{
  "data": {
    "a": {
      "slug": "ramp",
      "name": "Ramp",
      "vendor": "Ramp Business Corporation",
      "vendorUrl": "https://ramp.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Ramp is a finance platform with company cards, expense management, bill pay, procurement and travel. Its Developer API reads and writes transactions, receipts, funds, bills and purchase orders. A hosted MCP server and CLI work with the signed-in user's permissions.",
      "url": "https://www.anchorterminal.com/tools/ramp",
      "markdownUrl": "https://www.anchorterminal.com/tools/ramp.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ramp.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ramp.json",
      "repo": "https://github.com/ramp-public/ramp-cli",
      "license": "Proprietary service under the Ramp Platform Agreement and the API Agreement. The ramp-cli repository is MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.ramp.com",
      "packages": [],
      "auth": "oauth",
      "authNotes": "Access is self-serve for a Ramp customer. An admin creates an app at Company \u003e Developer, accepts the terms, and picks grant types and scopes. Client credentials tokens are requested from `/developer/v1/token` with HTTP Basic auth, last 10 days and act with the app creator's permissions. The authorisation code grant is for apps acting for other businesses, with one-hour access tokens by default, optional refresh tokens, and consent limited to Admin and Business Owner users. Scopes follow `resource:read` and `resource:write`, and `cards:read_vault` needs a production review by Ramp. The MCP server and CLI use OAuth and work with the signed-in user's permissions, and custom MCP clients need their redirect URI allowlisted by Ramp.",
      "pricing": "freemium",
      "pricingNotes": "No separate API fee is published. ramp.com/pricing lists Free at $0 per user per month, Plus at $15 per user per month plus a platform fee by team size, and Enterprise on request, with a 30-day Plus trial. The OpenAPI spec marks 51 of 260 operations as needing Plus. Access needs an approved Ramp business account, so an agent can't start without one. A sandbox at demo-api.ramp.com is available on request through a form. The API Agreement reserves the right to charge API fees (checked 2026-10-08).",
      "priceSummary": "$15 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "Ramp's own API isn't paid for by x402, MPP or L402. Ramp lets a connected agent pay other sellers by x402 from a funded wallet, or by Stripe MPP, per the agentic payments guide (https://docs.ramp.com/llms-guides/agent-payments.txt, checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 53,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.ramp.com",
      "llmsTxt": "https://docs.ramp.com/llms.txt",
      "openapi": "https://docs.ramp.com/openapi/developer-api.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "spend.procurement"
      ],
      "tags": [
        "hosted",
        "freemium",
        "oauth",
        "mcp",
        "cli",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "soc2",
        "pci-dss",
        "security-txt"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.3,
        "grade": "C",
        "agentReady": false,
        "rank": 423,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 74,
          "payments": 25,
          "reliability": 30,
          "schema": 86,
          "security": 79,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-06-25 and 2026-02-11. The changelog records the webhook event type `transactions.all_requirements_met_and_approved` removed on 25 June 2026, three days after the 22 June entry marked it a deprecated alias, and `functional_currency_amount` dropped from default transaction responses on 11 February 2026. Both are documented on the day they shipped and the first names a replacement. Notice by email couldn't be checked, so the smallest deduction applies (https://docs.ramp.com/developer-api/v1/changelog)."
        ],
        "verdict": "OAuth 2.0 scopes split read from write across about 40 resources, a 260-operation OpenAPI spec is public, and an audit log endpoint records actions by user and agent. No public status page was found, 89 operations are marked beta, the API Agreement allows changes without notice, and idempotency keys cover only eight write operations.",
        "bestFor": "A finance team already on Ramp that wants an agent to read transactions, upload receipts, code and split expenses, issue funds with limits, create bills and work with purchase orders and procurement requests.",
        "strengths": [
          "Public OpenAPI 3.0.2 spec with 260 operations, plus llms.txt and a plain-text export of every guide and the API reference",
          "OAuth 2.0 scopes follow `resource:read` and `resource:write`, tokens are bound to scopes at issue, and `POST /developer/v1/token/revoke` invalidates them",
          "`GET /developer/v1/audit-logs/events` filters events by user, date, event type and actor type, including Ramp's own agents",
          "A sandbox at demo-api.ramp.com and demo.ramp.com moves no real money and has demo actions that create test transactions",
          "The changelog is dated to the day, with 26 dated entries between 15 July and 7 October 2026 and an RSS feed"
        ],
        "weaknesses": [
          "No public status page was found. status.ramp.com doesn't resolve, and no status link appears in the docs, help centre or trust centre pages read",
          "89 of 260 operations carry `x-beta`, among them creating a fund and splitting a transaction, and the MCP guide says the server is subject to change",
          "`X-Idempotency-Key` is accepted on 8 of 155 write operations. Creating a bill, a purchase order or a vendor has none",
          "The API Agreement says Ramp may change or discontinue the APIs at any time with or without notice",
          "No official SDK was found in the docs, and 51 operations (custom records, purchase orders, the audit log) need the paid Plus plan"
        ],
        "agentNotes": [
          "Send `scope` on the client credentials token request. Without it Ramp issues a token with no scopes and every resource call fails with 403",
          "Follow the full URL in `next` to page. `page_size` defaults to 20 and stops at 100, and the cursor is opaque",
          "Stay under 200 requests in any 10 seconds per source IP and back off 1, 2 then 4 seconds on 429. No Retry-After header is documented",
          "Don't use `synced_after` or `from_created_at` to find changed records. Bills and transactions have no updated-at filter, so subscribe to webhooks",
          "Send `X-Idempotency-Key` when creating funds or procurement requests. Elsewhere a retried POST can create a duplicate, so read back before retrying"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.3
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 74,
          "payments": 25,
          "reliability": 30,
          "schema": 86,
          "security": 79,
          "transparency": 55
        },
        "provenanceScore": 84
      },
      "connect": {
        "install": "curl -fsSL https://agents.ramp.com/install.sh | sh",
        "http": "curl https://api.ramp.com/developer/v1/transactions \\\n  -H \"Authorization: Bearer $RAMP_ACCESS_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/ramp"
      },
      "area": "domain-data",
      "unitPrices": [
        {
          "item": "Free plan",
          "unit": "seat-month",
          "usd": 0,
          "note": "No separate API fee is published"
        },
        {
          "item": "Plus plan",
          "unit": "seat-month",
          "usd": 15,
          "note": "Plus a platform fee by team size, not stated. Enterprise is priced on request"
        }
      ],
      "provenance": {
        "legalEntity": "Ramp Business Corporation",
        "domain": "ramp.com",
        "domainRegistered": "1994-03-14",
        "endpointOnVendorDomain": true,
        "terms": "https://ramp.com/legal/developer-terms/developer-terms/api-agreement",
        "privacy": "https://ramp.com/legal/privacy-policy",
        "statusPage": "",
        "changelog": "https://docs.ramp.com/developer-api/v1/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The API Agreement (last updated 26 March 2026) names Ramp Business Corporation, 28 West 23rd Street, Floor 2, New York, NY 10010.",
          "The API answers at api.ramp.com and demo-api.ramp.com, and the MCP servers at mcp.ramp.com and demo-mcp.ramp.com.",
          "No status page was found. status.ramp.com doesn't resolve, and no status link appears in the docs, help centre, trust centre, home or pricing pages read on 8 October 2026.",
          "ramp.com/.well-known/security.txt gives security-external@ramp.com as the contact and expires on 18 March 2027.",
          "The Platform Agreement was last updated on 22 September 2026, the privacy policy on 21 August 2026 and the DPA on 10 July 2026. The legal pages render with JavaScript, and we read the published documents from the site's own script files.",
          "RDAP for ramp.com gives a registration date of 1994-03-14 and Cloudflare, Inc. as registrar."
        ],
        "score": 84
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ramp.json",
      "live": {
        "slug": "ramp",
        "probe": {
          "target": "https://api.ramp.com",
          "method": "get",
          "lastAt": "2026-10-08T18:20:38.384448827Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 139,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 137,
          "p95ms24h": 194,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "ramp-public/ramp-cli",
            "version": "v0.2.54",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:26:56.585492266Z"
          }
        ],
        "githubStars": 53,
        "securityTxt": {
          "url": "https://ramp.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-03-18T19:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:51.088112552Z"
        },
        "pages": [
          {
            "url": "https://docs.ramp.com/developer-api/v1/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:18.141617922Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "df9c69ecf0f3"
          },
          {
            "url": "https://ramp.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:23:38.570721399Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e3b0c44298fc"
          },
          {
            "url": "https://ramp.com/legal/developer-terms/developer-terms/api-agreement",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:23:36.289237573Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e3b0c44298fc"
          }
        ],
        "updatedAt": "2026-10-08T18:23:38.570721399Z"
      }
    },
    "answer": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Ramp's 57.3 (C), and leads in 4 of 7 scored categories. Ramp leads on payments \u0026 pricing and maintenance \u0026 community.",
    "b": {
      "slug": "spendesk",
      "name": "Spendesk API + MCP",
      "vendor": "Spendesk SAS",
      "vendorUrl": "https://www.spendesk.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Spend management platform from Spendesk SAS in Paris, covering company cards, expense claims, supplier invoices, purchase orders and accounting exports. Outside agents reach it through a REST API with scoped keys or OAuth, and a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/spendesk",
      "markdownUrl": "https://www.anchorterminal.com/tools/spendesk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/spendesk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/spendesk.json",
      "license": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://public-api.spendesk.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is granted by Spendesk, not self-serve. A customer asks its Spendesk representative for API access, then an Account Owner or Admin creates an API key (client ID and secret) with chosen scopes and an expiry of up to one year. The key is exchanged at POST /v1/auth/token with HTTP Basic for a Bearer token that lasts 60 minutes and can carry fewer scopes than the key. Partner integrations use OAuth 2.0 authorisation code with PKCE after approval by the partnerships team. The MCP server accepts only OAuth user tokens, refuses API keys, and limits use to Controllers and Account Owners. Experimental scopes are added on request.",
      "pricing": "paid",
      "pricingNotes": "No public prices. The pricing page describes a fixed monthly platform fee plus variable fees per transaction (card purchases, invoice payments and expense claims) and asks for a quote. It lists the open API and the MCP connection in the base package. No free tier, trial or self-serve sandbox was found. A demo environment exists at public-api.demo.spendesk.com, with credentials requested alongside API access (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI definition or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 62,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.spendesk.com",
      "llmsTxt": "https://developer.spendesk.com/llms.txt",
      "openapi": "https://developer.spendesk.com/openapi/spendesk-public-api.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "spend.procurement"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sales-led",
        "status-page",
        "iso27001",
        "bug-bounty"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.3,
        "grade": "B",
        "agentReady": false,
        "rank": 306,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.",
        "bestFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
        "strengths": [
          "OpenAPI 3.1 definition with 106 operations, llms.txt and a Markdown copy of every docs page, all public without sign-in",
          "37 documented scopes split by resource and by read or write. A token can carry fewer scopes than its key, and keys expire within one year",
          "MCP write permissions are off by default, enabled per connection by an admin with a second factor, then ticked by each user",
          "Every MCP tool call is recorded in an action log with date, tool, status, user, company and correlation ID",
          "Rate limits are published (1,000 requests a minute per company and credential) with x-ratelimit headers on every response"
        ],
        "weaknesses": [
          "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative",
          "Cards, transactions, invoices, purchase orders, webhooks and most writes sit behind experimental scopes granted on request, and may change",
          "No official SDK found on npm or PyPI, and the MCP server isn't in the official MCP registry",
          "status.spendesk.com has no API component and lists three critical and three major incidents opened between 2 and 29 September 2026",
          "An Idempotency-Key is documented only for creating an intake. A repeated purchase order or supplier request creates a second record"
        ],
        "agentNotes": [
          "Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401",
          "Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list",
          "With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400",
          "The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission",
          "After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.3
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 64
        },
        "provenanceScore": 96
      },
      "connect": {
        "http": "curl -X POST https://public-api.demo.spendesk.com/v1/auth/token \\\n  -u \"YOUR_CLIENT_ID:YOUR_CLIENT_SECRET\"\n\ncurl https://public-api.demo.spendesk.com/v1/wallet-summary \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/spendesk"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Spendesk SAS",
        "domain": "spendesk.com",
        "domainRegistered": "2015-10-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.spendesk.com/legals/terms/",
        "privacy": "https://www.spendesk.com/legals/privacy/",
        "statusPage": "https://status.spendesk.com",
        "changelog": "https://developer.spendesk.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The legal notice names Spendesk SAS, 7 Rue de Madrid, 75008 Paris, registration 821 893 286 R.C.S. Paris. The privacy policy (March 2025, version 0.5) gives the registered office as 51 rue de Londres, 75008 Paris.",
          "Payment services are supplied by Spendesk Financial Services (a French payment institution licensed by the ACPR, number 17518) in the EEA, Adyen in the UK and Sutton Bank in the US, per the site footer.",
          "The API and the MCP server answer at public-api.spendesk.com. An unauthenticated POST to /v1/mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata.",
          "www.spendesk.com/.well-known/security.txt is present with a contact and an expiry of 31 December 2026. developer.spendesk.com/.well-known/security.txt returns 404.",
          "The terms page lists the customer terms, a DORA addendum, a Spendesk API agreement and partner programme terms. The document links are drawn by JavaScript and we couldn't open them.",
          "RDAP for spendesk.com gives a registration date of 2015-10-30."
        ],
        "score": 96
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/spendesk.json",
      "live": {
        "slug": "spendesk",
        "probe": {
          "target": "https://public-api.spendesk.com",
          "method": "get",
          "lastAt": "2026-10-08T18:20:40.801700324Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 67,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 67,
          "p95ms24h": 103,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.spendesk.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-08T18:22:20.323763159Z"
        },
        "securityTxt": {
          "url": "https://spendesk.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-12-31T22:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:39.004780879Z"
        },
        "pages": [
          {
            "url": "https://developer.spendesk.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:18.275650963Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0a7493461e82"
          }
        ],
        "updatedAt": "2026-10-08T18:22:20.323763159Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Ramp Business Corporation",
        "b": "Spendesk SAS",
        "name": "Vendor"
      },
      {
        "a": "https://api.ramp.com",
        "b": "https://public-api.spendesk.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Ramp Platform Agreement and the API Agreement. The ramp-cli repository is MIT",
        "b": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "62",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-09-29",
        "name": "Last release"
      },
      {
        "a": "couldn't be read",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "2025-03-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "couldn't be read",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "couldn't be read",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "couldn't be read",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "couldn't be read",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "couldn't be read",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "53 stars",
        "b": "none",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Ramp's 57.3 (C), and leads in 4 of 7 scored categories. Ramp leads on payments \u0026 pricing and maintenance \u0026 community.",
        "question": "Which is better for AI agents, Ramp or Spendesk API + MCP?"
      },
      {
        "answer": "Ramp uses an OAuth sign-in. Spendesk API + MCP takes an API key or an OAuth sign-in.",
        "question": "Do Ramp and Spendesk API + MCP need an API key?"
      },
      {
        "answer": "Yes. Ramp has a hosted endpoint at https://api.ramp.com and Spendesk API + MCP at https://public-api.spendesk.com.",
        "question": "Can an agent call Ramp and Spendesk API + MCP without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 25 against 0",
          "Maintenance \u0026 community, 74 against 57"
        ],
        "also": null,
        "goodFor": "A finance team already on Ramp that wants an agent to read transactions, upload receipts, code and split expenses, issue funds with limits, create bills and work with purchase orders and procurement requests.",
        "slug": "ramp",
        "watchFor": "No public status page was found. status.ramp.com doesn't resolve, and no status link appears in the docs, help centre or trust centre pages read"
      },
      {
        "aheadOn": [
          "Reliability, 55 against 30",
          "Security \u0026 auth, 86 against 79",
          "Transparency \u0026 trust, 80 against 70"
        ],
        "also": [
          "No incidents deducted, where Ramp loses 3 points for them"
        ],
        "goodFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
        "slug": "spendesk",
        "watchFor": "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative"
      }
    ],
    "job": {
      "capability": "spend.transactions",
      "name": "Spend transactions"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-ramp.json",
        "title": "Brex vs Ramp",
        "url": "https://www.anchorterminal.com/compare/brex-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/brex-vs-spendesk.json",
        "title": "Brex vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/brex-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expensify-vs-ramp.json",
        "title": "Expensify vs Ramp",
        "url": "https://www.anchorterminal.com/compare/expensify-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/expensify-vs-spendesk.json",
        "title": "Expensify vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/expensify-vs-spendesk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pleo-vs-ramp.json",
        "title": "Pleo API + MCP vs Ramp",
        "url": "https://www.anchorterminal.com/compare/pleo-vs-ramp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/pleo-vs-spendesk.json",
        "title": "Pleo API + MCP vs Spendesk API + MCP",
        "url": "https://www.anchorterminal.com/compare/pleo-vs-spendesk"
      }
    ],
    "scores": [
      {
        "by": 25,
        "edge": "spendesk",
        "key": "reliability",
        "name": "Reliability",
        "ramp": 30,
        "spendesk": 55,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "edge": "spendesk",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "ramp": 86,
        "spendesk": 87,
        "weight": 13
      },
      {
        "by": 4,
        "edge": "ramp",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "ramp": 66,
        "spendesk": 62,
        "weight": 13
      },
      {
        "by": 7,
        "edge": "spendesk",
        "key": "security",
        "name": "Security \u0026 auth",
        "ramp": 79,
        "spendesk": 86,
        "weight": 14
      },
      {
        "by": 25,
        "edge": "ramp",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "ramp": 25,
        "spendesk": 0,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 17,
        "edge": "ramp",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "ramp": 74,
        "spendesk": 57,
        "weight": 7
      },
      {
        "by": 10,
        "edge": "spendesk",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "ramp": 70,
        "spendesk": 80,
        "weight": 7
      }
    ],
    "summary": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Ramp's 57.3 (C), and leads in 4 of 7 scored categories. Ramp leads on payments \u0026 pricing and maintenance \u0026 community. Both do spend transactions.",
    "verdicts": {
      "ramp": "OAuth 2.0 scopes split read from write across about 40 resources, a 260-operation OpenAPI spec is public, and an audit log endpoint records actions by user and agent. No public status page was found, 89 operations are marked beta, the API Agreement allows changes without notice, and idempotency keys cover only eight write operations.",
      "spendesk": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/ramp-vs-spendesk",
    "json": "https://www.anchorterminal.com/compare/ramp-vs-spendesk.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/ramp-vs-spendesk.md",
    "slim": "https://www.anchorterminal.com/compare/ramp-vs-spendesk.min.md"
  },
  "markdown": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Ramp's 57.3 (C), and leads in 4 of 7 scored categories. Ramp leads on payments \u0026 pricing and maintenance \u0026 community. Both do spend transactions.\n\n- Ramp: grade C, 57.3/100, rank #423 of 629. Markdown https://www.anchorterminal.com/tools/ramp.md · JSON https://www.anchorterminal.com/api/v1/tools/ramp.json\n- Spendesk API + MCP: grade B, 62.3/100, rank #306 of 629. Markdown https://www.anchorterminal.com/tools/spendesk.md · JSON https://www.anchorterminal.com/api/v1/tools/spendesk.json\n\n## Which one, for what\n\n### Ramp (C)\n\nGood for: A finance team already on Ramp that wants an agent to read transactions, upload receipts, code and split expenses, issue funds with limits, create bills and work with purchase orders and procurement requests.\n\nAhead on:\n- Payments \u0026 pricing, 25 against 0\n- Maintenance \u0026 community, 74 against 57\n\nWatch for: No public status page was found. status.ramp.com doesn't resolve, and no status link appears in the docs, help centre or trust centre pages read\n\n### Spendesk API + MCP (B)\n\nGood for: A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.\n\nAhead on:\n- Reliability, 55 against 30\n- Security \u0026 auth, 86 against 79\n- Transparency \u0026 trust, 80 against 70\n\nAlso in its favour:\n- No incidents deducted, where Ramp loses 3 points for them\n\nWatch for: No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative\n\n\n## Score by category\n\n| Category | Weight | Ramp | Spendesk API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 30 | 55 | Spendesk API + MCP +25 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 86 | 87 | Spendesk API + MCP +1 |\n| Agent ergonomics | 13% (16.2 this run) | 66 | 62 | Ramp +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 79 | 86 | Spendesk API + MCP +7 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 0 | Ramp +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 74 | 57 | Ramp +17 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 70 | 80 | Spendesk API + MCP +10 |\n| Negative events | ≤15 | -3 | 0 | |\n| **Total** | | **57.3 · C** | **62.3 · B** | |\n\n## Facts side by side\n\n| Fact | Ramp | Spendesk API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Ramp Business Corporation | Spendesk SAS |\n| Hosted endpoint | `https://api.ramp.com` | `https://public-api.spendesk.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Freemium | Paid |\n| x402 | no | no |\n| Licence | Proprietary service under the Ramp Platform Agreement and the API Agreement. The ramp-cli repository is MIT | Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement |\n| Tools exposed | none | 62 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-09-29 |\n| Terms last updated | couldn't be read | couldn't be read |\n| Privacy policy last updated | couldn't be read | 2025-03-01 |\n| Customer content may train models | couldn't be read | couldn't be read |\n| Terms restrict automated access | couldn't be read | couldn't be read |\n| Terms restrict benchmarking | couldn't be read | couldn't be read |\n| Terms or service can change without notice | couldn't be read | couldn't be read |\n| Arbitration or class-action waiver | couldn't be read | couldn't be read |\n| Popularity | 53 stars | none |\n\n## Verdicts\n\n**Ramp.** OAuth 2.0 scopes split read from write across about 40 resources, a 260-operation OpenAPI spec is public, and an audit log endpoint records actions by user and agent. No public status page was found, 89 operations are marked beta, the API Agreement allows changes without notice, and idempotency keys cover only eight write operations.\n\n**Spendesk API + MCP.** Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.\n\n## Before you call either\n\n### Ramp\n\n1. Send `scope` on the client credentials token request. Without it Ramp issues a token with no scopes and every resource call fails with 403\n2. Follow the full URL in `next` to page. `page_size` defaults to 20 and stops at 100, and the cursor is opaque\n3. Stay under 200 requests in any 10 seconds per source IP and back off 1, 2 then 4 seconds on 429. No Retry-After header is documented\n4. Don't use `synced_after` or `from_created_at` to find changed records. Bills and transactions have no updated-at filter, so subscribe to webhooks\n5. Send `X-Idempotency-Key` when creating funds or procurement requests. Elsewhere a retried POST can create a duplicate, so read back before retrying\n\n### Spendesk API + MCP\n\n1. Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401\n2. Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list\n3. With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400\n4. The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission\n5. After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two\n\n## Questions\n\n### Which is better for AI agents, Ramp or Spendesk API + MCP?\n\nSpendesk API + MCP scores 62.3 (B) on agent readiness against Ramp's 57.3 (C), and leads in 4 of 7 scored categories. Ramp leads on payments \u0026 pricing and maintenance \u0026 community.\n\n### Do Ramp and Spendesk API + MCP need an API key?\n\nRamp uses an OAuth sign-in. Spendesk API + MCP takes an API key or an OAuth sign-in.\n\n### Can an agent call Ramp and Spendesk API + MCP without installing anything?\n\nYes. Ramp has a hosted endpoint at https://api.ramp.com and Spendesk API + MCP at https://public-api.spendesk.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/ramp-vs-spendesk.json, and with the fewest tokens: https://www.anchorterminal.com/compare/ramp-vs-spendesk.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"ramp\", \"b\": \"spendesk\"}`. From a terminal: `anchor compare ramp spendesk`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/ramp.json and https://www.anchorterminal.com/api/v1/tools/spendesk.json\n\n## Other comparisons with Ramp or Spendesk API + MCP\n\n- [Brex vs Ramp](https://www.anchorterminal.com/compare/brex-vs-ramp.md)\n- [Brex vs Spendesk API + MCP](https://www.anchorterminal.com/compare/brex-vs-spendesk.md)\n- [Expensify vs Ramp](https://www.anchorterminal.com/compare/expensify-vs-ramp.md)\n- [Expensify vs Spendesk API + MCP](https://www.anchorterminal.com/compare/expensify-vs-spendesk.md)\n- [Pleo API + MCP vs Ramp](https://www.anchorterminal.com/compare/pleo-vs-ramp.md)\n- [Pleo API + MCP vs Spendesk API + MCP](https://www.anchorterminal.com/compare/pleo-vs-spendesk.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Ramp vs Spendesk API + MCP",
        "url": ""
      }
    ],
    "description": "Spendesk API + MCP scores 62.3 (B) on agent readiness against Ramp's 57.3 (C), and leads in 4 of 7 scored categories. Ramp leads on payments \u0026 pricing and maintenance \u0026 community. Both do spend transactions. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Ramp C 57.3",
      "Spendesk API + MCP B 62.3",
      "scores"
    ],
    "h1": "Ramp vs Spendesk API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-ramp-vs-spendesk.png",
    "path": "/compare/ramp-vs-spendesk",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Ramp vs Spendesk API + MCP for AI agents, C 57.3 vs B 62.3",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/ramp-vs-spendesk"
  },
  "tokens": {
    "markdown": 2050,
    "slim": 630
  },
  "version": 1
}
