# Airwallex Spend and Issuing (slim) > Airwallex is a multi-currency business account with company cards, expense management and bill pay. Its REST API issues and controls cards, reads card transactions and expenses, and creates vendors, purchase orders and bills. A CLI and MCP server use OAuth. - Full: https://www.anchorterminal.com/tools/airwallex.md (~9,200 tokens) · this version ~1,980 tokens · JSON https://www.anchorterminal.com/tools/airwallex.json · canonical https://www.anchorterminal.com/tools/airwallex - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 68.3/100 · rank #187 of 722 · #1 in Spend management & procurement · not agent-ready · confidence medium** Assessment: Scoped API keys split read from write per resource, tokens last 30 minutes, and the sandbox opens at once with no contract. No OpenAPI spec was found, every Spend endpoint read is marked beta, the pricing page lists direct Spend API integration under the custom-priced Accelerate plan, and no SLA was found. ## Facts - Kind: HTTP API · vendor: Airwallex · category: Spend management & procurement · legal entity: Airwallex US, LLC · provenance 92/100 - Endpoint: `https://api.airwallex.com` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under Airwallex's service agreement and API terms. The plugin and skills repository is Apache-2.0 and `@airwallex/node-sdk` is MIT - Probe metrics: not measured yet (probes haven't run) - API: REST at https://api.airwallex.com (sandbox https://api.sandbox.airwallex.com), dated versions with `2026-08-21` the latest. The scope catalogue links 34 Issuing and 24 Spend reference pages. No OpenAPI spec found - Spend endpoints: Card expenses and reimbursement reports (list, get, set sync status, mark paid externally), vendors, purchase orders and bills (create, list, get, set sync status). Each page we read is marked beta - Issuing endpoints: Cardholders, cards (create, activate, update, sensitive details, remaining limits), authorisations, card transaction events, card transactions and lifecycles, disputes, digital wallet tokens and issuing config - MCP servers: AgentOS MCP at https://mcp.airwallex.com/mcp (production, OAuth, 35 scopes advertised). Developer MCP at https://mcp.sandbox.airwallex.com/developer (sandbox, OAuth). Docs MCP at https://mcp.sandbox.airwallex.com/docs (no sign-in, 2 read-only tools) - CLI: `airwallex`, macOS and Linux, installed by script, OAuth sign-in, sandbox by default and `--prod` for production. `--dry-run`, `--compact`, `--api-schema-only`, and confirmation on writes unless `--confirm` is passed. Telemetry is on by default with an opt-out - Credentials: Scoped API keys (Read or Write per resource, optional IP allowlist) or admin keys, exchanged for a 30-minute bearer token. OAuth 2.0 with 64 scopes for partner apps, the CLI and MCP - Rate limits: Production 100 requests a second per account, 20 per endpoint, 50 concurrent. Sandbox 20, 10 and 10. Login endpoint 100 a minute per key - Pagination: `page` bookmark with `page_after` and `page_before` on Spend and card transaction events. `page_num` and `has_more` on cards and legacy transactions. `page_size` 1 to 100 - Errors: JSON with `code`, `message`, `source` and `details`. 429 returns `too_many_requests` with a `trace_id` - Card controls: Single or multiple use, allowed currencies, merchant category codes, active period, transaction limits by amount and interval, blocked transaction types, alert thresholds and remote authorisation - Webhooks: Signed with HMAC over timestamp and body, retried with exponential backoff for about three days. Spend events for bills, expenses and reimbursements - SDK: `@airwallex/node-sdk` 2.1.0-beta.5 (31 December 2025), MIT, Node only - Certifications: SOC 1 Type 2, SOC 2 Type 2, ISO/IEC 27001 and PCI DSS Level 1 per security.airwallex.com. Bug bounty by invitation since 13 July 2021 - Status: status.airwallex.com on Statuspage, 21 components including Spend, Issuing, API Gateway and Sandbox - Sub-processors: Public list updated 7 October 2026 with category, role and region. Google Cloud Platform is the primary host - Prices: Explore plan free per seat per month; Grow plan $12 per seat per month - Scores: Reliability 77, Performance pending, Schema & documentation 69, Agent ergonomics 69, Security & auth 84, Payments & pricing 25, Task success pending, Maintenance & community 66, Transparency & trust 78 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the REST API for Issuing and Spend. · Schema & documentation, No public OpenAPI spec was found. · Agent ergonomics, `page_size` runs from 1 to 100 and defaults to 100 on Spend lists. · Security & auth, Scoped API keys grant Read or Write per resource at organisation or account level, can be edited, regenerated, duplicated and deleted, and c… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The airwallex-marketplace repository, which carries the AgentOS and developer plugins, tagged v0.2.11 on 30 September 2026. The newest API v… · Transparency & trust, Closed service with terms at stable URLs. - Sources: 41, open questions: 12, both in the full twin - Capabilities: spend.transactions, spend.cards, spend.expenses, spend.bills, spend.procurement - JSON: https://www.anchorterminal.com/api/v1/tools/airwallex.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/airwallex.svg` or a link to https://www.anchorterminal.com/tools/airwallex from a page on airwallex.com or one of its subdomains, or the README of github.com/airwallex/airwallex-marketplace, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Exchange `x-client-id` and `x-api-key` at `POST /api/v1/authentication/login` once, then reuse the bearer token for 30 minutes. The login endpoint allows 100 requests a minute per key 2. Create Spend keys with organisation-level permissions. With a key linked to several accounts, send `x-login-as` at login or the token carries no account permissions 3. Send a fresh UUID as `request_id` on every create call and reuse the same value when retrying after a timeout 4. Expect two pagination styles. Spend and card transaction events use the `page` bookmark with `page_after` and `page_before`. Cards and legacy transactions use `page_num` and `has_more` 5. Card and expense lists default to the last 30 days. Pass both created-at bounds to read further back, and fetch a card singly to see its `authorization_controls` ## Connect ```bash curl -fsSL https://static.airwallex.com/developer-tools/airwallex-cli/install.sh | sh ``` ```bash curl -X POST https://api.sandbox.airwallex.com/api/v1/authentication/login \ -H 'Content-Type: application/json' \ -H 'x-api-key: {{YOUR_API_KEY}}' \ -H 'x-client-id: {{YOUR_CLIENT_ID}}' ``` ```bash claude mcp add-json airwallex '{ "type": "http", "url": "https://mcp.airwallex.com/mcp" }' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/airwallex ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Spendesk API + MCP | B | 62.3 | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | https://www.anchorterminal.com/tools/spendesk.min.md | | Ramp | C | 57.3 | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | https://www.anchorterminal.com/tools/ramp.min.md | | BILL | C | 60.9 | spend.transactions, spend.expenses, spend.cards, spend.bills | https://www.anchorterminal.com/tools/bill.min.md | | Brex | C | 60.7 | spend.transactions, spend.expenses, spend.cards, spend.bills | https://www.anchorterminal.com/tools/brex.min.md | | Mercury API | B | 63.8 | spend.transactions, spend.cards, spend.expenses | https://www.anchorterminal.com/tools/mercury.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)