# Ramp (slim) > Ramp is a finance platform with company cards, expense management, bill pay, procurement and travel. Its Developer API reads and writes transactions, receipts, funds, bills and purchase orders. A hosted MCP server and CLI work with the signed-in user's permissions. - Full: https://www.anchorterminal.com/tools/ramp.md (~7,300 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/ramp.json · canonical https://www.anchorterminal.com/tools/ramp - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 57.3/100 · rank #423 of 629 · #4 in Spend management & procurement · not agent-ready · confidence medium** Assessment: OAuth 2.0 scopes split read from write across about 40 resources, a 260-operation OpenAPI spec is public, and an audit log endpoint records actions by user and agent. No public status page was found, 89 operations are marked beta, the API Agreement allows changes without notice, and idempotency keys cover only eight write operations. ## Facts - Kind: HTTP API · vendor: Ramp Business Corporation · category: Spend management & procurement · legal entity: Ramp Business Corporation · provenance 84/100 - Endpoint: `https://api.ramp.com` (HTTP) - Auth: OAuth · pricing: Freemium · x402: no · licence: Proprietary service under the Ramp Platform Agreement and the API Agreement. The ramp-cli repository is MIT - Probe metrics: not measured yet (probes haven't run) - API: Developer API v1 at https://api.ramp.com (sandbox https://demo-api.ramp.com), one OpenAPI 3.0.2 spec, 260 operations, 89 marked beta and 51 marked as needing the Plus plan - MCP servers: Ramp MCP at https://mcp.ramp.com/mcp (demo data at https://demo-mcp.ramp.com/mcp), OAuth with PKCE under the signed-in user's permissions, described as subject to change. Developer MCP at https://mcp.ramp.com/developer/mcp, no sign-in, docs only. The tool count isn't published. The CLI's bundled spec marks 120 operations for MCP - CLI: ramp-cli, MIT, v0.2.54 on 6 October 2026, Python 3.11 or later, installed by script or Homebrew. JSON output in agent mode, a dry-run flag, sandbox by default - Credentials: OAuth 2.0. Client credentials tokens last 10 days with no refresh. Authorisation code tokens default to 1 hour with optional refresh. Revoke at POST /developer/v1/token/revoke - Scopes: About 80 in the spec in `resource:read` and `resource:write` form, such as transactions:read, receipts:write, funds:write, bills:write and purchase_orders:write. `cards:read_vault` needs a production review - Rate limits: 200 requests per rolling 10 seconds per source IP. 60-second request timeout (504). Higher limits by support ticket - Pagination: Keyset, with the next page as a full URL in `next`. `page_size` default 20, maximum 100 - Errors: `error_v2` with `error_code`, `message`, `additional_info` and `error_id`, and an `x-trace-id` header on every response - Idempotency: `X-Idempotency-Key` on 8 of 155 write operations (funds, procurement requests, vault cards, accounting syncs, agreement documents) - Webhooks: HMAC-SHA256 signature in `X-Ramp-Signature`, up to 10 delivery attempts on 429 and 5xx with a constant event ID, 10-second timeout - Sandbox: demo.ramp.com and demo-api.ramp.com, on request. No real money moves, and demo actions create transactions and mark bills paid - Audit: GET /developer/v1/audit-logs/events with filters by user, date, event type and actor type (Plus plan) - Certifications: SOC 1 Type 2, SOC 2 Type 2, ISO 27001:2022, ISO/IEC 42001:2023 and PCI DSS per trust.ramp.com, with reports behind an access request and NDA - Agent payments: Agent Cards, Stripe MPP and x402 from a separately funded wallet, for an agent paying other sellers on the connected user's behalf - Prices: Free plan free per seat per month; Plus plan $15 per seat per month - Scores: Reliability 30, Performance pending, Schema & documentation 86, Agent ergonomics 66, Security & auth 79, Payments & pricing 25, Task success pending, Maintenance & community 74, Transparency & trust 70 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the Developer API, the surface an outside agent calls with a token. · Schema & documentation, A public OpenAPI 3.0.2 spec with 260 operations at docs.ramp.com/openapi/developer-api.json (25). · Agent ergonomics, `page_size` sizes a page (default 20, maximum 100) and `functional_currency_amount` is opt-in on transactions. · Security & auth, OAuth 2.0 with client credentials or the authorisation code grant, about 80 scopes in the spec in `resource:read` and `resource:write` form… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The changelog's latest entry is 7 October 2026, and ramp-cli v0.2.54 was tagged on 6 October (30). · Transparency & trust, Closed service with terms at stable URLs, the Platform Agreement (updated 22 September 2026) and the API Agreement (26 March 2026). - Sources: 24, open questions: 10, both in the full twin - Capabilities: spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement - JSON: https://www.anchorterminal.com/api/v1/tools/ramp.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/ramp.svg` or a link to https://www.anchorterminal.com/tools/ramp from a page on ramp.com or one of its subdomains, or the README of github.com/ramp-public/ramp-cli, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `scope` on the client credentials token request. Without it Ramp issues a token with no scopes and every resource call fails with 403 2. Follow the full URL in `next` to page. `page_size` defaults to 20 and stops at 100, and the cursor is opaque 3. Stay under 200 requests in any 10 seconds per source IP and back off 1, 2 then 4 seconds on 429. No Retry-After header is documented 4. Don't use `synced_after` or `from_created_at` to find changed records. Bills and transactions have no updated-at filter, so subscribe to webhooks 5. Send `X-Idempotency-Key` when creating funds or procurement requests. Elsewhere a retried POST can create a duplicate, so read back before retrying ## Connect ```bash curl -fsSL https://agents.ramp.com/install.sh | sh ``` ```bash curl https://api.ramp.com/developer/v1/transactions \ -H "Authorization: Bearer $RAMP_ACCESS_TOKEN" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/ramp ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Spendesk API + MCP | B | 62.3 | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | https://www.anchorterminal.com/tools/spendesk.min.md | | Brex | C | 60.7 | spend.transactions, spend.expenses, spend.cards, spend.bills | https://www.anchorterminal.com/tools/brex.min.md | | Pleo API + MCP | B | 62.9 | spend.transactions, spend.expenses, spend.bills | https://www.anchorterminal.com/tools/pleo.min.md | | Expensify | E | 41.1 | spend.transactions, spend.expenses | https://www.anchorterminal.com/tools/expensify.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)