Pleo API + MCP
by Pleo Technologies A/S HTTP API in Spend management & procurement
Hosted
Pleo Technologies A/S · pleo.io since 2015 · status page · who's behind it
Spend management platform from Pleo Technologies A/S in Copenhagen, covering company cards, expenses, reimbursements, invoices and accounting exports. Outside agents reach it through a hosted MCP server for expense work and a REST API built for accounting integrations.
Good for An agent that completes, codes, reviews and queues expenses for a Pleo customer on the Optimise plan, or for a bookkeeping integration that exports accounting entries and syncs tags, tax codes, accounts and vendors.
Is this your product? Claim this listing or verify it
Assessment. The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found.
Facts
- Transport
- HTTP, Streamable HTTP
- Endpoint
https://external.pleo.io- Auth
- OAuth or key
- Pricing
- Paid · Paid
- x402
- No
- Licence
- Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms
- llms.txt
- published
- Last release
- Surfaces
- Pleo MCP server (https://mcp.pleo.io/mcp, Streamable HTTP) for expense work by a signed-in user, and the External API (https://external.pleo.io) for accounting integrations. The Legacy API at openapi.pleo.io is deprecated
- MCP scope
- Search and read expenses, set categories, tags and tax codes, split an expense, add notes and attendees, attach receipts, review and approve, and add expenses to the export queue. No company configuration, payments, card changes or limit changes
- External API
- Eleven current OpenAPI 3.0.1 specs, 162 operations. Accounting entries and receipts (read), enrichment (attach a receipt), export jobs and items (v1 to v3), tags, tax codes, chart of accounts, bookkeeping categories, vendors, employees and companies (read), teams, webhook subscriptions and app marketplace installations
- Access
- MCP needs the Optimise plan per the pricing page and an admin opt-in per entity. Standalone API keys are enabled on request by Pleo support. Partner OAuth clients are issued after review in the Early Access Programme, staging first
- Credentials
- MCP uses OAuth authorisation code with PKCE (S256), refresh tokens and dynamic client registration, with one scope named authenticated. API uses OAuth 2.0 bearer tokens with resource scopes such as export-jobs:read, or a scoped API key with an expiry sent as the Basic auth username
- Token lifetimes
- Access token lifetime is given in expires_in. Refresh tokens last at least 60 days and rotate on use. Reusing an expired refresh token invalidates every refresh token for that authorisation
- Rate limits
- 600 requests a minute per credential, shared across all endpoints and methods. The docs suggest targeting 500. No separate limit is documented for the MCP server
- Pagination
- Cursor (
before,after,limit) and offset (offset,limit) styles, withsorting_keysandsorting_order. Responses carryhasNextPage,startCursorandendCursor - Errors
- JSON body with a
typecode and amessage, such as MISSING_CONTRA_ACCOUNTS (400) or EXPORT_ALREADY_IN_PROGRESS (409). Every response carries a request-Id header for support - Webhooks
- Subscriptions API with two documented events, export job created and vendor created, signed with webhook-id, webhook-timestamp and webhook-signature headers
- Sandbox
- Staging at https://external.staging.pleo.io and https://mcp.staging.pleo.io/mcp with test data. Customers with keys enabled can create a staging key directly. Partners get staging through the Early Access Programme
- Plans
- Start £8 per user per month, billed monthly. Build £14 monthly or £12 billed yearly. Optimise £18 monthly or £16 billed yearly. Build and Optimise have a three-user minimum. GBP prices as shown to a UK visitor on 8 October 2026
- Audit
- Changes made through the MCP appear in Pleo's activity and audit logs and in the Activity tab of the expense. Users see and revoke connected clients under My Account, Security and Devices, MCP Connections
- Security programme
- Vulnerability disclosure policy with safe harbour (security-vd@pleo.io), a bug bounty on HackerOne, PCI-DSS and Google's CASA per the trust page. Compliance reports are shared under NDA on request
- Data location
- Customer data is stored and processed in AWS Ireland (eu-west-1) per the trust page. The sub-processor list names each provider's location
- Status
- status.pleo.io on incident.io, 25 components, among them Pleo API, Transactions, Card, E-money Account and 15 accounting integrations
- Capabilities
- spend.transactions spend.expenses spend.bills
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- MCP server at mcp.pleo.io/mcp uses OAuth with PKCE and dynamic client registration, and acts with the connecting user's Pleo permissions
- Payments, card changes and spending-limit changes are blocked through the MCP by design, per the AI Access Terms
- Eleven current OpenAPI 3.0.1 specs with 162 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page
- One documented rate limit of 600 requests a minute per credential, with written 429 and Retry-After guidance
- Staging hosts for both the API (external.staging.pleo.io) and the MCP server (mcp.staging.pleo.io/mcp)
- Sub-processor list with locations, customer data in AWS Ireland, and 30 days' notice of new sub-processors in the DPA
Weaknesses
- The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo)
- MCP tool names, schemas and count aren't published, so they can't be read without a customer sign-in
- Standalone API keys aren't self-service. Pleo support or a Customer Success Manager enables them, and partner OAuth clients go through a reviewed programme
- No Idempotency-Key header, no official SDK and no entry in the official MCP registry
- The API terms call the API a beta version that Pleo may discontinue at any time, and no SLA was found
- No end-of-life date is published for the deprecated Legacy API, and its Q3 2026 replacements for employee writes and wallet balance aren't in the docs
Before you call it notes for agents
- Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default
- Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist
- Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side
- Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there
- Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second
- Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in
Who's behind it provenance 87/100
- Legal entity namedPleo Technologies A/S20/20
- Domain agepleo.io, registered 2015-10-07 (11 years)15/15
- Endpoint on the vendor's domainexternal.pleo.io15/15
- Terms of serviceread, states 4 of the 7 things a reader expects7.4/10
- Privacy policypublished10/10
- Status pagestatus.pleo.io10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service gives no date, states 4 of 7, 1 to know
TL;DR Gives no date. States 4 of the 7 things a reader expects, and we didn't find the governing law or a service level. To know before relying on it, cut-off without notice or for any reason.
Says access can be ended without notice or for any reason
Pleo reserves the right to discontinue the API or any portion or feature or the access thereto for any reason and at any time without liability or other obligation to you.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts
Not found in the text.
Says where a dispute would be heard and under whose law.
States a limit on its liability
To the extent permitted by law, Pleo are not liable for failure or delay in performance to the extent caused by circumstances beyond our reasonable control.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Pleo Technologies A/S may suspend access to the APIs without notice if we reasonably believe that you are in violation of the Terms.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
We’ll post notice of modifications to the Terms within the API documentation.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
The Customer will not use the API to encourage or promote illegal activity, violation of third party rights or violate any legal terms which govern the services offered by Pleo Technologies A/S and Pleo Financial Services A/S, respectively.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
The API is described as a beta version still in development, supplied as is with no commitment on reliability or availability.
THE API IS A BETA VERSION AND IS STILL BEING DEVELOPED, TESTED AND EVALUATED.
Noted by a second reader on 2026-10-08.
Pleo reserves the right to introduce fees and payment terms for any use of the API.
Pleo reserves the right to implement fees and payment terms with respect to any use of the Pleo API.
Noted by a second reader on 2026-10-08.
The customer agrees that Pleo may monitor API use to check quality, improve its products and verify compliance with the terms.
THE CUSTOMER AGREES THAT PLEO TECHNOLOGIES A/S MAY MONITOR USE OF THE API TO ENSURE QUALITY, IMPROVE PLEO TECHNOLOGIES A/S (AND ITS AFFILIATES’) PRODUCTS AND SERVICES, AND VERIFY YOUR COMPLIANCE WITH THE TERMS.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 1,188 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The website footer names Pleo Technologies A/S (36538686), Ravnsborg Tværgade 5C, 2200 København N, Denmark. UK payment services come from Pleo Financial Services UK Ltd, FCA firm reference 1020730, company number 15842283.
The API Terms of Service on the developer portal name Pleo Technologies A/S, carry no date, and describe the API as a beta version. The UK Master Service Agreement has an effective date of 7 September 2026 and is governed by the laws of England and Wales.
The API answers at external.pleo.io and the MCP server at mcp.pleo.io, both pleo.io subdomains. The MCP host publishes its OAuth metadata at https://mcp.pleo.io/.well-known/oauth-authorization-server
www.pleo.io/.well-known/security.txt and pleo.io/.well-known/security.txt both return 403 with an AccessDenied body. The vulnerability disclosure policy gives security-vd@pleo.io as the reporting address.
The privacy notice is dated June 2026 and the Data Processing Agreement 14 October 2025. An AI Access Terms document covers the MCP server.
RDAP from the .io registry gives a registration date of 2015-10-07 for pleo.io.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://external.pleo.io. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 10 minutes ago
- security.txt unknown · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/pleo.json
Notable
- The Pleo MCP server is a remote Streamable HTTP endpoint at https://mcp.pleo.io/mcp with a staging twin at https://mcp.staging.pleo.io/mcp, and signs users in with OAuth in a browser source
- MCP access is off by default and enabled per entity by a company admin. Per-user enablement is not available yet, per the FAQ source
- The AI Access Terms say no agent can initiate payments or move money, issue, freeze or change cards, or change spending limits through the MCP source
- The pricing page lists MCP as included on Optimise and not included on Start or Build source
- Standalone API Keys are not self-service. A Customer Success Manager or Pleo Support enables them, and partner integrations register through the Early Access Programme with OAuth 2.0 source
- All Pleo APIs share one limit of 600 requests a minute per credential, across endpoints and methods source
- The Legacy API at openapi.pleo.io is deprecated with no end-of-life date published. Replacements for adding or removing users (a SCIM API) and for the wallet balance are listed for Q3 2026 source
- Pleo lists Anthropic among its sub-processors for AI-product enablement, with processing in the US source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 14.2 | |
| Read with the hosted lines and scored on the MCP server and the External API together. status.pleo.io on incident.io has 25 components with incident history, among them Pleo API (20). From 10 July to 8 October 2026 the page lists two incidents, both marked minor and neither on the Pleo API component. Card transactions failed intermittently for about 2 hours 30 minutes on 15 July during a Mastercard authentication fault, and instant top-up in Sweden was impaired from 10 to 15 September (20). One limit is published, 600 requests a minute per credential across all endpoints. No limit is documented for the MCP server (15). The docs tell clients to wait for Retry-After when present, otherwise back off from one second, and say which steps are unsafe to repeat after a 429. There is no Idempotency-Key header, and the OpenAPI specs don't declare 429 (11 of 15). No SLA found in the API terms or the UK Master Service Agreement (0). The API terms describe the API as a beta version, and the specs include /v0 and /v1-beta paths. The MCP server carries no beta label (5 of 10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 13.3 | |
| Eleven current OpenAPI 3.0.1 specs with 162 operations, linked from llms.txt, plus a spec for the deprecated Legacy API (25). llms.txt, llms-full.txt and a Markdown copy of every docs page at the same URL with .md (10). 107 of 162 operations carry a description, and long guides explain when each export and sync step applies. The MCP server has no public tool reference, only prose on what it can do, so its tool descriptions couldn't be read without a customer sign-in. Three specs carry internal titles (Gjoll, Oberon, Triton) (11 of 20). The specs hold 86 enums and required lists, and search endpoints take typed filter bodies. MCP input schemas are unread (11 of 15). 463 examples across the specs and typed error examples such as MISSING_CONTRA_ACCOUNTS and INVALID_TARGET_SYSTEM. 77 operations declare only a default error response and none declares 429 (11 of 15). Path versions, with Export API v1 to v3 documented side by side, and a public changelog of 56 dated entries back to November 2024. The current API has no written versioning policy (14 of 15). | |||
| Agent ergonomics | 13%16.2 | 8.9 | |
The MCP tool count and definitions aren't published, so context cost couldn't be measured. On the API, limit sizes a page and aggregated endpoints return tag groups and category groups in one call, with no field selection (13 of 25). Cursor and offset pagination with sorting keys, and search endpoints with filters for accounting entries, receipts, tags, vendors and employees. Two pagination styles are in use (17 of 20). Errors carry a type code and a message, and every response has a request-Id header. The general error page lists seven statuses with generic fixes and leaves out 409, 422 and 429 (13 of 20). No Idempotency-Key. The docs ask integrators to make their own processing idempotent, and export jobs can be resumed. MCP readOnlyHint and destructiveHint annotations couldn't be read (7 of 20). List calls need few parameters. No official SDK was found, only a Postman collection and two community libraries named for the Legacy API (5 of 15). | |||
| Security & auth | 14%17.5 | 12.4 | |
| The MCP server uses OAuth authorisation code with PKCE (S256), refresh tokens and dynamic client registration, with a single scope and the connecting user's Pleo role as the real boundary. The API uses OAuth 2.0 with resource scopes and rotating refresh tokens, or API keys with chosen scopes and an expiry, sent in the Authorization header (28 of 30). Read and write are separate API scopes. MCP access is off until an admin enables it per entity, can't be limited to named users yet, and has no read-only mode. Payments, card changes and limit changes are blocked through the MCP by design. Confirmation before a write is left to the AI client (15 of 20). Merchant names, notes and receipts are untrusted text. The docs say to review significant output and recommend approval for write tools, with no guidance on injected content (5 of 15). Changes made through the MCP appear in Pleo's activity and audit logs, and users can list and revoke MCP connections. No call log for API keys was found (10 of 15). A disclosure policy with safe harbour, a HackerOne bug bounty, PCI-DSS and Google's CASA per the trust page. No SOC 2 or ISO 27001 is claimed, reports are shared under NDA, and security.txt returns 403 (13 of 20). | |||
| Payments & pricing | 10%12.5 | 1.9 | |
| Read with the hosted rubric. No x402, MPP or L402 (0). Per-user plan prices are public (£8, £14 and £18 a month as shown to a UK visitor), with no per-call price for the API or MCP (10). The signup form states 21 days free on Start and Build, but the pricing page lists MCP on Optimise only, which is sold through a demo, and API keys need enabling by Pleo support. Whether the trial needs a card isn't stated. Partial credit (5 of 20). A person signs in with OAuth in a browser or creates a key in the web app, and Pleo issues partner OAuth clients after review (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 5.6 | |
| The newest changelog entry is 2 October 2026, a new Teams API (30). Sixteen dated entries between 15 July and 2 October 2026, among them the MCP documentation on 17 August and Export API v3 additions (20). Closed service with a dated changelog, api@pleo.io for partners and Pleo support for customers. The docs say custom implementation support is generally not given, and response times couldn't be observed (9 of 15). No official SDK was found, the MCP server isn't in the official MCP registry, and the docs say Pleo isn't in Claude's connector directory yet (0). No packages to assess. The published specs carry current version numbers and match the changelog (5 of 10). | |||
| Transparency & trusteditorial 63, provenance 87 | 7%8.8 | 6.6 | |
| Closed service with public API terms naming Pleo Technologies A/S, a Master Service Agreement and separate AI Access Terms for the MCP. The API terms carry no date and let Pleo discontinue the API at any time (14 of 30). A privacy notice dated June 2026, a DPA of 14 October 2025 and a trust page placing customer data in AWS Ireland agree with each other. Pleo's MCP page says it doesn't use customer data to train AI models. Retention for customer data is stated only as long as there is a valid purpose or legal requirement, with no periods (20 of 30). The Legacy API is deprecated with migration guides, but no end-of-life date is published, and replacements listed for Q3 2026 (a SCIM API and wallet balance) weren't in the docs index on 8 October. Changes to the API terms take effect no sooner than 30 days after posting (9 of 20). A public sub-processor list with each provider's role and location, and 30 days' notice of new sub-processors in the DPA (20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 62.9 · B | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 17 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Pleo API + MCP, or have the agent fetch /fixes/pleo.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Pleo API + MCP From Anchor Terminal's listing at https://www.anchorterminal.com/tools/pleo, the October 2026 research run, assessed 8 October 2026. Grade B, 62.9 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Pleo API + MCP: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 15 out of 100, up to 10.6 more on the total Why it scored 15: Read with the hosted rubric. No x402, MPP or L402 (0). Per-user plan prices are public (£8, £14 and £18 a month as shown to a UK visitor), with no per-call price for the API or MCP (10). The signup form states 21 days free on Start and Build, but the pricing page lists MCP on Optimise only, which is sold through a demo, and API keys need enabling by Pleo support. Whether the trial needs a card isn't stated. Partial credit (5 of 20). A person signs in with OAuth in a browser or creates a key in the web app, and Pleo issues partner OAuth clients after review (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Agent ergonomics, 55 out of 100, up to 7.3 more on the total Why it scored 55: The MCP tool count and definitions aren't published, so context cost couldn't be measured. On the API, `limit` sizes a page and aggregated endpoints return tag groups and category groups in one call, with no field selection (13 of 25). Cursor and offset pagination with sorting keys, and search endpoints with filters for accounting entries, receipts, tags, vendors and employees. Two pagination styles are in use (17 of 20). Errors carry a `type` code and a message, and every response has a request-Id header. The general error page lists seven statuses with generic fixes and leaves out 409, 422 and 429 (13 of 20). No Idempotency-Key. The docs ask integrators to make their own processing idempotent, and export jobs can be resumed. MCP readOnlyHint and destructiveHint annotations couldn't be read (7 of 20). List calls need few parameters. No official SDK was found, only a Postman collection and two community libraries named for the Legacy API (5 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 3. Reliability, 71 out of 100, up to 5.8 more on the total Why it scored 71: Read with the hosted lines and scored on the MCP server and the External API together. status.pleo.io on incident.io has 25 components with incident history, among them Pleo API (20). From 10 July to 8 October 2026 the page lists two incidents, both marked minor and neither on the Pleo API component. Card transactions failed intermittently for about 2 hours 30 minutes on 15 July during a Mastercard authentication fault, and instant top-up in Sweden was impaired from 10 to 15 September (20). One limit is published, 600 requests a minute per credential across all endpoints. No limit is documented for the MCP server (15). The docs tell clients to wait for Retry-After when present, otherwise back off from one second, and say which steps are unsafe to repeat after a 429. There is no Idempotency-Key header, and the OpenAPI specs don't declare 429 (11 of 15). No SLA found in the API terms or the UK Master Service Agreement (0). The API terms describe the API as a beta version, and the specs include /v0 and /v1-beta paths. The MCP server carries no beta label (5 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 4. Security & auth, 71 out of 100, up to 5.1 more on the total Why it scored 71: The MCP server uses OAuth authorisation code with PKCE (S256), refresh tokens and dynamic client registration, with a single scope and the connecting user's Pleo role as the real boundary. The API uses OAuth 2.0 with resource scopes and rotating refresh tokens, or API keys with chosen scopes and an expiry, sent in the Authorization header (28 of 30). Read and write are separate API scopes. MCP access is off until an admin enables it per entity, can't be limited to named users yet, and has no read-only mode. Payments, card changes and limit changes are blocked through the MCP by design. Confirmation before a write is left to the AI client (15 of 20). Merchant names, notes and receipts are untrusted text. The docs say to review significant output and recommend approval for write tools, with no guidance on injected content (5 of 15). Changes made through the MCP appear in Pleo's activity and audit logs, and users can list and revoke MCP connections. No call log for API keys was found (10 of 15). A disclosure policy with safe harbour, a HackerOne bug bounty, PCI-DSS and Google's CASA per the trust page. No SOC 2 or ISO 27001 is claimed, reports are shared under NDA, and security.txt returns 403 (13 of 20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 5. Maintenance & community, 64 out of 100, up to 3.2 more on the total Why it scored 64: The newest changelog entry is 2 October 2026, a new Teams API (30). Sixteen dated entries between 15 July and 2 October 2026, among them the MCP documentation on 17 August and Export API v3 additions (20). Closed service with a dated changelog, api@pleo.io for partners and Pleo support for customers. The docs say custom implementation support is generally not given, and response times couldn't be observed (9 of 15). No official SDK was found, the MCP server isn't in the official MCP registry, and the docs say Pleo isn't in Claude's connector directory yet (0). No packages to assess. The published specs carry current version numbers and match the changelog (5 of 10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 6. Schema & documentation, 82 out of 100, up to 2.9 more on the total Why it scored 82: Eleven current OpenAPI 3.0.1 specs with 162 operations, linked from llms.txt, plus a spec for the deprecated Legacy API (25). llms.txt, llms-full.txt and a Markdown copy of every docs page at the same URL with .md (10). 107 of 162 operations carry a description, and long guides explain when each export and sync step applies. The MCP server has no public tool reference, only prose on what it can do, so its tool descriptions couldn't be read without a customer sign-in. Three specs carry internal titles (Gjoll, Oberon, Triton) (11 of 20). The specs hold 86 enums and required lists, and search endpoints take typed filter bodies. MCP input schemas are unread (11 of 15). 463 examples across the specs and typed error examples such as MISSING_CONTRA_ACCOUNTS and INVALID_TARGET_SYSTEM. 77 operations declare only a default error response and none declares 429 (11 of 15). Path versions, with Export API v1 to v3 documented side by side, and a public changelog of 56 dated entries back to November 2024. The current API has no written versioning policy (14 of 15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 7. Transparency & trust, 75 out of 100, up to 2.2 more on the total Made of editorial 63, provenance 87. Why it scored 75: Closed service with public API terms naming Pleo Technologies A/S, a Master Service Agreement and separate AI Access Terms for the MCP. The API terms carry no date and let Pleo discontinue the API at any time (14 of 30). A privacy notice dated June 2026, a DPA of 14 October 2025 and a trust page placing customer data in AWS Ireland agree with each other. Pleo's MCP page says it doesn't use customer data to train AI models. Retention for customer data is stated only as long as there is a valid purpose or legal requirement, with no periods (20 of 30). The Legacy API is deprecated with migration guides, but no end-of-life date is published, and replacements listed for Q3 2026 (a SCIM API and wallet balance) weren't in the docs index on 8 October. Changes to the API terms take effect no sooner than 30 days after posting (9 of 20). A public sub-processor list with each provider's role and location, and 30 days' notice of new sub-processors in the DPA (20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 4 of the 7 things a reader expects (7.4 of 10) - security.txt: not found (0 of 10) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: MCP tool names, input schemas, annotations and count. tools/list needs a signed-in Pleo customer and we didn't register a client - unchecked: whether the 21-day trial needs a payment card, and whether a trial company can use the MCP server or API keys - unchecked: prices in USD. The pricing page showed GBP to our UK fetch, so unitPrices is empty - Whether Standalone API Keys are tied to a plan. The pricing page lists MCP by plan but doesn't mention the API - Whether the SCIM API and the wallet balance replacement, both listed for Q3 2026, have shipped - Whether a rate limit applies to the MCP server, and what its errors look like - unchecked: the HackerOne programme's scope and rewards. The trust page states the programme exists and we didn't read the HackerOne page - Whether an SLA exists in order forms for larger customers ## Weaknesses - The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo) - MCP tool names, schemas and count aren't published, so they can't be read without a customer sign-in - Standalone API keys aren't self-service. Pleo support or a Customer Success Manager enables them, and partner OAuth clients go through a reviewed programme - No Idempotency-Key header, no official SDK and no entry in the official MCP registry - The API terms call the API a beta version that Pleo may discontinue at any time, and no SLA was found - No end-of-life date is published for the deprecated Legacy API, and its Q3 2026 replacements for employee writes and wallet balance aren't in the docs ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default - Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist - Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side - Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there - Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second - Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: MCP tool names, input schemas, annotations and count. tools/list needs a signed-in Pleo customer and we didn't register a client
- unchecked: whether the 21-day trial needs a payment card, and whether a trial company can use the MCP server or API keys
- unchecked: prices in USD. The pricing page showed GBP to our UK fetch, so unitPrices is empty
- Whether Standalone API Keys are tied to a plan. The pricing page lists MCP by plan but doesn't mention the API
- Whether the SCIM API and the wallet balance replacement, both listed for Q3 2026, have shipped
- Whether a rate limit applies to the MCP server, and what its errors look like
- unchecked: the HackerOne programme's scope and rewards. The trust page states the programme exists and we didn't read the HackerOne page
- Whether an SLA exists in order forms for larger customers
Sources 30
- developer docs index (llms.txt) developers.pleo.io · seen 2026-10-08
- Pleo MCP overview developers.pleo.io · seen 2026-10-08
- Pleo MCP capabilities developers.pleo.io · seen 2026-10-08
- Pleo MCP access and permissions developers.pleo.io · seen 2026-10-08
- Pleo MCP FAQs developers.pleo.io · seen 2026-10-08
- custom MCP install, URLs and transport developers.pleo.io · seen 2026-10-08
- MCP OAuth metadata mcp.pleo.io · seen 2026-10-08
- API base URLs, authentication and rate limits developers.pleo.io · seen 2026-10-08
- Standalone API Keys overview developers.pleo.io · seen 2026-10-08
- Early Access Programme developers.pleo.io · seen 2026-10-08
- OAuth tokens overview developers.pleo.io · seen 2026-10-08
- pagination developers.pleo.io · seen 2026-10-08
- API response codes and errors developers.pleo.io · seen 2026-10-08
- Export API OpenAPI spec developers.pleo.io · seen 2026-10-08
- changelog developers.pleo.io · seen 2026-10-08
- API deprecation notice developers.pleo.io · seen 2026-10-08
- API Terms of Service developers.pleo.io · seen 2026-10-08
- pricing pleo.io · seen 2026-10-08
- MCP product page and FAQ pleo.io · seen 2026-10-08
- AI Access Terms pleo.io · seen 2026-10-08
- trust and security pleo.io · seen 2026-10-08
- vulnerability disclosure policy pleo.io · seen 2026-10-08
- sub-processors pleo.io · seen 2026-10-08
- privacy notice pleo.io · seen 2026-10-08
- Data Processing Agreement pleo.io · seen 2026-10-08
- UK Master Service Agreement pleo.io · seen 2026-10-08
- status incidents status.pleo.io · seen 2026-10-08
- status history feed status.pleo.io · seen 2026-10-08
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
- domain registration (RDAP) rdap.identitydigital.services · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid Paid Per-user plans, with no separate charge for the API or the MCP server. The pricing page shown to a UK visitor lists Start at £8 per user per month, Build at £14 and Optimise at £18, the last two cheaper billed yearly and with a three-user minimum. MCP is listed on Optimise only, which is sold through a demo. Start and Build have a Try for free button and the signup form states 21 days free. Whether the trial needs a payment card isn't stated. A staging environment with test data exists for customers with API keys enabled and for approved partners. Fees for payments and foreign exchange are extra (checked 2026-10-08).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/pleo.xml, or this listing's score history at history.json.
Connect
First request
curl --request GET \
-u "YOUR-API-KEY:" \
-H "Accept: application/json;charset=UTF-8" \
"https://external.staging.pleo.io/v2/employees"
Claude Code
claude mcp add --transport http pleo-mcp-staging https://mcp.staging.pleo.io/mcp
MCP client configuration
{
"mcpServers": {
"pleo": {
"url": "https://mcp.pleo.io/mcp"
}
}
}
Through letme picks today, calling later
GET https://letme.dev/pleo
letme picks this listing for spend.bills, because it's the top-graded tool for the job. letme picks this listing for spend.expenses, because it's the top-graded tool for the job. letme picks this listing for spend.transactions, because it's the top-graded tool for the job.
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Spendesk API + MCP BBrex CRamp C
Head to head Brex vs Pleo API + MCP · Pleo API + MCP vs Ramp · Pleo API + MCP vs Spendesk API + MCP
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Spendesk API + MCP Spendesk SAS | B | 62.3 | spend.transactions spend.expenses spend.bills | no |
| Brex Brex LLC | C | 60.7 | spend.transactions spend.expenses spend.bills | no |
| Ramp Ramp Business Corporation | C | 57.3 | spend.transactions spend.expenses spend.bills | no |
Machine-readable
- JSON
/api/v1/tools/pleo.json· historyhistory.json· badge/badges/pleo.svg· changes feed/feeds/tools/pleo.xml - Markdown
/tools/pleo.md· slim/tools/pleo.min.md(or sendAccept: text/markdown) - Fix list
/fixes/pleo.md·/fixes/pleo.json - From a terminal
anchor tool pleo --md(the CLI) · over MCPget_tool {"slug": "pleo"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/pleo"><img src="https://www.anchorterminal.com/badges/pleo.svg" alt="Pleo API + MCP on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/pleo)<a href="https://www.anchorterminal.com/tools/pleo">Pleo API + MCP on Anchor Terminal</a>It counts on a page on pleo.io or one of its subdomains.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "pleo", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
