{
  "data": {
    "a": {
      "slug": "bill",
      "name": "BILL",
      "vendor": "BILL Holdings, Inc.",
      "vendorUrl": "https://www.bill.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "BILL is a US financial operations platform for accounts payable, accounts receivable and company card spend. Its v3 REST API reads and writes bills, payments, invoices, budgets, cards, transactions and reimbursements, and an MCP server in beta gives read-only access.",
      "url": "https://www.anchorterminal.com/tools/bill",
      "markdownUrl": "https://www.anchorterminal.com/tools/bill.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/bill.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/bill.json",
      "license": "Proprietary service under the BILL Developer Terms and the BILL General Terms of Service",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://gateway.prod.bill.com/connect",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is self-serve. A person signs up for a sandbox or production account in a browser and generates a developer key under Settings \u003e Sync \u0026 Integrations \u003e Manage Developer Keys after accepting the Developer Terms. The AP and AR API signs in with `POST /v3/login` using a username, password, organisation ID and `devKey`, and returns a `sessionId` that expires after 35 minutes idle and carries the user's role, with no scopes. Payments and bank account changes need a session trusted by multi-factor authentication. The Spend \u0026 Expense API takes an `apiToken` header that an ADMIN user generates, with no login. App partners request their developer key by email and use customer sync tokens that can't make payments. The MCP server uses OAuth through auth.bill.com with PKCE, and clients other than Claude and ChatGPT need approval by email.",
      "pricing": "freemium",
      "pricingNotes": "No separate API fee is published. bill.com/product/pricing lists API access on every plan. AP and AR plans are Essentials at $49, Team at $65 and Corporate at $89 per user per month, with Enterprise on request, and Spend \u0026 Expense at $0 per user per month, which needs an approved credit application. Payment types such as cheques, ACH and international transfers carry per-transaction fees. The sandbox is self-serve and free, and production has a 30-day trial. The Developer Terms mention API licence and development fees set on the developer site or an order form (checked 2026-10-08).",
      "priceSummary": "$49 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI files or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.bill.com/docs/home",
      "llmsTxt": "https://developer.bill.com/llms.txt",
      "openapi": "https://developer.bill.com/openapi/bill-v3-api.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "accounting.invoices"
      ],
      "tags": [
        "hosted",
        "freemium",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-05-21",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.9,
        "grade": "C",
        "agentReady": false,
        "rank": 380,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 32,
          "payments": 25,
          "reliability": 81,
          "schema": 83,
          "security": 56,
          "transparency": 66
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.",
        "bestFor": "A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.",
        "strengths": [
          "Two public OpenAPI 3.0.1 files cover 326 operations, with llms.txt, a Markdown copy of every docs page and a docs MCP server at `https://developer.bill.com/mcp`",
          "Creating a payment, adding a funding bank account and enabling vendor auto-pay need an API session trusted by multi-factor authentication",
          "The sandbox is self-serve through a sign-up form, charges no subscription fee and moves no real money",
          "www.billcomstatus.com lists an API Servers component and shows no incident after 15 April 2026",
          "The Developer Terms commit BILL to commercially reasonable efforts at 30 days' notice of deprecations and breaking changes"
        ],
        "weaknesses": [
          "`POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes",
          "No idempotency key is accepted on the 203 write operations of the v3 API, payments included. `X-Idempotent-Key` exists only on two webhook subscription calls",
          "The MCP server is beta, read-only and limited to US organisations, and MCP clients other than Claude and ChatGPT need BILL's approval by email",
          "The changelog's latest entry is dated 21 May 2026, and the MCP server has no entry there",
          "No official SDK, sub-processor list, data processing agreement or security.txt was found, and the audit trail endpoint covers vendors only"
        ],
        "agentNotes": [
          "Sign in with `POST /v3/login` and send `sessionId` and `devKey` as headers on every AP and AR call. The session expires after 35 minutes idle",
          "Send the `apiToken` header alone on `/v3/spend/` paths. Spend \u0026 Expense calls need no login and are limited to 60 a minute per token",
          "Complete the MFA challenge before `POST /v3/payments`. An untrusted session fails with `BDC_1361`",
          "Read back payments before retrying a failed `POST /v3/payments`. No idempotency key is accepted, so a blind retry can pay twice",
          "Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After `BDC_1144`, wait for the next hour"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.9
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 32,
          "payments": 25,
          "reliability": 81,
          "schema": 83,
          "security": 56,
          "transparency": 44
        },
        "provenanceScore": 88
      },
      "connect": {
        "http": "curl --request POST \\\n--url 'https://gateway.stage.bill.com/connect/v3/login' \\\n--header 'content-type: application/json' \\\n--data '{\n  \"username\": \"{username}\", \n  \"password\": \"{password}\",\n  \"organizationId\": \"{organization_id}\", \n  \"devKey\": \"{developer_key}\"\n}'"
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/bill"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Spend \u0026 Expense",
          "unit": "seat-month",
          "usd": 0,
          "note": "API access listed. Needs an approved credit application"
        },
        {
          "item": "AP and AR Essentials",
          "unit": "seat-month",
          "usd": 49,
          "note": "API access listed. Per-transaction payment fees apply"
        },
        {
          "item": "AP and AR Team",
          "unit": "seat-month",
          "usd": 65,
          "note": "API access listed"
        },
        {
          "item": "AP and AR Corporate",
          "unit": "seat-month",
          "usd": 89,
          "note": "Enterprise is priced on request"
        }
      ],
      "provenance": {
        "legalEntity": "Bill.com, LLC",
        "domain": "bill.com",
        "domainRegistered": "1994-11-03",
        "endpointOnVendorDomain": true,
        "terms": "https://developer.bill.com/docs/bill-developer-terms",
        "privacy": "https://www.bill.com/privacy",
        "statusPage": "https://www.billcomstatus.com",
        "changelog": "https://developer.bill.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Developer Terms (effective 3 March 2026) are between the developer and Bill.com, LLC and its affiliates, and are accepted when a developer key is generated. The parent company named in the privacy notice is BILL Holdings, Inc.",
          "The BILL Privacy Notice (effective 30 January 2026) names BILL Holdings, Inc. and its subsidiaries Bill.com, LLC, DivvyPay, LLC and Invoice2go, LLC, of San Jose, California.",
          "The API answers at gateway.prod.bill.com and gateway.stage.bill.com, and OAuth for the MCP server at auth.bill.com. The docs send card number decoding to api.divvy.co, a second domain of the vendor's.",
          "The status page is on a separate domain, www.billcomstatus.com, linked from the developer docs. status.bill.com and trust.bill.com didn't answer.",
          "www.bill.com/.well-known/security.txt and www.bill.com/security.txt return 404. The security page sends reports to a HackerOne vulnerability disclosure programme.",
          "The BILL General Terms of Service (last updated 10 February 2025) and separate Spend \u0026 Expense terms govern a customer's account. No data processing agreement or sub-processor list was found on the legal index.",
          "RDAP for bill.com gives a registration date of 1994-11-03 and GoDaddy Corporate Domains, LLC as registrar."
        ],
        "score": 88
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/bill.json",
      "live": {
        "slug": "bill",
        "probe": {
          "target": "https://gateway.prod.bill.com/connect",
          "method": "get",
          "lastAt": "2026-10-08T21:53:17.219430668Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 522,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 449,
          "p95ms24h": 522,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.billcomstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:57:43.262829057Z"
        },
        "updatedAt": "2026-10-08T21:57:43.262829057Z"
      }
    },
    "answer": "Spendesk API + MCP scores 62.3 (B) on agent readiness against BILL's 60.9 (C), and leads in 5 of 7 scored categories. BILL leads on reliability and payments \u0026 pricing.",
    "b": {
      "slug": "spendesk",
      "name": "Spendesk API + MCP",
      "vendor": "Spendesk SAS",
      "vendorUrl": "https://www.spendesk.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Spend management platform from Spendesk SAS in Paris, covering company cards, expense claims, supplier invoices, purchase orders and accounting exports. Outside agents reach it through a REST API with scoped keys or OAuth, and a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/spendesk",
      "markdownUrl": "https://www.anchorterminal.com/tools/spendesk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/spendesk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/spendesk.json",
      "license": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://public-api.spendesk.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is granted by Spendesk, not self-serve. A customer asks its Spendesk representative for API access, then an Account Owner or Admin creates an API key (client ID and secret) with chosen scopes and an expiry of up to one year. The key is exchanged at POST /v1/auth/token with HTTP Basic for a Bearer token that lasts 60 minutes and can carry fewer scopes than the key. Partner integrations use OAuth 2.0 authorisation code with PKCE after approval by the partnerships team. The MCP server accepts only OAuth user tokens, refuses API keys, and limits use to Controllers and Account Owners. Experimental scopes are added on request.",
      "pricing": "paid",
      "pricingNotes": "No public prices. The pricing page describes a fixed monthly platform fee plus variable fees per transaction (card purchases, invoice payments and expense claims) and asks for a quote. It lists the open API and the MCP connection in the base package. No free tier, trial or self-serve sandbox was found. A demo environment exists at public-api.demo.spendesk.com, with credentials requested alongside API access (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI definition or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 62,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.spendesk.com",
      "llmsTxt": "https://developer.spendesk.com/llms.txt",
      "openapi": "https://developer.spendesk.com/openapi/spendesk-public-api.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "spend.procurement"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sales-led",
        "status-page",
        "iso27001",
        "bug-bounty"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.3,
        "grade": "B",
        "agentReady": false,
        "rank": 342,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.",
        "bestFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
        "strengths": [
          "OpenAPI 3.1 definition with 106 operations, llms.txt and a Markdown copy of every docs page, all public without sign-in",
          "37 documented scopes split by resource and by read or write. A token can carry fewer scopes than its key, and keys expire within one year",
          "MCP write permissions are off by default, enabled per connection by an admin with a second factor, then ticked by each user",
          "Every MCP tool call is recorded in an action log with date, tool, status, user, company and correlation ID",
          "Rate limits are published (1,000 requests a minute per company and credential) with x-ratelimit headers on every response"
        ],
        "weaknesses": [
          "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative",
          "Cards, transactions, invoices, purchase orders, webhooks and most writes sit behind experimental scopes granted on request, and may change",
          "No official SDK found on npm or PyPI, and the MCP server isn't in the official MCP registry",
          "status.spendesk.com has no API component and lists three critical and three major incidents opened between 2 and 29 September 2026",
          "An Idempotency-Key is documented only for creating an intake. A repeated purchase order or supplier request creates a second record"
        ],
        "agentNotes": [
          "Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401",
          "Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list",
          "With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400",
          "The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission",
          "After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.3
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 64
        },
        "provenanceScore": 96
      },
      "connect": {
        "http": "curl -X POST https://public-api.demo.spendesk.com/v1/auth/token \\\n  -u \"YOUR_CLIENT_ID:YOUR_CLIENT_SECRET\"\n\ncurl https://public-api.demo.spendesk.com/v1/wallet-summary \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/spendesk"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Spendesk SAS",
        "domain": "spendesk.com",
        "domainRegistered": "2015-10-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.spendesk.com/legals/terms/",
        "privacy": "https://www.spendesk.com/legals/privacy/",
        "statusPage": "https://status.spendesk.com",
        "changelog": "https://developer.spendesk.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The legal notice names Spendesk SAS, 7 Rue de Madrid, 75008 Paris, registration 821 893 286 R.C.S. Paris. The privacy policy (March 2025, version 0.5) gives the registered office as 51 rue de Londres, 75008 Paris.",
          "Payment services are supplied by Spendesk Financial Services (a French payment institution licensed by the ACPR, number 17518) in the EEA, Adyen in the UK and Sutton Bank in the US, per the site footer.",
          "The API and the MCP server answer at public-api.spendesk.com. An unauthenticated POST to /v1/mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata.",
          "www.spendesk.com/.well-known/security.txt is present with a contact and an expiry of 31 December 2026. developer.spendesk.com/.well-known/security.txt returns 404.",
          "The terms page lists the customer terms, a DORA addendum, a Spendesk API agreement and partner programme terms. The document links are drawn by JavaScript and we couldn't open them.",
          "RDAP for spendesk.com gives a registration date of 2015-10-30."
        ],
        "score": 96
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/spendesk.json",
      "live": {
        "slug": "spendesk",
        "probe": {
          "target": "https://public-api.spendesk.com",
          "method": "get",
          "lastAt": "2026-10-08T21:53:34.736116367Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 63,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 65,
          "p95ms24h": 110,
          "samples24h": 71,
          "samples30d": 71,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 71,
              "ok": 71
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.spendesk.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-08T21:58:15.095615847Z"
        },
        "securityTxt": {
          "url": "https://spendesk.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-12-31T22:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:39.004780879Z"
        },
        "pages": [
          {
            "url": "https://developer.spendesk.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:18.275650963Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0a7493461e82"
          },
          {
            "url": "https://www.spendesk.com/legals/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:38.654232386Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f77c18596c95"
          },
          {
            "url": "https://www.spendesk.com/legals/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:41.303104049Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "880e4794e2b0"
          }
        ],
        "updatedAt": "2026-10-08T21:58:15.095615847Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "BILL Holdings, Inc.",
        "b": "Spendesk SAS",
        "name": "Vendor"
      },
      {
        "a": "https://gateway.prod.bill.com/connect",
        "b": "https://public-api.spendesk.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the BILL Developer Terms and the BILL General Terms of Service",
        "b": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "62",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-05-21",
        "b": "2026-09-29",
        "name": "Last release"
      },
      {
        "a": "2026-03-03",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "2026-01-30",
        "b": "2025-03-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      }
    ],
    "faq": [
      {
        "answer": "Spendesk API + MCP scores 62.3 (B) on agent readiness against BILL's 60.9 (C), and leads in 5 of 7 scored categories. BILL leads on reliability and payments \u0026 pricing.",
        "question": "Which is better for AI agents, BILL or Spendesk API + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do BILL and Spendesk API + MCP need an API key?"
      },
      {
        "answer": "Yes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Spendesk API + MCP at https://public-api.spendesk.com.",
        "question": "Can an agent call BILL and Spendesk API + MCP without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 81 against 55",
          "Payments \u0026 pricing, 25 against 0"
        ],
        "also": null,
        "goodFor": "A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.",
        "slug": "bill",
        "watchFor": "`POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 86 against 56",
          "Maintenance \u0026 community, 57 against 32",
          "Transparency \u0026 trust, 80 against 66"
        ],
        "also": null,
        "goodFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
        "slug": "spendesk",
        "watchFor": "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative"
      }
    ],
    "job": {
      "capability": "spend.transactions",
      "name": "Spend transactions"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/airwallex-vs-bill.json",
        "title": "Airwallex Spend and Issuing vs BILL",
        "url": "https://www.anchorterminal.com/compare/airwallex-vs-bill"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airwallex-vs-spendesk.json",
        "title": "Airwallex Spend and Issuing vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/airwallex-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-brex.json",
        "title": "BILL vs Brex",
        "url": "https://www.anchorterminal.com/compare/bill-vs-brex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-expensify.json",
        "title": "BILL vs Expensify",
        "url": "https://www.anchorterminal.com/compare/bill-vs-expensify"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-mercury.json",
        "title": "BILL vs Mercury API",
        "url": "https://www.anchorterminal.com/compare/bill-vs-mercury"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-pleo.json",
        "title": "BILL vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/bill-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-ramp.json",
        "title": "BILL vs Ramp",
        "url": "https://www.anchorterminal.com/compare/bill-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-spendesk.json",
        "title": "Brex vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expensify-vs-spendesk.json",
        "title": "Expensify vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/expensify-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mercury-vs-spendesk.json",
        "title": "Mercury API vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/mercury-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pleo-vs-spendesk.json",
        "title": "Pleo API + MCP vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/pleo-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ramp-vs-spendesk.json",
        "title": "Ramp vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/ramp-vs-spendesk"
      }
    ],
    "scores": [
      {
        "bill": 81,
        "by": 26,
        "edge": "bill",
        "key": "reliability",
        "name": "Reliability",
        "spendesk": 55,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "bill": 83,
        "by": 4,
        "edge": "spendesk",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "spendesk": 87,
        "weight": 13
      },
      {
        "bill": 60,
        "by": 2,
        "edge": "spendesk",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "spendesk": 62,
        "weight": 13
      },
      {
        "bill": 56,
        "by": 30,
        "edge": "spendesk",
        "key": "security",
        "name": "Security \u0026 auth",
        "spendesk": 86,
        "weight": 14
      },
      {
        "bill": 25,
        "by": 25,
        "edge": "bill",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "spendesk": 0,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "bill": 32,
        "by": 25,
        "edge": "spendesk",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "spendesk": 57,
        "weight": 7
      },
      {
        "bill": 66,
        "by": 14,
        "edge": "spendesk",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "spendesk": 80,
        "weight": 7
      }
    ],
    "summary": "Spendesk API + MCP scores 62.3 (B) on agent readiness against BILL's 60.9 (C), and leads in 5 of 7 scored categories. BILL leads on reliability and payments \u0026 pricing. Both do spend transactions.",
    "verdicts": {
      "bill": "A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.",
      "spendesk": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/bill-vs-spendesk",
    "json": "https://www.anchorterminal.com/compare/bill-vs-spendesk.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/bill-vs-spendesk.md",
    "slim": "https://www.anchorterminal.com/compare/bill-vs-spendesk.min.md"
  },
  "markdown": "Spendesk API + MCP scores 62.3 (B) on agent readiness against BILL's 60.9 (C), and leads in 5 of 7 scored categories. BILL leads on reliability and payments \u0026 pricing. Both do spend transactions.\n\n- BILL: grade C, 60.9/100, rank #380 of 722. Markdown https://www.anchorterminal.com/tools/bill.md · JSON https://www.anchorterminal.com/api/v1/tools/bill.json\n- Spendesk API + MCP: grade B, 62.3/100, rank #342 of 722. Markdown https://www.anchorterminal.com/tools/spendesk.md · JSON https://www.anchorterminal.com/api/v1/tools/spendesk.json\n\n## Which one, for what\n\n### BILL (C)\n\nGood for: A US company already on BILL that wants an agent to create and read bills, run approvals, schedule vendor payments, raise invoices and manage budgets, vendor cards, card transactions and reimbursements.\n\nAhead on:\n- Reliability, 81 against 55\n- Payments \u0026 pricing, 25 against 0\n\nWatch for: `POST /v3/login` takes a user's username and password with a developer key, and the session carries that user's role with no scopes\n\n### Spendesk API + MCP (B)\n\nGood for: A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.\n\nAhead on:\n- Security \u0026 auth, 86 against 56\n- Maintenance \u0026 community, 57 against 32\n- Transparency \u0026 trust, 80 against 66\n\nWatch for: No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative\n\n\n## Score by category\n\n| Category | Weight | BILL | Spendesk API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 81 | 55 | BILL +26 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 83 | 87 | Spendesk API + MCP +4 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 62 | Spendesk API + MCP +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 56 | 86 | Spendesk API + MCP +30 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 0 | BILL +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 32 | 57 | Spendesk API + MCP +25 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 66 | 80 | Spendesk API + MCP +14 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **60.9 · C** | **62.3 · B** | |\n\n## Facts side by side\n\n| Fact | BILL | Spendesk API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | BILL Holdings, Inc. | Spendesk SAS |\n| Hosted endpoint | `https://gateway.prod.bill.com/connect` | `https://public-api.spendesk.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Paid |\n| x402 | no | no |\n| Licence | Proprietary service under the BILL Developer Terms and the BILL General Terms of Service | Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement |\n| Tools exposed | none | 62 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-05-21 | 2026-09-29 |\n| Terms last updated | 2026-03-03 | couldn't be read |\n| Privacy policy last updated | 2026-01-30 | 2025-03-01 |\n| Customer content may train models | not found in the text | couldn't be read |\n| Terms restrict automated access | not found in the text | couldn't be read |\n| Terms restrict benchmarking | not found in the text | couldn't be read |\n| Terms or service can change without notice | not found in the text | couldn't be read |\n| Arbitration or class-action waiver | not found in the text | couldn't be read |\n\n## Verdicts\n\n**BILL.** A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found.\n\n**Spendesk API + MCP.** Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.\n\n## Before you call either\n\n### BILL\n\n1. Sign in with `POST /v3/login` and send `sessionId` and `devKey` as headers on every AP and AR call. The session expires after 35 minutes idle\n2. Send the `apiToken` header alone on `/v3/spend/` paths. Spend \u0026 Expense calls need no login and are limited to 60 a minute per token\n3. Complete the MFA challenge before `POST /v3/payments`. An untrusted session fails with `BDC_1361`\n4. Read back payments before retrying a failed `POST /v3/payments`. No idempotency key is accepted, so a blind retry can pay twice\n5. Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After `BDC_1144`, wait for the next hour\n\n### Spendesk API + MCP\n\n1. Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401\n2. Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list\n3. With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400\n4. The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission\n5. After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two\n\n## Questions\n\n### Which is better for AI agents, BILL or Spendesk API + MCP?\n\nSpendesk API + MCP scores 62.3 (B) on agent readiness against BILL's 60.9 (C), and leads in 5 of 7 scored categories. BILL leads on reliability and payments \u0026 pricing.\n\n### Do BILL and Spendesk API + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call BILL and Spendesk API + MCP without installing anything?\n\nYes. BILL has a hosted endpoint at https://gateway.prod.bill.com/connect and Spendesk API + MCP at https://public-api.spendesk.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/bill-vs-spendesk.json, and with the fewest tokens: https://www.anchorterminal.com/compare/bill-vs-spendesk.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"bill\", \"b\": \"spendesk\"}`. From a terminal: `anchor compare bill spendesk`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/bill.json and https://www.anchorterminal.com/api/v1/tools/spendesk.json\n\n## Other comparisons with BILL or Spendesk API + MCP\n\n- [Airwallex Spend and Issuing vs BILL](https://www.anchorterminal.com/compare/airwallex-vs-bill.md)\n- [Airwallex Spend and Issuing vs Spendesk API + MCP](https://www.anchorterminal.com/compare/airwallex-vs-spendesk.md)\n- [BILL vs Brex](https://www.anchorterminal.com/compare/bill-vs-brex.md)\n- [BILL vs Expensify](https://www.anchorterminal.com/compare/bill-vs-expensify.md)\n- [BILL vs Mercury API](https://www.anchorterminal.com/compare/bill-vs-mercury.md)\n- [BILL vs Pleo API + MCP](https://www.anchorterminal.com/compare/bill-vs-pleo.md)\n- [BILL vs Ramp](https://www.anchorterminal.com/compare/bill-vs-ramp.md)\n- [Brex vs Spendesk API + MCP](https://www.anchorterminal.com/compare/brex-vs-spendesk.md)\n- [Expensify vs Spendesk API + MCP](https://www.anchorterminal.com/compare/expensify-vs-spendesk.md)\n- [Mercury API vs Spendesk API + MCP](https://www.anchorterminal.com/compare/mercury-vs-spendesk.md)\n- [Pleo API + MCP vs Spendesk API + MCP](https://www.anchorterminal.com/compare/pleo-vs-spendesk.md)\n- [Ramp vs Spendesk API + MCP](https://www.anchorterminal.com/compare/ramp-vs-spendesk.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "BILL vs Spendesk API + MCP",
        "url": ""
      }
    ],
    "description": "Spendesk API + MCP scores 62.3 (B) on agent readiness against BILL's 60.9 (C), and leads in 5 of 7 scored categories. BILL leads on reliability and payments \u0026 pricing. Both do spend transactions. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "BILL C 60.9",
      "Spendesk API + MCP B 62.3",
      "scores"
    ],
    "h1": "BILL vs Spendesk API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-bill-vs-spendesk.png",
    "path": "/compare/bill-vs-spendesk",
    "published": "2026-10-01",
    "section": "tools",
    "title": "BILL vs Spendesk API + MCP for AI agents, C 60.9 vs B 62.3",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/bill-vs-spendesk"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 730
  },
  "version": 1
}
