{
  "data": {
    "a": {
      "slug": "brex",
      "name": "Brex",
      "vendor": "Brex LLC",
      "vendorUrl": "https://www.brex.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Brex is a spend platform with corporate cards, expense management, bill pay, travel and business accounts. Its REST Developer API reads and writes cards, expenses, spend limits, vendors and transfers, and a hosted MCP server is in beta.",
      "url": "https://www.anchorterminal.com/tools/brex",
      "markdownUrl": "https://www.anchorterminal.com/tools/brex.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/brex.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/brex.json",
      "license": "Proprietary service under the Brex Platform Agreement and the Brex Access Agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.brex.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is self-serve for a Brex customer. An account admin or card admin accepts the Developer API agreement in the dashboard, then creates a user token with chosen scopes at Settings \u003e Developer. The token is sent as a Bearer header, is shown once, can be revoked, and expires after 90 days without a call. Partners acting for other Brex accounts apply to Brex for a client ID and secret and use the OAuth 2.0 authorisation code grant, with one-hour access tokens and refresh tokens. The MCP server takes OAuth with dynamic client registration, where each employee signs in with their own permissions, or an admin's user token.",
      "pricing": "freemium",
      "pricingNotes": "No separate API fee. brex.com/pricing lists Brex API access under Essentials at $0 per user per month, with Premium at $12 per user per month and Enterprise priced on request. Access needs an approved Brex business account, so an agent can't start without one. There is no customer sandbox, and the staging server is for approved partners only. The Access Agreement lets Brex introduce API fees on 30 days' notice (checked 2026-10-08).",
      "priceSummary": "$12 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 43,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.brex.com",
      "llmsTxt": "https://developer.brex.com/llms.txt",
      "openapi": "https://developer.brex.com/_bundle/openapi/team_api.yaml",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills"
      ],
      "tags": [
        "hosted",
        "freemium",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "status-page",
        "soc2",
        "pci-dss"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.7,
        "grade": "C",
        "agentReady": false,
        "rank": 345,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 66,
          "payments": 25,
          "reliability": 60,
          "schema": 80,
          "security": 72,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-02 and 2026-09. The changelog records the List expenses maximum `limit` cut from 1,000 to 100 in February 2026, and `GET /v2/users/{id}/limit` removed from the Team API in September 2026 without a deprecated label in the entry. The Team API is at version 1.0, and the launch-stages page says breaking changes to generally available APIs come as new versions with deprecation timelines. Both changes are documented in the month they shipped, and notice by email couldn't be checked, so the smallest deduction applies (https://developer.brex.com/changelog)."
        ],
        "verdict": "User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.",
        "bestFor": "A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.",
        "strengths": [
          "Ten public OpenAPI 3 specs covering 115 operations, plus llms.txt and a Markdown twin of every docs page",
          "User tokens take scopes chosen at creation, most with a read-only variant, and card numbers need the separate `cards.pan` scope",
          "Every POST and PUT accepts an `Idempotency-Key`, and Create transfer and Create card require one",
          "API access is listed on the Essentials plan at $0 per user per month",
          "The hosted MCP server uses OAuth with dynamic client registration and each employee's own Brex permissions"
        ],
        "weaknesses": [
          "The Expenses API update endpoint accepts only `memo`, so an outside agent can't set a category or custom field on an expense through it",
          "No customer sandbox. The docs say staging isn't a sandbox and won't accept customer tokens",
          "No official SDK. The docs list three community libraries that Brex doesn't support",
          "status.brex.com logs API request errors from 16:01 to 20:34 UTC on 4 August 2026 and invalidated developer tokens on 21 September 2026",
          "The MCP server is beta with 43 tools, and approvals and card management aren't available through it"
        ],
        "agentNotes": [
          "Ask an account admin or card admin for a user token with only the scopes the task needs, and prefer the `.readonly` variants. A token unused for 90 days expires.",
          "Send a stored `Idempotency-Key` on every POST and PUT. Create transfer and Create card reject requests without one.",
          "Only settled transactions are returned. Poll card and cash transactions with `posted_at_start` and a lookback of at least one day.",
          "Keep under 1,000 requests in 60 seconds per client and account, and back off exponentially with jitter on 429.",
          "Send only ASCII in free-text fields, and quote the `X-Brex-Trace-Id` response header when reporting an error."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.7
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 66,
          "payments": 25,
          "reliability": 60,
          "schema": 80,
          "security": 72,
          "transparency": 47
        },
        "provenanceScore": 86
      },
      "connect": {
        "http": "curl -i -X GET \\\n  https://api.brex.com/v2/users/me \\\n  -H 'Authorization: Bearer \u003cYOUR_TOKEN_FROM_STEP_1_HERE\u003e'",
        "claudeCode": "claude mcp add --transport http brex https://api.brex.com/mcp",
        "config": {
          "mcpServers": {
            "brex": {
              "headers": {
                "Authorization": "Bearer YOUR_BREX_ACCESS_TOKEN"
              },
              "type": "http",
              "url": "https://api.brex.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/brex"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Essentials plan",
          "unit": "seat-month",
          "usd": 0,
          "note": "Brex API access listed on this plan"
        },
        {
          "item": "Premium plan",
          "unit": "seat-month",
          "usd": 12,
          "note": "Enterprise is priced on request"
        }
      ],
      "provenance": {
        "legalEntity": "Brex LLC",
        "domain": "brex.com",
        "domainRegistered": "1998-10-22",
        "endpointOnVendorDomain": true,
        "terms": "https://www.brex.com/legal/platform-agreement",
        "privacy": "https://www.brex.com/legal/privacy",
        "statusPage": "https://status.brex.com",
        "changelog": "https://developer.brex.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Platform Agreement defines Brex as Brex LLC, a wholly owned subsidiary of Capital One, N.A., and the pricing page footer gives addresses in San Francisco and Salt Lake City.",
          "API use is also governed by the Brex Access Agreement at https://www.brex.com/legal/developer-portal, which an admin accepts in the dashboard before creating a token.",
          "The API and the MCP server answer at api.brex.com and the authorisation server at accounts-api.brex.com, both brex.com subdomains. The former host platform.brexapis.com still works per the docs.",
          "www.brex.com/.well-known/security.txt returns 404. brex.com/trust/responsible-disclosure has a disclosure policy and a form run with Bugcrowd.",
          "RDAP for brex.com gives a registration date of 1998-10-22."
        ],
        "score": 86
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/brex.json",
      "live": {
        "slug": "brex",
        "probe": {
          "target": "https://api.brex.com",
          "method": "get",
          "lastAt": "2026-10-08T18:20:26.579313312Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 355,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 434,
          "p95ms24h": 526,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.brex.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T18:21:50.939179332Z"
        },
        "securityTxt": {
          "url": "https://brex.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:43.637271768Z"
        },
        "pages": [
          {
            "url": "https://developer.brex.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:07.265606865Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "953aa59e7531"
          }
        ],
        "updatedAt": "2026-10-08T18:21:50.939179332Z"
      }
    },
    "answer": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on reliability, agent ergonomics, payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "spendesk",
      "name": "Spendesk API + MCP",
      "vendor": "Spendesk SAS",
      "vendorUrl": "https://www.spendesk.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Spend management platform from Spendesk SAS in Paris, covering company cards, expense claims, supplier invoices, purchase orders and accounting exports. Outside agents reach it through a REST API with scoped keys or OAuth, and a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/spendesk",
      "markdownUrl": "https://www.anchorterminal.com/tools/spendesk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/spendesk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/spendesk.json",
      "license": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://public-api.spendesk.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is granted by Spendesk, not self-serve. A customer asks its Spendesk representative for API access, then an Account Owner or Admin creates an API key (client ID and secret) with chosen scopes and an expiry of up to one year. The key is exchanged at POST /v1/auth/token with HTTP Basic for a Bearer token that lasts 60 minutes and can carry fewer scopes than the key. Partner integrations use OAuth 2.0 authorisation code with PKCE after approval by the partnerships team. The MCP server accepts only OAuth user tokens, refuses API keys, and limits use to Controllers and Account Owners. Experimental scopes are added on request.",
      "pricing": "paid",
      "pricingNotes": "No public prices. The pricing page describes a fixed monthly platform fee plus variable fees per transaction (card purchases, invoice payments and expense claims) and asks for a quote. It lists the open API and the MCP connection in the base package. No free tier, trial or self-serve sandbox was found. A demo environment exists at public-api.demo.spendesk.com, with credentials requested alongside API access (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI definition or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 62,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.spendesk.com",
      "llmsTxt": "https://developer.spendesk.com/llms.txt",
      "openapi": "https://developer.spendesk.com/openapi/spendesk-public-api.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "spend.procurement"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sales-led",
        "status-page",
        "iso27001",
        "bug-bounty"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.3,
        "grade": "B",
        "agentReady": false,
        "rank": 306,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.",
        "bestFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
        "strengths": [
          "OpenAPI 3.1 definition with 106 operations, llms.txt and a Markdown copy of every docs page, all public without sign-in",
          "37 documented scopes split by resource and by read or write. A token can carry fewer scopes than its key, and keys expire within one year",
          "MCP write permissions are off by default, enabled per connection by an admin with a second factor, then ticked by each user",
          "Every MCP tool call is recorded in an action log with date, tool, status, user, company and correlation ID",
          "Rate limits are published (1,000 requests a minute per company and credential) with x-ratelimit headers on every response"
        ],
        "weaknesses": [
          "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative",
          "Cards, transactions, invoices, purchase orders, webhooks and most writes sit behind experimental scopes granted on request, and may change",
          "No official SDK found on npm or PyPI, and the MCP server isn't in the official MCP registry",
          "status.spendesk.com has no API component and lists three critical and three major incidents opened between 2 and 29 September 2026",
          "An Idempotency-Key is documented only for creating an intake. A repeated purchase order or supplier request creates a second record"
        ],
        "agentNotes": [
          "Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401",
          "Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list",
          "With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400",
          "The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission",
          "After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.3
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 64
        },
        "provenanceScore": 96
      },
      "connect": {
        "http": "curl -X POST https://public-api.demo.spendesk.com/v1/auth/token \\\n  -u \"YOUR_CLIENT_ID:YOUR_CLIENT_SECRET\"\n\ncurl https://public-api.demo.spendesk.com/v1/wallet-summary \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/spendesk"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Spendesk SAS",
        "domain": "spendesk.com",
        "domainRegistered": "2015-10-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.spendesk.com/legals/terms/",
        "privacy": "https://www.spendesk.com/legals/privacy/",
        "statusPage": "https://status.spendesk.com",
        "changelog": "https://developer.spendesk.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The legal notice names Spendesk SAS, 7 Rue de Madrid, 75008 Paris, registration 821 893 286 R.C.S. Paris. The privacy policy (March 2025, version 0.5) gives the registered office as 51 rue de Londres, 75008 Paris.",
          "Payment services are supplied by Spendesk Financial Services (a French payment institution licensed by the ACPR, number 17518) in the EEA, Adyen in the UK and Sutton Bank in the US, per the site footer.",
          "The API and the MCP server answer at public-api.spendesk.com. An unauthenticated POST to /v1/mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata.",
          "www.spendesk.com/.well-known/security.txt is present with a contact and an expiry of 31 December 2026. developer.spendesk.com/.well-known/security.txt returns 404.",
          "The terms page lists the customer terms, a DORA addendum, a Spendesk API agreement and partner programme terms. The document links are drawn by JavaScript and we couldn't open them.",
          "RDAP for spendesk.com gives a registration date of 2015-10-30."
        ],
        "score": 96
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/spendesk.json",
      "live": {
        "slug": "spendesk",
        "probe": {
          "target": "https://public-api.spendesk.com",
          "method": "get",
          "lastAt": "2026-10-08T18:20:40.801700324Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 67,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 67,
          "p95ms24h": 103,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.spendesk.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-08T18:22:20.323763159Z"
        },
        "securityTxt": {
          "url": "https://spendesk.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-12-31T22:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:39.004780879Z"
        },
        "pages": [
          {
            "url": "https://developer.spendesk.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:18.275650963Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0a7493461e82"
          }
        ],
        "updatedAt": "2026-10-08T18:22:20.323763159Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Brex LLC",
        "b": "Spendesk SAS",
        "name": "Vendor"
      },
      {
        "a": "https://api.brex.com",
        "b": "https://public-api.spendesk.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Brex Platform Agreement and the Brex Access Agreement",
        "b": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
        "name": "Licence"
      },
      {
        "a": "43",
        "b": "62",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-01",
        "b": "2026-09-29",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2025-03-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      }
    ],
    "faq": [
      {
        "answer": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on reliability, agent ergonomics, payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Brex or Spendesk API + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Brex and Spendesk API + MCP need an API key?"
      },
      {
        "answer": "Yes. Brex has a hosted endpoint at https://api.brex.com and Spendesk API + MCP at https://public-api.spendesk.com.",
        "question": "Can an agent call Brex and Spendesk API + MCP without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 60 against 55",
          "Agent ergonomics, 70 against 62",
          "Payments \u0026 pricing, 25 against 0",
          "Maintenance \u0026 community, 66 against 57"
        ],
        "also": null,
        "goodFor": "A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.",
        "slug": "brex",
        "watchFor": "The Expenses API update endpoint accepts only `memo`, so an outside agent can't set a category or custom field on an expense through it"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 87 against 80",
          "Security \u0026 auth, 86 against 72",
          "Transparency \u0026 trust, 80 against 67"
        ],
        "also": [
          "No incidents deducted, where Brex loses 3 points for them"
        ],
        "goodFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
        "slug": "spendesk",
        "watchFor": "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative"
      }
    ],
    "job": {
      "capability": "spend.transactions",
      "name": "Spend transactions"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-expensify.json",
        "title": "Brex vs Expensify",
        "url": "https://www.anchorterminal.com/compare/brex-vs-expensify"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-pleo.json",
        "title": "Brex vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-ramp.json",
        "title": "Brex vs Ramp",
        "url": "https://www.anchorterminal.com/compare/brex-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expensify-vs-spendesk.json",
        "title": "Expensify vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/expensify-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pleo-vs-spendesk.json",
        "title": "Pleo API + MCP vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/pleo-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ramp-vs-spendesk.json",
        "title": "Ramp vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/ramp-vs-spendesk"
      }
    ],
    "scores": [
      {
        "brex": 60,
        "by": 5,
        "edge": "brex",
        "key": "reliability",
        "name": "Reliability",
        "spendesk": 55,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "brex": 80,
        "by": 7,
        "edge": "spendesk",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "spendesk": 87,
        "weight": 13
      },
      {
        "brex": 70,
        "by": 8,
        "edge": "brex",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "spendesk": 62,
        "weight": 13
      },
      {
        "brex": 72,
        "by": 14,
        "edge": "spendesk",
        "key": "security",
        "name": "Security \u0026 auth",
        "spendesk": 86,
        "weight": 14
      },
      {
        "brex": 25,
        "by": 25,
        "edge": "brex",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "spendesk": 0,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "brex": 66,
        "by": 9,
        "edge": "brex",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "spendesk": 57,
        "weight": 7
      },
      {
        "brex": 67,
        "by": 13,
        "edge": "spendesk",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "spendesk": 80,
        "weight": 7
      }
    ],
    "summary": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on reliability, agent ergonomics, payments \u0026 pricing and maintenance \u0026 community. Both do spend transactions.",
    "verdicts": {
      "brex": "User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.",
      "spendesk": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/brex-vs-spendesk",
    "json": "https://www.anchorterminal.com/compare/brex-vs-spendesk.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/brex-vs-spendesk.md",
    "slim": "https://www.anchorterminal.com/compare/brex-vs-spendesk.min.md"
  },
  "markdown": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on reliability, agent ergonomics, payments \u0026 pricing and maintenance \u0026 community. Both do spend transactions.\n\n- Brex: grade C, 60.7/100, rank #345 of 629. Markdown https://www.anchorterminal.com/tools/brex.md · JSON https://www.anchorterminal.com/api/v1/tools/brex.json\n- Spendesk API + MCP: grade B, 62.3/100, rank #306 of 629. Markdown https://www.anchorterminal.com/tools/spendesk.md · JSON https://www.anchorterminal.com/api/v1/tools/spendesk.json\n\n## Which one, for what\n\n### Brex (C)\n\nGood for: A finance team already on Brex that wants an agent to read expenses and transactions, issue and lock cards, set spend limits, upload receipts and pay vendors.\n\nAhead on:\n- Reliability, 60 against 55\n- Agent ergonomics, 70 against 62\n- Payments \u0026 pricing, 25 against 0\n- Maintenance \u0026 community, 66 against 57\n\nWatch for: The Expenses API update endpoint accepts only `memo`, so an outside agent can't set a category or custom field on an expense through it\n\n### Spendesk API + MCP (B)\n\nGood for: A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.\n\nAhead on:\n- Schema \u0026 documentation, 87 against 80\n- Security \u0026 auth, 86 against 72\n- Transparency \u0026 trust, 80 against 67\n\nAlso in its favour:\n- No incidents deducted, where Brex loses 3 points for them\n\nWatch for: No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative\n\n\n## Score by category\n\n| Category | Weight | Brex | Spendesk API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 60 | 55 | Brex +5 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 80 | 87 | Spendesk API + MCP +7 |\n| Agent ergonomics | 13% (16.2 this run) | 70 | 62 | Brex +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 72 | 86 | Spendesk API + MCP +14 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 0 | Brex +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 66 | 57 | Brex +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 67 | 80 | Spendesk API + MCP +13 |\n| Negative events | ≤15 | -3 | 0 | |\n| **Total** | | **60.7 · C** | **62.3 · B** | |\n\n## Facts side by side\n\n| Fact | Brex | Spendesk API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Brex LLC | Spendesk SAS |\n| Hosted endpoint | `https://api.brex.com` | `https://public-api.spendesk.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Paid |\n| x402 | no | no |\n| Licence | Proprietary service under the Brex Platform Agreement and the Brex Access Agreement | Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement |\n| Tools exposed | 43 | 62 |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-01 | 2026-09-29 |\n| Terms last updated | no date given | couldn't be read |\n| Privacy policy last updated | no date given | 2025-03-01 |\n| Customer content may train models | not found in the text | couldn't be read |\n| Terms restrict automated access | not found in the text | couldn't be read |\n| Terms restrict benchmarking | yes | couldn't be read |\n| Terms or service can change without notice | not found in the text | couldn't be read |\n| Arbitration or class-action waiver | yes | couldn't be read |\n\n## Verdicts\n\n**Brex.** User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026.\n\n**Spendesk API + MCP.** Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.\n\n## Before you call either\n\n### Brex\n\n1. Ask an account admin or card admin for a user token with only the scopes the task needs, and prefer the `.readonly` variants. A token unused for 90 days expires.\n2. Send a stored `Idempotency-Key` on every POST and PUT. Create transfer and Create card reject requests without one.\n3. Only settled transactions are returned. Poll card and cash transactions with `posted_at_start` and a lookback of at least one day.\n4. Keep under 1,000 requests in 60 seconds per client and account, and back off exponentially with jitter on 429.\n5. Send only ASCII in free-text fields, and quote the `X-Brex-Trace-Id` response header when reporting an error.\n\n### Spendesk API + MCP\n\n1. Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401\n2. Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list\n3. With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400\n4. The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission\n5. After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two\n\n## Questions\n\n### Which is better for AI agents, Brex or Spendesk API + MCP?\n\nSpendesk API + MCP scores 62.3 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on reliability, agent ergonomics, payments \u0026 pricing and maintenance \u0026 community.\n\n### Do Brex and Spendesk API + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Brex and Spendesk API + MCP without installing anything?\n\nYes. Brex has a hosted endpoint at https://api.brex.com and Spendesk API + MCP at https://public-api.spendesk.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/brex-vs-spendesk.json, and with the fewest tokens: https://www.anchorterminal.com/compare/brex-vs-spendesk.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"brex\", \"b\": \"spendesk\"}`. From a terminal: `anchor compare brex spendesk`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/brex.json and https://www.anchorterminal.com/api/v1/tools/spendesk.json\n\n## Other comparisons with Brex or Spendesk API + MCP\n\n- [Brex vs Expensify](https://www.anchorterminal.com/compare/brex-vs-expensify.md)\n- [Brex vs Pleo API + MCP](https://www.anchorterminal.com/compare/brex-vs-pleo.md)\n- [Brex vs Ramp](https://www.anchorterminal.com/compare/brex-vs-ramp.md)\n- [Expensify vs Spendesk API + MCP](https://www.anchorterminal.com/compare/expensify-vs-spendesk.md)\n- [Pleo API + MCP vs Spendesk API + MCP](https://www.anchorterminal.com/compare/pleo-vs-spendesk.md)\n- [Ramp vs Spendesk API + MCP](https://www.anchorterminal.com/compare/ramp-vs-spendesk.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Brex vs Spendesk API + MCP",
        "url": ""
      }
    ],
    "description": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Brex's 60.7 (C), and leads in 3 of 7 scored categories. Brex leads on reliability, agent ergonomics, payments \u0026 pricing and maintenance \u0026 community. Both do spend transactions. Category scores, facts, verdicts and…",
    "facts": [
      "Brex C 60.7",
      "Spendesk API + MCP B 62.3",
      "scores"
    ],
    "h1": "Brex vs Spendesk API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-brex-vs-spendesk.png",
    "path": "/compare/brex-vs-spendesk",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Brex vs Spendesk API + MCP for AI agents, C 60.7 vs B 62.3",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/brex-vs-spendesk"
  },
  "tokens": {
    "markdown": 2000,
    "slim": 730
  },
  "version": 1
}
