{
  "data": {
    "a": {
      "slug": "bill",
      "name": "BILL",
      "vendor": "BILL Holdings, Inc.",
      "vendorUrl": "https://www.bill.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "BILL is a US financial operations platform for accounts payable, accounts receivable and company card spend. Its v3 REST API reads and writes bills, payments, invoices, budgets, cards, transactions and reimbursements, and an MCP server in beta gives read-only access.",
      "url": "https://www.anchorterminal.com/tools/bill",
      "markdownUrl": "https://www.anchorterminal.com/tools/bill.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/bill.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/bill.json",
      "license": "Proprietary service under the BILL Developer Terms and the BILL General Terms of Service",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://gateway.prod.bill.com/connect",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is self-serve. A person signs up for a sandbox or production account in a browser and generates a developer key under Settings \u003e Sync \u0026 Integrations \u003e Manage Developer Keys after accepting the Developer Terms. The AP and AR API signs in with `POST /v3/login` using a username, password, organisation ID and `devKey`, and returns a `sessionId` that expires after 35 minutes idle and carries the user's role, with no scopes. Payments and bank account changes need a session trusted by multi-factor authentication. The Spend \u0026 Expense API takes an `apiToken` header that an ADMIN user generates, with no login. App partners request their developer key by email and use customer sync tokens that can't make payments. The MCP server uses OAuth through auth.bill.com with PKCE, and clients other than Claude and ChatGPT need approval by email.",
      "pricing": "freemium",
      "pricingNotes": "No separate API fee is published. bill.com/product/pricing lists API access on every plan. AP and AR plans are Essentials at $49, Team at $65 and Corporate at $89 per user per month, with Enterprise on request, and Spend \u0026 Expense at $0 per user per month, which needs an approved credit application. Payment types such as cheques, ACH and international transfers carry per-transaction fees. The sandbox is self-serve and free, and production has a 30-day trial. The Developer Terms mention API licence and development fees set on the developer site or an order form (checked 2026-10-08).",
      "priceSummary": "$49 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI files or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.bill.com/docs/home",
      "llmsTxt": "https://developer.bill.com/llms.txt",
      "openapi": "https://developer.bill.com/openapi/bill-v3-api.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "accounting.invoices"
      ],
      "tags": [
        "hosted",
        "freemium",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-05-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.9,
        "grade": "C",
        "agentReady": false,
        "rank": 380,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 32,
          "payments": 25,
          "reliability": 81,
          "schema": 83,
          "security": 56,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.",
        "bestFor": "A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.",
        "strengths": [
          "Two public OpenAPI 3.0.1 files cover 326 operations, with llms.txt, a Markdown copy of every docs page and a docs MCP server at `https://developer.bill.com/mcp`",
          "Creating a payment, adding a funding bank account and enabling vendor auto-pay need an API session trusted by multi-factor authentication",
          "The sandbox is self-serve through a sign-up form, charges no subscription fee and moves no real money",
          "www.billcomstatus.com lists an API Servers component and shows no incident after 15 April 2026",
          "The Developer Terms commit BILL to commercially reasonable efforts at 30 days' notice of deprecations and breaking changes"
        ],
        "weaknesses": [
          "`POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes",
          "No idempotency key is accepted on the 203 write operations of the v3 API, payments included. `X-Idempotent-Key` exists only on two webhook subscription calls",
          "The MCP server is beta, read-only and limited to US organisations, and MCP clients other than Claude and ChatGPT need BILL's approval by email",
          "The changelog's latest entry is dated 21 May 2026, and the MCP server has no entry there",
          "No official SDK, sub-processor list, data processing agreement or security.txt was found, and the audit trail endpoint covers vendors only"
        ],
        "agentNotes": [
          "Sign in with `POST /v3/login` and send `sessionId` and `devKey` as headers on every AP and AR call. The session expires after 35 minutes idle",
          "Send the `apiToken` header alone on `/v3/spend/` paths. Spend \u0026 Expense calls need no login and are limited to 60 a minute per token",
          "Complete the MFA challenge before `POST /v3/payments`. An untrusted session fails with `BDC_1361`",
          "Read back payments before retrying a failed `POST /v3/payments`. No idempotency key is accepted, so a blind retry can pay twice",
          "Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After `BDC_1144`, wait for the next hour"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.9
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 32,
          "payments": 25,
          "reliability": 81,
          "schema": 83,
          "security": 56,
          "transparency": 44
        },
        "provenanceScore": 88
      },
      "connect": {
        "http": "curl --request POST \\\n--url 'https://gateway.stage.bill.com/connect/v3/login' \\\n--header 'content-type: application/json' \\\n--data '{\n  \"username\": \"{username}\", \n  \"password\": \"{password}\",\n  \"organizationId\": \"{organization_id}\", \n  \"devKey\": \"{developer_key}\"\n}'"
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/bill"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Spend \u0026 Expense",
          "unit": "seat-month",
          "usd": 0,
          "note": "API access listed. Needs an approved credit application"
        },
        {
          "item": "AP and AR Essentials",
          "unit": "seat-month",
          "usd": 49,
          "note": "API access listed. Per-transaction payment fees apply"
        },
        {
          "item": "AP and AR Team",
          "unit": "seat-month",
          "usd": 65,
          "note": "API access listed"
        },
        {
          "item": "AP and AR Corporate",
          "unit": "seat-month",
          "usd": 89,
          "note": "Enterprise is priced on request"
        }
      ],
      "provenance": {
        "legalEntity": "Bill.com, LLC",
        "domain": "bill.com",
        "domainRegistered": "1994-11-03",
        "endpointOnVendorDomain": true,
        "terms": "https://developer.bill.com/docs/bill-developer-terms",
        "privacy": "https://www.bill.com/privacy",
        "statusPage": "https://www.billcomstatus.com",
        "changelog": "https://developer.bill.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Developer Terms (effective 3 March 2026) are between the developer and Bill.com, LLC and its affiliates, and are accepted when a developer key is generated. The parent company named in the privacy notice is BILL Holdings, Inc.",
          "The BILL Privacy Notice (effective 30 January 2026) names BILL Holdings, Inc. and its subsidiaries Bill.com, LLC, DivvyPay, LLC and Invoice2go, LLC, of San Jose, California.",
          "The API answers at gateway.prod.bill.com and gateway.stage.bill.com, and OAuth for the MCP server at auth.bill.com. The docs send card number decoding to api.divvy.co, a second domain of the vendor's.",
          "The status page is on a separate domain, www.billcomstatus.com, linked from the developer docs. status.bill.com and trust.bill.com didn't answer.",
          "www.bill.com/.well-known/security.txt and www.bill.com/security.txt return 404. The security page sends reports to a HackerOne vulnerability disclosure programme.",
          "The BILL General Terms of Service (last updated 10 February 2025) and separate Spend \u0026 Expense terms govern a customer's account. No data processing agreement or sub-processor list was found on the legal index.",
          "RDAP for bill.com gives a registration date of 1994-11-03 and GoDaddy Corporate Domains, LLC as registrar."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/bill.json",
      "live": {
        "slug": "bill",
        "probe": {
          "target": "https://gateway.prod.bill.com/connect",
          "method": "get",
          "lastAt": "2026-10-08T21:12:05.582437227Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 464,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 440,
          "p95ms24h": 521,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.billcomstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:05:52.445436869Z"
        },
        "updatedAt": "2026-10-08T21:12:05.582437227Z"
      }
    },
    "answer": "Pleo API + MCP scores 62.9 (B) on agent readiness against BILL's 60.9 (C), and leads in 3 of 7 scored categories. BILL leads on reliability, agent ergonomics and payments \u0026 pricing.",
    "b": {
      "slug": "pleo",
      "name": "Pleo API + MCP",
      "vendor": "Pleo Technologies A/S",
      "vendorUrl": "https://www.pleo.io/en",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Spend management platform from Pleo Technologies A/S in Copenhagen, covering company cards, expenses, reimbursements, invoices and accounting exports. Outside agents reach it through a hosted MCP server for expense work and a REST API built for accounting integrations.",
      "url": "https://www.anchorterminal.com/tools/pleo",
      "markdownUrl": "https://www.anchorterminal.com/tools/pleo.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/pleo.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/pleo.json",
      "license": "Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://external.pleo.io",
      "packages": [],
      "auth": "mixed",
      "authNotes": "A person signs in for every route. The MCP server uses OAuth 2.0 in a browser (authorisation code with PKCE, dynamic client registration, no keys to configure) and acts with the connecting user's Pleo role, once a company admin has enabled MCP access for that entity. The External API accepts OAuth 2.0 bearer tokens with resource scopes for partner integrations, whose client ID and secret Pleo issues after review in its Early Access Programme. A single company can use a Standalone API Key with chosen scopes and an expiry, sent as the Basic auth username, but only after Pleo support or a Customer Success Manager enables keys for the organisation.",
      "pricing": "paid",
      "pricingNotes": "Per-user plans, with no separate charge for the API or the MCP server. The pricing page shown to a UK visitor lists Start at £8 per user per month, Build at £14 and Optimise at £18, the last two cheaper billed yearly and with a three-user minimum. MCP is listed on Optimise only, which is sold through a demo. Start and Build have a Try for free button and the signup form states 21 days free. Whether the trial needs a payment card isn't stated. A staging environment with test data exists for customers with API keys enabled and for approved partners. Fees for payments and foreign exchange are extra (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.pleo.io/",
      "llmsTxt": "https://developers.pleo.io/llms.txt",
      "openapi": "https://developers.pleo.io/reference/Export%20API.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.bills"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "api-key",
        "openapi",
        "llms-txt",
        "webhooks",
        "closed-source",
        "status-page",
        "bug-bounty",
        "sandbox"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.9,
        "grade": "B",
        "agentReady": false,
        "rank": 325,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 55,
          "maintenance": 64,
          "payments": 15,
          "reliability": 71,
          "schema": 82,
          "security": 71,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.",
        "bestFor": "An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.",
        "strengths": [
          "MCP server at mcp.pleo.io/mcp uses OAuth with PKCE and dynamic client registration, and acts with the connecting user's Pleo permissions",
          "Payments, card changes and spending-limit changes are blocked through the MCP by design, per the AI Access Terms",
          "Eleven current OpenAPI 3.0.1 specs with 162 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page",
          "One documented rate limit of 600 requests a minute per credential, with written 429 and Retry-After guidance",
          "Staging hosts for both the API (external.staging.pleo.io) and the MCP server (mcp.staging.pleo.io/mcp)",
          "Sub-processor list with locations, customer data in AWS Ireland, and 30 days' notice of new sub-processors in the DPA"
        ],
        "weaknesses": [
          "The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)",
          "MCP tool names, schemas and count aren't published, so they can't be read without a customer sign-in",
          "Standalone API keys aren't self-service. Pleo support or a Customer Success Manager enables them, and partner OAuth clients go through a reviewed programme",
          "No Idempotency-Key header, no official SDK and no entry in the official MCP registry",
          "The API terms call the API a beta version that Pleo may discontinue at any time, and no SLA was found",
          "No end-of-life date is published for the deprecated Legacy API, and its Q3 2026 replacements for employee writes and wallet balance aren't in the docs"
        ],
        "agentNotes": [
          "Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default",
          "Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist",
          "Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side",
          "Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there",
          "Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second",
          "Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.9
          }
        ],
        "editorialScores": {
          "ergonomics": 55,
          "maintenance": 64,
          "payments": 15,
          "reliability": 71,
          "schema": 82,
          "security": 71,
          "transparency": 63
        },
        "provenanceScore": 87
      },
      "connect": {
        "http": "curl --request GET \\\n-u \"YOUR-API-KEY:\" \\\n-H \"Accept: application/json;charset=UTF-8\" \\\n\"https://external.staging.pleo.io/v2/employees\"",
        "claudeCode": "claude mcp add --transport http pleo-mcp-staging https://mcp.staging.pleo.io/mcp",
        "config": {
          "mcpServers": {
            "pleo": {
              "url": "https://mcp.pleo.io/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/pleo"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Pleo Technologies A/S",
        "domain": "pleo.io",
        "domainRegistered": "2015-10-07",
        "endpointOnVendorDomain": true,
        "terms": "https://developers.pleo.io/page/terms-of-service",
        "privacy": "https://www.pleo.io/legal-documents/pleo-privacy-policy-en.pdf",
        "statusPage": "https://status.pleo.io",
        "changelog": "https://developers.pleo.io/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The website footer names Pleo Technologies A/S (36538686), Ravnsborg Tværgade 5C, 2200 København N, Denmark. UK payment services come from Pleo Financial Services UK Ltd, FCA firm reference 1020730, company number 15842283.",
          "The API Terms of Service on the developer portal name Pleo Technologies A/S, carry no date, and describe the API as a beta version. The UK Master Service Agreement has an effective date of 7 September 2026 and is governed by the laws of England and Wales.",
          "The API answers at external.pleo.io and the MCP server at mcp.pleo.io, both pleo.io subdomains. The MCP host publishes its OAuth metadata at https://mcp.pleo.io/.well-known/oauth-authorization-server",
          "www.pleo.io/.well-known/security.txt and pleo.io/.well-known/security.txt both return 403 with an AccessDenied body. The vulnerability disclosure policy gives security-vd@pleo.io as the reporting address.",
          "The privacy notice is dated June 2026 and the Data Processing Agreement 14 October 2025. An AI Access Terms document covers the MCP server.",
          "RDAP from the .io registry gives a registration date of 2015-10-07 for pleo.io."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/pleo.json",
      "live": {
        "slug": "pleo",
        "probe": {
          "target": "https://external.pleo.io",
          "method": "get",
          "lastAt": "2026-10-08T21:12:18.801661057Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 75,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 88,
          "p95ms24h": 163,
          "samples24h": 64,
          "samples30d": 64,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 64,
              "ok": 64
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.pleo.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:06:22.5618046Z"
        },
        "securityTxt": {
          "url": "https://pleo.io/.well-known/security.txt",
          "state": "unknown",
          "checkedAt": "2026-10-08T15:38:57.657849973Z"
        },
        "pages": [
          {
            "url": "https://developers.pleo.io/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:58.324737763Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7369dd13eb7c"
          },
          {
            "url": "https://developers.pleo.io/page/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:00.641635735Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5da670693385"
          }
        ],
        "updatedAt": "2026-10-08T21:12:18.801661057Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "BILL Holdings, Inc.",
        "b": "Pleo Technologies A/S",
        "name": "Vendor"
      },
      {
        "a": "https://gateway.prod.bill.com/connect",
        "b": "https://external.pleo.io",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the BILL Developer Terms and the BILL General Terms of Service",
        "b": "Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-05-21",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "2026-03-03",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-01-30",
        "b": "",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      }
    ],
    "faq": [
      {
        "answer": "Pleo API + MCP scores 62.9 (B) on agent readiness against BILL's 60.9 (C), and leads in 3 of 7 scored categories. BILL leads on reliability, agent ergonomics and payments \u0026 pricing.",
        "question": "Which is better for AI agents, BILL or Pleo API + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do BILL and Pleo API + MCP need an API key?"
      },
      {
        "answer": "Yes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Pleo API + MCP at https://external.pleo.io.",
        "question": "Can an agent call BILL and Pleo API + MCP without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 81 against 71",
          "Agent ergonomics, 60 against 55",
          "Payments \u0026 pricing, 25 against 15"
        ],
        "also": null,
        "goodFor": "A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.",
        "slug": "bill",
        "watchFor": "`POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 71 against 56",
          "Maintenance \u0026 community, 64 against 32",
          "Transparency \u0026 trust, 75 against 66"
        ],
        "also": null,
        "goodFor": "An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.",
        "slug": "pleo",
        "watchFor": "The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)"
      }
    ],
    "job": {
      "capability": "spend.transactions",
      "name": "Spend transactions"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/airwallex-vs-bill.json",
        "title": "Airwallex Spend and Issuing vs BILL",
        "url": "https://www.anchorterminal.com/compare/airwallex-vs-bill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airwallex-vs-pleo.json",
        "title": "Airwallex Spend and Issuing vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/airwallex-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-brex.json",
        "title": "BILL vs Brex",
        "url": "https://www.anchorterminal.com/compare/bill-vs-brex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-expensify.json",
        "title": "BILL vs Expensify",
        "url": "https://www.anchorterminal.com/compare/bill-vs-expensify"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-mercury.json",
        "title": "BILL vs Mercury API",
        "url": "https://www.anchorterminal.com/compare/bill-vs-mercury"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-ramp.json",
        "title": "BILL vs Ramp",
        "url": "https://www.anchorterminal.com/compare/bill-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-spendesk.json",
        "title": "BILL vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/bill-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-pleo.json",
        "title": "Brex vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expensify-vs-pleo.json",
        "title": "Expensify vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/expensify-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mercury-vs-pleo.json",
        "title": "Mercury API vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/mercury-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pleo-vs-ramp.json",
        "title": "Pleo API + MCP vs Ramp",
        "url": "https://www.anchorterminal.com/compare/pleo-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pleo-vs-spendesk.json",
        "title": "Pleo API + MCP vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/pleo-vs-spendesk"
      }
    ],
    "scores": [
      {
        "bill": 81,
        "by": 10,
        "edge": "bill",
        "key": "reliability",
        "name": "Reliability",
        "pleo": 71,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "bill": 83,
        "by": 1,
        "edge": "bill",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "pleo": 82,
        "weight": 13
      },
      {
        "bill": 60,
        "by": 5,
        "edge": "bill",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "pleo": 55,
        "weight": 13
      },
      {
        "bill": 56,
        "by": 15,
        "edge": "pleo",
        "key": "security",
        "name": "Security \u0026 auth",
        "pleo": 71,
        "weight": 14
      },
      {
        "bill": 25,
        "by": 10,
        "edge": "bill",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "pleo": 15,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "bill": 32,
        "by": 32,
        "edge": "pleo",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "pleo": 64,
        "weight": 7
      },
      {
        "bill": 66,
        "by": 9,
        "edge": "pleo",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "pleo": 75,
        "weight": 7
      }
    ],
    "summary": "Pleo API + MCP scores 62.9 (B) on agent readiness against BILL's 60.9 (C), and leads in 3 of 7 scored categories. BILL leads on reliability, agent ergonomics and payments \u0026 pricing. Both do spend transactions.",
    "verdicts": {
      "bill": "A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.",
      "pleo": "The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/bill-vs-pleo",
    "json": "https://www.anchorterminal.com/compare/bill-vs-pleo.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/bill-vs-pleo.md",
    "slim": "https://www.anchorterminal.com/compare/bill-vs-pleo.min.md"
  },
  "markdown": "Pleo API + MCP scores 62.9 (B) on agent readiness against BILL's 60.9 (C), and leads in 3 of 7 scored categories. BILL leads on reliability, agent ergonomics and payments \u0026 pricing. Both do spend transactions.\n\n- BILL: grade C, 60.9/100, rank #380 of 722. Markdown https://www.anchorterminal.com/tools/bill.md · JSON https://www.anchorterminal.com/api/v1/tools/bill.json\n- Pleo API + MCP: grade B, 62.9/100, rank #325 of 722. Markdown https://www.anchorterminal.com/tools/pleo.md · JSON https://www.anchorterminal.com/api/v1/tools/pleo.json\n\n## Which one, for what\n\n### BILL (C)\n\nGood for: A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.\n\nAhead on:\n- Reliability, 81 against 71\n- Agent ergonomics, 60 against 55\n- Payments \u0026 pricing, 25 against 15\n\nWatch for: `POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes\n\n### Pleo API + MCP (B)\n\nGood for: An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.\n\nAhead on:\n- Security \u0026 auth, 71 against 56\n- Maintenance \u0026 community, 64 against 32\n- Transparency \u0026 trust, 75 against 66\n\nWatch for: The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)\n\n\n## Score by category\n\n| Category | Weight | BILL | Pleo API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 81 | 71 | BILL +10 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 83 | 82 | BILL +1 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 55 | BILL +5 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 71 | Pleo API + MCP +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 15 | BILL +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 32 | 64 | Pleo API + MCP +32 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 66 | 75 | Pleo API + MCP +9 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **60.9 · C** | **62.9 · B** | |\n\n## Facts side by side\n\n| Fact | BILL | Pleo API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | BILL Holdings, Inc. | Pleo Technologies A/S |\n| Hosted endpoint | `https://gateway.prod.bill.com/connect` | `https://external.pleo.io` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Paid |\n| x402 | no | no |\n| Licence | Proprietary service under the BILL Developer Terms and the BILL General Terms of Service | Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-05-21 | 2026-10-02 |\n| Terms last updated | 2026-03-03 | no date given |\n| Privacy policy last updated | 2026-01-30 |  |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n\n## Verdicts\n\n**BILL.** A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.\n\n**Pleo API + MCP.** The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.\n\n## Before you call either\n\n### BILL\n\n1. Sign in with `POST /v3/login` and send `sessionId` and `devKey` as headers on every AP and AR call. The session expires after 35 minutes idle\n2. Send the `apiToken` header alone on `/v3/spend/` paths. Spend \u0026 Expense calls need no login and are limited to 60 a minute per token\n3. Complete the MFA challenge before `POST /v3/payments`. An untrusted session fails with `BDC_1361`\n4. Read back payments before retrying a failed `POST /v3/payments`. No idempotency key is accepted, so a blind retry can pay twice\n5. Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After `BDC_1144`, wait for the next hour\n\n### Pleo API + MCP\n\n1. Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default\n2. Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist\n3. Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side\n4. Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there\n5. Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second\n6. Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in\n\n## Questions\n\n### Which is better for AI agents, BILL or Pleo API + MCP?\n\nPleo API + MCP scores 62.9 (B) on agent readiness against BILL's 60.9 (C), and leads in 3 of 7 scored categories. BILL leads on reliability, agent ergonomics and payments \u0026 pricing.\n\n### Do BILL and Pleo API + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call BILL and Pleo API + MCP without installing anything?\n\nYes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Pleo API + MCP at https://external.pleo.io.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/bill-vs-pleo.json, and with the fewest tokens: https://www.anchorterminal.com/compare/bill-vs-pleo.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"bill\", \"b\": \"pleo\"}`. From a terminal: `anchor compare bill pleo`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/bill.json and https://www.anchorterminal.com/api/v1/tools/pleo.json\n\n## Other comparisons with BILL or Pleo API + MCP\n\n- [Airwallex Spend and Issuing vs BILL](https://www.anchorterminal.com/compare/airwallex-vs-bill.md)\n- [Airwallex Spend and Issuing vs Pleo API + MCP](https://www.anchorterminal.com/compare/airwallex-vs-pleo.md)\n- [BILL vs Brex](https://www.anchorterminal.com/compare/bill-vs-brex.md)\n- [BILL vs Expensify](https://www.anchorterminal.com/compare/bill-vs-expensify.md)\n- [BILL vs Mercury API](https://www.anchorterminal.com/compare/bill-vs-mercury.md)\n- [BILL vs Ramp](https://www.anchorterminal.com/compare/bill-vs-ramp.md)\n- [BILL vs Spendesk API + MCP](https://www.anchorterminal.com/compare/bill-vs-spendesk.md)\n- [Brex vs Pleo API + MCP](https://www.anchorterminal.com/compare/brex-vs-pleo.md)\n- [Expensify vs Pleo API + MCP](https://www.anchorterminal.com/compare/expensify-vs-pleo.md)\n- [Mercury API vs Pleo API + MCP](https://www.anchorterminal.com/compare/mercury-vs-pleo.md)\n- [Pleo API + MCP vs Ramp](https://www.anchorterminal.com/compare/pleo-vs-ramp.md)\n- [Pleo API + MCP vs Spendesk API + MCP](https://www.anchorterminal.com/compare/pleo-vs-spendesk.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "BILL vs Pleo API + MCP",
        "url": ""
      }
    ],
    "description": "Pleo API + MCP scores 62.9 (B) on agent readiness against BILL's 60.9 (C), and leads in 3 of 7 scored categories. BILL leads on reliability, agent ergonomics and payments \u0026 pricing. Both do spend transactions. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "BILL C 60.9",
      "Pleo API + MCP B 62.9",
      "scores"
    ],
    "h1": "BILL vs Pleo API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-bill-vs-pleo.png",
    "path": "/compare/bill-vs-pleo",
    "published": "2026-10-01",
    "section": "tools",
    "title": "BILL vs Pleo API + MCP for AI agents, C 60.9 vs B 62.9",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/bill-vs-pleo"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 630
  },
  "version": 1
}
