{
  "data": {
    "a": {
      "slug": "pleo",
      "name": "Pleo API + MCP",
      "vendor": "Pleo Technologies A/S",
      "vendorUrl": "https://www.pleo.io/en",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Spend management platform from Pleo Technologies A/S in Copenhagen, covering company cards, expenses, reimbursements, invoices and accounting exports. Outside agents reach it through a hosted MCP server for expense work and a REST API built for accounting integrations.",
      "url": "https://www.anchorterminal.com/tools/pleo",
      "markdownUrl": "https://www.anchorterminal.com/tools/pleo.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/pleo.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/pleo.json",
      "license": "Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://external.pleo.io",
      "packages": [],
      "auth": "mixed",
      "authNotes": "A person signs in for every route. The MCP server uses OAuth 2.0 in a browser (authorisation code with PKCE, dynamic client registration, no keys to configure) and acts with the connecting user's Pleo role, once a company admin has enabled MCP access for that entity. The External API accepts OAuth 2.0 bearer tokens with resource scopes for partner integrations, whose client ID and secret Pleo issues after review in its Early Access Programme. A single company can use a Standalone API Key with chosen scopes and an expiry, sent as the Basic auth username, but only after Pleo support or a Customer Success Manager enables keys for the organisation.",
      "pricing": "paid",
      "pricingNotes": "Per-user plans, with no separate charge for the API or the MCP server. The pricing page shown to a UK visitor lists Start at £8 per user per month, Build at £14 and Optimise at £18, the last two cheaper billed yearly and with a three-user minimum. MCP is listed on Optimise only, which is sold through a demo. Start and Build have a Try for free button and the signup form states 21 days free. Whether the trial needs a payment card isn't stated. A staging environment with test data exists for customers with API keys enabled and for approved partners. Fees for payments and foreign exchange are extra (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developers.pleo.io/",
      "llmsTxt": "https://developers.pleo.io/llms.txt",
      "openapi": "https://developers.pleo.io/reference/Export%20API.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.bills"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "api-key",
        "openapi",
        "llms-txt",
        "webhooks",
        "closed-source",
        "status-page",
        "bug-bounty",
        "sandbox"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.9,
        "grade": "B",
        "agentReady": false,
        "rank": 293,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 55,
          "maintenance": 64,
          "payments": 15,
          "reliability": 71,
          "schema": 82,
          "security": 71,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.",
        "bestFor": "An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.",
        "strengths": [
          "MCP server at mcp.pleo.io/mcp uses OAuth with PKCE and dynamic client registration, and acts with the connecting user's Pleo permissions",
          "Payments, card changes and spending-limit changes are blocked through the MCP by design, per the AI Access Terms",
          "Eleven current OpenAPI 3.0.1 specs with 162 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page",
          "One documented rate limit of 600 requests a minute per credential, with written 429 and Retry-After guidance",
          "Staging hosts for both the API (external.staging.pleo.io) and the MCP server (mcp.staging.pleo.io/mcp)",
          "Sub-processor list with locations, customer data in AWS Ireland, and 30 days' notice of new sub-processors in the DPA"
        ],
        "weaknesses": [
          "The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)",
          "MCP tool names, schemas and count aren't published, so they can't be read without a customer sign-in",
          "Standalone API keys aren't self-service. Pleo support or a Customer Success Manager enables them, and partner OAuth clients go through a reviewed programme",
          "No Idempotency-Key header, no official SDK and no entry in the official MCP registry",
          "The API terms call the API a beta version that Pleo may discontinue at any time, and no SLA was found",
          "No end-of-life date is published for the deprecated Legacy API, and its Q3 2026 replacements for employee writes and wallet balance aren't in the docs"
        ],
        "agentNotes": [
          "Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default",
          "Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist",
          "Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side",
          "Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there",
          "Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second",
          "Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.9
          }
        ],
        "editorialScores": {
          "ergonomics": 55,
          "maintenance": 64,
          "payments": 15,
          "reliability": 71,
          "schema": 82,
          "security": 71,
          "transparency": 63
        },
        "provenanceScore": 87
      },
      "connect": {
        "http": "curl --request GET \\\n-u \"YOUR-API-KEY:\" \\\n-H \"Accept: application/json;charset=UTF-8\" \\\n\"https://external.staging.pleo.io/v2/employees\"",
        "claudeCode": "claude mcp add --transport http pleo-mcp-staging https://mcp.staging.pleo.io/mcp",
        "config": {
          "mcpServers": {
            "pleo": {
              "url": "https://mcp.pleo.io/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/pleo"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Pleo Technologies A/S",
        "domain": "pleo.io",
        "domainRegistered": "2015-10-07",
        "endpointOnVendorDomain": true,
        "terms": "https://developers.pleo.io/page/terms-of-service",
        "privacy": "https://www.pleo.io/legal-documents/pleo-privacy-policy-en.pdf",
        "statusPage": "https://status.pleo.io",
        "changelog": "https://developers.pleo.io/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The website footer names Pleo Technologies A/S (36538686), Ravnsborg Tværgade 5C, 2200 København N, Denmark. UK payment services come from Pleo Financial Services UK Ltd, FCA firm reference 1020730, company number 15842283.",
          "The API Terms of Service on the developer portal name Pleo Technologies A/S, carry no date, and describe the API as a beta version. The UK Master Service Agreement has an effective date of 7 September 2026 and is governed by the laws of England and Wales.",
          "The API answers at external.pleo.io and the MCP server at mcp.pleo.io, both pleo.io subdomains. The MCP host publishes its OAuth metadata at https://mcp.pleo.io/.well-known/oauth-authorization-server",
          "www.pleo.io/.well-known/security.txt and pleo.io/.well-known/security.txt both return 403 with an AccessDenied body. The vulnerability disclosure policy gives security-vd@pleo.io as the reporting address.",
          "The privacy notice is dated June 2026 and the Data Processing Agreement 14 October 2025. An AI Access Terms document covers the MCP server.",
          "RDAP from the .io registry gives a registration date of 2015-10-07 for pleo.io."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/pleo.json",
      "live": {
        "slug": "pleo",
        "probe": {
          "target": "https://external.pleo.io",
          "method": "get",
          "lastAt": "2026-10-08T18:20:37.689130608Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 107,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 94,
          "p95ms24h": 163,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.pleo.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T18:22:15.952094673Z"
        },
        "securityTxt": {
          "url": "https://pleo.io/.well-known/security.txt",
          "state": "unknown",
          "checkedAt": "2026-10-08T15:38:57.657849973Z"
        },
        "pages": [
          {
            "url": "https://developers.pleo.io/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:58.324737763Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7369dd13eb7c"
          },
          {
            "url": "https://developers.pleo.io/page/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:00.641635735Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5da670693385"
          }
        ],
        "updatedAt": "2026-10-08T18:22:15.952094673Z"
      }
    },
    "answer": "Pleo API + MCP and Spendesk API + MCP score within a point of each other on agent readiness, 62.9 (B) and 62.3 (B). Spendesk API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and transparency \u0026 trust.",
    "b": {
      "slug": "spendesk",
      "name": "Spendesk API + MCP",
      "vendor": "Spendesk SAS",
      "vendorUrl": "https://www.spendesk.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Spend management platform from Spendesk SAS in Paris, covering company cards, expense claims, supplier invoices, purchase orders and accounting exports. Outside agents reach it through a REST API with scoped keys or OAuth, and a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/spendesk",
      "markdownUrl": "https://www.anchorterminal.com/tools/spendesk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/spendesk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/spendesk.json",
      "license": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://public-api.spendesk.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is granted by Spendesk, not self-serve. A customer asks its Spendesk representative for API access, then an Account Owner or Admin creates an API key (client ID and secret) with chosen scopes and an expiry of up to one year. The key is exchanged at POST /v1/auth/token with HTTP Basic for a Bearer token that lasts 60 minutes and can carry fewer scopes than the key. Partner integrations use OAuth 2.0 authorisation code with PKCE after approval by the partnerships team. The MCP server accepts only OAuth user tokens, refuses API keys, and limits use to Controllers and Account Owners. Experimental scopes are added on request.",
      "pricing": "paid",
      "pricingNotes": "No public prices. The pricing page describes a fixed monthly platform fee plus variable fees per transaction (card purchases, invoice payments and expense claims) and asks for a quote. It lists the open API and the MCP connection in the base package. No free tier, trial or self-serve sandbox was found. A demo environment exists at public-api.demo.spendesk.com, with credentials requested alongside API access (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI definition or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 62,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.spendesk.com",
      "llmsTxt": "https://developer.spendesk.com/llms.txt",
      "openapi": "https://developer.spendesk.com/openapi/spendesk-public-api.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "spend.procurement"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sales-led",
        "status-page",
        "iso27001",
        "bug-bounty"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.3,
        "grade": "B",
        "agentReady": false,
        "rank": 306,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.",
        "bestFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
        "strengths": [
          "OpenAPI 3.1 definition with 106 operations, llms.txt and a Markdown copy of every docs page, all public without sign-in",
          "37 documented scopes split by resource and by read or write. A token can carry fewer scopes than its key, and keys expire within one year",
          "MCP write permissions are off by default, enabled per connection by an admin with a second factor, then ticked by each user",
          "Every MCP tool call is recorded in an action log with date, tool, status, user, company and correlation ID",
          "Rate limits are published (1,000 requests a minute per company and credential) with x-ratelimit headers on every response"
        ],
        "weaknesses": [
          "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative",
          "Cards, transactions, invoices, purchase orders, webhooks and most writes sit behind experimental scopes granted on request, and may change",
          "No official SDK found on npm or PyPI, and the MCP server isn't in the official MCP registry",
          "status.spendesk.com has no API component and lists three critical and three major incidents opened between 2 and 29 September 2026",
          "An Idempotency-Key is documented only for creating an intake. A repeated purchase order or supplier request creates a second record"
        ],
        "agentNotes": [
          "Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401",
          "Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list",
          "With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400",
          "The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission",
          "After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.3
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 64
        },
        "provenanceScore": 96
      },
      "connect": {
        "http": "curl -X POST https://public-api.demo.spendesk.com/v1/auth/token \\\n  -u \"YOUR_CLIENT_ID:YOUR_CLIENT_SECRET\"\n\ncurl https://public-api.demo.spendesk.com/v1/wallet-summary \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/spendesk"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Spendesk SAS",
        "domain": "spendesk.com",
        "domainRegistered": "2015-10-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.spendesk.com/legals/terms/",
        "privacy": "https://www.spendesk.com/legals/privacy/",
        "statusPage": "https://status.spendesk.com",
        "changelog": "https://developer.spendesk.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The legal notice names Spendesk SAS, 7 Rue de Madrid, 75008 Paris, registration 821 893 286 R.C.S. Paris. The privacy policy (March 2025, version 0.5) gives the registered office as 51 rue de Londres, 75008 Paris.",
          "Payment services are supplied by Spendesk Financial Services (a French payment institution licensed by the ACPR, number 17518) in the EEA, Adyen in the UK and Sutton Bank in the US, per the site footer.",
          "The API and the MCP server answer at public-api.spendesk.com. An unauthenticated POST to /v1/mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata.",
          "www.spendesk.com/.well-known/security.txt is present with a contact and an expiry of 31 December 2026. developer.spendesk.com/.well-known/security.txt returns 404.",
          "The terms page lists the customer terms, a DORA addendum, a Spendesk API agreement and partner programme terms. The document links are drawn by JavaScript and we couldn't open them.",
          "RDAP for spendesk.com gives a registration date of 2015-10-30."
        ],
        "score": 96
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/spendesk.json",
      "live": {
        "slug": "spendesk",
        "probe": {
          "target": "https://public-api.spendesk.com",
          "method": "get",
          "lastAt": "2026-10-08T18:20:40.801700324Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 67,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 67,
          "p95ms24h": 103,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.spendesk.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-08T18:22:20.323763159Z"
        },
        "securityTxt": {
          "url": "https://spendesk.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-12-31T22:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:39.004780879Z"
        },
        "pages": [
          {
            "url": "https://developer.spendesk.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:18.275650963Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0a7493461e82"
          }
        ],
        "updatedAt": "2026-10-08T18:22:20.323763159Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Pleo Technologies A/S",
        "b": "Spendesk SAS",
        "name": "Vendor"
      },
      {
        "a": "https://external.pleo.io",
        "b": "https://public-api.spendesk.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms",
        "b": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "62",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-02",
        "b": "2026-09-29",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "",
        "b": "2025-03-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      }
    ],
    "faq": [
      {
        "answer": "Pleo API + MCP and Spendesk API + MCP score within a point of each other on agent readiness, 62.9 (B) and 62.3 (B). Spendesk API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Pleo API + MCP or Spendesk API + MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Pleo API + MCP and Spendesk API + MCP need an API key?"
      },
      {
        "answer": "Yes. Pleo API + MCP has a hosted endpoint at https://external.pleo.io and Spendesk API + MCP at https://public-api.spendesk.com.",
        "question": "Can an agent call Pleo API + MCP and Spendesk API + MCP without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 71 against 55",
          "Payments \u0026 pricing, 15 against 0",
          "Maintenance \u0026 community, 64 against 57"
        ],
        "also": null,
        "goodFor": "An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.",
        "slug": "pleo",
        "watchFor": "The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 87 against 82",
          "Agent ergonomics, 62 against 55",
          "Security \u0026 auth, 86 against 71",
          "Transparency \u0026 trust, 80 against 75"
        ],
        "also": null,
        "goodFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
        "slug": "spendesk",
        "watchFor": "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative"
      }
    ],
    "job": {
      "capability": "spend.transactions",
      "name": "Spend transactions"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-pleo.json",
        "title": "Brex vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-spendesk.json",
        "title": "Brex vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expensify-vs-pleo.json",
        "title": "Expensify vs Pleo API + MCP",
        "url": "https://www.anchorterminal.com/compare/expensify-vs-pleo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expensify-vs-spendesk.json",
        "title": "Expensify vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/expensify-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pleo-vs-ramp.json",
        "title": "Pleo API + MCP vs Ramp",
        "url": "https://www.anchorterminal.com/compare/pleo-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ramp-vs-spendesk.json",
        "title": "Ramp vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/ramp-vs-spendesk"
      }
    ],
    "scores": [
      {
        "by": 16,
        "edge": "pleo",
        "key": "reliability",
        "name": "Reliability",
        "pleo": 71,
        "spendesk": 55,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "edge": "spendesk",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "pleo": 82,
        "spendesk": 87,
        "weight": 13
      },
      {
        "by": 7,
        "edge": "spendesk",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "pleo": 55,
        "spendesk": 62,
        "weight": 13
      },
      {
        "by": 15,
        "edge": "spendesk",
        "key": "security",
        "name": "Security \u0026 auth",
        "pleo": 71,
        "spendesk": 86,
        "weight": 14
      },
      {
        "by": 15,
        "edge": "pleo",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "pleo": 15,
        "spendesk": 0,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "edge": "pleo",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "pleo": 64,
        "spendesk": 57,
        "weight": 7
      },
      {
        "by": 5,
        "edge": "spendesk",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "pleo": 75,
        "spendesk": 80,
        "weight": 7
      }
    ],
    "summary": "Pleo API + MCP and Spendesk API + MCP score within a point of each other on agent readiness, 62.9 (B) and 62.3 (B). Spendesk API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and transparency \u0026 trust. Both do spend transactions.",
    "verdicts": {
      "pleo": "The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.",
      "spendesk": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/pleo-vs-spendesk",
    "json": "https://www.anchorterminal.com/compare/pleo-vs-spendesk.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/pleo-vs-spendesk.md",
    "slim": "https://www.anchorterminal.com/compare/pleo-vs-spendesk.min.md"
  },
  "markdown": "Pleo API + MCP and Spendesk API + MCP score within a point of each other on agent readiness, 62.9 (B) and 62.3 (B). Spendesk API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and transparency \u0026 trust. Both do spend transactions.\n\n- Pleo API + MCP: grade B, 62.9/100, rank #293 of 629. Markdown https://www.anchorterminal.com/tools/pleo.md · JSON https://www.anchorterminal.com/api/v1/tools/pleo.json\n- Spendesk API + MCP: grade B, 62.3/100, rank #306 of 629. Markdown https://www.anchorterminal.com/tools/spendesk.md · JSON https://www.anchorterminal.com/api/v1/tools/spendesk.json\n\n## Which one, for what\n\n### Pleo API + MCP (B)\n\nGood for: An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.\n\nAhead on:\n- Reliability, 71 against 55\n- Payments \u0026 pricing, 15 against 0\n- Maintenance \u0026 community, 64 against 57\n\nWatch for: The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)\n\n### Spendesk API + MCP (B)\n\nGood for: A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.\n\nAhead on:\n- Schema \u0026 documentation, 87 against 82\n- Agent ergonomics, 62 against 55\n- Security \u0026 auth, 86 against 71\n- Transparency \u0026 trust, 80 against 75\n\nWatch for: No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative\n\n\n## Score by category\n\n| Category | Weight | Pleo API + MCP | Spendesk API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 71 | 55 | Pleo API + MCP +16 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 82 | 87 | Spendesk API + MCP +5 |\n| Agent ergonomics | 13% (16.2 this run) | 55 | 62 | Spendesk API + MCP +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 71 | 86 | Spendesk API + MCP +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 15 | 0 | Pleo API + MCP +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 64 | 57 | Pleo API + MCP +7 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 75 | 80 | Spendesk API + MCP +5 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **62.9 · B** | **62.3 · B** | |\n\n## Facts side by side\n\n| Fact | Pleo API + MCP | Spendesk API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Pleo Technologies A/S | Spendesk SAS |\n| Hosted endpoint | `https://external.pleo.io` | `https://public-api.spendesk.com` |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Paid |\n| x402 | no | no |\n| Licence | Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms | Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement |\n| Tools exposed | none | 62 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-02 | 2026-09-29 |\n| Terms last updated | no date given | couldn't be read |\n| Privacy policy last updated |  | 2025-03-01 |\n| Customer content may train models | not found in the text | couldn't be read |\n| Terms restrict automated access | not found in the text | couldn't be read |\n| Terms restrict benchmarking | not found in the text | couldn't be read |\n| Terms or service can change without notice | not found in the text | couldn't be read |\n| Arbitration or class-action waiver | not found in the text | couldn't be read |\n\n## Verdicts\n\n**Pleo API + MCP.** The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.\n\n**Spendesk API + MCP.** Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.\n\n## Before you call either\n\n### Pleo API + MCP\n\n1. Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default\n2. Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist\n3. Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side\n4. Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there\n5. Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second\n6. Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in\n\n### Spendesk API + MCP\n\n1. Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401\n2. Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list\n3. With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400\n4. The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission\n5. After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two\n\n## Questions\n\n### Which is better for AI agents, Pleo API + MCP or Spendesk API + MCP?\n\nPleo API + MCP and Spendesk API + MCP score within a point of each other on agent readiness, 62.9 (B) and 62.3 (B). Spendesk API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and transparency \u0026 trust.\n\n### Do Pleo API + MCP and Spendesk API + MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Pleo API + MCP and Spendesk API + MCP without installing anything?\n\nYes. Pleo API + MCP has a hosted endpoint at https://external.pleo.io and Spendesk API + MCP at https://public-api.spendesk.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/pleo-vs-spendesk.json, and with the fewest tokens: https://www.anchorterminal.com/compare/pleo-vs-spendesk.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"pleo\", \"b\": \"spendesk\"}`. From a terminal: `anchor compare pleo spendesk`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/pleo.json and https://www.anchorterminal.com/api/v1/tools/spendesk.json\n\n## Other comparisons with Pleo API + MCP or Spendesk API + MCP\n\n- [Brex vs Pleo API + MCP](https://www.anchorterminal.com/compare/brex-vs-pleo.md)\n- [Brex vs Spendesk API + MCP](https://www.anchorterminal.com/compare/brex-vs-spendesk.md)\n- [Expensify vs Pleo API + MCP](https://www.anchorterminal.com/compare/expensify-vs-pleo.md)\n- [Expensify vs Spendesk API + MCP](https://www.anchorterminal.com/compare/expensify-vs-spendesk.md)\n- [Pleo API + MCP vs Ramp](https://www.anchorterminal.com/compare/pleo-vs-ramp.md)\n- [Ramp vs Spendesk API + MCP](https://www.anchorterminal.com/compare/ramp-vs-spendesk.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Pleo API + MCP vs Spendesk API + MCP",
        "url": ""
      }
    ],
    "description": "Pleo API + MCP and Spendesk API + MCP score within a point of each other on agent readiness, 62.9 (B) and 62.3 (B). Spendesk API + MCP leads on schema \u0026 documentation, agent ergonomics, security \u0026 auth and transparency \u0026 trust. Both do spend transactions. Category scores, facts…",
    "facts": [
      "Pleo API + MCP B 62.9",
      "Spendesk API + MCP B 62.3",
      "scores"
    ],
    "h1": "Pleo API + MCP vs Spendesk API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-pleo-vs-spendesk.png",
    "path": "/compare/pleo-vs-spendesk",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Pleo API + MCP vs Spendesk API + MCP for AI agents, B 62.9 vs B 62.3",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/pleo-vs-spendesk"
  },
  "tokens": {
    "markdown": 2150,
    "slim": 780
  },
  "version": 1
}
