# Payhawk API + MCP > Spend management platform from Payhawk Limited in London, covering company cards, expenses, bills, purchase orders and travel. Outside agents reach it through a REST Developer API with read-only or full-access keys, and a hosted MCP server. - Canonical: https://www.anchorterminal.com/tools/payhawk - Markdown: https://www.anchorterminal.com/tools/payhawk.md (~7,800 tokens) - Slim: https://www.anchorterminal.com/tools/payhawk.min.md (~1,880 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/payhawk.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade C · 57.1/100 · rank #561 of 842 · #8 in Spend management & procurement · not agent-ready · confidence medium** ## Assessment The Developer API has a public OpenAPI 3.1 definition with 179 operations, read-only or full-access keys and a published limit of 15 requests a second. It needs a Payhawk customer account, no official SDK or API changelog was found, and the 82-tool MCP server is added by hand because it is not yet in the assistant directories. ## Facts | Field | Value | | --- | --- | | Vendor | Payhawk Limited (https://payhawk.com) | | Kind | HTTP API | | Category | Spend management & procurement (https://www.anchorterminal.com/categories/spend-management) | | Transport | HTTP | | Endpoint | `https://api.payhawk.com` | | Auth | OAuth or key · Access needs a Payhawk customer account. An Administrator, an IT Administrator or a user with a custom role creates an API key in the portal under Settings, Integrations, choosing read-only or full access, and can regenerate it. The key goes in the `X-Payhawk-ApiKey` header or as a Bearer token. Two system-generated keys per account cannot be deleted by users. Group-level keys reach the group endpoints. If the key is not active, the API page says to write to partners@payhawk.com. The MCP server accepts OAuth 2 authorisation code with PKCE, where each user signs in with a Payhawk login and the assistant acts with that user's role. | | Pricing | Paid (Paid) · Sold by quote per module (Travel, Cards and Expenses, Accounts Payable, Procurement) on annual or multi-year contracts, with unit-based charges for extra cards, reimbursements, purchase orders and invoices. The one published price is the Growth programme at 149 pounds a month for single-entity firms in the UK or EEA with fewer than 20 employees, with an optional 7-day trial for eligible customers. The API page says the API is free for all Payhawk accounts, and the pricing page lists Developer API access and the MCP server in the modules. A development sandbox is requested through a form on the API page (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the OpenAPI definition, the help centre or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under Payhawk's general terms and conditions | | Tools exposed | 82 | | Docs | https://developers.payhawk.com | | llms.txt | https://payhawk.com/llms.txt | | Last release | 2026-10-08 | | API | REST, OpenAPI 3.1, version v3, 105 paths and 179 operations at https://api.payhawk.com/api/v3. 75 GET, 38 POST, 28 PATCH, 24 DELETE, 14 PUT | | Coverage | Expenses and files, expense reports, cards (issue, update, change status), fund accounts, deposits and bank statements, suppliers, purchase orders and goods received notes, spend policies, users, teams, custom fields, expense categories, tax rates, account codes and webhooks, at account and group level | | MCP server | Hosted at https://mcp.payhawk.com/mcp. 82 tools in the public reference, read and write, filtered by role. Works with Claude, ChatGPT and Codex as a custom connector. Launched with the Fall '26 edition in September 2026 | | Credentials | API key with read-only or full access in `X-Payhawk-ApiKey` or as a Bearer token. MCP uses OAuth 2 authorisation code with PKCE (S256), refresh tokens, a revocation endpoint and dynamic client registration | | Access | Payhawk customers only. Keys are created in the portal under Settings, Integrations by an Administrator, an IT Administrator or a custom role. A development sandbox is requested by form | | Rate limits | 15 requests a second on a one-second sliding window. Responses carry ratelimit-limit, ratelimit-remaining and ratelimit-reset headers, and a 429 carries Retry-After | | Pagination | Offset paging with `$skip` and `$take` on 7 list operations, `$filter` as URL-encoded JSON on 11 and `$orderBy` on 2. The help centre gives 1,000 records a page, the definition a maximum of 10,000 | | Errors | JSON with a `code` and a `message`. 400, 401, 403 and 429 are declared on nearly every operation and 404 on 134 | | Webhooks | 24 event types for expenses, payments, deposits, suppliers, purchase orders and expense reports. Signed with RSA and SHA256, retried on 408, 409, 429 and 5xx responses | | Idempotency | An Idempotency-Key header is accepted when creating an expense, except a per diem, per the operation's description. It is not declared as a parameter | | Certifications | SOC 1 Type 2, SOC 2 Type 2, ISO 27001, PCI DSS Level 1, CSA STAR Level 1 and IDW PS 880 per the trust page. Electronic money institution licences in the UK and the EEA | | Status | status.payhawk.com on PagerDuty, with services for Card Authorisation, Bank transfers, Web Portal, Core API and Developer API | | Data location | AWS and Google Cloud. EU and US customer data in Belgium, German customers' data in Frankfurt, per the trust page | | Sub-processors | Schedule 2 of the Data Processing Addendum lists Payhawk EOOD (Belgium and Germany, language models hosted on Google Cloud), Merge API for HR integrations and Duffel for travel, with 30 days' notice of changes | | Capabilities | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | | Tags | hosted, enterprise, api-key, oauth, mcp, openapi, llms-txt, webhooks, sales-led, status-page, soc2, iso27001 | | JSON | https://www.anchorterminal.com/api/v1/tools/payhawk.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 58 | 11.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 71 | 11.5 | | Agent ergonomics | 13% | 16.2 | 52 | 8.4 | | Security & auth | 14% | 17.5 | 71 | 12.4 | | Payments & pricing | 10% | 12.5 | 13 | 1.6 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 53 | 4.6 | | Transparency & trust (editorial 55, provenance 100) | 7% | 8.8 | 78 | 6.8 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **57.1 → C** | ### Why each score - Reliability 58: Read with the hosted lines and scored on the Developer API, with the MCP server as a second surface. status.payhawk.com, a PagerDuty status page created on 22 October 2025, lists five services, one of them the Developer API (20). The page is drawn by script and its feeds returned the same shell, so the incident history went unread (5). The limit of 15 requests a second is stated on the API page, in the help centre and on every operation (15). Every operation declares a 429 with Retry-After and RateLimit-Remaining headers, and an unauthenticated call returned ratelimit headers. An Idempotency-Key header is mentioned only for creating an expense and is not declared as a parameter (10). The API page claims 99.9 per cent uptime, while section 16.3.3 of the terms disclaims service levels and no figure is published, so this is a claim and not an SLA (0). API v3 carries no beta label. The MCP docs refer to a beta period and the server is not yet in the Claude or ChatGPT directories (8). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 71: A public OpenAPI 3.1 definition at api.payhawk.com/api/v3/docs.json with 105 paths and 179 operations, shown in a Swagger UI at developers.payhawk.com (25). payhawk.com/llms.txt and the help centre's index link Markdown copies of the help articles, the API overview and the MCP pages among them. The developer portal has no llms.txt and the reference exists only as the definition (8). 173 of 179 operations carry a description but only 34 run past 80 characters. Those that do state preconditions, such as which expense states allow an update. The MCP tool reference gives when to use and when not for five tools and names only for the rest (11). The definition has 167 enums, 18 patterns, required lists and closed objects. Filters are JSON passed as a query string, typed by a schema, and no header parameter is declared (12). 400, 401, 403 and 429 are declared on nearly every operation with one error model of a code and a message. Examples are sparse, 50 in a file of 1.4 MB (9). The version is in the path. No API changelog was found, and the help articles still cite api.payhawk.io and a v2 path (6). - Agent ergonomics 52: The API has no field selection. Lists take `$take` up to 10,000 and two operations take `$include`. The MCP server has 82 tools, the lowest band, with the list filtered by the user's role and long analyses run as background jobs (12). `$skip` and `$take` appear on 7 operations, `$filter` on 11 and `$orderBy` on 2 of 75 GET operations. Paging is by offset, and the help centre and the definition disagree on the page limit (14). Errors are a code and a message, and many 400 responses are described case by case in the definition. No list of codes was found, and the 401 we received had an empty message (11). An Idempotency-Key is accepted when creating an expense other than a per diem, and PUT operations replace whole lists. MCP writes show a preview and wait for confirmation. Tool annotations could not be listed without a customer sign-in (9). Few parameters are required beyond the account ID. No official SDK was found (6). - Security & auth 71: API keys are created as read-only or full access, can be regenerated, travel in the `X-Payhawk-ApiKey` or Authorization header, and are managed by administrators or a custom role. Two system keys per account cannot be deleted by users. The MCP server uses OAuth 2 authorisation code with PKCE (S256), refresh tokens and a revocation endpoint, with no scopes published (24). Read-only keys exist. Each MCP call runs with the signed-in user's role, every write is previewed and waits for confirmation according to the docs, and payments and transfers are excluded from the MCP server (16). Supplier names, invoice text and comments reach the model, and no guidance on prompt injection was found. The MCP docs say card numbers are cut to four digits and personal details are removed from lists (4). An activity tab records changes to expenses and requests and the MCP server has a `list_audit_logs` tool. No log of calls per API key was found (9). security.txt is valid and points to a disclosure policy with no paid bounty. The trust page links SOC 1 and SOC 2 Type 2, ISO 27001, PCI DSS Level 1 and penetration test documents (18). - Payments & pricing 13: Read with the hosted rubric. No x402, MPP or L402 (0). Pricing is by quote for each module, with one published plan, the Growth programme at 149 pounds a month for single-entity firms in the UK or EEA with under 20 employees. The API page says the API is free for all Payhawk accounts (8). The Growth programme has an optional 7-day trial for eligible customers, and a development sandbox is requested through a form. Neither is open to anyone without contact (5). A person signs up as a customer, creates the key in the portal or signs in to the MCP connector (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 53: The OpenAPI definition was last modified on 8 October 2026 by its response header and the newest release note is dated 7 October 2026 (30). The release notes have more than three dated entries since late September 2026, but they cover the product and none we read concerns the API, so partial credit (15). Closed service with public release notes, support and partner addresses and partner solution consultants. No public forum or issue tracker was found (8). No official SDK on npm or PyPI and no entry in the official MCP registry (0). Nothing is packaged to assess (0). - Transparency & trust 78: Closed service with public terms, last updated on 9 December 2025, which name the contracting entities and list developer APIs among the software services (15). The privacy policy (29 June 2026) and the Data Processing Addendum (26 June 2026) agree on roles. The addendum sets deletion at 90 days after termination and bars using customer personal data, prompts included, to train general models. The privacy policy gives no retention periods, and the addendum lists SOC 1 Type 1 where the trust page says Type 2 (21). No deprecation policy for the API was found. Fields are marked deprecated in descriptions without dates, and the terms give two business days' notice of scheduled maintenance (4). The addendum's schedule lists Payhawk EOOD in Belgium and Germany and two optional sub-processors, with 30 days' notice of changes. The trust page names AWS and Google Cloud and storage in Belgium and Frankfurt, but the schedule does not list the hosting providers (15). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/payhawk.md (JSON https://www.anchorterminal.com/fixes/payhawk.json) ### What we couldn't check - unchecked: the incident history on status.payhawk.com, which is drawn by script. Its feeds returned the same page shell - unchecked: MCP tool input schemas and readOnlyHint or destructiveHint annotations, which need a customer sign-in to list - unchecked: the SOC, ISO 27001 and penetration test PDFs linked from the trust page were not opened - unchecked: the fee schedules and the partner terms linked from the legal index - Whether the MCP server enforces confirmation of writes itself or relies on the assistant. The docs say every write waits for confirmation - Whether api.payhawk.io, cited in the help centre and the API page FAQ, still answers alongside api.payhawk.com - Whether the Growth programme includes Developer API access and whether its 7-day trial needs a card - The page limit. The help centre gives 1,000 records a page and the definition a maximum of 10,000 - Whether an API changelog exists behind sign-in. None is linked from the developer portal or the help centre - The lead was right on the header, the OpenAPI 3.1 definition and the 105 paths. It did not mention the MCP server at mcp.payhawk.com, launched with the Fall '26 edition in September 2026 - No search for security incidents was made beyond the vendor's own pages. The trust page states no material breaches in the last 12 months ### Sources - OpenAPI definition (API v3): (seen 2026-10-08) - developer portal (Swagger UI) and its config file: (seen 2026-10-08) - Developer API page and FAQ: (seen 2026-10-08) - help centre, overview of the Developer API: (seen 2026-10-08) - help centre, FAQ on the Developer API: (seen 2026-10-08) - help centre, API returns only 999 results: (seen 2026-10-08) - llms.txt: (seen 2026-10-08) - help centre index for agents: (seen 2026-10-08) - about the Payhawk MCP: (seen 2026-10-08) - connecting the Payhawk MCP: (seen 2026-10-08) - MCP tool reference: (seen 2026-10-08) - MCP troubleshooting: (seen 2026-10-08) - MCP authorisation server metadata: (seen 2026-10-08) - Fall '26 edition: (seen 2026-10-08) - sandbox accounts: (seen 2026-10-08) - pricing page: (seen 2026-10-08) - release notes: (seen 2026-10-08) - status page: (seen 2026-10-08) - trust centre: (seen 2026-10-08) - vulnerability disclosure policy: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - general terms and conditions: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - Data Processing Addendum: (seen 2026-10-08) - legal index: (seen 2026-10-08) - official MCP registry search: (seen 2026-10-08) - npm registry (no package): (seen 2026-10-08) - RDAP record for payhawk.com: (seen 2026-10-08) ## Who's behind it (provenance 100/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Payhawk Limited | 20/20 | | Domain age | payhawk.com, registered 2003-07-06 (23 years) | 15/15 | | Endpoint on the vendor's domain | api.payhawk.com | 15/15 | | Terms of service | read, states 7 of the 7 things a reader expects | 10/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | status.payhawk.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The terms name Payhawk Limited (company number 11747263, Chancery House, 53-64 Chancery Lane, London WC2A 1QS) as the contracting entity worldwide and Payhawk Inc., a Delaware corporation, in the US. Payhawk EOOD in Sofia owns the platform. Cards are issued by Payhawk Financial Services UAB in the EEA, Payhawk Financial Services Limited in the UK and Cross River Bank in the US, per the site footer. The API answers at api.payhawk.com and the MCP server at mcp.payhawk.com. An unauthenticated POST to /mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata. payhawk.com/.well-known/security.txt has a contact, a policy link and an expiry of 1 January 2030. The terms were last updated on 9 December 2025, the privacy policy on 29 June 2026 and the Data Processing Addendum on 26 June 2026. The release notes cover the product. No changelog for the API was found. RDAP for payhawk.com gives a registration date of 2003-07-06. The terms' company number dates the company later, so the domain predates the vendor. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://payhawk.com/terms), read 2026-10-08, dated 2025-12-09, states 7 of the 7 things a reader expects. - Gives the date it was last updated. Last updated 2025-12-09. - Names the governing law or courts. The law of England and Wales. - States a limit on its liability. Capped at the fees paid in the 3 months before the claim. - Says how changes to the terms are announced. Gives 30 days of notice before a change. - Also in the text (2026-10-08). Payhawk's total liability is limited to the software service fees paid in the three months before the event behind the claim, except for intent or gross negligence. "maximum aggregate liability to Company under this Framework Agreement is limited to the total amount of Fees for Payhawk Software Services actually paid by Company to Payhawk Limited or, as the case may be, Payhawk Inc, in the three months preceding the event that is the basis of Company's claim." - Also in the text (2026-10-08). Accepting the terms gives Payhawk permission to name the company publicly as a customer on its website or in communications during the agreement. "By accepting these Terms, Company gives Payhawk permission to publicly reference Company as a Payhawk customer on the Payhawk Website or in communications during the term of the Framework Agreement." - Also in the text (2026-10-08). If Payhawk suspends or terminates for unpaid fees, the company is liable for all fees for the remaining duration of the current subscription period. "Company will be liable to the relevant Payhawk provider for the aggregate amount of all Fees to be paid for the remaining duration of the-then current Subscription Period." **Privacy policy** (https://payhawk.com/privacy), read 2026-10-08, dated 2026-06-29, states 8 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2026-06-29. - Says how long data is kept. For as long as needed, with no period named. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. dpo@payhawk.com. - Says where data is transferred or stored. Relies on standard contractual clauses and the Data Privacy Framework. - Also in the text (2026-10-08). Payhawk uses Google reCAPTCHA, which evaluates behavioural data and device information to tell human users from automated bots. "This service evaluates behavioral data (such as mouse movements and typing patterns) and technical device information to distinguish human users from automated bots." ## Live (updated 2026-10-09 10:42 UTC) - Right now: up, HTTP 404, 49 ms, checked 2026-10-09 10:42 UTC (get on `https://api.payhawk.com`) - Uptime 24h 100.0% (33 probes) · 30 days 100.0% (33 probes) · p50 55 ms · p95 136 ms - Vendor status page: unknown, no machine-readable status found - Always current: https://www.anchorterminal.com/api/v1/live/payhawk.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - Public OpenAPI 3.1 definition with 105 paths and 179 operations, covering expenses, cards, fund accounts, suppliers, purchase orders and 24 webhook event types - API keys are created as read-only or full access, sent in a header, and managed by administrators or a custom role - The limit of 15 requests a second is stated on every operation, and responses carry RateLimit headers with Retry-After on a 429 - The MCP server acts with the signed-in user's own role, previews every write for confirmation, and never starts a payment or transfer - SOC 1 and SOC 2 Type 2, ISO 27001, PCI DSS Level 1 and a penetration test attestation are downloadable from the trust page ## Weaknesses - No self-serve route. The API needs a Payhawk customer account, and a development sandbox is requested through a form - No official SDK on npm or PyPI, no API changelog and no deprecation policy were found. Release notes cover the product only - The API page's FAQ contradicts the definition on the host name, the page size and whether expenses can be created or reviewed - The status page is drawn by script, so its incident history could not be read. The terms disclaim service levels - The MCP server has 82 tools, is not in the official MCP registry, and no guidance on prompt injection was found ## Before you call it (notes for agents) 1. Send the key in `X-Payhawk-ApiKey` or as a Bearer token to `https://api.payhawk.com/api/v3`. A read-only key returns 403 on writes 2. Page lists with `$skip` and `$take`. The help centre gives 1,000 a page and the definition a maximum of 10,000, so count what comes back 3. Pass `$filter` as URL-encoded JSON, for example `{"status":{"$equal":"draft"}}`. Date filters compare the date part only 4. Keep to 15 requests a second and wait for `Retry-After` on a 429. Do not send `Idempotency-Key` when creating a per diem expense, which returns 400 5. Use a group-level key and the `/groups/{groupId}` paths for master data in a multi-entity group. Expenses and payments stay on account paths ## Connect First request: ```bash curl https://api.payhawk.com/api/v3/accounts/YOUR_ACCOUNT_ID/fund-accounts \ -H "X-Payhawk-ApiKey: YOUR_API_KEY" ``` Through letme (picks today, calling later): https://letme.dev/payhawk. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Airwallex Spend and Issuing | B | 68.3 | 210 | spend.transactions, spend.cards, spend.expenses, spend.bills, spend.procurement | no | https://www.anchorterminal.com/tools/airwallex.md | | Spendesk API + MCP | B | 62.3 | 395 | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | no | https://www.anchorterminal.com/tools/spendesk.md | | Ramp | C | 57.3 | 554 | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | no | https://www.anchorterminal.com/tools/ramp.md | | BILL | C | 60.9 | 441 | spend.transactions, spend.expenses, spend.cards, spend.bills | no | https://www.anchorterminal.com/tools/bill.md | | Brex | C | 60.7 | 452 | spend.transactions, spend.expenses, spend.cards, spend.bills | no | https://www.anchorterminal.com/tools/brex.md | | Mercury API | B | 63.8 | 337 | spend.transactions, spend.cards, spend.expenses | no | https://www.anchorterminal.com/tools/mercury.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The MCP server at https://mcp.payhawk.com/mcp lists 82 tools in its public reference, filtered by the user's role, and never starts a payment or transfer (source: ) - The MCP server is not yet listed in the Claude or ChatGPT directories and is added by hand as a custom connector. ChatGPT and Codex need Developer Mode (source: ) - The FAQ on the API page says expenses cannot be created or reviewed through the API and gives https://api.payhawk.io/api/v3 as the address, while the definition at api.payhawk.com has operations for both (source: ) - Webhooks cover 24 event types and are signed with RSA and SHA256 in an X-Payhawk-Signature header, checked against the key at `/api/v3/rsa-public-key` (source: ) - The API page claims 99.9 per cent uptime. Section 16.3.3 of the terms says Payhawk does not guarantee any service levels (source: ) - The Data Processing Addendum bars using customer personal data, including prompts and conversation histories, to train general-purpose models (source: ) - The disclosure policy says Payhawk cannot run a paid bug bounty and gives a non-cash reward for qualifying reports (source: ) ## Compare - [Airwallex Spend and Issuing vs Payhawk API + MCP](https://www.anchorterminal.com/compare/airwallex-vs-payhawk.md): B 68.3 vs C 57.1 - [BILL vs Payhawk API + MCP](https://www.anchorterminal.com/compare/bill-vs-payhawk.md): C 60.9 vs C 57.1 - [Brex vs Payhawk API + MCP](https://www.anchorterminal.com/compare/brex-vs-payhawk.md): C 60.7 vs C 57.1 - [Expensify vs Payhawk API + MCP](https://www.anchorterminal.com/compare/expensify-vs-payhawk.md): E 41.1 vs C 57.1 - [Mercury API vs Payhawk API + MCP](https://www.anchorterminal.com/compare/mercury-vs-payhawk.md): B 63.8 vs C 57.1 - [Payhawk API + MCP vs Pleo API + MCP](https://www.anchorterminal.com/compare/payhawk-vs-pleo.md): C 57.1 vs B 62.9 - [Payhawk API + MCP vs Ramp](https://www.anchorterminal.com/compare/payhawk-vs-ramp.md): C 57.1 vs C 57.3 - [Payhawk API + MCP vs Spendesk API + MCP](https://www.anchorterminal.com/compare/payhawk-vs-spendesk.md): C 57.1 vs B 62.3 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on payhawk.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "payhawk", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Payhawk API + MCP on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Payhawk API + MCP on Anchor Terminal](https://www.anchorterminal.com/badges/payhawk.svg)](https://www.anchorterminal.com/tools/payhawk) ``` Plain link: ```html Payhawk API + MCP on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Payhawk API + MCP is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/payhawk-dark.png - Light: https://www.anchorterminal.com/assets/share/payhawk-light.png