- Schema \u0026 documentation, 83 against 71\n- Agent ergonomics, 60 against 52\n- Payments \u0026 pricing, 25 against 13\n\nWatch for: `POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes\n\n### Payhawk API + MCP (C)\n\nGood for: A finance team already on Payhawk that wants an ERP or accounting sync, master data kept in step, purchase orders raised from another system, or an assistant that answers spend questions and prepares approvals.\n\nAhead on:\n- Security \u0026 auth, 71 against 56\n- Maintenance \u0026 community, 53 against 32\n- Transparency \u0026 trust, 78 against 66\n\nWatch for: No self-serve route. The API needs a Payhawk customer account, and a development sandbox is requested through a form\n\n\n## Score by category\n\n| Category | Weight | BILL | Payhawk API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 81 | 58 | BILL +23 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 83 | 71 | BILL +12 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 52 | BILL +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 71 | Payhawk API + MCP +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 13 | BILL +12 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 32 | 53 | Payhawk API + MCP +21 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 66 | 78 | Payhawk API + MCP +12 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **60.9 · C** | **57.1 · C** | |\n\n## Facts side by side\n\n| Fact | BILL | Payhawk API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | BILL Holdings, Inc. | Payhawk Limited |\n| Hosted endpoint | `https://gateway.prod.bill.com/connect` | `https://api.payhawk.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Paid |\n| x402 | no | no |\n| Licence | Proprietary service under the BILL Developer Terms and the BILL General Terms of Service | Proprietary service under Payhawk's general terms and conditions |\n| Tools exposed | none | 82 |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| Last release | 2026-05-21 | 2026-10-08 |\n| Terms last updated | 2026-03-03 | 2025-12-09 |\n| Privacy policy last updated | 2026-01-30 | 2026-06-29 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n\n## Verdicts\n\n**BILL.** A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.\n\n**Payhawk API + MCP.** The Developer API has a public OpenAPI 3.1 definition with 179 operations, read-only or full-access keys and a published limit of 15 requests a second. It needs a Payhawk customer account, no official SDK or API changelog was found, and the 82-tool MCP server is added by hand because it is not yet in the assistant directories.\n\n## Before you call either\n\n### BILL\n\n1. Sign in with `POST /v3/login` and send `sessionId` and `devKey` as headers on every AP and AR call. The session expires after 35 minutes idle\n2. Send the `apiToken` header alone on `/v3/spend/` paths. Spend \u0026 Expense calls need no login and are limited to 60 a minute per token\n3. Complete the MFA challenge before `POST /v3/payments`. An untrusted session fails with `BDC_1361`\n4. Read back payments before retrying a failed `POST /v3/payments`. No idempotency key is accepted, so a blind retry can pay twice\n5. Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After `BDC_1144`, wait for the next hour\n\n### Payhawk API + MCP\n\n1. Send the key in `X-Payhawk-ApiKey` or as a Bearer token to `https://api.payhawk.com/api/v3`. A read-only key returns 403 on writes\n2. Page lists with `$skip` and `$take`. The help centre gives 1,000 a page and the definition a maximum of 10,000, so count what comes back\n3. Pass `$filter` as URL-encoded JSON, for example `{\"status\":{\"$equal\":\"draft\"}}`. Date filters compare the date part only\n4. Keep to 15 requests a second and wait for `Retry-After` on a 429. Do not send `Idempotency-Key` when creating a per diem expense, which returns 400\n5. Use a group-level key and the `/groups/{groupId}` paths for master data in a multi-entity group. Expenses and payments stay on account paths\n\n## Questions\n\n### Which is better for AI agents, BILL or Payhawk API + MCP?\n\nBILL scores 60.9 (C) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 4 of 7 scored categories. Payhawk API + MCP leads on security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust.\n\n### Do BILL and Payhawk API + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call BILL and Payhawk API + MCP without installing anything?\n\nYes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Payhawk API + MCP at https://api.payhawk.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/bill-vs-payhawk.json, and with the fewest tokens: https://www.anchorterminal.com/compare/bill-vs-payhawk.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"bill\", \"b\": \"payhawk\"}`. From a terminal: `anchor compare bill payhawk`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/bill.json and https://www.anchorterminal.com/api/v1/tools/payhawk.json\n\n## Other comparisons with BILL or Payhawk API + MCP\n\n- [Airwallex Spend and Issuing vs BILL](https://www.anchorterminal.com/compare/airwallex-vs-bill.md)\n- [Airwallex Spend and Issuing vs Payhawk API + MCP](https://www.anchorterminal.com/compare/airwallex-vs-payhawk.md)\n- [BILL vs Brex](https://www.anchorterminal.com/compare/bill-vs-brex.md)\n- [BILL vs Expensify](https://www.anchorterminal.com/compare/bill-vs-expensify.md)\n- [BILL vs Mercury API](https://www.anchorterminal.com/compare/bill-vs-mercury.md)\n- [BILL vs Pleo API + MCP](https://www.anchorterminal.com/compare/bill-vs-pleo.md)\n- [BILL vs Ramp](https://www.anchorterminal.com/compare/bill-vs-ramp.md)\n- [BILL vs Spendesk API + MCP](https://www.anchorterminal.com/compare/bill-vs-spendesk.md)\n- [Brex vs Payhawk API + MCP](https://www.anchorterminal.com/compare/brex-vs-payhawk.md)\n- [Expensify vs Payhawk API + MCP](https://www.anchorterminal.com/compare/expensify-vs-payhawk.md)\n- [Mercury API vs Payhawk API + MCP](https://www.anchorterminal.com/compare/mercury-vs-payhawk.md)\n- [Payhawk API + MCP vs Pleo API + MCP](https://www.anchorterminal.com/compare/payhawk-vs-pleo.md)\n- [Payhawk API + MCP vs Ramp](https://www.anchorterminal.com/compare/payhawk-vs-ramp.md)\n- [Payhawk API + MCP vs Spendesk API + MCP](https://www.anchorterminal.com/compare/payhawk-vs-spendesk.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "BILL vs Payhawk API + MCP",
        "url": ""
      }
    ],
    "description": "BILL scores 60.9 (C) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 4 of 7 scored categories. Payhawk API + MCP leads on security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust. Both do spend transactions. Category scores, facts, verdicts and…",
    "facts": [
      "BILL C 60.9",
      "Payhawk API + MCP C 57.1",
      "scores"
    ],
    "h1": "BILL vs Payhawk API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-bill-vs-payhawk.png",
    "path": "/compare/bill-vs-payhawk",
    "published": "2026-10-01",
    "section": "tools",
    "title": "BILL vs Payhawk API + MCP for AI agents, C 60.9 vs C 57.1",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/bill-vs-payhawk"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 680
  },
  "version": 1
}
