Head to head · Spend transactions · October 2026 research run

BILL vs Spendesk API + MCP

Spendesk API + MCP scores 62.3 (B) on agent readiness against BILL's 60.9 (C), and leads in 5 of 7 scored categories. BILL leads on reliability and payments & pricing. Both do spend transactions.

Which one, for what

BILL C

Good for A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.

Ahead on

  • Reliability, 81 against 55
  • Payments & pricing, 25 against 0

Watch for

POST /v3/login takes a user's username and password with a developer key, and the session carries that user's role with no scopes

Spendesk API + MCP B

Good for A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.

Ahead on

  • Security & auth, 86 against 56
  • Maintenance & community, 57 against 32
  • Transparency & trust, 80 against 66

Watch for

No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative

Score by category

CategoryWeight this runBILLSpendesk API + MCPEdge
Reliability16%208155BILL +26
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28387Spendesk API + MCP +4
Agent ergonomics13%16.26062Spendesk API + MCP +2
Security & auth14%17.55686Spendesk API + MCP +30
Payments & pricing10%12.5250BILL +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.83257Spendesk API + MCP +25
Transparency & trust7%8.86680Spendesk API + MCP +14
Negative events≤1500
Total60.9 · C62.3 · B

Facts side by side

FactBILLSpendesk API + MCP
KindHTTP APIHTTP API
VendorBILL Holdings, Inc.Spendesk SAS
Hosted endpointhttps://gateway.prod.bill.com/connecthttps://public-api.spendesk.com
TransportsHTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumPaid
x402nono
LicenceProprietary service under the BILL Developer Terms and the BILL General Terms of ServiceProprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement
Tools exposednone62
Read-only variant documentednono
llms.txtyesyes
Last release2026-05-212026-09-29
Terms last updated2026-03-03couldn't be read
Privacy policy last updated2026-01-302025-03-01
Customer content may train modelsnot found in the textcouldn't be read
Terms restrict automated accessnot found in the textcouldn't be read
Terms restrict benchmarkingnot found in the textcouldn't be read
Terms or service can change without noticenot found in the textcouldn't be read
Arbitration or class-action waivernot found in the textcouldn't be read

Verdicts

BILL

A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.

Spendesk API + MCP

Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.

Before you call either

BILL

  1. Sign in with POST /v3/login and send sessionId and devKey as headers on every AP and AR call. The session expires after 35 minutes idle
  2. Send the apiToken header alone on /v3/spend/ paths. Spend & Expense calls need no login and are limited to 60 a minute per token
  3. Complete the MFA challenge before POST /v3/payments. An untrusted session fails with BDC_1361
  4. Read back payments before retrying a failed POST /v3/payments. No idempotency key is accepted, so a blind retry can pay twice
  5. Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After BDC_1144, wait for the next hour

Spendesk API + MCP

  1. Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401
  2. Stop paging at the last page calculated from total and pageSize (maximum 30). A page past the end returns 404, not an empty list
  3. With an organisation-level token, send X-Company-Id on every v1 call or expect a 400
  4. The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat Tool not found (-32601) as a missing permission
  5. After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two

Questions

Which is better for AI agents, BILL or Spendesk API + MCP?

Spendesk API + MCP scores 62.3 (B) on agent readiness against BILL's 60.9 (C), and leads in 5 of 7 scored categories. BILL leads on reliability and payments & pricing.

Do BILL and Spendesk API + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call BILL and Spendesk API + MCP without installing anything?

Yes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Spendesk API + MCP at https://public-api.spendesk.com.

Other comparisons with BILL or Spendesk API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.