# Pleo API + MCP > Spend management platform from Pleo Technologies A/S in Copenhagen, covering company cards, expenses, reimbursements, invoices and accounting exports. Outside agents reach it through a hosted MCP server for expense work and a REST API built for accounting integrations. - Canonical: https://www.anchorterminal.com/tools/pleo - Markdown: https://www.anchorterminal.com/tools/pleo.md (~8,000 tokens) - Slim: https://www.anchorterminal.com/tools/pleo.min.md (~2,080 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/pleo.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 62.9/100 · rank #293 of 629 · #1 in Spend management & procurement · not agent-ready · confidence medium** ## Assessment The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found. ## Facts | Field | Value | | --- | --- | | Vendor | Pleo Technologies A/S (https://www.pleo.io/en) | | Kind | HTTP API | | Category | Spend management & procurement (https://www.anchorterminal.com/categories/spend-management) | | Transport | HTTP, Streamable HTTP | | Endpoint | `https://external.pleo.io` | | Auth | OAuth or key · A person signs in for every route. The MCP server uses OAuth 2.0 in a browser (authorisation code with PKCE, dynamic client registration, no keys to configure) and acts with the connecting user's Pleo role, once a company admin has enabled MCP access for that entity. The External API accepts OAuth 2.0 bearer tokens with resource scopes for partner integrations, whose client ID and secret Pleo issues after review in its Early Access Programme. A single company can use a Standalone API Key with chosen scopes and an expiry, sent as the Basic auth username, but only after Pleo support or a Customer Success Manager enables keys for the organisation. | | Pricing | Paid (Paid) · Per-user plans, with no separate charge for the API or the MCP server. The pricing page shown to a UK visitor lists Start at £8 per user per month, Build at £14 and Optimise at £18, the last two cheaper billed yearly and with a three-user minimum. MCP is listed on Optimise only, which is sold through a demo. Start and Build have a Try for free button and the signup form states 21 days free. Whether the trial needs a payment card isn't stated. A staging environment with test data exists for customers with API keys enabled and for approved partners. Fees for payments and foreign exchange are extra (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-08). | | Licence | Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms | | Docs | https://developers.pleo.io/ | | llms.txt | https://developers.pleo.io/llms.txt | | Last release | 2026-10-02 | | Surfaces | Pleo MCP server (https://mcp.pleo.io/mcp, Streamable HTTP) for expense work by a signed-in user, and the External API (https://external.pleo.io) for accounting integrations. The Legacy API at openapi.pleo.io is deprecated | | MCP scope | Search and read expenses, set categories, tags and tax codes, split an expense, add notes and attendees, attach receipts, review and approve, and add expenses to the export queue. No company configuration, payments, card changes or limit changes | | External API | Eleven current OpenAPI 3.0.1 specs, 162 operations. Accounting entries and receipts (read), enrichment (attach a receipt), export jobs and items (v1 to v3), tags, tax codes, chart of accounts, bookkeeping categories, vendors, employees and companies (read), teams, webhook subscriptions and app marketplace installations | | Access | MCP needs the Optimise plan per the pricing page and an admin opt-in per entity. Standalone API keys are enabled on request by Pleo support. Partner OAuth clients are issued after review in the Early Access Programme, staging first | | Credentials | MCP uses OAuth authorisation code with PKCE (S256), refresh tokens and dynamic client registration, with one scope named authenticated. API uses OAuth 2.0 bearer tokens with resource scopes such as export-jobs:read, or a scoped API key with an expiry sent as the Basic auth username | | Token lifetimes | Access token lifetime is given in expires_in. Refresh tokens last at least 60 days and rotate on use. Reusing an expired refresh token invalidates every refresh token for that authorisation | | Rate limits | 600 requests a minute per credential, shared across all endpoints and methods. The docs suggest targeting 500. No separate limit is documented for the MCP server | | Pagination | Cursor (`before`, `after`, `limit`) and offset (`offset`, `limit`) styles, with `sorting_keys` and `sorting_order`. Responses carry `hasNextPage`, `startCursor` and `endCursor` | | Errors | JSON body with a `type` code and a `message`, such as MISSING_CONTRA_ACCOUNTS (400) or EXPORT_ALREADY_IN_PROGRESS (409). Every response carries a request-Id header for support | | Webhooks | Subscriptions API with two documented events, export job created and vendor created, signed with webhook-id, webhook-timestamp and webhook-signature headers | | Sandbox | Staging at https://external.staging.pleo.io and https://mcp.staging.pleo.io/mcp with test data. Customers with keys enabled can create a staging key directly. Partners get staging through the Early Access Programme | | Plans | Start £8 per user per month, billed monthly. Build £14 monthly or £12 billed yearly. Optimise £18 monthly or £16 billed yearly. Build and Optimise have a three-user minimum. GBP prices as shown to a UK visitor on 8 October 2026 | | Audit | Changes made through the MCP appear in Pleo's activity and audit logs and in the Activity tab of the expense. Users see and revoke connected clients under My Account, Security and Devices, MCP Connections | | Security programme | Vulnerability disclosure policy with safe harbour (security-vd@pleo.io), a bug bounty on HackerOne, PCI-DSS and Google's CASA per the trust page. Compliance reports are shared under NDA on request | | Data location | Customer data is stored and processed in AWS Ireland (eu-west-1) per the trust page. The sub-processor list names each provider's location | | Status | status.pleo.io on incident.io, 25 components, among them Pleo API, Transactions, Card, E-money Account and 15 accounting integrations | | Capabilities | spend.transactions, spend.expenses, spend.bills | | Tags | official, hosted, mcp, oauth, api-key, openapi, llms-txt, webhooks, closed-source, status-page, bug-bounty, sandbox | | JSON | https://www.anchorterminal.com/api/v1/tools/pleo.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 71 | 14.2 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 82 | 13.3 | | Agent ergonomics | 13% | 16.2 | 55 | 8.9 | | Security & auth | 14% | 17.5 | 71 | 12.4 | | Payments & pricing | 10% | 12.5 | 15 | 1.9 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 64 | 5.6 | | Transparency & trust (editorial 63, provenance 87) | 7% | 8.8 | 75 | 6.6 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **62.9 → B** | ### Why each score - Reliability 71: Read with the hosted lines and scored on the MCP server and the External API together. status.pleo.io on incident.io has 25 components with incident history, among them Pleo API (20). From 10 July to 8 October 2026 the page lists two incidents, both marked minor and neither on the Pleo API component. Card transactions failed intermittently for about 2 hours 30 minutes on 15 July during a Mastercard authentication fault, and instant top-up in Sweden was impaired from 10 to 15 September (20). One limit is published, 600 requests a minute per credential across all endpoints. No limit is documented for the MCP server (15). The docs tell clients to wait for Retry-After when present, otherwise back off from one second, and say which steps are unsafe to repeat after a 429. There is no Idempotency-Key header, and the OpenAPI specs don't declare 429 (11 of 15). No SLA found in the API terms or the UK Master Service Agreement (0). The API terms describe the API as a beta version, and the specs include /v0 and /v1-beta paths. The MCP server carries no beta label (5 of 10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 82: Eleven current OpenAPI 3.0.1 specs with 162 operations, linked from llms.txt, plus a spec for the deprecated Legacy API (25). llms.txt, llms-full.txt and a Markdown copy of every docs page at the same URL with .md (10). 107 of 162 operations carry a description, and long guides explain when each export and sync step applies. The MCP server has no public tool reference, only prose on what it can do, so its tool descriptions couldn't be read without a customer sign-in. Three specs carry internal titles (Gjoll, Oberon, Triton) (11 of 20). The specs hold 86 enums and required lists, and search endpoints take typed filter bodies. MCP input schemas are unread (11 of 15). 463 examples across the specs and typed error examples such as MISSING_CONTRA_ACCOUNTS and INVALID_TARGET_SYSTEM. 77 operations declare only a default error response and none declares 429 (11 of 15). Path versions, with Export API v1 to v3 documented side by side, and a public changelog of 56 dated entries back to November 2024. The current API has no written versioning policy (14 of 15). - Agent ergonomics 55: The MCP tool count and definitions aren't published, so context cost couldn't be measured. On the API, `limit` sizes a page and aggregated endpoints return tag groups and category groups in one call, with no field selection (13 of 25). Cursor and offset pagination with sorting keys, and search endpoints with filters for accounting entries, receipts, tags, vendors and employees. Two pagination styles are in use (17 of 20). Errors carry a `type` code and a message, and every response has a request-Id header. The general error page lists seven statuses with generic fixes and leaves out 409, 422 and 429 (13 of 20). No Idempotency-Key. The docs ask integrators to make their own processing idempotent, and export jobs can be resumed. MCP readOnlyHint and destructiveHint annotations couldn't be read (7 of 20). List calls need few parameters. No official SDK was found, only a Postman collection and two community libraries named for the Legacy API (5 of 15). - Security & auth 71: The MCP server uses OAuth authorisation code with PKCE (S256), refresh tokens and dynamic client registration, with a single scope and the connecting user's Pleo role as the real boundary. The API uses OAuth 2.0 with resource scopes and rotating refresh tokens, or API keys with chosen scopes and an expiry, sent in the Authorization header (28 of 30). Read and write are separate API scopes. MCP access is off until an admin enables it per entity, can't be limited to named users yet, and has no read-only mode. Payments, card changes and limit changes are blocked through the MCP by design. Confirmation before a write is left to the AI client (15 of 20). Merchant names, notes and receipts are untrusted text. The docs say to review significant output and recommend approval for write tools, with no guidance on injected content (5 of 15). Changes made through the MCP appear in Pleo's activity and audit logs, and users can list and revoke MCP connections. No call log for API keys was found (10 of 15). A disclosure policy with safe harbour, a HackerOne bug bounty, PCI-DSS and Google's CASA per the trust page. No SOC 2 or ISO 27001 is claimed, reports are shared under NDA, and security.txt returns 403 (13 of 20). - Payments & pricing 15: Read with the hosted rubric. No x402, MPP or L402 (0). Per-user plan prices are public (£8, £14 and £18 a month as shown to a UK visitor), with no per-call price for the API or MCP (10). The signup form states 21 days free on Start and Build, but the pricing page lists MCP on Optimise only, which is sold through a demo, and API keys need enabling by Pleo support. Whether the trial needs a card isn't stated. Partial credit (5 of 20). A person signs in with OAuth in a browser or creates a key in the web app, and Pleo issues partner OAuth clients after review (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 64: The newest changelog entry is 2 October 2026, a new Teams API (30). Sixteen dated entries between 15 July and 2 October 2026, among them the MCP documentation on 17 August and Export API v3 additions (20). Closed service with a dated changelog, api@pleo.io for partners and Pleo support for customers. The docs say custom implementation support is generally not given, and response times couldn't be observed (9 of 15). No official SDK was found, the MCP server isn't in the official MCP registry, and the docs say Pleo isn't in Claude's connector directory yet (0). No packages to assess. The published specs carry current version numbers and match the changelog (5 of 10). - Transparency & trust 75: Closed service with public API terms naming Pleo Technologies A/S, a Master Service Agreement and separate AI Access Terms for the MCP. The API terms carry no date and let Pleo discontinue the API at any time (14 of 30). A privacy notice dated June 2026, a DPA of 14 October 2025 and a trust page placing customer data in AWS Ireland agree with each other. Pleo's MCP page says it doesn't use customer data to train AI models. Retention for customer data is stated only as long as there is a valid purpose or legal requirement, with no periods (20 of 30). The Legacy API is deprecated with migration guides, but no end-of-life date is published, and replacements listed for Q3 2026 (a SCIM API and wallet balance) weren't in the docs index on 8 October. Changes to the API terms take effect no sooner than 30 days after posting (9 of 20). A public sub-processor list with each provider's role and location, and 30 days' notice of new sub-processors in the DPA (20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/pleo.md (JSON https://www.anchorterminal.com/fixes/pleo.json) ### What we couldn't check - unchecked: MCP tool names, input schemas, annotations and count. tools/list needs a signed-in Pleo customer and we didn't register a client - unchecked: whether the 21-day trial needs a payment card, and whether a trial company can use the MCP server or API keys - unchecked: prices in USD. The pricing page showed GBP to our UK fetch, so unitPrices is empty - Whether Standalone API Keys are tied to a plan. The pricing page lists MCP by plan but doesn't mention the API - Whether the SCIM API and the wallet balance replacement, both listed for Q3 2026, have shipped - Whether a rate limit applies to the MCP server, and what its errors look like - unchecked: the HackerOne programme's scope and rewards. The trust page states the programme exists and we didn't read the HackerOne page - Whether an SLA exists in order forms for larger customers ### Sources - developer docs index (llms.txt): (seen 2026-10-08) - Pleo MCP overview: (seen 2026-10-08) - Pleo MCP capabilities: (seen 2026-10-08) - Pleo MCP access and permissions: (seen 2026-10-08) - Pleo MCP FAQs: (seen 2026-10-08) - custom MCP install, URLs and transport: (seen 2026-10-08) - MCP OAuth metadata: (seen 2026-10-08) - API base URLs, authentication and rate limits: (seen 2026-10-08) - Standalone API Keys overview: (seen 2026-10-08) - Early Access Programme: (seen 2026-10-08) - OAuth tokens overview: (seen 2026-10-08) - pagination: (seen 2026-10-08) - API response codes and errors: (seen 2026-10-08) - Export API OpenAPI spec: (seen 2026-10-08) - changelog: (seen 2026-10-08) - API deprecation notice: (seen 2026-10-08) - API Terms of Service: (seen 2026-10-08) - pricing: (seen 2026-10-08) - MCP product page and FAQ: (seen 2026-10-08) - AI Access Terms: (seen 2026-10-08) - trust and security: (seen 2026-10-08) - vulnerability disclosure policy: (seen 2026-10-08) - sub-processors: (seen 2026-10-08) - privacy notice: (seen 2026-10-08) - Data Processing Agreement: (seen 2026-10-08) - UK Master Service Agreement: (seen 2026-10-08) - status incidents: (seen 2026-10-08) - status history feed: (seen 2026-10-08) - official MCP registry search: (seen 2026-10-08) - domain registration (RDAP): (seen 2026-10-08) ## Who's behind it (provenance 87/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Pleo Technologies A/S | 20/20 | | Domain age | pleo.io, registered 2015-10-07 (11 years) | 15/15 | | Endpoint on the vendor's domain | external.pleo.io | 15/15 | | Terms of service | read, states 4 of the 7 things a reader expects | 7.4/10 | | Privacy policy | published | 10/10 | | Status page | status.pleo.io | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The website footer names Pleo Technologies A/S (36538686), Ravnsborg Tværgade 5C, 2200 København N, Denmark. UK payment services come from Pleo Financial Services UK Ltd, FCA firm reference 1020730, company number 15842283. The API Terms of Service on the developer portal name Pleo Technologies A/S, carry no date, and describe the API as a beta version. The UK Master Service Agreement has an effective date of 7 September 2026 and is governed by the laws of England and Wales. The API answers at external.pleo.io and the MCP server at mcp.pleo.io, both pleo.io subdomains. The MCP host publishes its OAuth metadata at https://mcp.pleo.io/.well-known/oauth-authorization-server www.pleo.io/.well-known/security.txt and pleo.io/.well-known/security.txt both return 403 with an AccessDenied body. The vulnerability disclosure policy gives security-vd@pleo.io as the reporting address. The privacy notice is dated June 2026 and the Data Processing Agreement 14 October 2025. An AI Access Terms document covers the MCP server. RDAP from the .io registry gives a registration date of 2015-10-07 for pleo.io. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://developers.pleo.io/page/terms-of-service), read 2026-10-08, gives no date, states 4 of the 7 things a reader expects. - To know. Says access can be ended without notice or for any reason. "Pleo reserves the right to discontinue the API or any portion or feature or the access thereto for any reason and at any time without liability or other obligation to you." - Not found in the text. Gives the date it was last updated. - Not found in the text. Names the governing law or courts. - Says how changes to the terms are announced. Says it gives notice of a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). The API is described as a beta version still in development, supplied as is with no commitment on reliability or availability. "THE API IS A BETA VERSION AND IS STILL BEING DEVELOPED, TESTED AND EVALUATED." - Also in the text (2026-10-08). Pleo reserves the right to introduce fees and payment terms for any use of the API. "Pleo reserves the right to implement fees and payment terms with respect to any use of the Pleo API." - Also in the text (2026-10-08). The customer agrees that Pleo may monitor API use to check quality, improve its products and verify compliance with the terms. "THE CUSTOMER AGREES THAT PLEO TECHNOLOGIES A/S MAY MONITOR USE OF THE API TO ENSURE QUALITY, IMPROVE PLEO TECHNOLOGIES A/S (AND ITS AFFILIATES’) PRODUCTS AND SERVICES, AND VERIFY YOUR COMPLIANCE WITH THE TERMS." **Privacy policy** (https://www.pleo.io/legal-documents/pleo-privacy-policy-en.pdf), not read yet. ## Live (updated 2026-10-08 19:08 UTC) - Right now: up, HTTP 403, 72 ms, checked 2026-10-08 19:08 UTC (get on `https://external.pleo.io`, asks for auth) - Uptime 24h 100.0% (42 probes) · 30 days 100.0% (42 probes) · p50 88 ms · p95 163 ms - Vendor status page: none, All Systems Operational - security.txt: unknown - Watching changelog - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/pleo.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - MCP server at mcp.pleo.io/mcp uses OAuth with PKCE and dynamic client registration, and acts with the connecting user's Pleo permissions - Payments, card changes and spending-limit changes are blocked through the MCP by design, per the AI Access Terms - Eleven current OpenAPI 3.0.1 specs with 162 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page - One documented rate limit of 600 requests a minute per credential, with written 429 and Retry-After guidance - Staging hosts for both the API (external.staging.pleo.io) and the MCP server (mcp.staging.pleo.io/mcp) - Sub-processor list with locations, customer data in AWS Ireland, and 30 days' notice of new sub-processors in the DPA ## Weaknesses - The pricing page lists MCP on the Optimise plan only (£18 per user per month, three users minimum, sold through a demo) - MCP tool names, schemas and count aren't published, so they can't be read without a customer sign-in - Standalone API keys aren't self-service. Pleo support or a Customer Success Manager enables them, and partner OAuth clients go through a reviewed programme - No Idempotency-Key header, no official SDK and no entry in the official MCP registry - The API terms call the API a beta version that Pleo may discontinue at any time, and no SLA was found - No end-of-life date is published for the deprecated Legacy API, and its Q3 2026 replacements for employee writes and wallet balance aren't in the docs ## Before you call it (notes for agents) 1. Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default 2. Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist 3. Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side 4. Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there 5. Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second 6. Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in ## Connect First request: ```bash curl --request GET \ -u "YOUR-API-KEY:" \ -H "Accept: application/json;charset=UTF-8" \ "https://external.staging.pleo.io/v2/employees" ``` Claude Code: ```bash claude mcp add --transport http pleo-mcp-staging https://mcp.staging.pleo.io/mcp ``` MCP client configuration: ```json { "mcpServers": { "pleo": { "url": "https://mcp.pleo.io/mcp" } } } ``` Through letme (picks today, calling later): https://letme.dev/pleo (letme picks it for spend.bills, the top-graded tool for the job, letme picks it for spend.expenses, the top-graded tool for the job, letme picks it for spend.transactions, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Spendesk API + MCP | B | 62.3 | 306 | spend.transactions, spend.expenses, spend.bills | no | https://www.anchorterminal.com/tools/spendesk.md | | Brex | C | 60.7 | 345 | spend.transactions, spend.expenses, spend.bills | no | https://www.anchorterminal.com/tools/brex.md | | Ramp | C | 57.3 | 423 | spend.transactions, spend.expenses, spend.bills | no | https://www.anchorterminal.com/tools/ramp.md | | Expensify | E | 41.1 | 593 | spend.transactions, spend.expenses | no | https://www.anchorterminal.com/tools/expensify.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The Pleo MCP server is a remote Streamable HTTP endpoint at https://mcp.pleo.io/mcp with a staging twin at https://mcp.staging.pleo.io/mcp, and signs users in with OAuth in a browser (source: ) - MCP access is off by default and enabled per entity by a company admin. Per-user enablement is not available yet, per the FAQ (source: ) - The AI Access Terms say no agent can initiate payments or move money, issue, freeze or change cards, or change spending limits through the MCP (source: ) - The pricing page lists MCP as included on Optimise and not included on Start or Build (source: ) - Standalone API Keys are not self-service. A Customer Success Manager or Pleo Support enables them, and partner integrations register through the Early Access Programme with OAuth 2.0 (source: ) - All Pleo APIs share one limit of 600 requests a minute per credential, across endpoints and methods (source: ) - The Legacy API at openapi.pleo.io is deprecated with no end-of-life date published. Replacements for adding or removing users (a SCIM API) and for the wallet balance are listed for Q3 2026 (source: ) - Pleo lists Anthropic among its sub-processors for AI-product enablement, with processing in the US (source: ) ## Compare - [Brex vs Pleo API + MCP](https://www.anchorterminal.com/compare/brex-vs-pleo.md): C 60.7 vs B 62.9 - [Expensify vs Pleo API + MCP](https://www.anchorterminal.com/compare/expensify-vs-pleo.md): E 41.1 vs B 62.9 - [Pleo API + MCP vs Ramp](https://www.anchorterminal.com/compare/pleo-vs-ramp.md): B 62.9 vs C 57.3 - [Pleo API + MCP vs Spendesk API + MCP](https://www.anchorterminal.com/compare/pleo-vs-spendesk.md): B 62.9 vs B 62.3 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on pleo.io or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "pleo", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Pleo API + MCP on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Pleo API + MCP on Anchor Terminal](https://www.anchorterminal.com/badges/pleo.svg)](https://www.anchorterminal.com/tools/pleo) ``` Plain link: ```html Pleo API + MCP on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Pleo API + MCP is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/pleo-dark.png - Light: https://www.anchorterminal.com/assets/share/pleo-light.png