# Spreedly

**Canonical:** https://apis.io/providers/spreedly/  
**Website:** https://www.spreedly.com/  
**APIs profiled:** 7

Spreedly is a United States payments orchestration platform and PCI-compliant card vault that lets merchants and platforms securely tokenize payment methods once and then transact against hundreds of payment gateways, processors, and third-party APIs through a single integration. Founded in 2008 and headquartered in Durham, North Carolina, Spreedly sits in the gateway/PSP layer of the deep, fragmented US payments market as an independent, network-agnostic intermediary rather than a card network or acquirer. Its Payments Orchestration offering combines a universal token vault, a normalized transaction API across many gateways, workflow-based routing (Composer), network tokenization, account updater (Card Refresher), 3-D Secure / SCA authentication, and Receivers for forwarding stored payment data to arbitrary third-party endpoints. Spreedly is strongly API-native: it publishes a public developer portal with complete reference documentation and a downloadable OpenAPI 3.1 specification for its Core Transactional API (https://core.spreedly.com/v1), authenticated with HTTP Basic auth using per-environment key/secret credentials.

## Kin Score — 61.0 / 100 (strong)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 61.0).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 66.2 |
| Governance | 20.8 |
| Operational Transparency | 63.2 |
| Developer Ergonomics | 79.9 |
| Commercial Clarity | 60.5 |

Regulatory layer — **Payments**: 46.9 (matched via tags).

## Agent readiness — 59.2 (agent-native)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | yes |
| Auth Clarity | yes |
| Idempotency | documented |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## APIs (7)

- **Spreedly Core Transactional API** — The Spreedly Core Transactional API — the primary REST surface for the Payments Orchestration platform. Covers payment method tokenization/vaulting, gateway creation and managem...
- **Spreedly Payment Methods & Vault API** — Create, retain, redact, recache, update, and inspect tokenized payment methods held in Spreedly's PCI-compliant universal vault, including field-level encryption and payment met...
- **Spreedly Composer (Workflows) API** — Workflow-driven orchestration endpoints (Composer) that execute an authorization, purchase, or verification against a configured routing workflow rather than a single named gate...
- **Spreedly Network Tokenization API** — Retrieve card metadata and lifecycle status for network tokens (Visa, Mastercard, Amex network-provisioned tokens) managed through Spreedly, supporting network tokenization for ...
- **Spreedly Account Updater (Card Refresher) API** — Card Refresher / account updater inquiries that refresh stored card credentials (expiration dates and PANs) against the card networks' account updater services to reduce decline...
- **Spreedly Receivers API** — Receivers let merchants forward securely vaulted payment data from the Spreedly vault to arbitrary third-party HTTP endpoints, extending tokenization beyond payment gateways to ...
- **Spreedly 3-D Secure / SCA Authentication API** — Strong Customer Authentication endpoints to authenticate a given payment method and manage SCA providers on a merchant profile, supporting 3-D Secure 2.x authentication flows fo...

## MCP servers (1)

- **spreedly-mcp.yml**

## Agentic access (1)

- **Spreedly Agentic Access** — 84 operations · 48 acting

## Security (3)

- **Spreedly Authentication** — http · 1 scheme
- **Spreedly Domain Security** — TLSv1.3 · HSTS · DMARC
- **Spreedly Trust Center** — SOC 2, PCI DSS

## Tags

Payments, United States, Payment Gateway, Payment Orchestration, Payment Processing, Card Vault, Tokenization, Network Tokenization, PCI Compliance, Subscriptions

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/spreedly/). Scores are computed from the provider's own public artifacts under a published rubric.
