{
  "data": {
    "a": {
      "slug": "payhawk",
      "name": "Payhawk API + MCP",
      "vendor": "Payhawk Limited",
      "vendorUrl": "https://payhawk.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Spend management platform from Payhawk Limited in London, covering company cards, expenses, bills, purchase orders and travel. Outside agents reach it through a REST Developer API with read-only or full-access keys, and a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/payhawk",
      "markdownUrl": "https://www.anchorterminal.com/tools/payhawk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/payhawk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/payhawk.json",
      "license": "Proprietary service under Payhawk's general terms and conditions",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.payhawk.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access needs a Payhawk customer account. An Administrator, an IT Administrator or a user with a custom role creates an API key in the portal under Settings, Integrations, choosing read-only or full access, and can regenerate it. The key goes in the `X-Payhawk-ApiKey` header or as a Bearer token. Two system-generated keys per account cannot be deleted by users. Group-level keys reach the group endpoints. If the key is not active, the API page says to write to partners@payhawk.com. The MCP server accepts OAuth 2 authorisation code with PKCE, where each user signs in with a Payhawk login and the assistant acts with that user's role.",
      "pricing": "paid",
      "pricingNotes": "Sold by quote per module (Travel, Cards and Expenses, Accounts Payable, Procurement) on annual or multi-year contracts, with unit-based charges for extra cards, reimbursements, purchase orders and invoices. The one published price is the Growth programme at 149 pounds a month for single-entity firms in the UK or EEA with fewer than 20 employees, with an optional 7-day trial for eligible customers. The API page says the API is free for all Payhawk accounts, and the pricing page lists Developer API access and the MCP server in the modules. A development sandbox is requested through a form on the API page (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the OpenAPI definition, the help centre or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 82,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.payhawk.com",
      "llmsTxt": "https://payhawk.com/llms.txt",
      "openapi": "https://api.payhawk.com/api/v3/docs.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "spend.procurement"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sales-led",
        "status-page",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.1,
        "grade": "C",
        "agentReady": false,
        "rank": 561,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 52,
          "maintenance": 53,
          "payments": 13,
          "reliability": 58,
          "schema": 71,
          "security": 71,
          "transparency": 78
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The Developer API has a public OpenAPI 3.1 definition with 179 operations, read-only or full-access keys and a published limit of 15 requests a second. It needs a Payhawk customer account, no official SDK or API changelog was found, and the 82-tool MCP server is added by hand because it is not yet in the assistant directories.",
        "bestFor": "A finance team already on Payhawk that wants an ERP or accounting sync, master data kept in step, purchase orders raised from another system, or an assistant that answers spend questions and prepares approvals.",
        "strengths": [
          "Public OpenAPI 3.1 definition with 105 paths and 179 operations, covering expenses, cards, fund accounts, suppliers, purchase orders and 24 webhook event types",
          "API keys are created as read-only or full access, sent in a header, and managed by administrators or a custom role",
          "The limit of 15 requests a second is stated on every operation, and responses carry RateLimit headers with Retry-After on a 429",
          "The MCP server acts with the signed-in user's own role, previews every write for confirmation, and never starts a payment or transfer",
          "SOC 1 and SOC 2 Type 2, ISO 27001, PCI DSS Level 1 and a penetration test attestation are downloadable from the trust page"
        ],
        "weaknesses": [
          "No self-serve route. The API needs a Payhawk customer account, and a development sandbox is requested through a form",
          "No official SDK on npm or PyPI, no API changelog and no deprecation policy were found. Release notes cover the product only",
          "The API page's FAQ contradicts the definition on the host name, the page size and whether expenses can be created or reviewed",
          "The status page is drawn by script, so its incident history could not be read. The terms disclaim service levels",
          "The MCP server has 82 tools, is not in the official MCP registry, and no guidance on prompt injection was found"
        ],
        "agentNotes": [
          "Send the key in `X-Payhawk-ApiKey` or as a Bearer token to `https://api.payhawk.com/api/v3`. A read-only key returns 403 on writes",
          "Page lists with `$skip` and `$take`. The help centre gives 1,000 a page and the definition a maximum of 10,000, so count what comes back",
          "Pass `$filter` as URL-encoded JSON, for example `{\"status\":{\"$equal\":\"draft\"}}`. Date filters compare the date part only",
          "Keep to 15 requests a second and wait for `Retry-After` on a 429. Do not send `Idempotency-Key` when creating a per diem expense, which returns 400",
          "Use a group-level key and the `/groups/{groupId}` paths for master data in a multi-entity group. Expenses and payments stay on account paths"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.1
          }
        ],
        "editorialScores": {
          "ergonomics": 52,
          "maintenance": 53,
          "payments": 13,
          "reliability": 58,
          "schema": 71,
          "security": 71,
          "transparency": 55
        },
        "provenanceScore": 100
      },
      "connect": {
        "http": "curl https://api.payhawk.com/api/v3/accounts/YOUR_ACCOUNT_ID/fund-accounts \\\n  -H \"X-Payhawk-ApiKey: YOUR_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/payhawk"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Payhawk Limited",
        "domain": "payhawk.com",
        "domainRegistered": "2003-07-06",
        "endpointOnVendorDomain": true,
        "terms": "https://payhawk.com/terms",
        "privacy": "https://payhawk.com/privacy",
        "statusPage": "https://status.payhawk.com",
        "changelog": "https://payhawk.com/release-notes",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms name Payhawk Limited (company number 11747263, Chancery House, 53-64 Chancery Lane, London WC2A 1QS) as the contracting entity worldwide and Payhawk Inc., a Delaware corporation, in the US. Payhawk EOOD in Sofia owns the platform.",
          "Cards are issued by Payhawk Financial Services UAB in the EEA, Payhawk Financial Services Limited in the UK and Cross River Bank in the US, per the site footer.",
          "The API answers at api.payhawk.com and the MCP server at mcp.payhawk.com. An unauthenticated POST to /mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata.",
          "payhawk.com/.well-known/security.txt has a contact, a policy link and an expiry of 1 January 2030.",
          "The terms were last updated on 9 December 2025, the privacy policy on 29 June 2026 and the Data Processing Addendum on 26 June 2026.",
          "The release notes cover the product. No changelog for the API was found.",
          "RDAP for payhawk.com gives a registration date of 2003-07-06. The terms' company number dates the company later, so the domain predates the vendor."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/payhawk.json",
      "live": {
        "slug": "payhawk",
        "probe": {
          "target": "https://api.payhawk.com",
          "method": "get",
          "lastAt": "2026-10-09T10:42:52.129616501Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 49,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 55,
          "p95ms24h": 136,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.payhawk.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:24.812233514Z"
        },
        "updatedAt": "2026-10-09T10:42:52.129616501Z"
      }
    },
    "answer": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 5 of 7 scored categories. Payhawk API + MCP leads on payments \u0026 pricing.",
    "b": {
      "slug": "spendesk",
      "name": "Spendesk API + MCP",
      "vendor": "Spendesk SAS",
      "vendorUrl": "https://www.spendesk.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Spend management platform from Spendesk SAS in Paris, covering company cards, expense claims, supplier invoices, purchase orders and accounting exports. Outside agents reach it through a REST API with scoped keys or OAuth, and a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/spendesk",
      "markdownUrl": "https://www.anchorterminal.com/tools/spendesk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/spendesk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/spendesk.json",
      "license": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://public-api.spendesk.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is granted by Spendesk, not self-serve. A customer asks its Spendesk representative for API access, then an Account Owner or Admin creates an API key (client ID and secret) with chosen scopes and an expiry of up to one year. The key is exchanged at POST /v1/auth/token with HTTP Basic for a Bearer token that lasts 60 minutes and can carry fewer scopes than the key. Partner integrations use OAuth 2.0 authorisation code with PKCE after approval by the partnerships team. The MCP server accepts only OAuth user tokens, refuses API keys, and limits use to Controllers and Account Owners. Experimental scopes are added on request.",
      "pricing": "paid",
      "pricingNotes": "No public prices. The pricing page describes a fixed monthly platform fee plus variable fees per transaction (card purchases, invoice payments and expense claims) and asks for a quote. It lists the open API and the MCP connection in the base package. No free tier, trial or self-serve sandbox was found. A demo environment exists at public-api.demo.spendesk.com, with credentials requested alongside API access (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI definition or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 62,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.spendesk.com",
      "llmsTxt": "https://developer.spendesk.com/llms.txt",
      "openapi": "https://developer.spendesk.com/openapi/spendesk-public-api.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "spend.procurement"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sales-led",
        "status-page",
        "iso27001",
        "bug-bounty"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.3,
        "grade": "B",
        "agentReady": false,
        "rank": 395,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.",
        "bestFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
        "strengths": [
          "OpenAPI 3.1 definition with 106 operations, llms.txt and a Markdown copy of every docs page, all public without sign-in",
          "37 documented scopes split by resource and by read or write. A token can carry fewer scopes than its key, and keys expire within one year",
          "MCP write permissions are off by default, enabled per connection by an admin with a second factor, then ticked by each user",
          "Every MCP tool call is recorded in an action log with date, tool, status, user, company and correlation ID",
          "Rate limits are published (1,000 requests a minute per company and credential) with x-ratelimit headers on every response"
        ],
        "weaknesses": [
          "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative",
          "Cards, transactions, invoices, purchase orders, webhooks and most writes sit behind experimental scopes granted on request, and may change",
          "No official SDK found on npm or PyPI, and the MCP server isn't in the official MCP registry",
          "status.spendesk.com has no API component and lists three critical and three major incidents opened between 2 and 29 September 2026",
          "An Idempotency-Key is documented only for creating an intake. A repeated purchase order or supplier request creates a second record"
        ],
        "agentNotes": [
          "Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401",
          "Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list",
          "With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400",
          "The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission",
          "After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.3
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 64
        },
        "provenanceScore": 96
      },
      "connect": {
        "http": "curl -X POST https://public-api.demo.spendesk.com/v1/auth/token \\\n  -u \"YOUR_CLIENT_ID:YOUR_CLIENT_SECRET\"\n\ncurl https://public-api.demo.spendesk.com/v1/wallet-summary \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/spendesk"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Spendesk SAS",
        "domain": "spendesk.com",
        "domainRegistered": "2015-10-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.spendesk.com/legals/terms/",
        "privacy": "https://www.spendesk.com/legals/privacy/",
        "statusPage": "https://status.spendesk.com",
        "changelog": "https://developer.spendesk.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The legal notice names Spendesk SAS, 7 Rue de Madrid, 75008 Paris, registration 821 893 286 R.C.S. Paris. The privacy policy (March 2025, version 0.5) gives the registered office as 51 rue de Londres, 75008 Paris.",
          "Payment services are supplied by Spendesk Financial Services (a French payment institution licensed by the ACPR, number 17518) in the EEA, Adyen in the UK and Sutton Bank in the US, per the site footer.",
          "The API and the MCP server answer at public-api.spendesk.com. An unauthenticated POST to /v1/mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata.",
          "www.spendesk.com/.well-known/security.txt is present with a contact and an expiry of 31 December 2026. developer.spendesk.com/.well-known/security.txt returns 404.",
          "The terms page lists the customer terms, a DORA addendum, a Spendesk API agreement and partner programme terms. The document links are drawn by JavaScript and we couldn't open them.",
          "RDAP for spendesk.com gives a registration date of 2015-10-30."
        ],
        "score": 96
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/spendesk.json",
      "live": {
        "slug": "spendesk",
        "probe": {
          "target": "https://public-api.spendesk.com",
          "method": "get",
          "lastAt": "2026-10-09T10:42:57.570708465Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 85,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 65,
          "p95ms24h": 94,
          "samples24h": 207,
          "samples30d": 207,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 93,
              "ok": 93
            },
            {
              "date": "2026-10-09",
              "probes": 114,
              "ok": 114
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.spendesk.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-09T10:42:04.455575681Z"
        },
        "securityTxt": {
          "url": "https://spendesk.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-12-31T22:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:39.004780879Z"
        },
        "pages": [
          {
            "url": "https://developer.spendesk.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:18.275650963Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0a7493461e82"
          },
          {
            "url": "https://www.spendesk.com/legals/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:38.654232386Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f77c18596c95"
          },
          {
            "url": "https://www.spendesk.com/legals/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:41.303104049Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "880e4794e2b0"
          }
        ],
        "updatedAt": "2026-10-09T10:42:57.570708465Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Payhawk Limited",
        "b": "Spendesk SAS",
        "name": "Vendor"
      },
      {
        "a": "https://api.payhawk.com",
        "b": "https://public-api.spendesk.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Payhawk's general terms and conditions",
        "b": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
        "name": "Licence"
      },
      {
        "a": "82",
        "b": "62",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-08",
        "b": "2026-09-29",
        "name": "Last release"
      },
      {
        "a": "2025-12-09",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "2026-06-29",
        "b": "2025-03-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      }
    ],
    "faq": [
      {
        "answer": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 5 of 7 scored categories. Payhawk API + MCP leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Payhawk API + MCP or Spendesk API + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Payhawk API + MCP and Spendesk API + MCP need an API key?"
      },
      {
        "answer": "Yes. Payhawk API + MCP has a hosted endpoint at https://api.payhawk.com and Spendesk API + MCP at https://public-api.spendesk.com.",
        "question": "Can an agent call Payhawk API + MCP and Spendesk API + MCP without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 13 against 0"
        ],
        "also": null,
        "goodFor": "A finance team already on Payhawk that wants an ERP or accounting sync, master data kept in step, purchase orders raised from another system, or an assistant that answers spend questions and prepares approvals.",
        "slug": "payhawk",
        "watchFor": "No self-serve route. The API needs a Payhawk customer account, and a development sandbox is requested through a form"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 87 against 71",
          "Agent ergonomics, 62 against 52",
          "Security \u0026 auth, 86 against 71"
        ],
        "also": null,
        "goodFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
        "slug": "spendesk",
        "watchFor": "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative"
      }
    ],
    "job": {
      "capability": "spend.transactions",
      "name": "Spend transactions"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/airwallex-vs-payhawk.json",
        "title": "Airwallex Spend and Issuing vs Payhawk API + MCP",
        "url": "https://www.anchorterminal.com/compare/airwallex-vs-payhawk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/airwallex-vs-spendesk.json",
        "title": "Airwallex Spend and Issuing vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/airwallex-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-payhawk.json",
        "title": "BILL vs Payhawk API + MCP",
        "url": "https://www.anchorterminal.com/compare/bill-vs-payhawk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bill-vs-spendesk.json",
        "title": "BILL vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/bill-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-payhawk.json",
        "title": "Brex vs Payhawk API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-payhawk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-spendesk.json",
        "title": "Brex vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expensify-vs-payhawk.json",
        "title": "Expensify vs Payhawk API + MCP",
        "url": "https://www.anchorterminal.com/compare/expensify-vs-payhawk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expensify-vs-spendesk.json",
        "title": "Expensify vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/expensify-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mercury-vs-payhawk.json",
        "title": "Mercury API vs Payhawk API + MCP",
        "url": "https://www.anchorterminal.com/compare/mercury-vs-payhawk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mercury-vs-spendesk.json",
        "title": "Mercury API vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/mercury-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payhawk-vs-pleo.json",
        "title": "Payhawk API + MCP vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/payhawk-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/payhawk-vs-ramp.json",
        "title": "Payhawk API + MCP vs Ramp",
        "url": "https://www.anchorterminal.com/compare/payhawk-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pleo-vs-spendesk.json",
        "title": "Pleo API + MCP vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/pleo-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ramp-vs-spendesk.json",
        "title": "Ramp vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/ramp-vs-spendesk"
      }
    ],
    "scores": [
      {
        "by": 3,
        "edge": "payhawk",
        "key": "reliability",
        "name": "Reliability",
        "payhawk": 58,
        "spendesk": 55,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 16,
        "edge": "spendesk",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "payhawk": 71,
        "spendesk": 87,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "spendesk",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "payhawk": 52,
        "spendesk": 62,
        "weight": 13
      },
      {
        "by": 15,
        "edge": "spendesk",
        "key": "security",
        "name": "Security \u0026 auth",
        "payhawk": 71,
        "spendesk": 86,
        "weight": 14
      },
      {
        "by": 13,
        "edge": "payhawk",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "payhawk": 13,
        "spendesk": 0,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "spendesk",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "payhawk": 53,
        "spendesk": 57,
        "weight": 7
      },
      {
        "by": 2,
        "edge": "spendesk",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "payhawk": 78,
        "spendesk": 80,
        "weight": 7
      }
    ],
    "summary": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 5 of 7 scored categories. Payhawk API + MCP leads on payments \u0026 pricing. Both do spend transactions.",
    "verdicts": {
      "payhawk": "The Developer API has a public OpenAPI 3.1 definition with 179 operations, read-only or full-access keys and a published limit of 15 requests a second. It needs a Payhawk customer account, no official SDK or API changelog was found, and the 82-tool MCP server is added by hand because it is not yet in the assistant directories.",
      "spendesk": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/payhawk-vs-spendesk",
    "json": "https://www.anchorterminal.com/compare/payhawk-vs-spendesk.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/payhawk-vs-spendesk.md",
    "slim": "https://www.anchorterminal.com/compare/payhawk-vs-spendesk.min.md"
  },
  "markdown": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 5 of 7 scored categories. Payhawk API + MCP leads on payments \u0026 pricing. Both do spend transactions.\n\n- Payhawk API + MCP: grade C, 57.1/100, rank #561 of 842. Markdown https://www.anchorterminal.com/tools/payhawk.md · JSON https://www.anchorterminal.com/api/v1/tools/payhawk.json\n- Spendesk API + MCP: grade B, 62.3/100, rank #395 of 842. Markdown https://www.anchorterminal.com/tools/spendesk.md · JSON https://www.anchorterminal.com/api/v1/tools/spendesk.json\n\n## Which one, for what\n\n### Payhawk API + MCP (C)\n\nGood for: A finance team already on Payhawk that wants an ERP or accounting sync, master data kept in step, purchase orders raised from another system, or an assistant that answers spend questions and prepares approvals.\n\nAhead on:\n- Payments \u0026 pricing, 13 against 0\n\nWatch for: No self-serve route. The API needs a Payhawk customer account, and a development sandbox is requested through a form\n\n### Spendesk API + MCP (B)\n\nGood for: A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.\n\nAhead on:\n- Schema \u0026 documentation, 87 against 71\n- Agent ergonomics, 62 against 52\n- Security \u0026 auth, 86 against 71\n\nWatch for: No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative\n\n\n## Score by category\n\n| Category | Weight | Payhawk API + MCP | Spendesk API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 58 | 55 | Payhawk API + MCP +3 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 71 | 87 | Spendesk API + MCP +16 |\n| Agent ergonomics | 13% (16.2 this run) | 52 | 62 | Spendesk API + MCP +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 71 | 86 | Spendesk API + MCP +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 13 | 0 | Payhawk API + MCP +13 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 53 | 57 | Spendesk API + MCP +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 78 | 80 | Spendesk API + MCP +2 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **57.1 · C** | **62.3 · B** | |\n\n## Facts side by side\n\n| Fact | Payhawk API + MCP | Spendesk API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Payhawk Limited | Spendesk SAS |\n| Hosted endpoint | `https://api.payhawk.com` | `https://public-api.spendesk.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Paid |\n| x402 | no | no |\n| Licence | Proprietary service under Payhawk's general terms and conditions | Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement |\n| Tools exposed | 82 | 62 |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-08 | 2026-09-29 |\n| Terms last updated | 2025-12-09 | couldn't be read |\n| Privacy policy last updated | 2026-06-29 | 2025-03-01 |\n| Customer content may train models | not found in the text | couldn't be read |\n| Terms restrict automated access | not found in the text | couldn't be read |\n| Terms restrict benchmarking | not found in the text | couldn't be read |\n| Terms or service can change without notice | not found in the text | couldn't be read |\n| Arbitration or class-action waiver | not found in the text | couldn't be read |\n\n## Verdicts\n\n**Payhawk API + MCP.** The Developer API has a public OpenAPI 3.1 definition with 179 operations, read-only or full-access keys and a published limit of 15 requests a second. It needs a Payhawk customer account, no official SDK or API changelog was found, and the 82-tool MCP server is added by hand because it is not yet in the assistant directories.\n\n**Spendesk API + MCP.** Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.\n\n## Before you call either\n\n### Payhawk API + MCP\n\n1. Send the key in `X-Payhawk-ApiKey` or as a Bearer token to `https://api.payhawk.com/api/v3`. A read-only key returns 403 on writes\n2. Page lists with `$skip` and `$take`. The help centre gives 1,000 a page and the definition a maximum of 10,000, so count what comes back\n3. Pass `$filter` as URL-encoded JSON, for example `{\"status\":{\"$equal\":\"draft\"}}`. Date filters compare the date part only\n4. Keep to 15 requests a second and wait for `Retry-After` on a 429. Do not send `Idempotency-Key` when creating a per diem expense, which returns 400\n5. Use a group-level key and the `/groups/{groupId}` paths for master data in a multi-entity group. Expenses and payments stay on account paths\n\n### Spendesk API + MCP\n\n1. Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401\n2. Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list\n3. With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400\n4. The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission\n5. After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two\n\n## Questions\n\n### Which is better for AI agents, Payhawk API + MCP or Spendesk API + MCP?\n\nSpendesk API + MCP scores 62.3 (B) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 5 of 7 scored categories. Payhawk API + MCP leads on payments \u0026 pricing.\n\n### Do Payhawk API + MCP and Spendesk API + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Payhawk API + MCP and Spendesk API + MCP without installing anything?\n\nYes. Payhawk API + MCP has a hosted endpoint at https://api.payhawk.com and Spendesk API + MCP at https://public-api.spendesk.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/payhawk-vs-spendesk.json, and with the fewest tokens: https://www.anchorterminal.com/compare/payhawk-vs-spendesk.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"payhawk\", \"b\": \"spendesk\"}`. From a terminal: `anchor compare payhawk spendesk`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/payhawk.json and https://www.anchorterminal.com/api/v1/tools/spendesk.json\n\n## Other comparisons with Payhawk API + MCP or Spendesk API + MCP\n\n- [Airwallex Spend and Issuing vs Payhawk API + MCP](https://www.anchorterminal.com/compare/airwallex-vs-payhawk.md)\n- [Airwallex Spend and Issuing vs Spendesk API + MCP](https://www.anchorterminal.com/compare/airwallex-vs-spendesk.md)\n- [BILL vs Payhawk API + MCP](https://www.anchorterminal.com/compare/bill-vs-payhawk.md)\n- [BILL vs Spendesk API + MCP](https://www.anchorterminal.com/compare/bill-vs-spendesk.md)\n- [Brex vs Payhawk API + MCP](https://www.anchorterminal.com/compare/brex-vs-payhawk.md)\n- [Brex vs Spendesk API + MCP](https://www.anchorterminal.com/compare/brex-vs-spendesk.md)\n- [Expensify vs Payhawk API + MCP](https://www.anchorterminal.com/compare/expensify-vs-payhawk.md)\n- [Expensify vs Spendesk API + MCP](https://www.anchorterminal.com/compare/expensify-vs-spendesk.md)\n- [Mercury API vs Payhawk API + MCP](https://www.anchorterminal.com/compare/mercury-vs-payhawk.md)\n- [Mercury API vs Spendesk API + MCP](https://www.anchorterminal.com/compare/mercury-vs-spendesk.md)\n- [Payhawk API + MCP vs Pleo API + MCP](https://www.anchorterminal.com/compare/payhawk-vs-pleo.md)\n- [Payhawk API + MCP vs Ramp](https://www.anchorterminal.com/compare/payhawk-vs-ramp.md)\n- [Pleo API + MCP vs Spendesk API + MCP](https://www.anchorterminal.com/compare/pleo-vs-spendesk.md)\n- [Ramp vs Spendesk API + MCP](https://www.anchorterminal.com/compare/ramp-vs-spendesk.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Payhawk API + MCP vs Spendesk API + MCP",
        "url": ""
      }
    ],
    "description": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Payhawk API + MCP's 57.1 (C), and leads in 5 of 7 scored categories. Payhawk API + MCP leads on payments \u0026 pricing. Both do spend transactions. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Payhawk API + MCP C 57.1",
      "Spendesk API + MCP B 62.3",
      "scores"
    ],
    "h1": "Payhawk API + MCP vs Spendesk API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-payhawk-vs-spendesk.png",
    "path": "/compare/payhawk-vs-spendesk",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Payhawk API + MCP vs Spendesk API + MCP for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/payhawk-vs-spendesk"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 730
  },
  "version": 1
}
