# Pleo API + MCP (slim) > Spend management platform from Pleo Technologies A/S in Copenhagen, covering company cards, expenses, reimbursements, invoices and accounting exports. Outside agents reach it through a hosted MCP server for expense work and a REST API built for accounting integrations. - Full: https://www.anchorterminal.com/tools/pleo.md (~8,000 tokens) · this version ~2,080 tokens · JSON https://www.anchorterminal.com/tools/pleo.json · canonical https://www.anchorterminal.com/tools/pleo - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 62.9/100 · rank #293 of 629 · #1 in Spend management & procurement · not agent-ready · confidence medium** Assessment: The hosted MCP server acts with the connecting user's own Pleo permissions, is off until an admin enables it per entity, and can't move money, change cards or alter limits. It is listed only on the Optimise plan, its tool definitions aren't published, API keys need enabling by Pleo support, and no official SDK or SLA was found. ## Facts - Kind: HTTP API · vendor: Pleo Technologies A/S · category: Spend management & procurement · legal entity: Pleo Technologies A/S · provenance 87/100 - Endpoint: `https://external.pleo.io` (HTTP, Streamable HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under Pleo's Master Service Agreement, API Terms of Service and AI Access Terms - Probe metrics: not measured yet (probes haven't run) - Surfaces: Pleo MCP server (https://mcp.pleo.io/mcp, Streamable HTTP) for expense work by a signed-in user, and the External API (https://external.pleo.io) for accounting integrations. The Legacy API at openapi.pleo.io is deprecated - MCP scope: Search and read expenses, set categories, tags and tax codes, split an expense, add notes and attendees, attach receipts, review and approve, and add expenses to the export queue. No company configuration, payments, card changes or limit changes - External API: Eleven current OpenAPI 3.0.1 specs, 162 operations. Accounting entries and receipts (read), enrichment (attach a receipt), export jobs and items (v1 to v3), tags, tax codes, chart of accounts, bookkeeping categories, vendors, employees and companies (read), teams, webhook subscriptions and app marketplace installations - Access: MCP needs the Optimise plan per the pricing page and an admin opt-in per entity. Standalone API keys are enabled on request by Pleo support. Partner OAuth clients are issued after review in the Early Access Programme, staging first - Credentials: MCP uses OAuth authorisation code with PKCE (S256), refresh tokens and dynamic client registration, with one scope named authenticated. API uses OAuth 2.0 bearer tokens with resource scopes such as export-jobs:read, or a scoped API key with an expiry sent as the Basic auth username - Token lifetimes: Access token lifetime is given in expires_in. Refresh tokens last at least 60 days and rotate on use. Reusing an expired refresh token invalidates every refresh token for that authorisation - Rate limits: 600 requests a minute per credential, shared across all endpoints and methods. The docs suggest targeting 500. No separate limit is documented for the MCP server - Pagination: Cursor (`before`, `after`, `limit`) and offset (`offset`, `limit`) styles, with `sorting_keys` and `sorting_order`. Responses carry `hasNextPage`, `startCursor` and `endCursor` - Errors: JSON body with a `type` code and a `message`, such as MISSING_CONTRA_ACCOUNTS (400) or EXPORT_ALREADY_IN_PROGRESS (409). Every response carries a request-Id header for support - Webhooks: Subscriptions API with two documented events, export job created and vendor created, signed with webhook-id, webhook-timestamp and webhook-signature headers - Sandbox: Staging at https://external.staging.pleo.io and https://mcp.staging.pleo.io/mcp with test data. Customers with keys enabled can create a staging key directly. Partners get staging through the Early Access Programme - Plans: Start £8 per user per month, billed monthly. Build £14 monthly or £12 billed yearly. Optimise £18 monthly or £16 billed yearly. Build and Optimise have a three-user minimum. GBP prices as shown to a UK visitor on 8 October 2026 - Audit: Changes made through the MCP appear in Pleo's activity and audit logs and in the Activity tab of the expense. Users see and revoke connected clients under My Account, Security and Devices, MCP Connections - Security programme: Vulnerability disclosure policy with safe harbour (security-vd@pleo.io), a bug bounty on HackerOne, PCI-DSS and Google's CASA per the trust page. Compliance reports are shared under NDA on request - Data location: Customer data is stored and processed in AWS Ireland (eu-west-1) per the trust page. The sub-processor list names each provider's location - Status: status.pleo.io on incident.io, 25 components, among them Pleo API, Transactions, Card, E-money Account and 15 accounting integrations - Scores: Reliability 71, Performance pending, Schema & documentation 82, Agent ergonomics 55, Security & auth 71, Payments & pricing 15, Task success pending, Maintenance & community 64, Transparency & trust 75 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the MCP server and the External API together. · Schema & documentation, Eleven current OpenAPI 3.0.1 specs with 162 operations, linked from llms.txt, plus a spec for the deprecated Legacy API (25). · Agent ergonomics, The MCP tool count and definitions aren't published, so context cost couldn't be measured. · Security & auth, The MCP server uses OAuth authorisation code with PKCE (S256), refresh tokens and dynamic client registration, with a single scope and the c… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The newest changelog entry is 2 October 2026, a new Teams API (30). · Transparency & trust, Closed service with public API terms naming Pleo Technologies A/S, a Master Service Agreement and separate AI Access Terms for the MCP. - Sources: 30, open questions: 8, both in the full twin - Capabilities: spend.transactions, spend.expenses, spend.bills - JSON: https://www.anchorterminal.com/api/v1/tools/pleo.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/pleo.svg` or a link to https://www.anchorterminal.com/tools/pleo from a page on pleo.io or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Ask a company admin to enable Pleo MCP access under Settings, General, Pleo AI for each entity before connecting. It is off by default 2. Name the entity in every request when working outside the default one. Each MCP request targets one entity and the choice doesn't persist 3. Set the AI client to require approval for Pleo write tools. Pleo leaves confirmation to the client and doesn't enforce it server-side 4. Send API keys as the Basic auth username with an empty password to external.pleo.io. Legacy tokens for openapi.pleo.io don't work there 5. Budget every endpoint against one bucket of 600 requests a minute per credential, and on 429 wait for Retry-After or back off from one second 6. Swap mcp.staging.pleo.io for mcp.pleo.io in the Claude Code command when moving from staging to production. Each needs its own OAuth sign-in ## Connect ```bash curl --request GET \ -u "YOUR-API-KEY:" \ -H "Accept: application/json;charset=UTF-8" \ "https://external.staging.pleo.io/v2/employees" ``` ```bash claude mcp add --transport http pleo-mcp-staging https://mcp.staging.pleo.io/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/pleo ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Spendesk API + MCP | B | 62.3 | spend.transactions, spend.expenses, spend.bills | https://www.anchorterminal.com/tools/spendesk.min.md | | Brex | C | 60.7 | spend.transactions, spend.expenses, spend.bills | https://www.anchorterminal.com/tools/brex.min.md | | Ramp | C | 57.3 | spend.transactions, spend.expenses, spend.bills | https://www.anchorterminal.com/tools/ramp.min.md | | Expensify | E | 41.1 | spend.transactions, spend.expenses | https://www.anchorterminal.com/tools/expensify.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)