# Spendesk API + MCP (slim) > Spend management platform from Spendesk SAS in Paris, covering company cards, expense claims, supplier invoices, purchase orders and accounting exports. Outside agents reach it through a REST API with scoped keys or OAuth, and a hosted MCP server. - Full: https://www.anchorterminal.com/tools/spendesk.md (~7,350 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/spendesk.json · canonical https://www.anchorterminal.com/tools/spendesk - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 62.3/100 · rank #306 of 629 · #2 in Spend management & procurement · not agent-ready · confidence medium** Assessment: Scoped credentials, MCP write permissions that are off by default, an action log and published guidance on prompt injection suit delegated finance work. Access needs a paying customer and a request to Spendesk, most write endpoints are experimental, no official SDK was found, and the status page lists three critical incidents between 2 and 29 September 2026. ## Facts - Kind: HTTP API · vendor: Spendesk SAS · category: Spend management & procurement · legal entity: Spendesk SAS · provenance 96/100 - Endpoint: `https://public-api.spendesk.com` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under Spendesk's terms and conditions and a separate Spendesk API agreement - Probe metrics: not measured yet (probes haven't run) - API: REST, OpenAPI 3.1, 106 operations under /v1 and /v2 at https://public-api.spendesk.com, with a demo environment at https://public-api.demo.spendesk.com. 54 GET, 26 POST, 10 PATCH, 8 PUT, 8 DELETE - MCP server: Hosted at https://public-api.spendesk.com/v1/mcp, Streamable HTTP, tools only. 62 tools (36 read, 26 act). Reading is generally available, write actions are in beta. Clients for Claude, ChatGPT and Dust are created in Spendesk settings. Dust and Langdock can use dynamic client registration - Credentials: API key (client ID and secret, valid up to one year, scopes ticked at creation) exchanged for a 60-minute token, or OAuth 2.0 authorisation code with PKCE for partner apps and MCP. Refresh tokens rotate and last about 30 days - Scopes: 12 standard scopes (11 read, plus `cost-center:manage`) and 25 experimental ones listed in the docs, among them experimental:transaction:read, experimental:card:read, experimental:invoice:read and experimental:purchase-order:write - Access: Customers ask a Spendesk representative for API access, then an Account Owner or Admin creates the key. Partner OAuth apps go through the partnerships team. Demo credentials are requested with API access - Rate limits: 1,000 requests a minute per company and credential, 500 concurrent requests per consumer, 10 a minute for dynamic client registration. MCP adds 100 concurrent requests per company and 200 per organisation - Pagination: Page-based on most lists (pageSize default and maximum 30), cursor-based on invoices, intakes, analytical field values and expense categories, offset on accounts. MCP list tools return 100 items by default, up to 1,000, with fetchAll capped at 5,000 - Errors: JSON with a correlationId and a list of errors, each with a stable code, a detail and the source field. Bulk updates return 207 with a per-item outcome. MCP tool errors return isError true with a sentence - Webhooks: Experimental. Events payables:created, payables:prepared and settlements:created, signed with HMAC SHA256 in x-spendesk-webhook-signature, retried for 3 days, 50 instances per company - Audit: MCP action log per connection (date, tool, status, user, company, duration, correlation ID), without tool arguments. No equivalent log for API keys was found in the docs - Versioning: Major version in the path. Deprecation and Sunset response headers carry dates. Experimental endpoints may change - Certifications: ISO 27001:2022 per the security page. Card partners are PCI DSS certified. Trust centre at trust.spendesk.com - Status: status.spendesk.com on Atlassian Statuspage, components by product area (Login, cards, Invoices, Bookkeep exports and others), none for the public API - Sub-processors: List dated 31 August 2026 with address, purpose, data types, location and safeguards for each. Hosting on AWS in the European Union - Scores: Reliability 55, Performance pending, Schema & documentation 87, Agent ergonomics 62, Security & auth 86, Payments & pricing 0, Task success pending, Maintenance & community 57, Transparency & trust 80 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the public REST API and the MCP server on the same host. · Schema & documentation, A public OpenAPI 3.1 definition with 106 operations at developer.spendesk.com/openapi/spendesk-public-api.json (25). · Agent ergonomics, The MCP server has 62 tools, which is the lowest band, but tools/list returns only the tools the user's permissions allow and write permissi… · Security & auth, OAuth 2.0 authorisation code with PKCE (S256), 37 documented scopes, one-hour access tokens and rotating refresh tokens for MCP and partner… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The newest changelog entry was created on 29 September 2026, MCP write actions arrived on 25 September, and docs pages were updated on 1 Oct… · Transparency & trust, Closed service. - Sources: 27, open questions: 8, both in the full twin - Capabilities: spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement - JSON: https://www.anchorterminal.com/api/v1/tools/spendesk.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/spendesk.svg` or a link to https://www.anchorterminal.com/tools/spendesk from a page on spendesk.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Request a token at POST /v1/auth/token with HTTP Basic (client ID and secret). It lasts 3,600 seconds, so renew on a 401 2. Stop paging at the last page calculated from `total` and `pageSize` (maximum 30). A page past the end returns 404, not an empty list 3. With an organisation-level token, send `X-Company-Id` on every v1 call or expect a 400 4. The MCP server refuses API keys. Connect with OAuth authorisation code and PKCE, and treat `Tool not found` (-32601) as a missing permission 5. After an unclear write result, read the object again before retrying. Creating a purchase order or supplier twice creates two ## Connect ```bash curl -X POST https://public-api.demo.spendesk.com/v1/auth/token \ -u "YOUR_CLIENT_ID:YOUR_CLIENT_SECRET" curl https://public-api.demo.spendesk.com/v1/wallet-summary \ -H "Authorization: Bearer YOUR_ACCESS_TOKEN" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/spendesk ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Ramp | C | 57.3 | spend.transactions, spend.expenses, spend.cards, spend.bills, spend.procurement | https://www.anchorterminal.com/tools/ramp.min.md | | Brex | C | 60.7 | spend.transactions, spend.expenses, spend.cards, spend.bills | https://www.anchorterminal.com/tools/brex.min.md | | Pleo API + MCP | B | 62.9 | spend.transactions, spend.expenses, spend.bills | https://www.anchorterminal.com/tools/pleo.min.md | | Expensify | E | 41.1 | spend.transactions, spend.expenses | https://www.anchorterminal.com/tools/expensify.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)