{
  "data": {
    "a": {
      "slug": "brex",
      "name": "Brex",
      "vendor": "Brex LLC",
      "vendorUrl": "https://www.brex.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Brex is a spend platform with corporate cards, expense management, bill pay, travel and business accounts. Its REST Developer API reads and writes cards, expenses, spend limits, vendors and transfers, and a hosted MCP server is in beta.",
      "url": "https://www.anchorterminal.com/tools/brex",
      "markdownUrl": "https://www.anchorterminal.com/tools/brex.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/brex.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/brex.json",
      "license": "Proprietary service under the Brex Platform Agreement and the Brex Access Agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.brex.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is self-serve for a Brex customer. An account admin or card admin accepts the Developer API agreement in the dashboard, then creates a user token with chosen scopes at Settings \u003e Developer. The token is sent as a Bearer header, is shown once, can be revoked, and expires after 90 days without a call. Partners acting for other Brex accounts apply to Brex for a client ID and secret and use the OAuth 2.0 authorisation code grant, with one-hour access tokens and refresh tokens. The MCP server takes OAuth with dynamic client registration, where each employee signs in with their own permissions, or an admin's user token.",
      "pricing": "freemium",
      "pricingNotes": "No separate API fee. brex.com/pricing lists Brex API access under Essentials at $0 per user per month, with Premium at $12 per user per month and Enterprise priced on request. Access needs an approved Brex business account, so an agent can't start without one. There is no customer sandbox, and the staging server is for approved partners only. The Access Agreement lets Brex introduce API fees on 30 days' notice (checked 2026-10-08).",
      "priceSummary": "$12 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 43,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.brex.com",
      "llmsTxt": "https://developer.brex.com/llms.txt",
      "openapi": "https://developer.brex.com/_bundle/openapi/team_api.yaml",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills"
      ],
      "tags": [
        "hosted",
        "freemium",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "status-page",
        "soc2",
        "pci-dss"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.7,
        "grade": "C",
        "agentReady": false,
        "rank": 345,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 66,
          "payments": 25,
          "reliability": 60,
          "schema": 80,
          "security": 72,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-02 and 2026-09. The changelog records the List expenses maximum `limit` cut from 1,000 to 100 in February 2026, and `GET /v2/users/{id}/limit` removed from the Team API in September 2026 without a deprecated label in the entry. The Team API is at version 1.0, and the launch-stages page says breaking changes to generally available APIs come as new versions with deprecation timelines. Both changes are documented in the month they shipped, and notice by email couldn't be checked, so the smallest deduction applies (https://developer.brex.com/changelog)."
        ],
        "verdict": "User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.",
        "bestFor": "A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.",
        "strengths": [
          "Ten public OpenAPI 3 specs covering 115 operations, plus llms.txt and a Markdown twin of every docs page",
          "User tokens take scopes chosen at creation, most with a read-only variant, and card numbers need the separate `cards.pan` scope",
          "Every POST and PUT accepts an `Idempotency-Key`, and Create transfer and Create card require one",
          "API access is listed on the Essentials plan at $0 per user per month",
          "The hosted MCP server uses OAuth with dynamic client registration and each employee's own Brex permissions"
        ],
        "weaknesses": [
          "The Expenses API update endpoint accepts only `memo`, so an outside agent can't set a category or custom field on an expense through it",
          "No customer sandbox. The docs say staging isn't a sandbox and won't accept customer tokens",
          "No official SDK. The docs list three community libraries that Brex doesn't support",
          "status.brex.com logs API request errors from 16:01 to 20:34 UTC on 4 August 2026 and invalidated developer tokens on 21 September 2026",
          "The MCP server is beta with 43 tools, and approvals and card management aren't available through it"
        ],
        "agentNotes": [
          "Ask an account admin or card admin for a user token with only the scopes the task needs, and prefer the `.readonly` variants. A token unused for 90 days expires.",
          "Send a stored `Idempotency-Key` on every POST and PUT. Create transfer and Create card reject requests without one.",
          "Only settled transactions are returned. Poll card and cash transactions with `posted_at_start` and a lookback of at least one day.",
          "Keep under 1,000 requests in 60 seconds per client and account, and back off exponentially with jitter on 429.",
          "Send only ASCII in free-text fields, and quote the `X-Brex-Trace-Id` response header when reporting an error."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.7
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 66,
          "payments": 25,
          "reliability": 60,
          "schema": 80,
          "security": 72,
          "transparency": 47
        },
        "provenanceScore": 86
      },
      "connect": {
        "http": "curl -i -X GET \\\n  https://api.brex.com/v2/users/me \\\n  -H 'Authorization: Bearer \u003cYOUR_TOKEN_FROM_STEP_1_HERE\u003e'",
        "claudeCode": "claude mcp add --transport http brex https://api.brex.com/mcp",
        "config": {
          "mcpServers": {
            "brex": {
              "headers": {
                "Authorization": "Bearer YOUR_BREX_ACCESS_TOKEN"
              },
              "type": "http",
              "url": "https://api.brex.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/brex"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Essentials plan",
          "unit": "seat-month",
          "usd": 0,
          "note": "Brex API access listed on this plan"
        },
        {
          "item": "Premium plan",
          "unit": "seat-month",
          "usd": 12,
          "note": "Enterprise is priced on request"
        }
      ],
      "provenance": {
        "legalEntity": "Brex LLC",
        "domain": "brex.com",
        "domainRegistered": "1998-10-22",
        "endpointOnVendorDomain": true,
        "terms": "https://www.brex.com/legal/platform-agreement",
        "privacy": "https://www.brex.com/legal/privacy",
        "statusPage": "https://status.brex.com",
        "changelog": "https://developer.brex.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Platform Agreement defines Brex as Brex LLC, a wholly owned subsidiary of Capital One, N.A., and the pricing page footer gives addresses in San Francisco and Salt Lake City.",
          "API use is also governed by the Brex Access Agreement at https://www.brex.com/legal/developer-portal, which an admin accepts in the dashboard before creating a token.",
          "The API and the MCP server answer at api.brex.com and the authorisation server at accounts-api.brex.com, both brex.com subdomains. The former host platform.brexapis.com still works per the docs.",
          "www.brex.com/.well-known/security.txt returns 404. brex.com/trust/responsible-disclosure has a disclosure policy and a form run with Bugcrowd.",
          "RDAP for brex.com gives a registration date of 1998-10-22."
        ],
        "score": 86
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/brex.json",
      "live": {
        "slug": "brex",
        "probe": {
          "target": "https://api.brex.com",
          "method": "get",
          "lastAt": "2026-10-08T18:20:26.579313312Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 355,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 434,
          "p95ms24h": 526,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.brex.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T18:21:50.939179332Z"
        },
        "securityTxt": {
          "url": "https://brex.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:43.637271768Z"
        },
        "pages": [
          {
            "url": "https://developer.brex.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:07.265606865Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "953aa59e7531"
          }
        ],
        "updatedAt": "2026-10-08T18:21:50.939179332Z"
      }
    },
    "answer": "Pleo API + MCP scores 62.9 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on agent ergonomics and payments \u0026 pricing.",
    "b": {
      "slug": "pleo",
      "name": "Pleo API + MCP",
      "vendor": "Pleo Technologies A/S",
      "vendorUrl": "https://www.pleo.io/en",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Spend management platform from Pleo Technologies A/S in Copenhagen, covering company cards, expenses, reimbursements, invoices and accounting exports. Outside agents reach it through a hosted MCP server for expense work and a REST API built for accounting integrations.",
      "url": "https://www.anchorterminal.com/tools/pleo",
      "markdownUrl": "https://www.anchorterminal.com/tools/pleo.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/pleo.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/pleo.json",
      "license": "Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://external.pleo.io",
      "packages": [],
      "auth": "mixed",
      "authNotes": "A person signs in for every route. The MCP server uses OAuth 2.0 in a browser (authorisation code with PKCE, dynamic client registration, no keys to configure) and acts with the connecting user's Pleo role, once a company admin has enabled MCP access for that entity. The External API accepts OAuth 2.0 bearer tokens with resource scopes for partner integrations, whose client ID and secret Pleo issues after review in its Early Access Programme. A single company can use a Standalone API Key with chosen scopes and an expiry, sent as the Basic auth username, but only after Pleo support or a Customer Success Manager enables keys for the organisation.",
      "pricing": "paid",
      "pricingNotes": "Per-user plans, with no separate charge for the API or the MCP server. The pricing page shown to a UK visitor lists Start at £8 per user per month, Build at £14 and Optimise at £18, the last two cheaper billed yearly and with a three-user minimum. MCP is listed on Optimise only, which is sold through a demo. Start and Build have a Try for free button and the signup form states 21 days free. Whether the trial needs a payment card isn't stated. A staging environment with test data exists for customers with API keys enabled and for approved partners. Fees for payments and foreign exchange are extra (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.pleo.io/",
      "llmsTxt": "https://developers.pleo.io/llms.txt",
      "openapi": "https://developers.pleo.io/reference/Export%20API.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.bills"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "api-key",
        "openapi",
        "llms-txt",
        "webhooks",
        "closed-source",
        "status-page",
        "bug-bounty",
        "sandbox"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.9,
        "grade": "B",
        "agentReady": false,
        "rank": 293,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 55,
          "maintenance": 64,
          "payments": 15,
          "reliability": 71,
          "schema": 82,
          "security": 71,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.",
        "bestFor": "An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.",
        "strengths": [
          "MCP server at mcp.pleo.io/mcp uses OAuth with PKCE and dynamic client registration, and acts with the connecting user's Pleo permissions",
          "Payments, card changes and spending-limit changes are blocked through the MCP by design, per the AI Access Terms",
          "Eleven current OpenAPI 3.0.1 specs with 162 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page",
          "One documented rate limit of 600 requests a minute per credential, with written 429 and Retry-After guidance",
          "Staging hosts for both the API (external.staging.pleo.io) and the MCP server (mcp.staging.pleo.io/mcp)",
          "Sub-processor list with locations, customer data in AWS Ireland, and 30 days' notice of new sub-processors in the DPA"
        ],
        "weaknesses": [
          "The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)",
          "MCP tool names, schemas and count aren't published, so they can't be read without a customer sign-in",
          "Standalone API keys aren't self-service. Pleo support or a Customer Success Manager enables them, and partner OAuth clients go through a reviewed programme",
          "No Idempotency-Key header, no official SDK and no entry in the official MCP registry",
          "The API terms call the API a beta version that Pleo may discontinue at any time, and no SLA was found",
          "No end-of-life date is published for the deprecated Legacy API, and its Q3 2026 replacements for employee writes and wallet balance aren't in the docs"
        ],
        "agentNotes": [
          "Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default",
          "Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist",
          "Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side",
          "Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there",
          "Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second",
          "Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.9
          }
        ],
        "editorialScores": {
          "ergonomics": 55,
          "maintenance": 64,
          "payments": 15,
          "reliability": 71,
          "schema": 82,
          "security": 71,
          "transparency": 63
        },
        "provenanceScore": 87
      },
      "connect": {
        "http": "curl --request GET \\\n-u \"YOUR-API-KEY:\" \\\n-H \"Accept: application/json;charset=UTF-8\" \\\n\"https://external.staging.pleo.io/v2/employees\"",
        "claudeCode": "claude mcp add --transport http pleo-mcp-staging https://mcp.staging.pleo.io/mcp",
        "config": {
          "mcpServers": {
            "pleo": {
              "url": "https://mcp.pleo.io/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/pleo"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Pleo Technologies A/S",
        "domain": "pleo.io",
        "domainRegistered": "2015-10-07",
        "endpointOnVendorDomain": true,
        "terms": "https://developers.pleo.io/page/terms-of-service",
        "privacy": "https://www.pleo.io/legal-documents/pleo-privacy-policy-en.pdf",
        "statusPage": "https://status.pleo.io",
        "changelog": "https://developers.pleo.io/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The website footer names Pleo Technologies A/S (36538686), Ravnsborg Tværgade 5C, 2200 København N, Denmark. UK payment services come from Pleo Financial Services UK Ltd, FCA firm reference 1020730, company number 15842283.",
          "The API Terms of Service on the developer portal name Pleo Technologies A/S, carry no date, and describe the API as a beta version. The UK Master Service Agreement has an effective date of 7 September 2026 and is governed by the laws of England and Wales.",
          "The API answers at external.pleo.io and the MCP server at mcp.pleo.io, both pleo.io subdomains. The MCP host publishes its OAuth metadata at https://mcp.pleo.io/.well-known/oauth-authorization-server",
          "www.pleo.io/.well-known/security.txt and pleo.io/.well-known/security.txt both return 403 with an AccessDenied body. The vulnerability disclosure policy gives security-vd@pleo.io as the reporting address.",
          "The privacy notice is dated June 2026 and the Data Processing Agreement 14 October 2025. An AI Access Terms document covers the MCP server.",
          "RDAP from the .io registry gives a registration date of 2015-10-07 for pleo.io."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/pleo.json",
      "live": {
        "slug": "pleo",
        "probe": {
          "target": "https://external.pleo.io",
          "method": "get",
          "lastAt": "2026-10-08T18:20:37.689130608Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 107,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 94,
          "p95ms24h": 163,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.pleo.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T18:22:15.952094673Z"
        },
        "securityTxt": {
          "url": "https://pleo.io/.well-known/security.txt",
          "state": "unknown",
          "checkedAt": "2026-10-08T15:38:57.657849973Z"
        },
        "pages": [
          {
            "url": "https://developers.pleo.io/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:58.324737763Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7369dd13eb7c"
          },
          {
            "url": "https://developers.pleo.io/page/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:00.641635735Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5da670693385"
          }
        ],
        "updatedAt": "2026-10-08T18:22:15.952094673Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Brex LLC",
        "b": "Pleo Technologies A/S",
        "name": "Vendor"
      },
      {
        "a": "https://api.brex.com",
        "b": "https://external.pleo.io",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Brex Platform Agreement and the Brex Access Agreement",
        "b": "Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms",
        "name": "Licence"
      },
      {
        "a": "43",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-01",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      }
    ],
    "faq": [
      {
        "answer": "Pleo API + MCP scores 62.9 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on agent ergonomics and payments \u0026 pricing.",
        "question": "Which is better for AI agents, Brex or Pleo API + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Brex and Pleo API + MCP need an API key?"
      },
      {
        "answer": "Yes. Brex has a hosted endpoint at https://api.brex.com and Pleo API + MCP at https://external.pleo.io.",
        "question": "Can an agent call Brex and Pleo API + MCP without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 70 against 55",
          "Payments \u0026 pricing, 25 against 15"
        ],
        "also": null,
        "goodFor": "A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.",
        "slug": "brex",
        "watchFor": "The Expenses API update endpoint accepts only `memo`, so an outside agent can't set a category or custom field on an expense through it"
      },
      {
        "aheadOn": [
          "Reliability, 71 against 60",
          "Transparency \u0026 trust, 75 against 67"
        ],
        "also": [
          "No incidents deducted, where Brex loses 3 points for them"
        ],
        "goodFor": "An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.",
        "slug": "pleo",
        "watchFor": "The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)"
      }
    ],
    "job": {
      "capability": "spend.transactions",
      "name": "Spend transactions"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-expensify.json",
        "title": "Brex vs Expensify",
        "url": "https://www.anchorterminal.com/compare/brex-vs-expensify"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-ramp.json",
        "title": "Brex vs Ramp",
        "url": "https://www.anchorterminal.com/compare/brex-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-spendesk.json",
        "title": "Brex vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expensify-vs-pleo.json",
        "title": "Expensify vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/expensify-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pleo-vs-ramp.json",
        "title": "Pleo API + MCP vs Ramp",
        "url": "https://www.anchorterminal.com/compare/pleo-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pleo-vs-spendesk.json",
        "title": "Pleo API + MCP vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/pleo-vs-spendesk"
      }
    ],
    "scores": [
      {
        "brex": 60,
        "by": 11,
        "edge": "pleo",
        "key": "reliability",
        "name": "Reliability",
        "pleo": 71,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "brex": 80,
        "by": 2,
        "edge": "pleo",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "pleo": 82,
        "weight": 13
      },
      {
        "brex": 70,
        "by": 15,
        "edge": "brex",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "pleo": 55,
        "weight": 13
      },
      {
        "brex": 72,
        "by": 1,
        "edge": "brex",
        "key": "security",
        "name": "Security \u0026 auth",
        "pleo": 71,
        "weight": 14
      },
      {
        "brex": 25,
        "by": 10,
        "edge": "brex",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "pleo": 15,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "brex": 66,
        "by": 2,
        "edge": "brex",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "pleo": 64,
        "weight": 7
      },
      {
        "brex": 67,
        "by": 8,
        "edge": "pleo",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "pleo": 75,
        "weight": 7
      }
    ],
    "summary": "Pleo API + MCP scores 62.9 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on agent ergonomics and payments \u0026 pricing. Both do spend transactions.",
    "verdicts": {
      "brex": "User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.",
      "pleo": "The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/brex-vs-pleo",
    "json": "https://www.anchorterminal.com/compare/brex-vs-pleo.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/brex-vs-pleo.md",
    "slim": "https://www.anchorterminal.com/compare/brex-vs-pleo.min.md"
  },
  "markdown": "Pleo API + MCP scores 62.9 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on agent ergonomics and payments \u0026 pricing. Both do spend transactions.\n\n- Brex: grade C, 60.7/100, rank #345 of 629. Markdown https://www.anchorterminal.com/tools/brex.md · JSON https://www.anchorterminal.com/api/v1/tools/brex.json\n- Pleo API + MCP: grade B, 62.9/100, rank #293 of 629. Markdown https://www.anchorterminal.com/tools/pleo.md · JSON https://www.anchorterminal.com/api/v1/tools/pleo.json\n\n## Which one, for what\n\n### Brex (C)\n\nGood for: A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.\n\nAhead on:\n- Agent ergonomics, 70 against 55\n- Payments \u0026 pricing, 25 against 15\n\nWatch for: The Expenses API update endpoint accepts only `memo`, so an outside agent can't set a category or custom field on an expense through it\n\n### Pleo API + MCP (B)\n\nGood for: An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.\n\nAhead on:\n- Reliability, 71 against 60\n- Transparency \u0026 trust, 75 against 67\n\nAlso in its favour:\n- No incidents deducted, where Brex loses 3 points for them\n\nWatch for: The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)\n\n\n## Score by category\n\n| Category | Weight | Brex | Pleo API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 60 | 71 | Pleo API + MCP +11 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 80 | 82 | Pleo API + MCP +2 |\n| Agent ergonomics | 13% (16.2 this run) | 70 | 55 | Brex +15 |\n| Security \u0026 auth | 14% (17.5 this run) | 72 | 71 | Brex +1 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 15 | Brex +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 66 | 64 | Brex +2 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 67 | 75 | Pleo API + MCP +8 |\n| Negative events | ≤15 | -3 | 0 | |\n| **Total** | | **60.7 · C** | **62.9 · B** | |\n\n## Facts side by side\n\n| Fact | Brex | Pleo API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Brex LLC | Pleo Technologies A/S |\n| Hosted endpoint | `https://api.brex.com` | `https://external.pleo.io` |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Paid |\n| x402 | no | no |\n| Licence | Proprietary service under the Brex Platform Agreement and the Brex Access Agreement | Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms |\n| Tools exposed | 43 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-01 | 2026-10-02 |\n| Terms last updated | no date given | no date given |\n| Privacy policy last updated | no date given |  |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n\n## Verdicts\n\n**Brex.** User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.\n\n**Pleo API + MCP.** The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.\n\n## Before you call either\n\n### Brex\n\n1. Ask an account admin or card admin for a user token with only the scopes the task needs, and prefer the `.readonly` variants. A token unused for 90 days expires.\n2. Send a stored `Idempotency-Key` on every POST and PUT. Create transfer and Create card reject requests without one.\n3. Only settled transactions are returned. Poll card and cash transactions with `posted_at_start` and a lookback of at least one day.\n4. Keep under 1,000 requests in 60 seconds per client and account, and back off exponentially with jitter on 429.\n5. Send only ASCII in free-text fields, and quote the `X-Brex-Trace-Id` response header when reporting an error.\n\n### Pleo API + MCP\n\n1. Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default\n2. Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist\n3. Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side\n4. Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there\n5. Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second\n6. Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in\n\n## Questions\n\n### Which is better for AI agents, Brex or Pleo API + MCP?\n\nPleo API + MCP scores 62.9 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on agent ergonomics and payments \u0026 pricing.\n\n### Do Brex and Pleo API + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Brex and Pleo API + MCP without installing anything?\n\nYes. Brex has a hosted endpoint at https://api.brex.com and Pleo API + MCP at https://external.pleo.io.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/brex-vs-pleo.json, and with the fewest tokens: https://www.anchorterminal.com/compare/brex-vs-pleo.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"brex\", \"b\": \"pleo\"}`. From a terminal: `anchor compare brex pleo`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/brex.json and https://www.anchorterminal.com/api/v1/tools/pleo.json\n\n## Other comparisons with Brex or Pleo API + MCP\n\n- [Brex vs Expensify](https://www.anchorterminal.com/compare/brex-vs-expensify.md)\n- [Brex vs Ramp](https://www.anchorterminal.com/compare/brex-vs-ramp.md)\n- [Brex vs Spendesk API + MCP](https://www.anchorterminal.com/compare/brex-vs-spendesk.md)\n- [Expensify vs Pleo API + MCP](https://www.anchorterminal.com/compare/expensify-vs-pleo.md)\n- [Pleo API + MCP vs Ramp](https://www.anchorterminal.com/compare/pleo-vs-ramp.md)\n- [Pleo API + MCP vs Spendesk API + MCP](https://www.anchorterminal.com/compare/pleo-vs-spendesk.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Brex vs Pleo API + MCP",
        "url": ""
      }
    ],
    "description": "Pleo API + MCP scores 62.9 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on agent ergonomics and payments \u0026 pricing. Both do spend transactions. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Brex C 60.7",
      "Pleo API + MCP B 62.9",
      "scores"
    ],
    "h1": "Brex vs Pleo API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-brex-vs-pleo.png",
    "path": "/compare/brex-vs-pleo",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Brex vs Pleo API + MCP for AI agents, C 60.7 vs B 62.9",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/brex-vs-pleo"
  },
  "tokens": {
    "markdown": 2000,
    "slim": 630
  },
  "version": 1
}
