# Payhawk API + MCP (slim) > Spend management platform from Payhawk Limited in London, covering company cards, expenses, bills, purchase orders and travel. Outside agents reach it through a REST Developer API with read-only or full-access keys, and a hosted MCP server. - Full: https://www.anchorterminal.com/tools/payhawk.md (~7,800 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/payhawk.json · canonical https://www.anchorterminal.com/tools/payhawk - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 57.1/100 · rank #561 of 842 · #8 in Spend management & procurement · not agent-ready · confidence medium** Assessment: The Developer API has a public OpenAPI 3.1 definition with 179 operations, read-only or full-access keys and a published limit of 15 requests a second. It needs a Payhawk customer account, no official SDK or API changelog was found, and the 82-tool MCP server is added by hand because it is not yet in the assistant directories. ## Facts - Kind: HTTP API · vendor: Payhawk Limited · category: Spend management & procurement · legal entity: Payhawk Limited · provenance 100/100 - Endpoint: `https://api.payhawk.com` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under Payhawk's general terms and conditions - Probe metrics: not measured yet (probes haven't run) - API: REST, OpenAPI 3.1, version v3, 105 paths and 179 operations at https://api.payhawk.com/api/v3. 75 GET, 38 POST, 28 PATCH, 24 DELETE, 14 PUT - Coverage: Expenses and files, expense reports, cards (issue, update, change status), fund accounts, deposits and bank statements, suppliers, purchase orders and goods received notes, spend policies, users, teams, custom fields, expense categories, tax rates, account codes and webhooks, at account and group level - MCP server: Hosted at https://mcp.payhawk.com/mcp. 82 tools in the public reference, read and write, filtered by role. Works with Claude, ChatGPT and Codex as a custom connector. Launched with the Fall '26 edition in September 2026 - Credentials: API key with read-only or full access in `X-Payhawk-ApiKey` or as a Bearer token. MCP uses OAuth 2 authorisation code with PKCE (S256), refresh tokens, a revocation endpoint and dynamic client registration - Access: Payhawk customers only. Keys are created in the portal under Settings, Integrations by an Administrator, an IT Administrator or a custom role. A development sandbox is requested by form - Rate limits: 15 requests a second on a one-second sliding window. Responses carry ratelimit-limit, ratelimit-remaining and ratelimit-reset headers, and a 429 carries Retry-After - Pagination: Offset paging with `$skip` and `$take` on 7 list operations, `$filter` as URL-encoded JSON on 11 and `$orderBy` on 2. The help centre gives 1,000 records a page, the definition a maximum of 10,000 - Errors: JSON with a `code` and a `message`. 400, 401, 403 and 429 are declared on nearly every operation and 404 on 134 - Webhooks: 24 event types for expenses, payments, deposits, suppliers, purchase orders and expense reports. Signed with RSA and SHA256, retried on 408, 409, 429 and 5xx responses - Idempotency: An Idempotency-Key header is accepted when creating an expense, except a per diem, per the operation's description. It is not declared as a parameter - Certifications: SOC 1 Type 2, SOC 2 Type 2, ISO 27001, PCI DSS Level 1, CSA STAR Level 1 and IDW PS 880 per the trust page. Electronic money institution licences in the UK and the EEA - Status: status.payhawk.com on PagerDuty, with services for Card Authorisation, Bank transfers, Web Portal, Core API and Developer API - Data location: AWS and Google Cloud. EU and US customer data in Belgium, German customers' data in Frankfurt, per the trust page - Sub-processors: Schedule 2 of the Data Processing Addendum lists Payhawk EOOD (Belgium and Germany, language models hosted on Google Cloud), Merge API for HR integrations and Duffel for travel, with 30 days' notice of changes - Scores: Reliability 58, Performance pending, Schema & documentation 71, Agent ergonomics 52, Security & auth 71, Payments & pricing 13, Task success pending, Maintenance & community 53, Transparency & trust 78 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the Developer API, with the MCP server as a second surface. · Schema & documentation, A public OpenAPI 3.1 definition at api.payhawk.com/api/v3/docs.json with 105 paths and 179 operations, shown in a Swagger UI at developers.p… · Agent ergonomics, The API has no field selection. · Security & auth, API keys are created as read-only or full access, can be regenerated, travel in the `X-Payhawk-ApiKey` or Authorization header, and are mana… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The OpenAPI definition was last modified on 8 October 2026 by its response header and the newest release note is dated 7 October 2026 (30). · Transparency & trust, Closed service with public terms, last updated on 9 December 2025, which name the contracting entities and list developer APIs among the sof… - Sources: 28, open questions: 11, both in the full twin - Capabilities: spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement - JSON: https://www.anchorterminal.com/api/v1/tools/payhawk.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/payhawk.svg` or a link to https://www.anchorterminal.com/tools/payhawk from a page on payhawk.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send the key in `X-Payhawk-ApiKey` or as a Bearer token to `https://api.payhawk.com/api/v3`. A read-only key returns 403 on writes 2. Page lists with `$skip` and `$take`. The help centre gives 1,000 a page and the definition a maximum of 10,000, so count what comes back 3. Pass `$filter` as URL-encoded JSON, for example `{"status":{"$equal":"draft"}}`. Date filters compare the date part only 4. Keep to 15 requests a second and wait for `Retry-After` on a 429. Do not send `Idempotency-Key` when creating a per diem expense, which returns 400 5. Use a group-level key and the `/groups/{groupId}` paths for master data in a multi-entity group. Expenses and payments stay on account paths ## Connect ```bash curl https://api.payhawk.com/api/v3/accounts/YOUR_ACCOUNT_ID/fund-accounts \ -H "X-Payhawk-ApiKey: YOUR_API_KEY" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/payhawk ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Airwallex Spend and Issuing | B | 68.3 | spend.transactions, spend.cards, spend.expenses, spend.bills, spend.procurement | https://www.anchorterminal.com/tools/airwallex.min.md | | Spendesk API + MCP | B | 62.3 | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | https://www.anchorterminal.com/tools/spendesk.min.md | | Ramp | C | 57.3 | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | https://www.anchorterminal.com/tools/ramp.min.md | | BILL | C | 60.9 | spend.transactions, spend.expenses, spend.cards, spend.bills | https://www.anchorterminal.com/tools/bill.min.md | | Brex | C | 60.7 | spend.transactions, spend.expenses, spend.cards, spend.bills | https://www.anchorterminal.com/tools/brex.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)