# Brex (slim) > Brex is a spend platform with corporate cards, expense management, bill pay, travel and business accounts. Its REST Developer API reads and writes cards, expenses, spend limits, vendors and transfers, and a hosted MCP server is in beta. - Full: https://www.anchorterminal.com/tools/brex.md (~7,750 tokens) · this version ~1,780 tokens · JSON https://www.anchorterminal.com/tools/brex.json · canonical https://www.anchorterminal.com/tools/brex - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 60.7/100 · rank #345 of 629 · #3 in Spend management & procurement · not agent-ready · confidence medium** Assessment: User tokens carry per-resource scopes with read-only variants, every POST and PUT accepts an `Idempotency-Key`, and ten OpenAPI specs are public. The Expenses API changes only an expense's memo, there is no customer sandbox or official SDK, and the status page logs API errors lasting over four hours on 4 August 2026. ## Facts - Kind: HTTP API · vendor: Brex LLC · category: Spend management & procurement · legal entity: Brex LLC · provenance 86/100 - Endpoint: `https://api.brex.com` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary service under the Brex Platform Agreement and the Brex Access Agreement - Probe metrics: not measured yet (probes haven't run) - APIs: Team (35 operations), Budgets (17), Webhooks (13), Payments (10), Fields (10, beta), Transactions (8), Expenses (7), Accounting (6, alpha), Onboarding (5), Travel (4), all OpenAPI 3 at https://developer.brex.com/_bundle/openapi/_api.yaml and served from https://api.brex.com - Write access: Create, update, lock, unlock and terminate cards. Create and update spend limits and budgets. Create vendors and ACH, wire, cheque and book transfers. Upload and match receipts. Expense updates accept `memo` only - MCP server: Hosted at https://api.brex.com/mcp, beta, 43 tools, mostly reads plus memo, receipt, attendee and limit-assignment updates on expenses. An admin accepts the Developer API agreement and enables the Brex in AI assistants beta first - Credentials: User token (prefix `bxt_`) created by an account admin or card admin with chosen scopes, shown once, revocable, expires after 90 days unused. Partners use OAuth 2.0 authorisation code (PKCE optional) with one-hour access tokens. MCP uses OAuth with dynamic client registration or a user token - Scopes: 41 documented scopes across nine APIs, most split into a view scope and a view-and-manage scope, with `cards.pan` separate for card numbers - Rate limits: 1,000 requests in 60 seconds per client ID and account. 1,000 transfers, 100 international wires and 5,000 cards created in 24 hours - Pagination: Cursor and limit on list endpoints, default 100. The pagination guide gives a maximum of 1,000, while List expenses was cut to 100 in February 2026 - Errors: JSON body with `type`, `message` and optional `code`. `X-Brex-Trace-Id` on responses. The docs recommend exponential backoff with jitter on 429 - Sandbox: None for customers. Staging at https://api-staging.brex.com is for approved partners, with data that can be purged at any time - Webhooks: HMAC SHA-256 signatures in `Webhook-Signature`, signing secrets from GET /v1/webhooks/secrets with two keys during rotation, 20 event types in the spec - Launch stages: Alpha (at least 15 days' notice of breaking changes), beta (at least 60 days, opt-in) and general availability (new versions with deprecation timelines) - Certifications: SOC 1 Type II, SOC 2 Type II and PCI DSS per brex.com/trust. Vulnerability reports go through a form run with Bugcrowd - Status: status.brex.com on Atlassian Statuspage, 12 components among them Partner API, Authentication, Spend Management and Bill Pay - Prices: Essentials plan free per seat per month; Premium plan $12 per seat per month - Scores: Reliability 60, Performance pending, Schema & documentation 80, Agent ergonomics 70, Security & auth 72, Payments & pricing 25, Task success pending, Maintenance & community 66, Transparency & trust 67 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the REST Developer API, the surface an outside agent calls with a token. · Schema & documentation, Ten public OpenAPI 3 specs, 115 operations, each downloadable from the reference page (25). · Agent ergonomics, `limit` sizes a page, related objects arrive only through `expand[]`, and custom fields only with `load_custom_fields`. · Security & auth, User tokens with scopes chosen at creation, shown once, revocable in the dashboard and expired after 90 days unused. · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The changelog's latest entry is October 2026 (30). · Transparency & trust, Closed service with terms published at stable URLs and as Markdown, the Platform Agreement and the Brex Access Agreement for API use (15 of… - Sources: 28, open questions: 10, both in the full twin - Capabilities: spend.transactions, spend.expenses, spend.cards, spend.bills - JSON: https://www.anchorterminal.com/api/v1/tools/brex.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/brex.svg` or a link to https://www.anchorterminal.com/tools/brex from a page on brex.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Ask an account admin or card admin for a user token with only the scopes the task needs, and prefer the `.readonly` variants. A token unused for 90 days expires. 2. Send a stored `Idempotency-Key` on every POST and PUT. Create transfer and Create card reject requests without one. 3. Only settled transactions are returned. Poll card and cash transactions with `posted_at_start` and a lookback of at least one day. 4. Keep under 1,000 requests in 60 seconds per client and account, and back off exponentially with jitter on 429. 5. Send only ASCII in free-text fields, and quote the `X-Brex-Trace-Id` response header when reporting an error. ## Connect ```bash curl -i -X GET \ https://api.brex.com/v2/users/me \ -H 'Authorization: Bearer ' ``` ```bash claude mcp add --transport http brex https://api.brex.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/brex ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Spendesk API + MCP | B | 62.3 | spend.transactions, spend.expenses, spend.cards, spend.bills | https://www.anchorterminal.com/tools/spendesk.min.md | | Ramp | C | 57.3 | spend.transactions, spend.expenses, spend.cards, spend.bills | https://www.anchorterminal.com/tools/ramp.min.md | | Pleo API + MCP | B | 62.9 | spend.transactions, spend.expenses, spend.bills | https://www.anchorterminal.com/tools/pleo.min.md | | Expensify | E | 41.1 | spend.transactions, spend.expenses | https://www.anchorterminal.com/tools/expensify.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)