Airwallex Spend and Issuing
by Airwallex HTTP API in Spend management & procurement
Hosted
Airwallex US, LLC · airwallex.com since 2015 · status page · who's behind it
Airwallex is a multi-currency business account with company cards, expense management and bill pay. Its REST API issues and controls cards, reads card transactions and expenses, and creates vendors, purchase orders and bills. A CLI and MCP server use OAuth.
Good for A company already banking with Airwallex in several currencies that wants an agent to issue cards with limits, read card transactions and expenses, load vendors, purchase orders and bills, and sync status to an ERP.
Is this your product? Claim this listing or verify it
Assessment. Scoped API keys split read from write per resource, tokens last 30 minutes, and the sandbox opens at once with no contract. No OpenAPI spec was found, every Spend endpoint read is marked beta, the pricing page lists direct Spend API integration under the custom-priced Accelerate plan, and no SLA was found.
Facts
- Transport
- HTTP
- Endpoint
https://api.airwallex.com- Auth
- OAuth or key
- Pricing
- Freemium · $12 / seat-mo
- x402
- No
- Licence
- Proprietary service under Airwallex's service agreement and API terms. The plugin and skills repository is Apache-2.0 and `@airwallex/node-sdk` is MIT
- Packages
npm@airwallex/node-sdk- llms.txt
- published
- Last release
- GitHub stars
- 7
- npm / week
- 44k
- API
- REST at https://api.airwallex.com (sandbox https://api.sandbox.airwallex.com), dated versions with
2026-08-21the latest. The scope catalogue links 34 Issuing and 24 Spend reference pages. No OpenAPI spec found - Spend endpoints
- Card expenses and reimbursement reports (list, get, set sync status, mark paid externally), vendors, purchase orders and bills (create, list, get, set sync status). Each page we read is marked beta
- Issuing endpoints
- Cardholders, cards (create, activate, update, sensitive details, remaining limits), authorisations, card transaction events, card transactions and lifecycles, disputes, digital wallet tokens and issuing config
- MCP servers
- AgentOS MCP at https://mcp.airwallex.com/mcp (production, OAuth, 35 scopes advertised). Developer MCP at https://mcp.sandbox.airwallex.com/developer (sandbox, OAuth). Docs MCP at https://mcp.sandbox.airwallex.com/docs (no sign-in, 2 read-only tools)
- CLI
airwallex, macOS and Linux, installed by script, OAuth sign-in, sandbox by default and--prodfor production.--dry-run,--compact,--api-schema-only, and confirmation on writes unless--confirmis passed. Telemetry is on by default with an opt-out- Credentials
- Scoped API keys (Read or Write per resource, optional IP allowlist) or admin keys, exchanged for a 30-minute bearer token. OAuth 2.0 with 64 scopes for partner apps, the CLI and MCP
- Rate limits
- Production 100 requests a second per account, 20 per endpoint, 50 concurrent. Sandbox 20, 10 and 10. Login endpoint 100 a minute per key
- Pagination
pagebookmark withpage_afterandpage_beforeon Spend and card transaction events.page_numandhas_moreon cards and legacy transactions.page_size1 to 100- Errors
- JSON with
code,message,sourceanddetails. 429 returnstoo_many_requestswith atrace_id - Card controls
- Single or multiple use, allowed currencies, merchant category codes, active period, transaction limits by amount and interval, blocked transaction types, alert thresholds and remote authorisation
- Webhooks
- Signed with HMAC over timestamp and body, retried with exponential backoff for about three days. Spend events for bills, expenses and reimbursements
- SDK
@airwallex/node-sdk2.1.0-beta.5 (31 December 2025), MIT, Node only- Certifications
- SOC 1 Type 2, SOC 2 Type 2, ISO/IEC 27001 and PCI DSS Level 1 per security.airwallex.com. Bug bounty by invitation since 13 July 2021
- Status
- status.airwallex.com on Statuspage, 21 components including Spend, Issuing, API Gateway and Sandbox
- Sub-processors
- Public list updated 7 October 2026 with category, role and region. Google Cloud Platform is the primary host
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Scoped API keys grant Read or Write per resource, can be limited to listed IP ranges, and exchange for bearer tokens that last 30 minutes
- A sandbox account opens at once from a signup form, with the full API except Connected Accounts and simulation endpoints for card transactions
- Rate limits are published with numbers, 100 requests a second per account and 20 per endpoint in production, with backoff guidance for 429
- Create calls such as
POST /api/v1/issuing/cards/createandPOST /api/v1/spend/bills/createrequire arequest_id, so a retried request isn't applied twice - status.airwallex.com has separate Spend, Issuing, API Gateway and Sandbox components, and none was named in an incident between 27 April and 8 October 2026
Weaknesses
- No OpenAPI spec was found. The reference is a Markdown page per endpoint, and the CLI prints one endpoint's schema at a time
- Each Spend endpoint we read (expenses, vendors, bills, purchase orders) is marked beta, and the pricing page lists direct Spend API integration under the custom-priced Accelerate plan
- The Spend API reads expenses and sets sync status. No endpoint was found to attach a receipt, code a card expense or approve one
- The only server SDK is
@airwallex/node-sdk, still in beta and last published on 31 December 2025 - No SLA was found, and the Security Audit Logs API is open to selected accounts only and covers logins, user changes and key changes, not API calls
Before you call it notes for agents
- Exchange
x-client-idandx-api-keyatPOST /api/v1/authentication/loginonce, then reuse the bearer token for 30 minutes. The login endpoint allows 100 requests a minute per key - Create Spend keys with organisation-level permissions. With a key linked to several accounts, send
x-login-asat login or the token carries no account permissions - Send a fresh UUID as
request_idon every create call and reuse the same value when retrying after a timeout - Expect two pagination styles. Spend and card transaction events use the
pagebookmark withpage_afterandpage_before. Cards and legacy transactions usepage_numandhas_more - Card and expense lists default to the last 30 days. Pass both created-at bounds to read further back, and fetch a card singly to see its
authorization_controls
Who's behind it provenance 92/100
- Legal entity namedAirwallex US, LLC20/20
- Domain ageairwallex.com, registered 2015-11-08 (10 years)15/15
- Endpoint on the vendor's domainapi.airwallex.com15/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
- Privacy policyread, states 7 of the 8 things a reader expects, and has 1 clause that costs points7.3/10
- Status pagestatus.airwallex.com10/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service dated 2025-06-20, states 6 of 7, 3 to know
TL;DR Dated 2025-06-20. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access, limits on benchmarking and cut-off without notice or for any reason.
Restricts automated accesscosts points
(d) download, scrape, post or transmit any part of the other Party’s website or content;
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
(j) access the other Party’s platform for competitive purposes or publicly disseminate performance information or analysis relating to the other Party’s APIs.
A clause against publishing test results or using the service to build something that competes.
Says access can be ended without notice or for any reason
Airwallex may terminate these API Terms for any reason upon providing 10 days notice to the Developer.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Gives the date it was last updated Last updated 2025-06-20
Last updated: 20 June 2025
Without a date nobody can tell which version they agreed to.
Names the governing law or courts
If any provision of these API Terms is determined to be invalid or unenforceable by a court of law, the remaining provisions of these API Terms will remain in full force and effect.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at USD $1,000
To the maximum extent permitted by Applicable Laws, Airwallex’s liability to Developer in relation to these API Terms, whether in contract, negligence, liability, tort or other legal or equitable theory, for losses or damages shall not exceed USD $1,000 (or local currency equivalent).
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
The Developer may terminate these API Terms at any time by ceasing all use of the Developer platform, servers, or systems and notifying Airwallex.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 10 days of notice before a change
Airwallex may terminate these API Terms for any reason upon providing 10 days notice to the Developer.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
If the Developer uses the Airwallex Platform and provides a financial service or product (as described in Airwallex’s Acceptable Use Policy), the Developer is prohibited from using the Airwallex Platform without Airwallex’s prior written consent (“Airwallex Approval”).
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Airwallex's liability to the developer under the API Terms is capped at 1,000 US dollars or the local currency equivalent.
Airwallex’s liability to Developer in relation to these API Terms, whether in contract, negligence, liability, tort or other legal or equitable theory, for losses or damages shall not exceed USD $1,000 (or local currency equivalent).
Noted by a second reader on 2026-10-08.
Airwallex may publish the developer's marks on its websites, in press releases and in promotional materials without prior consent.
Airwallex may also publish the Developer’s Marks (with or without a link to the Developer’s website or content) on our websites, in press releases, and in promotional materials without your prior consent.
Noted by a second reader on 2026-10-08.
The developer must implement any update within the time Airwallex specifies, and no later than six months after Airwallex issues it.
The Developer agrees to implement any Update within a reasonable time, as specified by Airwallex, and in any case no longer than six (6) months of Airwallex issuing the Update.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,487 words
Privacy policy gives no date, states 7 of 8, 1 to know
TL;DR Gives no date. States 7 of the 8 things a reader expects. To know before relying on it, model training with no opt-out found.
Says it may use customer content to train or improve models, and no opt-out was foundcosts points
We may also process personal data to develop or improve our AI or ML technologies as described in section 4 of this Policy in accordance with applicable law and internal standards.
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This Privacy Policy (the “Policy”) describes the personal data (sometimes also referred to as personal information) we collect as a data controller from you and how that information is used and shared by us.
The basic statement a privacy policy exists to make.
Says how long data is kept
When a relevant retention period has passed, Airwallex will destroy personal information or, where applicable, sufficiently anonymize the personal information.
Says when data sent to the service is deleted.
Says who else receives the data
Our affiliates and select third parties support the operation of the Services and will necessarily receive and/or transfer personal information in order to facilitate the Services and services provided by third parties at your request and/or with your consent where legally required.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
To learn more about behavioral advertising and online tracking, visit the Network Advertising Initiative.
A plain statement either way.
Says what rights people have over their data
to verify your identity or authenticate your right to access an account or other information;
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact Names a data protection officer
If you want to reach out to our Data Protection Officer, please contact [email protected].
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
…security requirements, as well as the standards described in this Policy, including the use of mandated Standard Contractual Clauses (for the European Union and Brazil) and International Data Transfer Agreement (for the United Kingdom) or any equivalent standard contracts issued by relevant authorities into its agreem…
The countries data goes to and the safeguard used.
Airwallex may keep personal information after an account is closed or after a deletion request.
We may retain your personal information even after you close your Airwallex account or request deletion of your personal information.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 8,347 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms and privacy policy cited are the US ones. The US privacy policy names Airwallex US, LLC among the entities responsible, and the site footer gives Airwallex US, LLC (NMLS #1928093) as the licensed money transmitter. Other regions have their own entities and documents.
The API terms (API Developer Terms and Conditions) are dated 20 June 2025. The service agreement was last updated on 2 December 2025 and took effect on 1 January 2026. The Spend Management Terms are dated 6 December 2023.
The API answers at api.airwallex.com and api.sandbox.airwallex.com, and the MCP servers at mcp.airwallex.com and mcp.sandbox.airwallex.com.
www.airwallex.com/.well-known/security.txt lists bugbounty@airwallex.com and security@airwallex.com and an expiry of 30 June 2030. The timestamp has a space inside it, which isn't the RFC 9116 format.
The US privacy policy shows no last-updated line in the text we read. The global policy at /terms/privacy-policy is dated 26 February 2026.
RDAP for airwallex.com gives a registration date of 2015-11-08.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-09 01:57 UTC
Probed every five minutes at https://api.airwallex.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- Vendor status page minor, Minor Service Outage · 9 minutes ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/airwallex.json
Notable
- The four Spend reference pages we read (list expenses, list vendors, create bill, create purchase order) are headed Status beta source
- The Spend API is built for ERP sync. It reads card expenses and reimbursements and sets their sync status, and creates vendors, purchase orders and bills source
- The AgentOS MCP server at https://mcp.airwallex.com/mcp acts on a production account over OAuth, and Airwallex says its tools don't start transfers, conversions or payouts by default source
- Scoped API keys grant Read or Write per resource and can be restricted to listed IP ranges source
- Production limits are 100 requests a second per account, 20 per endpoint and 50 concurrent requests source
- The US pricing page lists direct Spend API integration with an ERP under the Accelerate plan, which is priced on request source
- The docs carry two pages of instructions addressed to AI agents and an install prompt that asks an assistant to fetch and follow the AgentOS guide source
- The privacy policy says personal data may be processed to develop or improve Airwallex's AI and machine learning technologies source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 15.4 | |
Read with the hosted lines and scored on the REST API for Issuing and Spend. status.airwallex.com is a Statuspage site with 21 components in three groups, among them Spend, Issuing, API Gateway and Sandbox (20). Eleven incidents are listed since 27 April 2026 and none names Spend, Issuing or the API Gateway. Three marked major fall in the last 90 days on neighbouring products (Mastercard 3DS on 15 July, Mastercard payments on 15 August, USD deposits from 29 September to 5 October), each attributed to a third party, so 25 of 30. Limits are published, 100 requests a second per account, 20 per endpoint and 50 concurrent in production, and 20, 10 and 10 in the sandbox (15). The docs ask for exponential backoff with jitter on 429 and creates take a required request_id. No Retry-After header is documented (12 of 15). No SLA was found, and the service agreement supplies the services as is and as available (0). Issuing is generally available, but the four Spend endpoints we read are marked beta, as are the Node SDK and the AgentOS skills (5 of 10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 11.2 | |
No public OpenAPI spec was found. The paths we tried under /docs/api return the docs shell, and the CLI prints one endpoint's schema with --api-schema-only. Each endpoint has a structured Markdown reference page, which earns part credit (6 of 25). llms.txt at /docs/llms.txt and a Markdown twin of every guide and reference page (10). Endpoint and field descriptions state purpose, and deprecated endpoints name their replacement. Few say when not to call (14 of 20). Fields carry types, formats, required flags and possible values. Amounts are strings, and status filters warn that new values may appear (12 of 15). Every reference page has a cURL request and a response example, and Spend and Issuing each have an error code page. The create bill page lists 400, 404 and 500 but not 401 or 429 (12 of 15). Dated API versions (latest 2026-08-21), an x-api-version override and a changelog of backwards-incompatible changes by version (15). | |||
| Agent ergonomics | 13%16.2 | 11.2 | |
page_size runs from 1 to 100 and defaults to 100 on Spend lists. No field selection or expand parameter was found, and the CLI has a --compact flag (15 of 25). Spend lists and card transaction events page with a page bookmark and page_after and page_before, while cards and legacy transactions use page_num and has_more. Filters cover status, sync status, legal entity and created-at range, with a 30-day default window (16 of 20). Errors return code, message, source and details, and 429 responses carry a trace_id. The Spend error page lists three codes (15 of 20). request_id is required on create calls for cards, bills and purchase orders. Airwallex says the production MCP server annotates write tools, which we couldn't read without an account. The two tools on the keyless Docs MCP server carry readOnlyHint (16 of 20). Creating a bill needs eleven required fields. The only server SDK is @airwallex/node-sdk in beta, and the CLI has a dry-run flag (7 of 15). | |||
| Security & auth | 14%17.5 | 14.7 | |
Scoped API keys grant Read or Write per resource at organisation or account level, can be edited, regenerated, duplicated and deleted, and can be tied to IP ranges. Keys travel only in headers and exchange for a bearer token that lasts 30 minutes. Partner apps, the CLI and the MCP server use OAuth with 64 scopes (30). Read is separate from Write, the AgentOS tools don't start transfers, conversions or payouts by default, CLI writes ask for confirmation, and cards take limits, merchant category rules and remote authorisation. Unrestricted admin keys still exist, and API writes have no confirmation step (17 of 20). The AgentOS page warns about indirect prompt injection from documents and web pages, tool poisoning by other MCP servers and auto-approve modes. Expense descriptions, comments and merchant names are untrusted text (11 of 15). GET /api/v1/audit_log/security_audit_logs records logins, user management and key changes for selected accounts only, key changes trigger an email, and no per-call log was found (8 of 15). security.txt with contacts, a bug bounty that has been invite-only since 13 July 2021, SOC 1 and SOC 2 Type 2, ISO 27001 and PCI DSS Level 1 on the trust centre (18 of 20). | |||
| Payments & pricing | 10%12.5 | 3.1 | |
| Read with the hosted rubric. No x402, MPP or L402 was found in the docs or on the pricing page (0). US plan prices are public, Explore at $0 with up to 10 free Spend users and Grow at $12 per active Spend user a month. The pricing page lists direct Spend API integration with an ERP under Accelerate, which is priced on request, and sends platform API use to sales, so half the plan-pricing credit (5 of 20). A sandbox account opens at once from a form asking for email, name, country and password, with no payment card and no contract, and the Explore plan is free (20). A person has to sign up in a browser and create a key in the web app or complete an OAuth sign-in. The Docs MCP server needs no account but answers docs questions only (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 5.8 | |
The airwallex-marketplace repository, which carries the AgentOS and developer plugins, tagged v0.2.11 on 30 September 2026. The newest API version is 2026-08-21 (30). Eight marketplace tags between 6 August and 30 September, and API versions on 17 July and 21 August (20). Closed service. The changelog lists backwards-incompatible changes only, support is a help centre ticket or developer.support@airwallex.com, and the marketplace repository shows one open issue. Response times couldn't be observed (9 of 15). @airwallex/node-sdk was last published on 31 December 2025 as 2.1.0-beta.5 and is the only server SDK. The official MCP registry has no Airwallex entry of the vendor's own, only a third party's (io.github.codespar/mcp-airwallex) (4 of 15). The marketplace repository has no CI workflow, and the CLI is a binary installed by script whose version we couldn't read (3 of 10). | |||
| Transparency & trusteditorial 64, provenance 92 | 7%8.8 | 6.8 | |
| Closed service with terms at stable URLs. The API terms are dated 20 June 2025, the service agreement took effect on 1 January 2026 and the Spend Management Terms are dated 6 December 2023. The plugin repository is Apache-2.0 and the Node SDK is MIT (16 of 30). The privacy policy describes retention by purpose and legal duty without fixed periods, names the countries where data is hosted, and says personal data may be processed to develop or improve Airwallex's AI and machine learning. A DPA is published as part of the customer agreement (18 of 30). Breaking changes ship as dated versions and an account stays on its version until it migrates. The API terms require a developer to implement an update within six months at most, give 30 days' notice of adverse changes to the terms, and let Airwallex discontinue services at its discretion. No retirement dates for old versions were found (12 of 20). A public list of processors and sub-processors, updated 7 October 2026, gives each one's category, role and region (18 of 20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 68.3 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 21 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Airwallex Spend and Issuing, or have the agent fetch /fixes/airwallex.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Airwallex Spend and Issuing From Anchor Terminal's listing at https://www.anchorterminal.com/tools/airwallex, the October 2026 research run, assessed 8 October 2026. Grade B, 68.3 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Airwallex Spend and Issuing: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 25 out of 100, up to 9.4 more on the total Why it scored 25: Read with the hosted rubric. No x402, MPP or L402 was found in the docs or on the pricing page (0). US plan prices are public, Explore at $0 with up to 10 free Spend users and Grow at $12 per active Spend user a month. The pricing page lists direct Spend API integration with an ERP under Accelerate, which is priced on request, and sends platform API use to sales, so half the plan-pricing credit (5 of 20). A sandbox account opens at once from a form asking for email, name, country and password, with no payment card and no contract, and the Explore plan is free (20). A person has to sign up in a browser and create a key in the web app or complete an OAuth sign-in. The Docs MCP server needs no account but answers docs questions only (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Schema & documentation, 69 out of 100, up to 5 more on the total Why it scored 69: No public OpenAPI spec was found. The paths we tried under /docs/api return the docs shell, and the CLI prints one endpoint's schema with `--api-schema-only`. Each endpoint has a structured Markdown reference page, which earns part credit (6 of 25). llms.txt at /docs/llms.txt and a Markdown twin of every guide and reference page (10). Endpoint and field descriptions state purpose, and deprecated endpoints name their replacement. Few say when not to call (14 of 20). Fields carry types, formats, required flags and possible values. Amounts are strings, and status filters warn that new values may appear (12 of 15). Every reference page has a cURL request and a response example, and Spend and Issuing each have an error code page. The create bill page lists 400, 404 and 500 but not 401 or 429 (12 of 15). Dated API versions (latest `2026-08-21`), an `x-api-version` override and a changelog of backwards-incompatible changes by version (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 3. Agent ergonomics, 69 out of 100, up to 5 more on the total Why it scored 69: `page_size` runs from 1 to 100 and defaults to 100 on Spend lists. No field selection or expand parameter was found, and the CLI has a `--compact` flag (15 of 25). Spend lists and card transaction events page with a `page` bookmark and `page_after` and `page_before`, while cards and legacy transactions use `page_num` and `has_more`. Filters cover status, sync status, legal entity and created-at range, with a 30-day default window (16 of 20). Errors return `code`, `message`, `source` and `details`, and 429 responses carry a `trace_id`. The Spend error page lists three codes (15 of 20). `request_id` is required on create calls for cards, bills and purchase orders. Airwallex says the production MCP server annotates write tools, which we couldn't read without an account. The two tools on the keyless Docs MCP server carry readOnlyHint (16 of 20). Creating a bill needs eleven required fields. The only server SDK is `@airwallex/node-sdk` in beta, and the CLI has a dry-run flag (7 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 4. Reliability, 77 out of 100, up to 4.6 more on the total Why it scored 77: Read with the hosted lines and scored on the REST API for Issuing and Spend. status.airwallex.com is a Statuspage site with 21 components in three groups, among them Spend, Issuing, API Gateway and Sandbox (20). Eleven incidents are listed since 27 April 2026 and none names Spend, Issuing or the API Gateway. Three marked major fall in the last 90 days on neighbouring products (Mastercard 3DS on 15 July, Mastercard payments on 15 August, USD deposits from 29 September to 5 October), each attributed to a third party, so 25 of 30. Limits are published, 100 requests a second per account, 20 per endpoint and 50 concurrent in production, and 20, 10 and 10 in the sandbox (15). The docs ask for exponential backoff with jitter on 429 and creates take a required `request_id`. No Retry-After header is documented (12 of 15). No SLA was found, and the service agreement supplies the services as is and as available (0). Issuing is generally available, but the four Spend endpoints we read are marked beta, as are the Node SDK and the AgentOS skills (5 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 5. Maintenance & community, 66 out of 100, up to 3 more on the total Why it scored 66: The airwallex-marketplace repository, which carries the AgentOS and developer plugins, tagged v0.2.11 on 30 September 2026. The newest API version is `2026-08-21` (30). Eight marketplace tags between 6 August and 30 September, and API versions on 17 July and 21 August (20). Closed service. The changelog lists backwards-incompatible changes only, support is a help centre ticket or developer.support@airwallex.com, and the marketplace repository shows one open issue. Response times couldn't be observed (9 of 15). `@airwallex/node-sdk` was last published on 31 December 2025 as 2.1.0-beta.5 and is the only server SDK. The official MCP registry has no Airwallex entry of the vendor's own, only a third party's (io.github.codespar/mcp-airwallex) (4 of 15). The marketplace repository has no CI workflow, and the CLI is a binary installed by script whose version we couldn't read (3 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 6. Security & auth, 84 out of 100, up to 2.8 more on the total Why it scored 84: Scoped API keys grant Read or Write per resource at organisation or account level, can be edited, regenerated, duplicated and deleted, and can be tied to IP ranges. Keys travel only in headers and exchange for a bearer token that lasts 30 minutes. Partner apps, the CLI and the MCP server use OAuth with 64 scopes (30). Read is separate from Write, the AgentOS tools don't start transfers, conversions or payouts by default, CLI writes ask for confirmation, and cards take limits, merchant category rules and remote authorisation. Unrestricted admin keys still exist, and API writes have no confirmation step (17 of 20). The AgentOS page warns about indirect prompt injection from documents and web pages, tool poisoning by other MCP servers and auto-approve modes. Expense descriptions, comments and merchant names are untrusted text (11 of 15). `GET /api/v1/audit_log/security_audit_logs` records logins, user management and key changes for selected accounts only, key changes trigger an email, and no per-call log was found (8 of 15). security.txt with contacts, a bug bounty that has been invite-only since 13 July 2021, SOC 1 and SOC 2 Type 2, ISO 27001 and PCI DSS Level 1 on the trust centre (18 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 7. Transparency & trust, 78 out of 100, up to 1.9 more on the total Made of editorial 64, provenance 92. Why it scored 78: Closed service with terms at stable URLs. The API terms are dated 20 June 2025, the service agreement took effect on 1 January 2026 and the Spend Management Terms are dated 6 December 2023. The plugin repository is Apache-2.0 and the Node SDK is MIT (16 of 30). The privacy policy describes retention by purpose and legal duty without fixed periods, names the countries where data is hosted, and says personal data may be processed to develop or improve Airwallex's AI and machine learning. A DPA is published as part of the customer agreement (18 of 30). Breaking changes ship as dated versions and an account stays on its version until it migrates. The API terms require a developer to implement an update within six months at most, give 30 days' notice of adverse changes to the terms, and let Airwallex discontinue services at its discretion. No retirement dates for old versions were found (12 of 20). A public list of processors and sub-processors, updated 7 October 2026, gives each one's category, role and region (18 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10) - Privacy policy: read, states 7 of the 8 things a reader expects, and has 1 clause that costs points (7.3 of 10) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the production MCP server's tool list, input schemas and annotations at https://mcp.airwallex.com/mcp, which need an OAuth sign-in to an Airwallex account. `toolCount` is left empty - unchecked: the CLI's version and release history. static.airwallex.com didn't answer our requests for the install script - unchecked: whether a sandbox or Explore account can call the Spend endpoints. The pricing page lists direct Spend API integration under Accelerate, and the docs state no plan requirement - unchecked: whether Issuing API access needs approval on every account. The CLI guide says card and Issuing commands may return 403 until support enables access, and the service agreement says API access must first be approved - unchecked: whether 429 responses carry a Retry-After header. None is documented - unchecked: whether an OpenAPI spec is published somewhere we didn't look. None is linked from llms.txt or the API introduction - unchecked: the date of the US privacy policy, which shows no last-updated line in the text we read. The global policy is dated 26 February 2026 - unchecked: whether an SLA exists in Accelerate or platform contracts. None was found in the service agreement or the API terms - The lead described a plain REST API with a sandbox. It left out that the Spend endpoints are beta and that the vendor also runs a CLI and three MCP servers - The docs carry two pages titled Instructions for AI agents and an install prompt that asks an assistant to fetch and follow the AgentOS guide. We recorded them as facts and didn't act on them - The pricing page is the US one in USD. Plans and fees differ by region, and the terms and privacy policy cited are those of Airwallex US, LLC - security.txt gives its expiry as `2030-06-30 T00:00:00.000Z` with a space inside the timestamp, which isn't the RFC 9116 format. We recorded it as valid because the contacts and a future expiry are present ## Weaknesses - No OpenAPI spec was found. The reference is a Markdown page per endpoint, and the CLI prints one endpoint's schema at a time - Each Spend endpoint we read (expenses, vendors, bills, purchase orders) is marked beta, and the pricing page lists direct Spend API integration under the custom-priced Accelerate plan - The Spend API reads expenses and sets sync status. No endpoint was found to attach a receipt, code a card expense or approve one - The only server SDK is `@airwallex/node-sdk`, still in beta and last published on 31 December 2025 - No SLA was found, and the Security Audit Logs API is open to selected accounts only and covers logins, user changes and key changes, not API calls ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Exchange `x-client-id` and `x-api-key` at `POST /api/v1/authentication/login` once, then reuse the bearer token for 30 minutes. The login endpoint allows 100 requests a minute per key - Create Spend keys with organisation-level permissions. With a key linked to several accounts, send `x-login-as` at login or the token carries no account permissions - Send a fresh UUID as `request_id` on every create call and reuse the same value when retrying after a timeout - Expect two pagination styles. Spend and card transaction events use the `page` bookmark with `page_after` and `page_before`. Cards and legacy transactions use `page_num` and `has_more` - Card and expense lists default to the last 30 days. Pass both created-at bounds to read further back, and fetch a card singly to see its `authorization_controls` ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the production MCP server's tool list, input schemas and annotations at https://mcp.airwallex.com/mcp, which need an OAuth sign-in to an Airwallex account.
toolCountis left empty - unchecked: the CLI's version and release history. static.airwallex.com didn't answer our requests for the install script
- unchecked: whether a sandbox or Explore account can call the Spend endpoints. The pricing page lists direct Spend API integration under Accelerate, and the docs state no plan requirement
- unchecked: whether Issuing API access needs approval on every account. The CLI guide says card and Issuing commands may return 403 until support enables access, and the service agreement says API access must first be approved
- unchecked: whether 429 responses carry a Retry-After header. None is documented
- unchecked: whether an OpenAPI spec is published somewhere we didn't look. None is linked from llms.txt or the API introduction
- unchecked: the date of the US privacy policy, which shows no last-updated line in the text we read. The global policy is dated 26 February 2026
- unchecked: whether an SLA exists in Accelerate or platform contracts. None was found in the service agreement or the API terms
- The lead described a plain REST API with a sandbox. It left out that the Spend endpoints are beta and that the vendor also runs a CLI and three MCP servers
- The docs carry two pages titled Instructions for AI agents and an install prompt that asks an assistant to fetch and follow the AgentOS guide. We recorded them as facts and didn't act on them
- The pricing page is the US one in USD. Plans and fees differ by region, and the terms and privacy policy cited are those of Airwallex US, LLC
- security.txt gives its expiry as
2030-06-30 T00:00:00.000Zwith a space inside the timestamp, which isn't the RFC 9116 format. We recorded it as valid because the contacts and a future expiry are present
Sources 41
- docs index for agents airwallex.com · seen 2026-10-08
- how the Spend API works airwallex.com · seen 2026-10-08
- card expenses guide airwallex.com · seen 2026-10-08
- bills guide airwallex.com · seen 2026-10-08
- Spend error codes airwallex.com · seen 2026-10-08
- list expenses reference, marked beta airwallex.com · seen 2026-10-08
- create bill reference airwallex.com · seen 2026-10-08
- create card reference airwallex.com · seen 2026-10-08
- card authorisation controls airwallex.com · seen 2026-10-08
- rate limits airwallex.com · seen 2026-10-08
- API key management airwallex.com · seen 2026-10-08
- API key scopes airwallex.com · seen 2026-10-08
- API key practices and IP allowlisting airwallex.com · seen 2026-10-08
- OAuth scopes airwallex.com · seen 2026-10-08
- security audit logs airwallex.com · seen 2026-10-08
- sandbox overview airwallex.com · seen 2026-10-08
- API versioning airwallex.com · seen 2026-10-08
- API changelog airwallex.com · seen 2026-10-08
- API errors airwallex.com · seen 2026-10-08
- AgentOS and the production MCP server airwallex.com · seen 2026-10-08
- developer and docs MCP servers airwallex.com · seen 2026-10-08
- CLI guide airwallex.com · seen 2026-10-08
- server-side SDK guide airwallex.com · seen 2026-10-08
- webhooks overview airwallex.com · seen 2026-10-08
- MCP protected resource metadata, 35 scopes mcp.airwallex.com · seen 2026-10-08
- Docs MCP server, tools/list mcp.sandbox.airwallex.com · seen 2026-10-08
- plugin repository, tags and licence github.com · seen 2026-10-08
- Node SDK on npm registry.npmjs.org · seen 2026-10-08
- status incidents status.airwallex.com · seen 2026-10-08
- status components status.airwallex.com · seen 2026-10-08
- US pricing airwallex.com · seen 2026-10-08
- API terms airwallex.com · seen 2026-10-08
- service agreement airwallex.com · seen 2026-10-08
- Spend Management Terms airwallex.com · seen 2026-10-08
- privacy policy airwallex.com · seen 2026-10-08
- processors and sub-processors airwallex.com · seen 2026-10-08
- trust centre security.airwallex.com · seen 2026-10-08
- security.txt airwallex.com · seen 2026-10-08
- bug bounty rules help.airwallex.com · seen 2026-10-08
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
- RDAP for airwallex.com rdap.verisign.com · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $12 / seat-mo No separate API fee is published. The US pricing page lists Explore at $0 with up to 10 free Spend users, Grow at $12 per active Spend user a month up to 250 users, and Accelerate on request. It lists direct Spend API integration with an ERP under Accelerate and sends platform API and embedded finance use to sales. A sandbox account opens at once from a signup form with no payment card or contract, so an agent's owner can start there. Card, FX and transfer fees are on a separate fee schedule (checked 2026-10-08).
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Explore plan | free | per seat per month | Up to 10 free Spend users. No separate API fee is published |
| Grow plan | $12 | per seat per month | Per active Spend user, up to 250. Accelerate, which lists direct Spend API integration, is priced on request |
Compared across listings on the price index.
Recent changes
- Airwallex Spend and Issuing status page: none → minor source
- Latest release
Follow them as a feed at /feeds/tools/airwallex.xml, or this listing's score history at history.json.
Connect
Install
curl -fsSL https://static.airwallex.com/developer-tools/airwallex-cli/install.sh | sh
First request
curl -X POST https://api.sandbox.airwallex.com/api/v1/authentication/login \
-H 'Content-Type: application/json' \
-H 'x-api-key: {{YOUR_API_KEY}}' \
-H 'x-client-id: {{YOUR_CLIENT_ID}}'
Claude Code
claude mcp add-json airwallex '{ "type": "http", "url": "https://mcp.airwallex.com/mcp" }'
MCP client configuration
{
"mcpServers": {
"airwallex": {
"type": "http",
"url": "https://mcp.airwallex.com/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/airwallex
letme picks this listing for spend.bills, because it's the top-graded tool for the job. letme picks this listing for spend.cards, because it's the top-graded tool for the job. letme picks this listing for spend.expenses, because it's the top-graded tool for the job. letme picks this listing for spend.procurement, because it's the top-graded tool for the job. letme picks this listing for spend.transactions, because it's the top-graded tool for the job.
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Spendesk API + MCP BRamp CBILL CBrex CMercury API BPleo API + MCP B
Head to head Airwallex Spend and Issuing vs BILL · Airwallex Spend and Issuing vs Brex · Airwallex Spend and Issuing vs Expensify · Airwallex Spend and Issuing vs Mercury API · Airwallex Spend and Issuing vs Pleo API + MCP · Airwallex Spend and Issuing vs Ramp · Airwallex Spend and Issuing vs Spendesk API + MCP
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Spendesk API + MCP Spendesk SAS | B | 62.3 | spend.transactions spend.expenses spend.cards spend.bills spend.procurement | no |
| Ramp Ramp Business Corporation | C | 57.3 | spend.transactions spend.expenses spend.cards spend.bills spend.procurement | no |
| BILL BILL Holdings, Inc. | C | 60.9 | spend.transactions spend.expenses spend.cards spend.bills | no |
| Brex Brex LLC | C | 60.7 | spend.transactions spend.expenses spend.cards spend.bills | no |
| Mercury API Mercury Technologies, Inc. | B | 63.8 | spend.transactions spend.cards spend.expenses | no |
| Pleo API + MCP Pleo Technologies A/S | B | 62.9 | spend.transactions spend.expenses spend.bills | no |
Machine-readable
- JSON
/api/v1/tools/airwallex.json· historyhistory.json· badge/badges/airwallex.svg· changes feed/feeds/tools/airwallex.xml - Markdown
/tools/airwallex.md· slim/tools/airwallex.min.md(or sendAccept: text/markdown) - Fix list
/fixes/airwallex.md·/fixes/airwallex.json - From a terminal
anchor tool airwallex --md(the CLI) · over MCPget_tool {"slug": "airwallex"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/airwallex"><img src="https://www.anchorterminal.com/badges/airwallex.svg" alt="Airwallex Spend and Issuing on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/airwallex)<a href="https://www.anchorterminal.com/tools/airwallex">Airwallex Spend and Issuing on Anchor Terminal</a>It counts on a page on airwallex.com or one of its subdomains, or the README of github.com/airwallex/airwallex-marketplace.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "airwallex", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


