Head to head · Spend transactions · October 2026 research run

BILL vs Pleo API + MCP

Pleo API + MCP scores 62.9 (B) on agent readiness against BILL's 60.9 (C), and leads in 3 of 7 scored categories. BILL leads on reliability, agent ergonomics and payments & pricing. Both do spend transactions.

Which one, for what

BILL C

Good for A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.

Ahead on

  • Reliability, 81 against 71
  • Agent ergonomics, 60 against 55
  • Payments & pricing, 25 against 15

Watch for

POST /v3/login takes a user's username and password with a developer key, and the session carries that user's role with no scopes

Pleo API + MCP B

Good for An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.

Ahead on

  • Security & auth, 71 against 56
  • Maintenance & community, 64 against 32
  • Transparency & trust, 75 against 66

Watch for

The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)

Score by category

CategoryWeight this runBILLPleo API + MCPEdge
Reliability16%208171BILL +10
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28382BILL +1
Agent ergonomics13%16.26055BILL +5
Security & auth14%17.55671Pleo API + MCP +15
Payments & pricing10%12.52515BILL +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.83264Pleo API + MCP +32
Transparency & trust7%8.86675Pleo API + MCP +9
Negative events≤1500
Total60.9 · C62.9 · B

Facts side by side

FactBILLPleo API + MCP
KindHTTP APIHTTP API
VendorBILL Holdings, Inc.Pleo Technologies A/S
Hosted endpointhttps://gateway.prod.bill.com/connecthttps://external.pleo.io
TransportsHTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumPaid
x402nono
LicenceProprietary service under the BILL Developer Terms and the BILL General Terms of ServiceProprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms
Read-only variant documentednono
llms.txtyesyes
Last release2026-05-212026-10-02
Terms last updated2026-03-03no date given
Privacy policy last updated2026-01-30
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text

Verdicts

BILL

A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.

Pleo API + MCP

The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.

Before you call either

BILL

  1. Sign in with POST /v3/login and send sessionId and devKey as headers on every AP and AR call. The session expires after 35 minutes idle
  2. Send the apiToken header alone on /v3/spend/ paths. Spend & Expense calls need no login and are limited to 60 a minute per token
  3. Complete the MFA challenge before POST /v3/payments. An untrusted session fails with BDC_1361
  4. Read back payments before retrying a failed POST /v3/payments. No idempotency key is accepted, so a blind retry can pay twice
  5. Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After BDC_1144, wait for the next hour

Pleo API + MCP

  1. Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default
  2. Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist
  3. Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side
  4. Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there
  5. Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second
  6. Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in

Questions

Which is better for AI agents, BILL or Pleo API + MCP?

Pleo API + MCP scores 62.9 (B) on agent readiness against BILL's 60.9 (C), and leads in 3 of 7 scored categories. BILL leads on reliability, agent ergonomics and payments & pricing.

Do BILL and Pleo API + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call BILL and Pleo API + MCP without installing anything?

Yes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Pleo API + MCP at https://external.pleo.io.

Other comparisons with BILL or Pleo API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.