Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Yokoy

Yokoy (now part of Perk / TravelPerk) is an AI-powered spend-management platform for expenses, supplier invoices and corporate cards. Its public REST API (OpenAPI 3.0, 105 operations) imports master and configuration data into Yokoy and exports financial data — expenses, trips, invoices, transactions, journal entries and FX rates — to third-party ERP and accounting systems. Authentication uses the OAuth2 client-credentials flow; every request is scoped to an organization ID and most resources to a legal entity (company). The API spans expenses, invoices, trips, transactions, company cards and card accounts, cost centers, categories, tax rates, suppliers, users, policies, tags and finance-export tasks.

agent ready

Real signal across most facets with visible, nameable gaps — the contract exists but is thin, or the portal is good while governance and commercial terms are absent.

Kin Score

API Evangelist profiles Yokoy the way a machine reads it — 28 machine-readable artifacts across 22 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Yokoy scores 47.2/100 (developing), with a separate agent-readiness read of 50/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 47.2/100 · developing
Contract Quality 14.5 / 25
Developer Ergonomics 13.0 / 20
Commercial Clarity 3.2 / 20
Operational Transparency 6.5 / 13
Governance 0.0 / 12
Discoverability 10.0 / 10
Agent readiness — 50/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 15
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 5 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 3 / 3

How we profile Yokoy

Each block below is one kind of artifact we hold for Yokoy. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 22

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

Yokoy Card account API

Card account associated to one of Yokoy's card programs. Only active card accounts are allowed to order new cards.

Yokoy Company card API

Company card entity in Yokoy. Company cards can be Yokoy Pay cards or external cards.

Yokoy Cost center API

Cost objects (also called cost centers) is a hierarchical construct to which costs that occur within a company can be assigned. Cost objects are created at legal entity level an...

Yokoy Daily statement API

Daily CAMT statement files associated with a card account. Statements provide a daily summary of transactions in a standardized banking format.

Yokoy Expense API

An expense is a cost incurred during the performance of a business activity. Employees can create reimbursable or non-reimbursable expenses. The Expense endpoints let you query ...

Yokoy Expense category API

Categories for expenses (also called booking accounts). These categories only apply to expenses and trips. For invoices, use supplier invoice categories.

Yokoy External invoice API

Invoices that are not present in Yokoy, but that are used for matching in purchase orders and goods receipts.

Yokoy Finance export API

Finance export mechanism in Yokoy. The Yokoy API exposes three different endpoints for the management of finance exports: 1. `/export-tasks` to trigger an export (separate endpo...

Yokoy FX rates API

Extend the offered and Yokoy-managed foreign exchange rates (Open Exchange Rates, CNB, NPB and NBS national bank rates) with your own customer-specific FX rates. The created FX ...

Yokoy Goods receipt API

Goods receipt are usually provided by suppliers when the goods of an order are delivered. Yokoy uses goods receipts to perform three-way matching (controlling invoice spending b...

Yokoy Invoice API

In the Yokoy API, invoices can only be created or retrieved. You can only update custom information via API. To update other attributes or delete the invoice, use the Yokoy web ...

Yokoy Invoice category API

Categories for invoices (equivalent to GL accounts in financial systems). These categories only apply to invoices. For expenses and trips, use expense categories.

Yokoy Invoice payment terms API

Payment terms determine the expectation of payment agreed between the company and the supplier. By default, all payment terms can be used with any supplier of the legal entity. ...

Yokoy Legal entity API

Legal entity or company. An organization can have multiple legal entities.

Yokoy Policy API

An employee policy determines the settings made available to a group of employees. A policy determines: - **categories**: the categories available to users to select. - **tags**...

Yokoy Purchase order API

Purchase orders are legal orders that companies send to their suppliers to buy items, services, products. Yokoy uses purchase orders to perform two-way and three-way matching (m...

Yokoy Supplier API

Companies that supply your company with goods, services, items. The Supplier entity contains information on the name, address, and bank accounts of the supplier. Suppliers can b...

Yokoy Tag API

Tag is a custom dimension that can be added to each category that help map additional information to that spend and use it at multiple levels, such as analytics or for accountin...

Yokoy Tax rates API

Tax rates. Tax rates apply to expenses, trips, and invoices. In Yokoy, you can consult them in **Admin > VAT / Tax rates**. For invoices, you can set up advanced tax components ...

Yokoy Transaction API

A transaction is a cleared payment that is made using a credit, debit, or prepaid card. The card issuer can be either Yokoy or a third party that has been integrated with Yokoy.

Yokoy Trip API

A trip is a collection of various types of expenses that occurred on a business trip over a period of time.

Yokoy User API

Users in Yokoy reflect the fundamental roles of submitter, approver, and finance user. Mandatory user information depends on the specific organization requirements and Yokoy fea...

Scroll within the panel for all 22 ·

MCP Servers 1

Model Context Protocol servers expose these APIs directly to AI agents. We profile them because agent-native access is the fastest-growing way this provider's capabilities actually get used.

Model Context Protocol servers that expose these APIs to AI agents.

yokoy-mcp.yml

MCP SERVER

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Yokoy Authentication

oauth2 · 1 scheme

SECURITY

Yokoy Domain Security

TLSv1.3 · DMARC

SECURITY

Yokoy Vulnerability Disclosure

Intigriti · security.txt · contact published

SECURITY

Yokoy Trust Center

ISO 27001, SOC 2, Cyber Essentials, GDPR

SECURITY

Scopes 1

OAuth scopes are the vocabulary of least-privilege access. Profiling them shows exactly what an integration — or an agent acting on a user's behalf — is allowed to do.

OAuth scopes governing access to this provider's APIs.

Yokoy Scopes

OAuth 2.0 · no documented scopes

0 scopes

SCOPES

Resources

Every other property we hold for Yokoy — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Get Started 2

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 4

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 2

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Company 1

The organization behind the API

← All providers · Data indexed from github.com/api-evangelist/yokoy · machine-readable index on apis.io