{
  "data": {
    "similar": [
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/ramp.json",
        "name": "Ramp",
        "score": 57.3,
        "shared": [
          "spend.transactions",
          "spend.expenses",
          "spend.cards",
          "spend.bills",
          "spend.procurement"
        ],
        "slug": "ramp"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/brex.json",
        "name": "Brex",
        "score": 60.7,
        "shared": [
          "spend.transactions",
          "spend.expenses",
          "spend.cards",
          "spend.bills"
        ],
        "slug": "brex"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/pleo.json",
        "name": "Pleo API + MCP",
        "score": 62.9,
        "shared": [
          "spend.transactions",
          "spend.expenses",
          "spend.bills"
        ],
        "slug": "pleo"
      },
      {
        "grade": "E",
        "json": "https://www.anchorterminal.com/tools/expensify.json",
        "name": "Expensify",
        "score": 41.1,
        "shared": [
          "spend.transactions",
          "spend.expenses"
        ],
        "slug": "expensify"
      }
    ],
    "tool": {
      "slug": "spendesk",
      "name": "Spendesk API + MCP",
      "vendor": "Spendesk SAS",
      "vendorUrl": "https://www.spendesk.com",
      "kind": "http-api",
      "category": "spend-management",
      "summary": "Spend management platform from Spendesk SAS in Paris, covering company cards, expense claims, supplier invoices, purchase orders and accounting exports. Outside agents reach it through a REST API with scoped keys or OAuth, and a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/spendesk",
      "markdownUrl": "https://www.anchorterminal.com/tools/spendesk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/spendesk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/spendesk.json",
      "license": "Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://public-api.spendesk.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is granted by Spendesk, not self-serve. A customer asks its Spendesk representative for API access, then an Account Owner or Admin creates an API key (client ID and secret) with chosen scopes and an expiry of up to one year. The key is exchanged at POST /v1/auth/token with HTTP Basic for a Bearer token that lasts 60 minutes and can carry fewer scopes than the key. Partner integrations use OAuth 2.0 authorisation code with PKCE after approval by the partnerships team. The MCP server accepts only OAuth user tokens, refuses API keys, and limits use to Controllers and Account Owners. Experimental scopes are added on request.",
      "pricing": "paid",
      "pricingNotes": "No public prices. The pricing page describes a fixed monthly platform fee plus variable fees per transaction (card purchases, invoice payments and expense claims) and asks for a quote. It lists the open API and the MCP connection in the base package. No free tier, trial or self-serve sandbox was found. A demo environment exists at public-api.demo.spendesk.com, with credentials requested alongside API access (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI definition or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 62,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.spendesk.com",
      "llmsTxt": "https://developer.spendesk.com/llms.txt",
      "openapi": "https://developer.spendesk.com/openapi/spendesk-public-api.json",
      "capabilities": [
        "spend.transactions",
        "spend.expenses",
        "spend.cards",
        "spend.bills",
        "spend.procurement"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "api-key",
        "oauth",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "sales-led",
        "status-page",
        "iso27001",
        "bug-bounty"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.3,
        "grade": "B",
        "agentReady": false,
        "rank": 306,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 55,
            "points": 11,
            "reason": "Read with the hosted lines and scored on the public REST API and the MCP server on the same host. status.spendesk.com on Atlassian Statuspage has components by product area with incident history, though none for the public API (20). From 10 July to 8 October 2026 the page lists eleven incidents, three marked critical and three major. Platform access and latency failed for about 1 hour 55 minutes on 2 September, sign-in to the application for about 59 minutes on 29 September, and international transfers in the EEA for about 22 hours from 16 September. No entry says whether the API was affected, so we scored it between one major outage and several (5). Limits are published as 1,000 requests a minute per company and credential and 500 concurrent requests (15). Every response carries x-ratelimit-limit, remaining and reset headers and the docs give pacing guidance, but an Idempotency-Key exists only for creating an intake and Retry-After is documented on one endpoint (10). The docs say the team attempts to guarantee 99 per cent availability, which is a target and not a published SLA (0). The read API is generally available, while cards, transactions, invoices, purchase orders, webhooks and MCP write actions are experimental or beta (5)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 87,
            "points": 14.14,
            "reason": "A public OpenAPI 3.1 definition with 106 operations at developer.spendesk.com/openapi/spendesk-public-api.json (25). llms.txt indexes every page and each page has a Markdown copy at the same URL with .md (10). 98 of 106 operations carry a description longer than 80 characters, and several say which endpoint to use instead, such as successful against failed transactions. The MCP tool definitions can't be listed without a customer sign-in, and the public tool reference gives a name, a one-line label, the permission and whether the action can be undone (15). The definition has 270 enums, 55 patterns and required lists throughout (13). 400, 401, 403, 429 and 500 are declared on 101 operations with one error model, and 29 operations carry examples (12). Versioning is by path with Deprecation and Sunset headers. The public changelog has ten entries, all created on 28 and 29 September 2026, and the definition's version field is a fixed 1.0 (12)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 62,
            "points": 10.07,
            "reason": "The MCP server has 62 tools, which is the lowest band, but tools/list returns only the tools the user's permissions allow and write permissions start unticked, so a default connection sees at most the 36 read tools. Analysis tools return totals so an agent needn't sum pages (14). Lists paginate with filters, though in three styles (page, cursor and offset), the page-based maximum is 30 and a page past the end returns 404. MCP list tools take pageSize up to 1,000 and fetchAll up to 5,000 with a truncated flag (17). Errors carry a stable code, the field at fault and a correlationId, and a page explains every MCP error. A missing permission is indistinguishable from a missing tool (17). An Idempotency-Key is documented only for creating an intake. Payable updates are refused on a stale `version`, and batch calls report each item. No readOnlyHint or destructiveHint annotations are documented, and we couldn't list the tools to check (8). Few parameters are required. No official SDK was found, only a Postman collection and copy-and-run scripts (6)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 86,
            "points": 15.05,
            "reason": "OAuth 2.0 authorisation code with PKCE (S256), 37 documented scopes, one-hour access tokens and rotating refresh tokens for MCP and partner apps. API keys carry only the scopes ticked, expire within a year, and a token can request fewer scopes than its key (30). Read and write are separate scopes. MCP write permissions are off on every connection until an Admin enables them with a second factor, each user then ticks them, and every call checks the user's role. Confirmation before a write is an instruction to the assistant, not enforced, and production has no dry-run mode apart from export previews (17). The safety page names prompt injection through supplier names, invoice lines and documents, and advises read-only use and approval of each action (12). An action log per MCP connection records date, tool, status, user, company and correlation ID, without arguments. No equivalent for API keys was found (12). security.txt is valid until 31 December 2026 and describes a bug bounty paying up to 2,000 euros. The security page states ISO 27001:2022. No SOC 2 report or public advisories were found, and the trust centre needs JavaScript (15)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 0,
            "points": 0,
            "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). The pricing page describes a fixed monthly fee plus variable fees per transaction and asks for a quote, with no figures (0). No free tier or trial found. Demo credentials are requested from Spendesk together with API access (0). A person at a paying customer creates the key or approves the OAuth connection, and dynamic client registration is open to supported partners only (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 57,
            "points": 4.99,
            "reason": "The newest changelog entry was created on 29 September 2026, MCP write actions arrived on 25 September, and docs pages were updated on 1 October (30). The changelog has ten entries, all created on 28 and 29 September 2026, so they meet the count but look like a backfill, and we gave partial credit (15). Closed service with a public changelog and a support address for API consumers (support-public-api@spendesk.com). No public forum or issue tracker was found (8). No official SDK on npm or PyPI, and no entry in the official MCP registry (0). Nothing is packaged to assess. Convention pages state they are replayed against the demo environment weekly, last on 29 September 2026 (4)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 80,
            "points": 7,
            "note": "editorial 64, provenance 96",
            "reason": "Closed service. The terms page lists the customer terms, a DORA addendum, a Spendesk API agreement and partner terms, with a subscription for updates and previous versions. We couldn't open the documents, whose links are drawn by JavaScript (12). The privacy policy (March 2025, version 0.5) names a DPO, EU hosting and retention periods for the data Spendesk controls, and refers to a DPA for platform data, which we didn't read. The MCP docs say that data read by an assistant goes to the assistant's provider (20). Deprecation and Sunset headers carry dates and the policy supports the current and previous version, with no minimum notice period stated. Experimental endpoints may change (12). The sub-processor list dated 31 August 2026 gives each processor's address, purpose, data types, location and safeguards (20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The MCP server has 62 tools, which is the lowest band, but tools/list returns only the tools the user's permissions allow and write permissions start unticked, so a default connection sees at most the 36 read tools. Analysis tools return totals so an agent needn't sum pages (14). Lists paginate with filters, though in three styles (page, cursor and offset), the page-based maximum is 30 and a page past the end returns 404. MCP list tools take pageSize up to 1,000 and fetchAll up to 5,000 with a truncated flag (17). Errors carry a stable code, the field at fault and a correlationId, and a page explains every MCP error. A missing permission is indistinguishable from a missing tool (17). An Idempotency-Key is documented only for creating an intake. Payable updates are refused on a stale `version`, and batch calls report each item. No readOnlyHint or destructiveHint annotations are documented, and we couldn't list the tools to check (8). Few parameters are required. No official SDK was found, only a Postman collection and copy-and-run scripts (6).",
            "maintenance": "The newest changelog entry was created on 29 September 2026, MCP write actions arrived on 25 September, and docs pages were updated on 1 October (30). The changelog has ten entries, all created on 28 and 29 September 2026, so they meet the count but look like a backfill, and we gave partial credit (15). Closed service with a public changelog and a support address for API consumers (support-public-api@spendesk.com). No public forum or issue tracker was found (8). No official SDK on npm or PyPI, and no entry in the official MCP registry (0). Nothing is packaged to assess. Convention pages state they are replayed against the demo environment weekly, last on 29 September 2026 (4).",
            "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). The pricing page describes a fixed monthly fee plus variable fees per transaction and asks for a quote, with no figures (0). No free tier or trial found. Demo credentials are requested from Spendesk together with API access (0). A person at a paying customer creates the key or approves the OAuth connection, and dynamic client registration is open to supported partners only (0).",
            "reliability": "Read with the hosted lines and scored on the public REST API and the MCP server on the same host. status.spendesk.com on Atlassian Statuspage has components by product area with incident history, though none for the public API (20). From 10 July to 8 October 2026 the page lists eleven incidents, three marked critical and three major. Platform access and latency failed for about 1 hour 55 minutes on 2 September, sign-in to the application for about 59 minutes on 29 September, and international transfers in the EEA for about 22 hours from 16 September. No entry says whether the API was affected, so we scored it between one major outage and several (5). Limits are published as 1,000 requests a minute per company and credential and 500 concurrent requests (15). Every response carries x-ratelimit-limit, remaining and reset headers and the docs give pacing guidance, but an Idempotency-Key exists only for creating an intake and Retry-After is documented on one endpoint (10). The docs say the team attempts to guarantee 99 per cent availability, which is a target and not a published SLA (0). The read API is generally available, while cards, transactions, invoices, purchase orders, webhooks and MCP write actions are experimental or beta (5).",
            "schema": "A public OpenAPI 3.1 definition with 106 operations at developer.spendesk.com/openapi/spendesk-public-api.json (25). llms.txt indexes every page and each page has a Markdown copy at the same URL with .md (10). 98 of 106 operations carry a description longer than 80 characters, and several say which endpoint to use instead, such as successful against failed transactions. The MCP tool definitions can't be listed without a customer sign-in, and the public tool reference gives a name, a one-line label, the permission and whether the action can be undone (15). The definition has 270 enums, 55 patterns and required lists throughout (13). 400, 401, 403, 429 and 500 are declared on 101 operations with one error model, and 29 operations carry examples (12). Versioning is by path with Deprecation and Sunset headers. The public changelog has ten entries, all created on 28 and 29 September 2026, and the definition's version field is a fixed 1.0 (12).",
            "security": "OAuth 2.0 authorisation code with PKCE (S256), 37 documented scopes, one-hour access tokens and rotating refresh tokens for MCP and partner apps. API keys carry only the scopes ticked, expire within a year, and a token can request fewer scopes than its key (30). Read and write are separate scopes. MCP write permissions are off on every connection until an Admin enables them with a second factor, each user then ticks them, and every call checks the user's role. Confirmation before a write is an instruction to the assistant, not enforced, and production has no dry-run mode apart from export previews (17). The safety page names prompt injection through supplier names, invoice lines and documents, and advises read-only use and approval of each action (12). An action log per MCP connection records date, tool, status, user, company and correlation ID, without arguments. No equivalent for API keys was found (12). security.txt is valid until 31 December 2026 and describes a bug bounty paying up to 2,000 euros. The security page states ISO 27001:2022. No SOC 2 report or public advisories were found, and the trust centre needs JavaScript (15).",
            "transparency": "Closed service. The terms page lists the customer terms, a DORA addendum, a Spendesk API agreement and partner terms, with a subscription for updates and previous versions. We couldn't open the documents, whose links are drawn by JavaScript (12). The privacy policy (March 2025, version 0.5) names a DPO, EU hosting and retention periods for the data Spendesk controls, and refers to a DPA for platform data, which we didn't read. The MCP docs say that data read by an assistant goes to the assistant's provider (20). Deprecation and Sunset headers carry dates and the policy supports the current and previous version, with no minimum notice period stated. Experimental endpoints may change (12). The sub-processor list dated 31 August 2026 gives each processor's address, purpose, data types, location and safeguards (20)."
          },
          "sources": [
            {
              "what": "developer docs index (llms.txt)",
              "url": "https://developer.spendesk.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "getting access, API keys and experimental scopes",
              "url": "https://developer.spendesk.com/reference/getting-access.md",
              "seen": "2026-10-08"
            },
            {
              "what": "authentication (API keys and OAuth2)",
              "url": "https://developer.spendesk.com/reference/how-to-authenticate.md",
              "seen": "2026-10-08"
            },
            {
              "what": "scopes",
              "url": "https://developer.spendesk.com/reference/scopes.md",
              "seen": "2026-10-08"
            },
            {
              "what": "rate limiting",
              "url": "https://developer.spendesk.com/reference/rate-limiting.md",
              "seen": "2026-10-08"
            },
            {
              "what": "pagination",
              "url": "https://developer.spendesk.com/reference/pagination.md",
              "seen": "2026-10-08"
            },
            {
              "what": "error handling",
              "url": "https://developer.spendesk.com/reference/error-handling.md",
              "seen": "2026-10-08"
            },
            {
              "what": "versioning and deprecation",
              "url": "https://developer.spendesk.com/reference/versioning-deprecation.md",
              "seen": "2026-10-08"
            },
            {
              "what": "webhooks (experimental)",
              "url": "https://developer.spendesk.com/reference/using-webhooks.md",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI definition",
              "url": "https://developer.spendesk.com/openapi/spendesk-public-api.json",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server overview and developer notes",
              "url": "https://developer.spendesk.com/reference/connect-an-ai-assistant-mcp.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP tool reference",
              "url": "https://developer.spendesk.com/reference/mcp-tool-reference.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP actions and safety",
              "url": "https://developer.spendesk.com/reference/mcp-actions-and-safety.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP safety, audit and security review notes",
              "url": "https://developer.spendesk.com/reference/mcp-using-the-assistant-safely.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP errors and limits",
              "url": "https://developer.spendesk.com/reference/mcp-errors-and-limits.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP protected resource metadata",
              "url": "https://public-api.spendesk.com/.well-known/oauth-protected-resource/v1/mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog",
              "url": "https://developer.spendesk.com/changelog",
              "seen": "2026-10-08"
            },
            {
              "what": "status incidents (JSON)",
              "url": "https://status.spendesk.com/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing page",
              "url": "https://www.spendesk.com/pricing/",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://www.spendesk.com/spendesk-security/",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.spendesk.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "legal terms index",
              "url": "https://www.spendesk.com/legals/terms/",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.spendesk.com/legals/privacy/",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processor list",
              "url": "https://www.spendesk.com/legals/subprocessors/",
              "seen": "2026-10-08"
            },
            {
              "what": "legal notice",
              "url": "https://helpcenter.spendesk.com/en/articles/4168878-our-legal-notice",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=spendesk",
              "seen": "2026-10-08"
            },
            {
              "what": "npm registry entry (unpublished)",
              "url": "https://registry.npmjs.org/spendesk",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the customer terms, DORA addendum and Spendesk API agreement, whose links on the terms page are drawn by JavaScript",
            "unchecked: the trust centre at trust.spendesk.com (JavaScript only), so SOC 2 status and the ISO certificate weren't confirmed there",
            "unchecked: MCP tool input schemas and readOnlyHint or destructiveHint annotations, which need a customer sign-in to list",
            "unchecked: the DPA and its retention terms for platform data",
            "Whether the September 2026 platform incidents affected public-api.spendesk.com. The status page has no API component",
            "Whether API access is included on every plan or sold separately. The pricing page lists it in the base package, the docs say to ask a representative",
            "Whether the ten changelog entries created on 28 and 29 September 2026 are a backfill of older changes",
            "No search for security incidents was made beyond the vendor's own pages"
          ]
        },
        "negative": 0,
        "verdict": "Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.",
        "bestFor": "A finance team already on Spendesk that wants an assistant to analyse spend, follow invoices and prepare the accounting close, or an ERP sync reading payables and settlements.",
        "strengths": [
          "OpenAPI 3.1 definition with 106 operations, llms.txt and a Markdown copy of every docs page, all public without sign-in",
          "37 documented scopes split by resource and by read or write. A token can carry fewer scopes than its key, and keys expire within one year",
          "MCP write permissions are off by default, enabled per connection by an admin with a second factor, then ticked by each user",
          "Every MCP tool call is recorded in an action log with date, tool, status, user, company and correlation ID",
          "Rate limits are published (1,000 requests a minute per company and credential) with x-ratelimit headers on every response"
        ],
        "weaknesses": [
          "No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative",
          "Cards, transactions, invoices, purchase orders, webhooks and most writes sit behind experimental scopes granted on request, and may change",
          "No official SDK found on npm or PyPI, and the MCP server isn't in the official MCP registry",
          "status.spendesk.com has no API component and lists three critical and three major incidents opened between 2 and 29 September 2026",
          "An Idempotency-Key is documented only for creating an intake. A repeated purchase order or supplier request creates a second record"
        ],
        "agentNotes": [
          "Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401",
          "Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list",
          "With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400",
          "The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission",
          "After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.3
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 57,
          "payments": 0,
          "reliability": 55,
          "schema": 87,
          "security": 86,
          "transparency": 64
        },
        "provenanceScore": 96
      },
      "connect": {
        "http": "curl -X POST https://public-api.demo.spendesk.com/v1/auth/token \\\n  -u \"YOUR_CLIENT_ID:YOUR_CLIENT_SECRET\"\n\ncurl https://public-api.demo.spendesk.com/v1/wallet-summary \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/spend.transactions",
        "tool": "https://letme.dev/spendesk"
      },
      "notable": [
        "The MCP server at https://public-api.spendesk.com/v1/mcp has 62 tools, 36 that read and 26 that act, and write actions have been in beta since 25 September 2026 (https://developer.spendesk.com/reference/mcp-tool-reference)",
        "No MCP tool approves or rejects a request or invoice, pays an invoice, creates or changes cards or users, or reads budgets (https://developer.spendesk.com/reference/connect-an-ai-assistant-mcp)",
        "Spendesk tells the assistant to confirm before acting but says this is an instruction, not a lock. The enforced checks are the user's permissions and Spendesk role (https://developer.spendesk.com/reference/mcp-actions-and-safety)",
        "Experimental endpoints (invoices, payable search, accounting exports, purchase orders, cards and transactions, webhooks, organisation-level access) are available on request from a Customer Success Manager (https://developer.spendesk.com/reference/getting-access)",
        "A second MCP server for the documentation at https://developer.spendesk.com/mcp needs no account and lists, searches and reads the API's endpoints (https://developer.spendesk.com/reference/using-the-docs-with-an-ai-assistant)",
        "The docs state that the team attempts to guarantee 99 per cent availability on the API, measured by latency and error rate (https://developer.spendesk.com/reference/general)",
        "security.txt describes a bug bounty covering app.spendesk.com and api.spendesk.com, with rewards up to 2,000 euros for a critical finding (https://www.spendesk.com/.well-known/security.txt)"
      ],
      "area": "domain-data",
      "details": [
        {
          "label": "API",
          "value": "REST, OpenAPI 3.1, 106 operations under /v1 and /v2 at https://public-api.spendesk.com, with a demo environment at https://public-api.demo.spendesk.com. 54 GET, 26 POST, 10 PATCH, 8 PUT, 8 DELETE"
        },
        {
          "label": "MCP server",
          "value": "Hosted at https://public-api.spendesk.com/v1/mcp, Streamable HTTP, tools only. 62 tools (36 read, 26 act). Reading is generally available, write actions are in beta. Clients for Claude, ChatGPT and Dust are created in Spendesk settings. Dust and Langdock can use dynamic client registration"
        },
        {
          "label": "Credentials",
          "value": "API key (client ID and secret, valid up to one year, scopes ticked at creation) exchanged for a 60-minute token, or OAuth 2.0 authorisation code with PKCE for partner apps and MCP. Refresh tokens rotate and last about 30 days"
        },
        {
          "label": "Scopes",
          "value": "12 standard scopes (11 read, plus `cost-center:manage`) and 25 experimental ones listed in the docs, among them experimental:transaction:read, experimental:card:read, experimental:invoice:read and experimental:purchase-order:write"
        },
        {
          "label": "Access",
          "value": "Customers ask a Spendesk representative for API access, then an Account Owner or Admin creates the key. Partner OAuth apps go through the partnerships team. Demo credentials are requested with API access"
        },
        {
          "label": "Rate limits",
          "value": "1,000 requests a minute per company and credential, 500 concurrent requests per consumer, 10 a minute for dynamic client registration. MCP adds 100 concurrent requests per company and 200 per organisation"
        },
        {
          "label": "Pagination",
          "value": "Page-based on most lists (pageSize default and maximum 30), cursor-based on invoices, intakes, analytical field values and expense categories, offset on accounts. MCP list tools return 100 items by default, up to 1,000, with fetchAll capped at 5,000"
        },
        {
          "label": "Errors",
          "value": "JSON with a correlationId and a list of errors, each with a stable code, a detail and the source field. Bulk updates return 207 with a per-item outcome. MCP tool errors return isError true with a sentence"
        },
        {
          "label": "Webhooks",
          "value": "Experimental. Events payables:created, payables:prepared and settlements:created, signed with HMAC SHA256 in x-spendesk-webhook-signature, retried for 3 days, 50 instances per company"
        },
        {
          "label": "Audit",
          "value": "MCP action log per connection (date, tool, status, user, company, duration, correlation ID), without tool arguments. No equivalent log for API keys was found in the docs"
        },
        {
          "label": "Versioning",
          "value": "Major version in the path. Deprecation and Sunset response headers carry dates. Experimental endpoints may change"
        },
        {
          "label": "Certifications",
          "value": "ISO 27001:2022 per the security page. Card partners are PCI DSS certified. Trust centre at trust.spendesk.com"
        },
        {
          "label": "Status",
          "value": "status.spendesk.com on Atlassian Statuspage, components by product area (Login, cards, Invoices, Bookkeep exports and others), none for the public API"
        },
        {
          "label": "Sub-processors",
          "value": "List dated 31 August 2026 with address, purpose, data types, location and safeguards for each. Hosting on AWS in the European Union"
        }
      ],
      "provenance": {
        "legalEntity": "Spendesk SAS",
        "domain": "spendesk.com",
        "domainRegistered": "2015-10-30",
        "endpointOnVendorDomain": true,
        "terms": "https://www.spendesk.com/legals/terms/",
        "privacy": "https://www.spendesk.com/legals/privacy/",
        "statusPage": "https://status.spendesk.com",
        "changelog": "https://developer.spendesk.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The legal notice names Spendesk SAS, 7 Rue de Madrid, 75008 Paris, registration 821 893 286 R.C.S. Paris. The privacy policy (March 2025, version 0.5) gives the registered office as 51 rue de Londres, 75008 Paris.",
          "Payment services are supplied by Spendesk Financial Services (a French payment institution licensed by the ACPR, number 17518) in the EEA, Adyen in the UK and Sutton Bank in the US, per the site footer.",
          "The API and the MCP server answer at public-api.spendesk.com. An unauthenticated POST to /v1/mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata.",
          "www.spendesk.com/.well-known/security.txt is present with a contact and an expiry of 31 December 2026. developer.spendesk.com/.well-known/security.txt returns 404.",
          "The terms page lists the customer terms, a DORA addendum, a Spendesk API agreement and partner programme terms. The document links are drawn by JavaScript and we couldn't open them.",
          "RDAP for spendesk.com gives a registration date of 2015-10-30."
        ],
        "score": 96,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Spendesk SAS",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "spendesk.com, registered 2015-10-30 (10 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "public-api.spendesk.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "published, but our reader couldn't read it",
            "points": 7,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 6 of the 8 things a reader expects",
            "points": 8.5,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.spendesk.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.spendesk.com/legals/terms/",
            "state": "unreadable",
            "reason": "the page at this address is a list of links to several documents, not the document itself",
            "readAt": "2026-10-08",
            "points": 7,
            "max": 10,
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The page says the Spendesk API is governed by a separate agreement for a limited list of partners and customers who are contractually granted API keys.",
                "quote": "Target audience: Limited list of technical partners and customers who are contractually granted API keys to develop a direct integration"
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.spendesk.com/legals/privacy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-03-01",
            "words": 2732,
            "points": 8.5,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: March 2025 (Version 0.5)",
                "says": "Last updated 2025-03-01"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": false
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Details of the retention periods are provided in the Cookies Policy*)"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Your Personal Data may be transmitted to service providers which Spendesk uses to carry out all or part of the Processing described above."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": false
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "In accordance with the Personal Data Regulation, you have at any time a right of access, rectification, restriction, erasure and deletion of Personal Data concerning you, as well as a right to object and a right to portability."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "To supervise Spendesk’s commitments and its compliance with the Personal Data Regulation, Spendesk has appointed a Data Protection Officer (DPO), who can be contacted by email (privacy@spendesk.com).",
                "says": "privacy@spendesk.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "…to a country designated as adequate by the European Commission, signature of the European Commission's Standard Contractual Clauses, additional security measures, etc.).",
                "says": "Relies on standard contractual clauses"
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/spendesk.json",
      "live": {
        "slug": "spendesk",
        "probe": {
          "target": "https://public-api.spendesk.com",
          "method": "get",
          "lastAt": "2026-10-08T19:08:59.237952658Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 65,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 65,
          "p95ms24h": 110,
          "samples24h": 42,
          "samples30d": 42,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 42,
              "ok": 42
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.spendesk.com",
          "indicator": "minor",
          "summary": "Partially Degraded Service",
          "checkedAt": "2026-10-08T19:06:59.782257412Z"
        },
        "securityTxt": {
          "url": "https://spendesk.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-12-31T22:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:39.004780879Z"
        },
        "pages": [
          {
            "url": "https://developer.spendesk.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:18.275650963Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0a7493461e82"
          },
          {
            "url": "https://www.spendesk.com/legals/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:38.654232386Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f77c18596c95"
          },
          {
            "url": "https://www.spendesk.com/legals/terms/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:41.303104049Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "880e4794e2b0"
          }
        ],
        "updatedAt": "2026-10-08T19:08:59.237952658Z"
      }
    },
    "verify": {
      "accepts": "a page on spendesk.com or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/spendesk.svg",
      "body": {
        "slug": "spendesk",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/spendesk",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/spendesk\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/spendesk.svg\" alt=\"Spendesk API + MCP on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Spendesk API + MCP on Anchor Terminal](https://www.anchorterminal.com/badges/spendesk.svg)](https://www.anchorterminal.com/tools/spendesk)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/spendesk\"\u003eSpendesk API + MCP on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/spendesk",
    "json": "https://www.anchorterminal.com/tools/spendesk.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/spendesk.md",
    "slim": "https://www.anchorterminal.com/tools/spendesk.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 62.3/100 · rank #306 of 629 · #2 in Spend management \u0026 procurement · not agent-ready · confidence medium**\n\n\n## Assessment\n\nScoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Spendesk SAS (https://www.spendesk.com) |\n| Kind | HTTP API |\n| Category | Spend management \u0026 procurement (https://www.anchorterminal.com/categories/spend-management) |\n| Transport | HTTP |\n| Endpoint | `https://public-api.spendesk.com` |\n| Auth | OAuth or key · Access is granted by Spendesk, not self-serve. A customer asks its Spendesk representative for API access, then an Account Owner or Admin creates an API key (client ID and secret) with chosen scopes and an expiry of up to one year. The key is exchanged at POST /v1/auth/token with HTTP Basic for a Bearer token that lasts 60 minutes and can carry fewer scopes than the key. Partner integrations use OAuth 2.0 authorisation code with PKCE after approval by the partnerships team. The MCP server accepts only OAuth user tokens, refuses API keys, and limits use to Controllers and Account Owners. Experimental scopes are added on request. |\n| Pricing | Paid (Paid) · No public prices. The pricing page describes a fixed monthly platform fee plus variable fees per transaction (card purchases, invoice payments and expense claims) and asks for a quote. It lists the open API and the MCP connection in the base package. No free tier, trial or self-serve sandbox was found. A demo environment exists at public-api.demo.spendesk.com, with credentials requested alongside API access (checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the developer docs, the OpenAPI definition or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement |\n| Tools exposed | 62 |\n| Docs | https://developer.spendesk.com |\n| llms.txt | https://developer.spendesk.com/llms.txt |\n| Last release | 2026-09-29 |\n| API | REST, OpenAPI 3.1, 106 operations under /v1 and /v2 at https://public-api.spendesk.com, with a demo environment at https://public-api.demo.spendesk.com. 54 GET, 26 POST, 10 PATCH, 8 PUT, 8 DELETE |\n| MCP server | Hosted at https://public-api.spendesk.com/v1/mcp, Streamable HTTP, tools only. 62 tools (36 read, 26 act). Reading is generally available, write actions are in beta. Clients for Claude, ChatGPT and Dust are created in Spendesk settings. Dust and Langdock can use dynamic client registration |\n| Credentials | API key (client ID and secret, valid up to one year, scopes ticked at creation) exchanged for a 60-minute token, or OAuth 2.0 authorisation code with PKCE for partner apps and MCP. Refresh tokens rotate and last about 30 days |\n| Scopes | 12 standard scopes (11 read, plus `cost-center:manage`) and 25 experimental ones listed in the docs, among them experimental:transaction:read, experimental:card:read, experimental:invoice:read and experimental:purchase-order:write |\n| Access | Customers ask a Spendesk representative for API access, then an Account Owner or Admin creates the key. Partner OAuth apps go through the partnerships team. Demo credentials are requested with API access |\n| Rate limits | 1,000 requests a minute per company and credential, 500 concurrent requests per consumer, 10 a minute for dynamic client registration. MCP adds 100 concurrent requests per company and 200 per organisation |\n| Pagination | Page-based on most lists (pageSize default and maximum 30), cursor-based on invoices, intakes, analytical field values and expense categories, offset on accounts. MCP list tools return 100 items by default, up to 1,000, with fetchAll capped at 5,000 |\n| Errors | JSON with a correlationId and a list of errors, each with a stable code, a detail and the source field. Bulk updates return 207 with a per-item outcome. MCP tool errors return isError true with a sentence |\n| Webhooks | Experimental. Events payables:created, payables:prepared and settlements:created, signed with HMAC SHA256 in x-spendesk-webhook-signature, retried for 3 days, 50 instances per company |\n| Audit | MCP action log per connection (date, tool, status, user, company, duration, correlation ID), without tool arguments. No equivalent log for API keys was found in the docs |\n| Versioning | Major version in the path. Deprecation and Sunset response headers carry dates. Experimental endpoints may change |\n| Certifications | ISO 27001:2022 per the security page. Card partners are PCI DSS certified. Trust centre at trust.spendesk.com |\n| Status | status.spendesk.com on Atlassian Statuspage, components by product area (Login, cards, Invoices, Bookkeep exports and others), none for the public API |\n| Sub-processors | List dated 31 August 2026 with address, purpose, data types, location and safeguards for each. Hosting on AWS in the European Union |\n| Capabilities | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement |\n| Tags | hosted, enterprise, api-key, oauth, mcp, openapi, llms-txt, webhooks, sales-led, status-page, iso27001, bug-bounty |\n| JSON | https://www.anchorterminal.com/api/v1/tools/spendesk.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 55 | 11.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 87 | 14.1 |\n| Agent ergonomics | 13% | 16.2 | 62 | 10.1 |\n| Security \u0026 auth | 14% | 17.5 | 86 | 15.1 |\n| Payments \u0026 pricing | 10% | 12.5 | 0 | 0.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 57 | 5.0 |\n| Transparency \u0026 trust (editorial 64, provenance 96) | 7% | 8.8 | 80 | 7.0 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **62.3 → B** |\n\n### Why each score\n\n- Reliability 55: Read with the hosted lines and scored on the public REST API and the MCP server on the same host. status.spendesk.com on Atlassian Statuspage has components by product area with incident history, though none for the public API (20). From 10 July to 8 October 2026 the page lists eleven incidents, three marked critical and three major. Platform access and latency failed for about 1 hour 55 minutes on 2 September, sign-in to the application for about 59 minutes on 29 September, and international transfers in the EEA for about 22 hours from 16 September. No entry says whether the API was affected, so we scored it between one major outage and several (5). Limits are published as 1,000 requests a minute per company and credential and 500 concurrent requests (15). Every response carries x-ratelimit-limit, remaining and reset headers and the docs give pacing guidance, but an Idempotency-Key exists only for creating an intake and Retry-After is documented on one endpoint (10). The docs say the team attempts to guarantee 99 per cent availability, which is a target and not a published SLA (0). The read API is generally available, while cards, transactions, invoices, purchase orders, webhooks and MCP write actions are experimental or beta (5).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 87: A public OpenAPI 3.1 definition with 106 operations at developer.spendesk.com/openapi/spendesk-public-api.json (25). llms.txt indexes every page and each page has a Markdown copy at the same URL with .md (10). 98 of 106 operations carry a description longer than 80 characters, and several say which endpoint to use instead, such as successful against failed transactions. The MCP tool definitions can't be listed without a customer sign-in, and the public tool reference gives a name, a one-line label, the permission and whether the action can be undone (15). The definition has 270 enums, 55 patterns and required lists throughout (13). 400, 401, 403, 429 and 500 are declared on 101 operations with one error model, and 29 operations carry examples (12). Versioning is by path with Deprecation and Sunset headers. The public changelog has ten entries, all created on 28 and 29 September 2026, and the definition's version field is a fixed 1.0 (12).\n- Agent ergonomics 62: The MCP server has 62 tools, which is the lowest band, but tools/list returns only the tools the user's permissions allow and write permissions start unticked, so a default connection sees at most the 36 read tools. Analysis tools return totals so an agent needn't sum pages (14). Lists paginate with filters, though in three styles (page, cursor and offset), the page-based maximum is 30 and a page past the end returns 404. MCP list tools take pageSize up to 1,000 and fetchAll up to 5,000 with a truncated flag (17). Errors carry a stable code, the field at fault and a correlationId, and a page explains every MCP error. A missing permission is indistinguishable from a missing tool (17). An Idempotency-Key is documented only for creating an intake. Payable updates are refused on a stale `version`, and batch calls report each item. No readOnlyHint or destructiveHint annotations are documented, and we couldn't list the tools to check (8). Few parameters are required. No official SDK was found, only a Postman collection and copy-and-run scripts (6).\n- Security \u0026 auth 86: OAuth 2.0 authorisation code with PKCE (S256), 37 documented scopes, one-hour access tokens and rotating refresh tokens for MCP and partner apps. API keys carry only the scopes ticked, expire within a year, and a token can request fewer scopes than its key (30). Read and write are separate scopes. MCP write permissions are off on every connection until an Admin enables them with a second factor, each user then ticks them, and every call checks the user's role. Confirmation before a write is an instruction to the assistant, not enforced, and production has no dry-run mode apart from export previews (17). The safety page names prompt injection through supplier names, invoice lines and documents, and advises read-only use and approval of each action (12). An action log per MCP connection records date, tool, status, user, company and correlation ID, without arguments. No equivalent for API keys was found (12). security.txt is valid until 31 December 2026 and describes a bug bounty paying up to 2,000 euros. The security page states ISO 27001:2022. No SOC 2 report or public advisories were found, and the trust centre needs JavaScript (15).\n- Payments \u0026 pricing 0: Read with the hosted rubric. No x402, MPP or L402 (0). The pricing page describes a fixed monthly fee plus variable fees per transaction and asks for a quote, with no figures (0). No free tier or trial found. Demo credentials are requested from Spendesk together with API access (0). A person at a paying customer creates the key or approves the OAuth connection, and dynamic client registration is open to supported partners only (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 57: The newest changelog entry was created on 29 September 2026, MCP write actions arrived on 25 September, and docs pages were updated on 1 October (30). The changelog has ten entries, all created on 28 and 29 September 2026, so they meet the count but look like a backfill, and we gave partial credit (15). Closed service with a public changelog and a support address for API consumers (support-public-api@spendesk.com). No public forum or issue tracker was found (8). No official SDK on npm or PyPI, and no entry in the official MCP registry (0). Nothing is packaged to assess. Convention pages state they are replayed against the demo environment weekly, last on 29 September 2026 (4).\n- Transparency \u0026 trust 80: Closed service. The terms page lists the customer terms, a DORA addendum, a Spendesk API agreement and partner terms, with a subscription for updates and previous versions. We couldn't open the documents, whose links are drawn by JavaScript (12). The privacy policy (March 2025, version 0.5) names a DPO, EU hosting and retention periods for the data Spendesk controls, and refers to a DPA for platform data, which we didn't read. The MCP docs say that data read by an assistant goes to the assistant's provider (20). Deprecation and Sunset headers carry dates and the policy supports the current and previous version, with no minimum notice period stated. Experimental endpoints may change (12). The sub-processor list dated 31 August 2026 gives each processor's address, purpose, data types, location and safeguards (20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/spendesk.md (JSON https://www.anchorterminal.com/fixes/spendesk.json)\n\n### What we couldn't check\n\n- unchecked: the customer terms, DORA addendum and Spendesk API agreement, whose links on the terms page are drawn by JavaScript\n- unchecked: the trust centre at trust.spendesk.com (JavaScript only), so SOC 2 status and the ISO certificate weren't confirmed there\n- unchecked: MCP tool input schemas and readOnlyHint or destructiveHint annotations, which need a customer sign-in to list\n- unchecked: the DPA and its retention terms for platform data\n- Whether the September 2026 platform incidents affected public-api.spendesk.com. The status page has no API component\n- Whether API access is included on every plan or sold separately. The pricing page lists it in the base package, the docs say to ask a representative\n- Whether the ten changelog entries created on 28 and 29 September 2026 are a backfill of older changes\n- No search for security incidents was made beyond the vendor's own pages\n\n### Sources\n\n- developer docs index (llms.txt): \u003chttps://developer.spendesk.com/llms.txt\u003e (seen 2026-10-08)\n- getting access, API keys and experimental scopes: \u003chttps://developer.spendesk.com/reference/getting-access.md\u003e (seen 2026-10-08)\n- authentication (API keys and OAuth2): \u003chttps://developer.spendesk.com/reference/how-to-authenticate.md\u003e (seen 2026-10-08)\n- scopes: \u003chttps://developer.spendesk.com/reference/scopes.md\u003e (seen 2026-10-08)\n- rate limiting: \u003chttps://developer.spendesk.com/reference/rate-limiting.md\u003e (seen 2026-10-08)\n- pagination: \u003chttps://developer.spendesk.com/reference/pagination.md\u003e (seen 2026-10-08)\n- error handling: \u003chttps://developer.spendesk.com/reference/error-handling.md\u003e (seen 2026-10-08)\n- versioning and deprecation: \u003chttps://developer.spendesk.com/reference/versioning-deprecation.md\u003e (seen 2026-10-08)\n- webhooks (experimental): \u003chttps://developer.spendesk.com/reference/using-webhooks.md\u003e (seen 2026-10-08)\n- OpenAPI definition: \u003chttps://developer.spendesk.com/openapi/spendesk-public-api.json\u003e (seen 2026-10-08)\n- MCP server overview and developer notes: \u003chttps://developer.spendesk.com/reference/connect-an-ai-assistant-mcp.md\u003e (seen 2026-10-08)\n- MCP tool reference: \u003chttps://developer.spendesk.com/reference/mcp-tool-reference.md\u003e (seen 2026-10-08)\n- MCP actions and safety: \u003chttps://developer.spendesk.com/reference/mcp-actions-and-safety.md\u003e (seen 2026-10-08)\n- MCP safety, audit and security review notes: \u003chttps://developer.spendesk.com/reference/mcp-using-the-assistant-safely.md\u003e (seen 2026-10-08)\n- MCP errors and limits: \u003chttps://developer.spendesk.com/reference/mcp-errors-and-limits.md\u003e (seen 2026-10-08)\n- MCP protected resource metadata: \u003chttps://public-api.spendesk.com/.well-known/oauth-protected-resource/v1/mcp\u003e (seen 2026-10-08)\n- changelog: \u003chttps://developer.spendesk.com/changelog\u003e (seen 2026-10-08)\n- status incidents (JSON): \u003chttps://status.spendesk.com/api/v2/incidents.json\u003e (seen 2026-10-08)\n- pricing page: \u003chttps://www.spendesk.com/pricing/\u003e (seen 2026-10-08)\n- security page: \u003chttps://www.spendesk.com/spendesk-security/\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.spendesk.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- legal terms index: \u003chttps://www.spendesk.com/legals/terms/\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.spendesk.com/legals/privacy/\u003e (seen 2026-10-08)\n- sub-processor list: \u003chttps://www.spendesk.com/legals/subprocessors/\u003e (seen 2026-10-08)\n- legal notice: \u003chttps://helpcenter.spendesk.com/en/articles/4168878-our-legal-notice\u003e (seen 2026-10-08)\n- official MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0.1/servers?search=spendesk\u003e (seen 2026-10-08)\n- npm registry entry (unpublished): \u003chttps://registry.npmjs.org/spendesk\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 96/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Spendesk SAS | 20/20 |\n| Domain age | spendesk.com, registered 2015-10-30 (10 years) | 15/15 |\n| Endpoint on the vendor's domain | public-api.spendesk.com | 15/15 |\n| Terms of service | published, but our reader couldn't read it | 7/10 |\n| Privacy policy | read, states 6 of the 8 things a reader expects | 8.5/10 |\n| Status page | status.spendesk.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nThe legal notice names Spendesk SAS, 7 Rue de Madrid, 75008 Paris, registration 821 893 286 R.C.S. Paris. The privacy policy (March 2025, version 0.5) gives the registered office as 51 rue de Londres, 75008 Paris.\n\nPayment services are supplied by Spendesk Financial Services (a French payment institution licensed by the ACPR, number 17518) in the EEA, Adyen in the UK and Sutton Bank in the US, per the site footer.\n\nThe API and the MCP server answer at public-api.spendesk.com. An unauthenticated POST to /v1/mcp returned 401 with a WWW-Authenticate header naming the protected resource metadata.\n\nwww.spendesk.com/.well-known/security.txt is present with a contact and an expiry of 31 December 2026. developer.spendesk.com/.well-known/security.txt returns 404.\n\nThe terms page lists the customer terms, a DORA addendum, a Spendesk API agreement and partner programme terms. The document links are drawn by JavaScript and we couldn't open them.\n\nRDAP for spendesk.com gives a registration date of 2015-10-30.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.spendesk.com/legals/terms/), read 2026-10-08. Our reader couldn't read it (the page at this address is a list of links to several documents, not the document itself).\n\n- Also in the text (2026-10-08). The page says the Spendesk API is governed by a separate agreement for a limited list of partners and customers who are contractually granted API keys. \"Target audience: Limited list of technical partners and customers who are contractually granted API keys to develop a direct integration\"\n\n**Privacy policy** (https://www.spendesk.com/legals/privacy/), read 2026-10-08, dated 2025-03-01, states 6 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2025-03-01.\n- Not found in the text. Says what personal data is collected.\n- Not found in the text. Says whether personal data is sold or shared for advertising.\n- Gives a privacy contact. privacy@spendesk.com.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n\n## Live (updated 2026-10-08 19:08 UTC)\n\n- Right now: up, HTTP 403, 65 ms, checked 2026-10-08 19:08 UTC (get on `https://public-api.spendesk.com`, asks for auth)\n- Uptime 24h 100.0% (42 probes) · 30 days 100.0% (42 probes) · p50 65 ms · p95 110 ms\n- Vendor status page: minor, Partially Degraded Service\n- security.txt: valid, expires 2026-12-31T22:00:00.000Z\n- Watching changelog \u003chttps://developer.spendesk.com/changelog\u003e\n- Watching privacy \u003chttps://www.spendesk.com/legals/privacy/\u003e\n- Watching terms \u003chttps://www.spendesk.com/legals/terms/\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/spendesk.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- OpenAPI 3.1 definition with 106 operations, llms.txt and a Markdown copy of every docs page, all public without sign-in\n- 37 documented scopes split by resource and by read or write. A token can carry fewer scopes than its key, and keys expire within one year\n- MCP write permissions are off by default, enabled per connection by an admin with a second factor, then ticked by each user\n- Every MCP tool call is recorded in an action log with date, tool, status, user, company and correlation ID\n- Rate limits are published (1,000 requests a minute per company and credential) with x-ratelimit headers on every response\n\n## Weaknesses\n\n- No public price, free tier or self-serve signup. API access and demo credentials are requested from a Spendesk representative\n- Cards, transactions, invoices, purchase orders, webhooks and most writes sit behind experimental scopes granted on request, and may change\n- No official SDK found on npm or PyPI, and the MCP server isn't in the official MCP registry\n- status.spendesk.com has no API component and lists three critical and three major incidents opened between 2 and 29 September 2026\n- An Idempotency-Key is documented only for creating an intake. A repeated purchase order or supplier request creates a second record\n\n## Before you call it (notes for agents)\n\n1. Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401\n2. Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list\n3. With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400\n4. The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission\n5. After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -X POST https://public-api.demo.spendesk.com/v1/auth/token \\\n  -u \"YOUR_CLIENT_ID:YOUR_CLIENT_SECRET\"\n\ncurl https://public-api.demo.spendesk.com/v1/wallet-summary \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\"\n```\n\nThrough letme (picks today, calling later): https://letme.dev/spendesk (letme picks it for spend.cards, the top-graded tool for the job, letme picks it for spend.procurement, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Ramp | C | 57.3 | 423 | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | no | https://www.anchorterminal.com/tools/ramp.md |\n| Brex | C | 60.7 | 345 | spend.transactions, spend.expenses, spend.cards, spend.bills | no | https://www.anchorterminal.com/tools/brex.md |\n| Pleo API + MCP | B | 62.9 | 293 | spend.transactions, spend.expenses, spend.bills | no | https://www.anchorterminal.com/tools/pleo.md |\n| Expensify | E | 41.1 | 593 | spend.transactions, spend.expenses | no | https://www.anchorterminal.com/tools/expensify.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The MCP server at https://public-api.spendesk.com/v1/mcp has 62 tools, 36 that read and 26 that act, and write actions have been in beta since 25 September 2026 (source: \u003chttps://developer.spendesk.com/reference/mcp-tool-reference\u003e)\n- No MCP tool approves or rejects a request or invoice, pays an invoice, creates or changes cards or users, or reads budgets (source: \u003chttps://developer.spendesk.com/reference/connect-an-ai-assistant-mcp\u003e)\n- Spendesk tells the assistant to confirm before acting but says this is an instruction, not a lock. The enforced checks are the user's permissions and Spendesk role (source: \u003chttps://developer.spendesk.com/reference/mcp-actions-and-safety\u003e)\n- Experimental endpoints (invoices, payable search, accounting exports, purchase orders, cards and transactions, webhooks, organisation-level access) are available on request from a Customer Success Manager (source: \u003chttps://developer.spendesk.com/reference/getting-access\u003e)\n- A second MCP server for the documentation at https://developer.spendesk.com/mcp needs no account and lists, searches and reads the API's endpoints (source: \u003chttps://developer.spendesk.com/reference/using-the-docs-with-an-ai-assistant\u003e)\n- The docs state that the team attempts to guarantee 99 per cent availability on the API, measured by latency and error rate (source: \u003chttps://developer.spendesk.com/reference/general\u003e)\n- security.txt describes a bug bounty covering app.spendesk.com and api.spendesk.com, with rewards up to 2,000 euros for a critical finding (source: \u003chttps://www.spendesk.com/.well-known/security.txt\u003e)\n\n## Compare\n\n- [Brex vs Spendesk API + MCP](https://www.anchorterminal.com/compare/brex-vs-spendesk.md): C 60.7 vs B 62.3\n- [Expensify vs Spendesk API + MCP](https://www.anchorterminal.com/compare/expensify-vs-spendesk.md): E 41.1 vs B 62.3\n- [Pleo API + MCP vs Spendesk API + MCP](https://www.anchorterminal.com/compare/pleo-vs-spendesk.md): B 62.9 vs B 62.3\n- [Ramp vs Spendesk API + MCP](https://www.anchorterminal.com/compare/ramp-vs-spendesk.md): C 57.3 vs B 62.3\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on spendesk.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"spendesk\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/spendesk\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/spendesk.svg\" alt=\"Spendesk API + MCP on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Spendesk API + MCP on Anchor Terminal](https://www.anchorterminal.com/badges/spendesk.svg)](https://www.anchorterminal.com/tools/spendesk)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/spendesk\"\u003eSpendesk API + MCP on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Spendesk API + MCP is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/spendesk-dark.png\n- Light: https://www.anchorterminal.com/assets/share/spendesk-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Spend management \u0026 procurement",
        "url": "https://www.anchorterminal.com/categories/spend-management"
      },
      {
        "name": "Spendesk API + MCP",
        "url": ""
      }
    ],
    "description": "Spend management platform from Spendesk SAS in Paris, covering company cards, expense claims, supplier invoices, purchase orders and accounting exports. Outside agents reach it through a REST API with scoped keys or OAuth, and a hosted MCP server.",
    "facts": [
      "rank #306 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Spendesk API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/tools-spendesk.png",
    "path": "/tools/spendesk",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Spendesk API + MCP review for AI agents, grade B (62.3/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/spendesk"
  },
  "tokens": {
    "markdown": 7350,
    "slim": 1880
  },
  "version": 1
}
