# Airwallex Spend and Issuing > Airwallex is a multi-currency business account with company cards, expense management and bill pay. Its REST API issues and controls cards, reads card transactions and expenses, and creates vendors, purchase orders and bills. A CLI and MCP server use OAuth. - Canonical: https://www.anchorterminal.com/tools/airwallex - Markdown: https://www.anchorterminal.com/tools/airwallex.md (~9,200 tokens) - Slim: https://www.anchorterminal.com/tools/airwallex.min.md (~1,980 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/airwallex.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade B · 68.3/100 · rank #187 of 722 · #1 in Spend management & procurement · not agent-ready · confidence medium** ## Assessment Scoped API keys split read from write per resource, tokens last 30 minutes, and the sandbox opens at once with no contract. No OpenAPI spec was found, every Spend endpoint read is marked beta, the pricing page lists direct Spend API integration under the custom-priced Accelerate plan, and no SLA was found. ## Facts | Field | Value | | --- | --- | | Vendor | Airwallex (https://www.airwallex.com) | | Kind | HTTP API | | Category | Spend management & procurement (https://www.anchorterminal.com/categories/spend-management) | | Transport | HTTP | | Endpoint | `https://api.airwallex.com` | | Auth | OAuth or key · Access is self-serve in the sandbox and for an Airwallex customer in production. A user with the Owner, Admin or Developer role creates a key in the web app under Developer, then API keys. Scoped keys grant Read or Write per resource and can be tied to IP ranges, and admin keys are unrestricted. A key and client ID exchange at `POST /api/v1/authentication/login` for a bearer token that lasts 30 minutes. Spend resources need organisation-level permissions. The CLI, the MCP servers and partner apps use OAuth 2.0 with 64 scopes, and only Owner, Admin and Finance Admin users can consent. The service agreement says Airwallex must first approve API access, and the CLI guide says card and Issuing commands may need support to enable them. | | Pricing | Freemium ($12 / seat-mo) · No separate API fee is published. The US pricing page lists Explore at $0 with up to 10 free Spend users, Grow at $12 per active Spend user a month up to 250 users, and Accelerate on request. It lists direct Spend API integration with an ERP under Accelerate and sends platform API and embedded finance use to sales. A sandbox account opens at once from a signup form with no payment card or contract, so an agent's owner can start there. Card, FX and transfer fees are on a separate fee schedule (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the docs index, the API reference pages read or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under Airwallex's service agreement and API terms. The plugin and skills repository is Apache-2.0 and `@airwallex/node-sdk` is MIT | | Packages | npm: `@airwallex/node-sdk` | | Source | https://github.com/airwallex/airwallex-marketplace | | Docs | https://www.airwallex.com/docs/ | | llms.txt | https://www.airwallex.com/docs/llms.txt | | Last release | 2026-09-30 | | GitHub stars | 7 (as of 2026-10-08) | | npm downloads / week | 44,464 | | API | REST at https://api.airwallex.com (sandbox https://api.sandbox.airwallex.com), dated versions with `2026-08-21` the latest. The scope catalogue links 34 Issuing and 24 Spend reference pages. No OpenAPI spec found | | Spend endpoints | Card expenses and reimbursement reports (list, get, set sync status, mark paid externally), vendors, purchase orders and bills (create, list, get, set sync status). Each page we read is marked beta | | Issuing endpoints | Cardholders, cards (create, activate, update, sensitive details, remaining limits), authorisations, card transaction events, card transactions and lifecycles, disputes, digital wallet tokens and issuing config | | MCP servers | AgentOS MCP at https://mcp.airwallex.com/mcp (production, OAuth, 35 scopes advertised). Developer MCP at https://mcp.sandbox.airwallex.com/developer (sandbox, OAuth). Docs MCP at https://mcp.sandbox.airwallex.com/docs (no sign-in, 2 read-only tools) | | CLI | `airwallex`, macOS and Linux, installed by script, OAuth sign-in, sandbox by default and `--prod` for production. `--dry-run`, `--compact`, `--api-schema-only`, and confirmation on writes unless `--confirm` is passed. Telemetry is on by default with an opt-out | | Credentials | Scoped API keys (Read or Write per resource, optional IP allowlist) or admin keys, exchanged for a 30-minute bearer token. OAuth 2.0 with 64 scopes for partner apps, the CLI and MCP | | Rate limits | Production 100 requests a second per account, 20 per endpoint, 50 concurrent. Sandbox 20, 10 and 10. Login endpoint 100 a minute per key | | Pagination | `page` bookmark with `page_after` and `page_before` on Spend and card transaction events. `page_num` and `has_more` on cards and legacy transactions. `page_size` 1 to 100 | | Errors | JSON with `code`, `message`, `source` and `details`. 429 returns `too_many_requests` with a `trace_id` | | Card controls | Single or multiple use, allowed currencies, merchant category codes, active period, transaction limits by amount and interval, blocked transaction types, alert thresholds and remote authorisation | | Webhooks | Signed with HMAC over timestamp and body, retried with exponential backoff for about three days. Spend events for bills, expenses and reimbursements | | SDK | `@airwallex/node-sdk` 2.1.0-beta.5 (31 December 2025), MIT, Node only | | Certifications | SOC 1 Type 2, SOC 2 Type 2, ISO/IEC 27001 and PCI DSS Level 1 per security.airwallex.com. Bug bounty by invitation since 13 July 2021 | | Status | status.airwallex.com on Statuspage, 21 components including Spend, Issuing, API Gateway and Sandbox | | Sub-processors | Public list updated 7 October 2026 with category, role and region. Google Cloud Platform is the primary host | | Capabilities | spend.transactions, spend.cards, spend.expenses, spend.bills, spend.procurement | | Tags | hosted, freemium, api-key, oauth, mcp, cli, llms-txt, webhooks, sandbox, multi-currency, soc2, pci-dss, iso27001, status-page, security-txt, bug-bounty | | JSON | https://www.anchorterminal.com/api/v1/tools/airwallex.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 77 | 15.4 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 69 | 11.2 | | Agent ergonomics | 13% | 16.2 | 69 | 11.2 | | Security & auth | 14% | 17.5 | 84 | 14.7 | | Payments & pricing | 10% | 12.5 | 25 | 3.1 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 66 | 5.8 | | Transparency & trust (editorial 64, provenance 92) | 7% | 8.8 | 78 | 6.8 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **68.3 → B** | ### Why each score - Reliability 77: Read with the hosted lines and scored on the REST API for Issuing and Spend. status.airwallex.com is a Statuspage site with 21 components in three groups, among them Spend, Issuing, API Gateway and Sandbox (20). Eleven incidents are listed since 27 April 2026 and none names Spend, Issuing or the API Gateway. Three marked major fall in the last 90 days on neighbouring products (Mastercard 3DS on 15 July, Mastercard payments on 15 August, USD deposits from 29 September to 5 October), each attributed to a third party, so 25 of 30. Limits are published, 100 requests a second per account, 20 per endpoint and 50 concurrent in production, and 20, 10 and 10 in the sandbox (15). The docs ask for exponential backoff with jitter on 429 and creates take a required `request_id`. No Retry-After header is documented (12 of 15). No SLA was found, and the service agreement supplies the services as is and as available (0). Issuing is generally available, but the four Spend endpoints we read are marked beta, as are the Node SDK and the AgentOS skills (5 of 10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 69: No public OpenAPI spec was found. The paths we tried under /docs/api return the docs shell, and the CLI prints one endpoint's schema with `--api-schema-only`. Each endpoint has a structured Markdown reference page, which earns part credit (6 of 25). llms.txt at /docs/llms.txt and a Markdown twin of every guide and reference page (10). Endpoint and field descriptions state purpose, and deprecated endpoints name their replacement. Few say when not to call (14 of 20). Fields carry types, formats, required flags and possible values. Amounts are strings, and status filters warn that new values may appear (12 of 15). Every reference page has a cURL request and a response example, and Spend and Issuing each have an error code page. The create bill page lists 400, 404 and 500 but not 401 or 429 (12 of 15). Dated API versions (latest `2026-08-21`), an `x-api-version` override and a changelog of backwards-incompatible changes by version (15). - Agent ergonomics 69: `page_size` runs from 1 to 100 and defaults to 100 on Spend lists. No field selection or expand parameter was found, and the CLI has a `--compact` flag (15 of 25). Spend lists and card transaction events page with a `page` bookmark and `page_after` and `page_before`, while cards and legacy transactions use `page_num` and `has_more`. Filters cover status, sync status, legal entity and created-at range, with a 30-day default window (16 of 20). Errors return `code`, `message`, `source` and `details`, and 429 responses carry a `trace_id`. The Spend error page lists three codes (15 of 20). `request_id` is required on create calls for cards, bills and purchase orders. Airwallex says the production MCP server annotates write tools, which we couldn't read without an account. The two tools on the keyless Docs MCP server carry readOnlyHint (16 of 20). Creating a bill needs eleven required fields. The only server SDK is `@airwallex/node-sdk` in beta, and the CLI has a dry-run flag (7 of 15). - Security & auth 84: Scoped API keys grant Read or Write per resource at organisation or account level, can be edited, regenerated, duplicated and deleted, and can be tied to IP ranges. Keys travel only in headers and exchange for a bearer token that lasts 30 minutes. Partner apps, the CLI and the MCP server use OAuth with 64 scopes (30). Read is separate from Write, the AgentOS tools don't start transfers, conversions or payouts by default, CLI writes ask for confirmation, and cards take limits, merchant category rules and remote authorisation. Unrestricted admin keys still exist, and API writes have no confirmation step (17 of 20). The AgentOS page warns about indirect prompt injection from documents and web pages, tool poisoning by other MCP servers and auto-approve modes. Expense descriptions, comments and merchant names are untrusted text (11 of 15). `GET /api/v1/audit_log/security_audit_logs` records logins, user management and key changes for selected accounts only, key changes trigger an email, and no per-call log was found (8 of 15). security.txt with contacts, a bug bounty that has been invite-only since 13 July 2021, SOC 1 and SOC 2 Type 2, ISO 27001 and PCI DSS Level 1 on the trust centre (18 of 20). - Payments & pricing 25: Read with the hosted rubric. No x402, MPP or L402 was found in the docs or on the pricing page (0). US plan prices are public, Explore at $0 with up to 10 free Spend users and Grow at $12 per active Spend user a month. The pricing page lists direct Spend API integration with an ERP under Accelerate, which is priced on request, and sends platform API use to sales, so half the plan-pricing credit (5 of 20). A sandbox account opens at once from a form asking for email, name, country and password, with no payment card and no contract, and the Explore plan is free (20). A person has to sign up in a browser and create a key in the web app or complete an OAuth sign-in. The Docs MCP server needs no account but answers docs questions only (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 66: The airwallex-marketplace repository, which carries the AgentOS and developer plugins, tagged v0.2.11 on 30 September 2026. The newest API version is `2026-08-21` (30). Eight marketplace tags between 6 August and 30 September, and API versions on 17 July and 21 August (20). Closed service. The changelog lists backwards-incompatible changes only, support is a help centre ticket or developer.support@airwallex.com, and the marketplace repository shows one open issue. Response times couldn't be observed (9 of 15). `@airwallex/node-sdk` was last published on 31 December 2025 as 2.1.0-beta.5 and is the only server SDK. The official MCP registry has no Airwallex entry of the vendor's own, only a third party's (io.github.codespar/mcp-airwallex) (4 of 15). The marketplace repository has no CI workflow, and the CLI is a binary installed by script whose version we couldn't read (3 of 10). - Transparency & trust 78: Closed service with terms at stable URLs. The API terms are dated 20 June 2025, the service agreement took effect on 1 January 2026 and the Spend Management Terms are dated 6 December 2023. The plugin repository is Apache-2.0 and the Node SDK is MIT (16 of 30). The privacy policy describes retention by purpose and legal duty without fixed periods, names the countries where data is hosted, and says personal data may be processed to develop or improve Airwallex's AI and machine learning. A DPA is published as part of the customer agreement (18 of 30). Breaking changes ship as dated versions and an account stays on its version until it migrates. The API terms require a developer to implement an update within six months at most, give 30 days' notice of adverse changes to the terms, and let Airwallex discontinue services at its discretion. No retirement dates for old versions were found (12 of 20). A public list of processors and sub-processors, updated 7 October 2026, gives each one's category, role and region (18 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/airwallex.md (JSON https://www.anchorterminal.com/fixes/airwallex.json) ### What we couldn't check - unchecked: the production MCP server's tool list, input schemas and annotations at https://mcp.airwallex.com/mcp, which need an OAuth sign-in to an Airwallex account. `toolCount` is left empty - unchecked: the CLI's version and release history. static.airwallex.com didn't answer our requests for the install script - unchecked: whether a sandbox or Explore account can call the Spend endpoints. The pricing page lists direct Spend API integration under Accelerate, and the docs state no plan requirement - unchecked: whether Issuing API access needs approval on every account. The CLI guide says card and Issuing commands may return 403 until support enables access, and the service agreement says API access must first be approved - unchecked: whether 429 responses carry a Retry-After header. None is documented - unchecked: whether an OpenAPI spec is published somewhere we didn't look. None is linked from llms.txt or the API introduction - unchecked: the date of the US privacy policy, which shows no last-updated line in the text we read. The global policy is dated 26 February 2026 - unchecked: whether an SLA exists in Accelerate or platform contracts. None was found in the service agreement or the API terms - The lead described a plain REST API with a sandbox. It left out that the Spend endpoints are beta and that the vendor also runs a CLI and three MCP servers - The docs carry two pages titled Instructions for AI agents and an install prompt that asks an assistant to fetch and follow the AgentOS guide. We recorded them as facts and didn't act on them - The pricing page is the US one in USD. Plans and fees differ by region, and the terms and privacy policy cited are those of Airwallex US, LLC - security.txt gives its expiry as `2030-06-30 T00:00:00.000Z` with a space inside the timestamp, which isn't the RFC 9116 format. We recorded it as valid because the contacts and a future expiry are present ### Sources - docs index for agents: (seen 2026-10-08) - how the Spend API works: (seen 2026-10-08) - card expenses guide: (seen 2026-10-08) - bills guide: (seen 2026-10-08) - Spend error codes: (seen 2026-10-08) - list expenses reference, marked beta: (seen 2026-10-08) - create bill reference: (seen 2026-10-08) - create card reference: (seen 2026-10-08) - card authorisation controls: (seen 2026-10-08) - rate limits: (seen 2026-10-08) - API key management: (seen 2026-10-08) - API key scopes: (seen 2026-10-08) - API key practices and IP allowlisting: (seen 2026-10-08) - OAuth scopes: (seen 2026-10-08) - security audit logs: (seen 2026-10-08) - sandbox overview: (seen 2026-10-08) - API versioning: (seen 2026-10-08) - API changelog: (seen 2026-10-08) - API errors: (seen 2026-10-08) - AgentOS and the production MCP server: (seen 2026-10-08) - developer and docs MCP servers: (seen 2026-10-08) - CLI guide: (seen 2026-10-08) - server-side SDK guide: (seen 2026-10-08) - webhooks overview: (seen 2026-10-08) - MCP protected resource metadata, 35 scopes: (seen 2026-10-08) - Docs MCP server, tools/list: (seen 2026-10-08) - plugin repository, tags and licence: (seen 2026-10-08) - Node SDK on npm: (seen 2026-10-08) - status incidents: (seen 2026-10-08) - status components: (seen 2026-10-08) - US pricing: (seen 2026-10-08) - API terms: (seen 2026-10-08) - service agreement: (seen 2026-10-08) - Spend Management Terms: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - processors and sub-processors: (seen 2026-10-08) - trust centre: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - bug bounty rules: (seen 2026-10-08) - official MCP registry search: (seen 2026-10-08) - RDAP for airwallex.com: (seen 2026-10-08) ## Who's behind it (provenance 92/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Airwallex US, LLC | 20/20 | | Domain age | airwallex.com, registered 2015-11-08 (10 years) | 15/15 | | Endpoint on the vendor's domain | api.airwallex.com | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 | | Privacy policy | read, states 7 of the 8 things a reader expects, and has 1 clause that costs points | 7.3/10 | | Status page | status.airwallex.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The terms and privacy policy cited are the US ones. The US privacy policy names Airwallex US, LLC among the entities responsible, and the site footer gives Airwallex US, LLC (NMLS #1928093) as the licensed money transmitter. Other regions have their own entities and documents. The API terms (API Developer Terms and Conditions) are dated 20 June 2025. The service agreement was last updated on 2 December 2025 and took effect on 1 January 2026. The Spend Management Terms are dated 6 December 2023. The API answers at api.airwallex.com and api.sandbox.airwallex.com, and the MCP servers at mcp.airwallex.com and mcp.sandbox.airwallex.com. www.airwallex.com/.well-known/security.txt lists bugbounty@airwallex.com and security@airwallex.com and an expiry of 30 June 2030. The timestamp has a space inside it, which isn't the RFC 9116 format. The US privacy policy shows no last-updated line in the text we read. The global policy at /terms/privacy-policy is dated 26 February 2026. RDAP for airwallex.com gives a registration date of 2015-11-08. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.airwallex.com/us/terms/application-programming-interface-terms), read 2026-10-08, dated 2025-06-20, states 6 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "(d) download, scrape, post or transmit any part of the other Party’s website or content;" - To know. Restricts benchmarking or competitive use (costs points). "(j) access the other Party’s platform for competitive purposes or publicly disseminate performance information or analysis relating to the other Party’s APIs." - To know. Says access can be ended without notice or for any reason. "Airwallex may terminate these API Terms for any reason upon providing 10 days notice to the Developer." - Gives the date it was last updated. Last updated 2025-06-20. - States a limit on its liability. Capped at USD $1,000. - Says how changes to the terms are announced. Gives 10 days of notice before a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Airwallex's liability to the developer under the API Terms is capped at 1,000 US dollars or the local currency equivalent. "Airwallex’s liability to Developer in relation to these API Terms, whether in contract, negligence, liability, tort or other legal or equitable theory, for losses or damages shall not exceed USD $1,000 (or local currency equivalent)." - Also in the text (2026-10-08). Airwallex may publish the developer's marks on its websites, in press releases and in promotional materials without prior consent. "Airwallex may also publish the Developer’s Marks (with or without a link to the Developer’s website or content) on our websites, in press releases, and in promotional materials without your prior consent." - Also in the text (2026-10-08). The developer must implement any update within the time Airwallex specifies, and no later than six months after Airwallex issues it. "The Developer agrees to implement any Update within a reasonable time, as specified by Airwallex, and in any case no longer than six (6) months of Airwallex issuing the Update." **Privacy policy** (https://www.airwallex.com/us/terms/privacy-policy-airwallex), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "We may also process personal data to develop or improve our AI or ML technologies as described in section 4 of this Policy in accordance with applicable law and internal standards." - Not found in the text. Gives the date it was last updated. - Gives a privacy contact. Names a data protection officer. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). Airwallex may keep personal information after an account is closed or after a deletion request. "We may retain your personal information even after you close your Airwallex account or request deletion of your personal information." ## Live (updated 2026-10-09 02:45 UTC) - Right now: up, HTTP 404, 53 ms, checked 2026-10-09 02:42 UTC (get on `https://api.airwallex.com`) - Uptime 24h 100.0% (79 probes) · 30 days 100.0% (79 probes) · p50 44 ms · p95 73 ms - Vendor status page: none, All Systems Operational - Always current: https://www.anchorterminal.com/api/v1/live/airwallex.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Explore plan | free | per seat per month | Up to 10 free Spend users. No separate API fee is published | | Grow plan | $12 | per seat per month | Per active Spend user, up to 250. Accelerate, which lists direct Spend API integration, is priced on request | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Scoped API keys grant Read or Write per resource, can be limited to listed IP ranges, and exchange for bearer tokens that last 30 minutes - A sandbox account opens at once from a signup form, with the full API except Connected Accounts and simulation endpoints for card transactions - Rate limits are published with numbers, 100 requests a second per account and 20 per endpoint in production, with backoff guidance for 429 - Create calls such as `POST /api/v1/issuing/cards/create` and `POST /api/v1/spend/bills/create` require a `request_id`, so a retried request isn't applied twice - status.airwallex.com has separate Spend, Issuing, API Gateway and Sandbox components, and none was named in an incident between 27 April and 8 October 2026 ## Weaknesses - No OpenAPI spec was found. The reference is a Markdown page per endpoint, and the CLI prints one endpoint's schema at a time - Each Spend endpoint we read (expenses, vendors, bills, purchase orders) is marked beta, and the pricing page lists direct Spend API integration under the custom-priced Accelerate plan - The Spend API reads expenses and sets sync status. No endpoint was found to attach a receipt, code a card expense or approve one - The only server SDK is `@airwallex/node-sdk`, still in beta and last published on 31 December 2025 - No SLA was found, and the Security Audit Logs API is open to selected accounts only and covers logins, user changes and key changes, not API calls ## Before you call it (notes for agents) 1. Exchange `x-client-id` and `x-api-key` at `POST /api/v1/authentication/login` once, then reuse the bearer token for 30 minutes. The login endpoint allows 100 requests a minute per key 2. Create Spend keys with organisation-level permissions. With a key linked to several accounts, send `x-login-as` at login or the token carries no account permissions 3. Send a fresh UUID as `request_id` on every create call and reuse the same value when retrying after a timeout 4. Expect two pagination styles. Spend and card transaction events use the `page` bookmark with `page_after` and `page_before`. Cards and legacy transactions use `page_num` and `has_more` 5. Card and expense lists default to the last 30 days. Pass both created-at bounds to read further back, and fetch a card singly to see its `authorization_controls` ## Connect Install: ```bash curl -fsSL https://static.airwallex.com/developer-tools/airwallex-cli/install.sh | sh ``` First request: ```bash curl -X POST https://api.sandbox.airwallex.com/api/v1/authentication/login \ -H 'Content-Type: application/json' \ -H 'x-api-key: {{YOUR_API_KEY}}' \ -H 'x-client-id: {{YOUR_CLIENT_ID}}' ``` Claude Code: ```bash claude mcp add-json airwallex '{ "type": "http", "url": "https://mcp.airwallex.com/mcp" }' ``` MCP client configuration: ```json { "mcpServers": { "airwallex": { "type": "http", "url": "https://mcp.airwallex.com/mcp" } } } ``` Through letme (picks today, calling later): https://letme.dev/airwallex (letme picks it for spend.bills, the top-graded tool for the job, letme picks it for spend.cards, the top-graded tool for the job, letme picks it for spend.expenses, the top-graded tool for the job, letme picks it for spend.procurement, the top-graded tool for the job, letme picks it for spend.transactions, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Spendesk API + MCP | B | 62.3 | 342 | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | no | https://www.anchorterminal.com/tools/spendesk.md | | Ramp | C | 57.3 | 478 | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | no | https://www.anchorterminal.com/tools/ramp.md | | BILL | C | 60.9 | 380 | spend.transactions, spend.expenses, spend.cards, spend.bills | no | https://www.anchorterminal.com/tools/bill.md | | Brex | C | 60.7 | 391 | spend.transactions, spend.expenses, spend.cards, spend.bills | no | https://www.anchorterminal.com/tools/brex.md | | Mercury API | B | 63.8 | 293 | spend.transactions, spend.cards, spend.expenses | no | https://www.anchorterminal.com/tools/mercury.md | | Pleo API + MCP | B | 62.9 | 325 | spend.transactions, spend.expenses, spend.bills | no | https://www.anchorterminal.com/tools/pleo.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The four Spend reference pages we read (list expenses, list vendors, create bill, create purchase order) are headed Status beta (source: ) - The Spend API is built for ERP sync. It reads card expenses and reimbursements and sets their sync status, and creates vendors, purchase orders and bills (source: ) - The AgentOS MCP server at https://mcp.airwallex.com/mcp acts on a production account over OAuth, and Airwallex says its tools don't start transfers, conversions or payouts by default (source: ) - Scoped API keys grant Read or Write per resource and can be restricted to listed IP ranges (source: ) - Production limits are 100 requests a second per account, 20 per endpoint and 50 concurrent requests (source: ) - The US pricing page lists direct Spend API integration with an ERP under the Accelerate plan, which is priced on request (source: ) - The docs carry two pages of instructions addressed to AI agents and an install prompt that asks an assistant to fetch and follow the AgentOS guide (source: ) - The privacy policy says personal data may be processed to develop or improve Airwallex's AI and machine learning technologies (source: ) ## Compare - [Airwallex Spend and Issuing vs BILL](https://www.anchorterminal.com/compare/airwallex-vs-bill.md): B 68.3 vs C 60.9 - [Airwallex Spend and Issuing vs Brex](https://www.anchorterminal.com/compare/airwallex-vs-brex.md): B 68.3 vs C 60.7 - [Airwallex Spend and Issuing vs Expensify](https://www.anchorterminal.com/compare/airwallex-vs-expensify.md): B 68.3 vs E 41.1 - [Airwallex Spend and Issuing vs Mercury API](https://www.anchorterminal.com/compare/airwallex-vs-mercury.md): B 68.3 vs B 63.8 - [Airwallex Spend and Issuing vs Pleo API + MCP](https://www.anchorterminal.com/compare/airwallex-vs-pleo.md): B 68.3 vs B 62.9 - [Airwallex Spend and Issuing vs Ramp](https://www.anchorterminal.com/compare/airwallex-vs-ramp.md): B 68.3 vs C 57.3 - [Airwallex Spend and Issuing vs Spendesk API + MCP](https://www.anchorterminal.com/compare/airwallex-vs-spendesk.md): B 68.3 vs B 62.3 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on airwallex.com or one of its subdomains, or the README of github.com/airwallex/airwallex-marketplace. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "airwallex", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Airwallex Spend and Issuing on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Airwallex Spend and Issuing on Anchor Terminal](https://www.anchorterminal.com/badges/airwallex.svg)](https://www.anchorterminal.com/tools/airwallex) ``` Plain link: ```html Airwallex Spend and Issuing on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Airwallex Spend and Issuing is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/airwallex-dark.png - Light: https://www.anchorterminal.com/assets/share/airwallex-light.png