# BILL (slim) > BILL is a US financial operations platform for accounts payable, accounts receivable and company card spend. Its v3 REST API reads and writes bills, payments, invoices, budgets, cards, transactions and reimbursements, and an MCP server in beta gives read-only access. - Full: https://www.anchorterminal.com/tools/bill.md (~8,400 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/bill.json · canonical https://www.anchorterminal.com/tools/bill - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 60.9/100 · rank #380 of 722 · #5 in Spend management & procurement · not agent-ready · confidence medium** Assessment: A public OpenAPI 3.0.1 spec covers 326 operations, a self-serve sandbox moves no money, and payments need a session trusted by multi-factor authentication. The AP and AR API signs in with a user's password and has no scopes, no idempotency key protects payment calls, and no official SDK was found. ## Facts - Kind: HTTP API · vendor: BILL Holdings, Inc. · category: Spend management & procurement · legal entity: Bill.com, LLC · provenance 88/100 - Endpoint: `https://gateway.prod.bill.com/connect` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under the BILL Developer Terms and the BILL General Terms of Service - Probe metrics: not measured yet (probes haven't run) - API: BILL v3 REST API at https://gateway.prod.bill.com/connect (sandbox https://gateway.stage.bill.com/connect). 314 operations in `bill-v3-api.json`, 203 of them writes, across AP, AR, BILL Network, organisation, partner and Spend & Expense - Webhooks API: 12 operations at https://gateway.prod.bill.com/connect-events. Notifications are signed with HMAC-SHA256 in `x-bill-sha-signature`, time out after 10 seconds and are tried five times. Up to 10 subscriptions per organisation - MCP server: Beta, read-only, at https://gateway.prod.bill.com/ai-mcp-server/v1 (sandbox https://gateway.stage.bill.com/ai-mcp-server/v1). OAuth through auth.bill.com with PKCE. One US organisation per connection. The tool list isn't published - Docs for agents: llms.txt, a Markdown copy of each page at the page URL plus `.md`, and a docs MCP server at https://developer.bill.com/mcp - Credentials: AP and AR, `sessionId` and `devKey` headers after `POST /v3/login` with username and password. Spend & Expense, `apiToken` header. Partners, `appKey` after `POST /v3/partner/login`. Sync tokens for app partners, with no payment access - Rate limits: 20,000 requests an hour per developer key, three concurrent per key per organisation, 200 logins an hour, five text messages a minute, and 60 Spend & Expense calls a minute per token - Pagination: `max` up to 100 on AP and AR lists and up to 50 on Spend & Expense lists (default 20), with `nextPage` and `prevPage` cursors, `filters` with nine operators and `sort` - Errors: A JSON array of objects with `timestamp`, `code` (BDC_ prefix), `severity`, `category` and `message`. BILL says there are over 500 codes, listed by the v2 `Errors.json` call - Idempotency: `X-Idempotent-Key` on creating a webhook subscription and a security key only. None on the v3 API's write operations - Sandbox: Self-serve sign-up form, no subscription fee, no real money movement, no accounting system connections. BILL says it deploys there at least twice a day with no SLA - Audit: `GET /v3/reports/audit-trail/vendor/{vendorId}` lists create and edit records for a vendor with the user and source. No audit endpoint for other objects was found - Certifications: Annual SOC 1 and SOC 2 Type II audits per bill.com/security, card payments through a PCI certified vendor, and a vulnerability disclosure programme on HackerOne - Status: www.billcomstatus.com on Statuspage, 15 components including API Servers, Virtual Card and Multi-Factor Authentication - Elements: BILL Elements are embeddable UI widgets for onboarding, MFA and AP payments, for partners building BILL into their own application - Prices: Spend & Expense free per seat per month; AP and AR Essentials $49 per seat per month; AP and AR Team $65 per seat per month; AP and AR Corporate $89 per seat per month - Scores: Reliability 81, Performance pending, Schema & documentation 83, Agent ergonomics 60, Security & auth 56, Payments & pricing 25, Task success pending, Maintenance & community 32, Transparency & trust 66 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the v3 REST API. · Schema & documentation, Two public OpenAPI 3.0.1 files, `bill-v3-api.json` with 314 operations and `connect-events-api.json` with 12 (25). · Agent ergonomics, `max` sizes a page, with a default of 20 and a ceiling of 100 on AP and AR lists and 50 on Spend & Expense lists. · Security & auth, The AP and AR API signs in with a user's username and password plus a developer key, sent in the request body, and the session carries that… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The changelog's latest dated entry is 21 May 2026, 140 days before the check. · Transparency & trust, Closed service with terms at stable URLs, the Developer Terms (effective 3 March 2026) and the General Terms of Service (last updated 10 Feb… - Sources: 32, open questions: 10, both in the full twin - Capabilities: spend.transactions, spend.expenses, spend.cards, spend.bills, accounting.invoices - JSON: https://www.anchorterminal.com/api/v1/tools/bill.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/bill.svg` or a link to https://www.anchorterminal.com/tools/bill from a page on bill.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Sign in with `POST /v3/login` and send `sessionId` and `devKey` as headers on every AP and AR call. The session expires after 35 minutes idle 2. Send the `apiToken` header alone on `/v3/spend/` paths. Spend & Expense calls need no login and are limited to 60 a minute per token 3. Complete the MFA challenge before `POST /v3/payments`. An untrusted session fails with `BDC_1361` 4. Read back payments before retrying a failed `POST /v3/payments`. No idempotency key is accepted, so a blind retry can pay twice 5. Keep to three concurrent requests per developer key per organisation and 20,000 an hour. After `BDC_1144`, wait for the next hour ## Connect ```bash curl --request POST \ --url 'https://gateway.stage.bill.com/connect/v3/login' \ --header 'content-type: application/json' \ --data '{ "username": "{username}", "password": "{password}", "organizationId": "{organization_id}", "devKey": "{developer_key}" }' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/bill ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Airwallex Spend and Issuing | B | 68.3 | spend.transactions, spend.cards, spend.expenses, spend.bills | https://www.anchorterminal.com/tools/airwallex.min.md | | Spendesk API + MCP | B | 62.3 | spend.transactions, spend.expenses, spend.cards, spend.bills | https://www.anchorterminal.com/tools/spendesk.min.md | | Brex | C | 60.7 | spend.transactions, spend.expenses, spend.cards, spend.bills | https://www.anchorterminal.com/tools/brex.min.md | | Ramp | C | 57.3 | spend.transactions, spend.expenses, spend.cards, spend.bills | https://www.anchorterminal.com/tools/ramp.min.md | | Mercury API | B | 63.8 | spend.transactions, spend.cards, spend.expenses | https://www.anchorterminal.com/tools/mercury.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)