# Mesh Payments

**Canonical:** https://apis.io/providers/mesh-payments/  
**Website:** https://meshpayments.com/  
**APIs profiled:** 2

Mesh Payments is a global travel and expense (T&E) and spend management platform for finance teams, combining corporate virtual and physical card issuing, expense management, accounts payable, procurement (ProcurePay), travel booking and accounting automation in a single system. Mesh exposes a RESTful API on api.meshpayments.com for virtual card lifecycle management, merchant and category controls, metadata tagging, authorization and settlement retrieval and real-time balance queries, authenticated with either HMAC-SHA256 request signing or OAuth 2.0 client credentials. It also publishes an OAuth-protected Model Context Protocol (MCP) server at api.meshpayments.com/mcp and a configurable webhooks surface, plus ERP, HRIS and TMC integrations.

## Kin Score — 52.5 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 52.5).

| Facet | Score |
|---|---|
| Discoverability | 87.0 |
| Contract Quality | 51.6 |
| Governance | 12.5 |
| Operational Transparency | 39.5 |
| Developer Ergonomics | 43.5 |
| Commercial Clarity | 60.5 |

Regulatory layer — **Payments**: 71.9 (matched via tags).

## Agent readiness — 41.4 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| MCP Server | yes |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## APIs (2)

- **Mesh Payments API** — RESTful API for the Mesh spend management platform. Documented capabilities include connectivity verification, virtual card lifecycle management (issuance, suspension, cancellat...
- **Mesh Payments MCP Server** — OAuth-protected Model Context Protocol (MCP) server operated by Mesh at api.meshpayments.com/mcp. The endpoint advertises RFC 9728 OAuth 2.0 Protected Resource Metadata at /.wel...

## MCP servers (1)

- **mesh-payments-mcp.yml**

## Security (4)

- **Mesh Payments Authentication** — http/oauth2/custom-hmac · 3 schemes
- **Mesh Payments Domain Security** — TLSv1.3 · HSTS · DMARC
- **Mesh Payments Vulnerability Disclosure** — security.txt · contact published
- **Mesh Payments Trust Center** — SOC 1 Type II, SOC 2 Type II, PCI DSS, GDPR, CCPA, Vendor Security Alliance (VSA)

## Tags

Company, Payments, Spend Management, Expense Management, Corporate Cards, Travel, Accounts Payable, Fintech, Card Issuing, Accounting Automation

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/mesh-payments/). Scores are computed from the provider's own public artifacts under a published rubric.
