# Cledara > Cledara is a SaaS management and spend platform (London, UK) that gives finance, IT and procurement teams one place to see every software subscription a company pays for, pay for it on per-vendor virtual cards, and control it with budgets and approval workflows. It publishes two machine surfaces: a small read-only REST API over your own workspace, and an OAuth-protected MCP endpoint over its public SaaS market dataset. This file is generated by API Evangelist from Cledara's own published artifacts, captured 2026-09-05. It is not authored by Cledara. Cledara publishes its own llms.txt for the market data hub at https://data.cledara.com/llms.txt. ## Cledara API (workspace data) - [API documentation](https://api-docs.cledara.com/): the reference, rendered from Cledara's OpenAPI. - [OpenAPI 3.1.0](https://cledara-public.s3.eu-west-2.amazonaws.com/public-api/open-api.json): the published contract. Base URL https://api.cledara.com. - [Launch post](https://www.cledara.com/blog/introducing-the-cledara-api): what the API is and how to get a key. - [Ten things to build with it](https://www.cledara.com/blog/10-things-to-build-with-the-cledara-api): Cledara's own use cases. Shape, as of 2026-09-05: three operations, all GET, all read-only. - `GET /v0/applications` — every software subscription in the workspace, with status, owner, teams, budget, balance, next renewal date and expected next payment. No pagination, no filters. - `GET /v0/transactions` — card payments, transfers and account movements. Filter with `from`/`to` (RFC 3339) and `applicationIds[]`; page with `offset`, following `nextOffset` while `hasMore` is true. - `GET /v0/transactions/{transactionId}/invoice-url` — a download URL for a transaction's invoice, valid for 5 minutes. Only call it when the transaction's `hasInvoice` is true. Auth: `Authorization: Bearer `. Keys are self-served in the Cledara app under Settings → Profile Details → API Keys, and carry the same permissions as the user who created them. There are no scopes. Rate limit: 120 requests per minute per API key. `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset` are returned on every success; `Retry-After` on 429. What does NOT exist, as of 2026-09-05: no write operations, no webhooks or events, no AsyncAPI, no sandbox, no SDKs in any language, no CLI, no Postman collection, no GraphQL, no deprecation policy, and no RFC 9457 problem details. The API is included at no extra cost on every Cledara plan. ## Cledara SaaS Market Data Hub (public dataset) - [Data hub](https://data.cledara.com/): market share, adoption and spend across 9,300+ SaaS and AI products, from aggregated anonymized purchasing signals. - [Cledara's own llms.txt](https://data.cledara.com/llms.txt): the provider-authored index of the dataset's pages. - [MCP endpoint](https://data.cledara.com/mcp): remote MCP server over the same dataset. OAuth-protected; `tools/list` returns 401 without a token. - [OAuth authorization server metadata](https://data.cledara.com/.well-known/oauth-authorization-server): RFC 8414 document with dynamic client registration, PKCE S256, and the single scope `mcp:read`. - [Market Movements feed](https://data.cledara.com/feed.xml): dated Atom feed of notable changes. - [Ask Cledara](https://data.cledara.com/ask): natural-language queries over the dataset. The two surfaces do not overlap. The REST API reads your own workspace; the MCP endpoint reads the public market dataset. Neither can do the other's job, and neither credential works on the other. ## Company - [Website](https://www.cledara.com/) - [Pricing](https://www.cledara.com/pricing) — Basic £100/month, Premium and Pro on request; all three advertise unlimited API access. - [Security](https://www.cledara.com/security) — SOC 2 Type II and GDPR. FCA EMD Agent 902831, under Modulr FS Limited (FRN 900573). - [Trust center](https://trust.cledara.com/) — Vanta-hosted; documents are request-gated. - [Status](https://statuspage.cledara.com/) — BetterStack; monitors app.cledara.com only, not the API hosts. - [Announcements](https://announcements.cledara.com/announcements) — dated product changelog. The API launched 27 Aug 2026. - [Help center](https://help.cledara.com/hc/) - [Blog](https://www.cledara.com/blog) - [Integrations](https://www.cledara.com/integrations) - [Terms](https://www.cledara.com/terms-and-conditions) · [Privacy](https://www.cledara.com/privacy-policy) ## API Evangelist artifacts in this repository - `openapi/cledara-api-openapi.json` — the provider's spec, verbatim. - `authentication/cledara-authentication.yml` · `scopes/cledara-scopes.yml` - `conventions/cledara-conventions.yml` — pagination, money, versioning, idempotency and reversibility (both `na`: the API is read-only). - `errors/cledara-problem-types.yml` — the vendor error envelope, recorded from a live probe. - `data-model/cledara-data-model.yml` · `rate-limits/cledara-rate-limits.yml` · `plans/cledara-plans-pricing.yml` - `lifecycle/cledara-lifecycle.yml` · `changelog/cledara-changelog.yml` · `conformance/cledara-conformance.yml` - `mcp/cledara-mcp.yml` · `mcp/cledara-tool-crosswalk.yml` · `well-known/cledara-well-known.yml` - `security/` — domain security, trust center, vulnerability disclosure (none published). - `skills/` — four packaged agent skills grounded in the three real operations.