{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "adobe-commerce",
    "name": "Adobe Commerce (Magento)",
    "vendor": "Adobe Inc.",
    "vendorUrl": "https://business.adobe.com/products/commerce.html",
    "kind": "http-api",
    "category": "commerce",
    "summary": "Commerce platform from Adobe, built on the open-source Magento core. It runs as Adobe Commerce as a Cloud Service, on Adobe's cloud infrastructure or on the merchant's own servers, and agents reach a store through its REST and GraphQL APIs.",
    "url": "https://www.anchorterminal.com/tools/adobe-commerce",
    "markdownUrl": "https://www.anchorterminal.com/tools/adobe-commerce.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/adobe-commerce.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/adobe-commerce.json",
    "repo": "https://github.com/magento/magento2",
    "license": "Proprietary for Adobe Commerce under Adobe's General Terms and product-specific licensing terms. The Magento Open Source core is OSL 3.0",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "npm",
        "name": "@adobe/aio-commerce-sdk"
      }
    ],
    "auth": "mixed",
    "authNotes": "Access comes from the merchant, with no Adobe review of the caller. On Adobe Commerce as a Cloud Service an organisation admin creates an OAuth credential in Adobe Developer Console, and calls carry an Adobe IMS bearer token, from client credentials with the `commerce.accs` scope or from a user flow tied to an Admin role. On Adobe Commerce on Cloud, on-premises and Magento Open Source, the merchant creates an integration limited to chosen ACL resources and requests are signed by OAuth 1.0a. Admin tokens last 4 hours and customer tokens 1 hour by default, and a bare integration token as a bearer token is off by default.",
    "pricing": "freemium",
    "pricingNotes": "No price was read. business.adobe.com timed out on every request on 8 October 2026, and the cloud service licensing terms define an account as one opened under a sales order. No sandbox or trial open without a contract was found in the pages we could read. Magento Open Source, the core with the same REST and GraphQL framework, is free under OSL 3.0, so an owner can start on a self-hosted store with no contract. Its Composer install needs keys from a Commerce Marketplace account.",
    "priceSummary": "Freemium",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the web API docs or the Swagger and GraphQL schemas (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 12198,
      "npmWeekly": 1317,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.adobe.com/commerce/webapi/",
    "openapi": "https://github.com/AdobeDocs/commerce-webapi/tree/main/src/openapi",
    "capabilities": [
      "commerce.products",
      "commerce.orders",
      "commerce.cart",
      "commerce.checkout",
      "commerce.headless"
    ],
    "tags": [
      "hosted",
      "self-hosted",
      "enterprise",
      "open-source",
      "openapi",
      "graphql",
      "oauth",
      "php",
      "sales-led",
      "status-page",
      "bug-bounty",
      "b2b"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 63.9,
      "grade": "B",
      "agentReady": false,
      "rank": 290,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 9,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 67,
        "maintenance": 75,
        "payments": 30,
        "reliability": 55,
        "schema": 82,
        "security": 60,
        "transparency": 90
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 55,
          "points": 11,
          "reason": "Graded with the hosted lines, because Adobe runs the cloud service and Adobe Commerce on Cloud. status.adobe.com lists Adobe Commerce with its components and regions (20). Its event feed shows eight Commerce events between 1 and 23 September 2026, three marked major. Catalogue Service, Live Search and the Admin panel had 2 hours 10 minutes of availability and performance trouble on 1 September, Live Search 45 minutes on 2 September, and Commerce Admin and provisioning on the cloud service 1 hour 39 minutes on 18 September. None names the REST or GraphQL endpoint itself, so 5 of 30 where several majors would score 0 (5). Input limits are published with numbers (20 items in a list input, 5,000 for asynchronous calls, 300 a page, GraphQL complexity 300 and depth 20), but no request rate limit was found (5). The server-to-server sample retries on 429 after `retry-after`, with no written guidance and no idempotency keys found (5). The Unified SLA's Actionability Addendum of 23 July 2026 covers Adobe Commerce. We didn't read the percentage (10). Generally available (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 82,
          "points": 13.33,
          "reason": "Swagger 2.0 YAML files in the public docs repository for the cloud service (510 operations, version September 2026) and for the admin, customer and guest APIs of 2.4.6 to 2.4.9, plus GraphQL introspection JSON for each (25). Every page on developer.adobe.com is also served as Markdown at the same path with `.md`. No llms.txt there, and Experience League has one for the operations and admin guides (10). All 510 cloud service operations carry a description, with a median length of 39 characters and 147 under 30, and 239 of 246 GraphQL queries and mutations have one. None says when not to use a call (11). Definitions are typed and GraphQL uses enums, while `searchCriteria` parameters are plain strings and `custom_attributes` and `extension_attributes` are open (10). Tutorials with full requests and responses, a status code table, and 400, 401 and 500 responses in the spec, with no list of error codes (11). A schema per release, monthly cloud service release notes and release notes for each 2.4 version (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 67,
          "points": 10.89,
          "reason": "`?fields=` trims any REST response and GraphQL returns only the fields asked for. The surface is large, at 510 REST operations and 246 GraphQL queries and mutations on the cloud service (23). `searchCriteria` gives filters with comparison operators such as `eq`, `in` and `like`, sort orders, `pageSize` and `currentPage`, and GraphQL lists page the same way (20). REST errors are an HTTP code and a message with parameters. GraphQL answers 200 for business errors with a message and a category, and no stable list of codes was found (12). No idempotency keys found. Asynchronous and bulk endpoints return a bulk UUID whose status can be read back, and PUT by SKU updates in place (6). List calls need the long `searchCriteria` syntax, 2.4 stores need OAuth 1.0a signing, and the only official client library is `@adobe/aio-commerce-sdk` for JavaScript (6)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 60,
          "points": 10.5,
          "reason": "The cloud service takes OAuth 2 tokens from Adobe IMS, by client credentials with the `commerce.accs` scope or by a user flow tied to an Admin role. A 2.4 store issues integrations whose requests are signed by OAuth 1.0a, admin tokens that last 4 hours and customer tokens that last 1 hour, and bare integration tokens as bearer tokens are off by default. No secret in a URL was found. Scopes stop at the product level, so finer limits come from roles (26). Each integration or admin role is limited to chosen ACL resources. No read-only switch or confirmation step for writes was found (12). The APIs return shopper-written text such as names, order comments and reviews, and no prompt-injection guidance was found (0). Action Logs record admin users' changes with user, IP address and date on Adobe Commerce, not on Magento Open Source. Whether integration calls are logged wasn't established (8). security.txt is valid to 30 July 2027 and names a public Intigriti programme and PSIRT, and security patches are tied to numbered bulletins. The compliance list didn't show its Commerce rows to our reader (14)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 in the API docs or the schemas (0). business.adobe.com timed out on every request on 8 October 2026, so the pricing page is unread and scored as absent. The cloud service licensing terms define an account as one opened under a sales order (0). Magento Open Source, the core with the same REST and GraphQL framework, is free under OSL 3.0 with no card (20). Its Composer install needs authentication keys from a Commerce Marketplace account, which a person creates. The public Git repository can be cloned with no account and the install guide points contributors to it, so half the points (10)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 75,
          "points": 6.56,
          "reason": "The cloud service's latest production release is dated 7 October 2026 (30). Four cloud service releases since August 2026, in August, twice in September and in October. The 2.4 line last shipped on 12 May 2026 with 2.4.9 and security patches for 2.4.6 to 2.4.8 (20). The API docs repository merged pull requests on 8 October 2026. magento/magento2 has 1,230 open issues and we couldn't read how recent the replies are, because the GitHub API refused us for its rate limit (12). `@adobe/aio-commerce-sdk` is at 2.0.0 with alpha builds published on 8 October 2026. It is for App Builder and JavaScript only, and no Adobe Commerce server is in the official MCP registry (8). The docs repository carries tests and link checks. CI on the core repository wasn't read (5)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 90,
          "points": 7.88,
          "note": "editorial 80, provenance 99",
          "reason": "Magento Open Source is OSL 3.0. Adobe Commerce is proprietary under Adobe's General Terms (2025v1, 3 October 2025) and a product-specific document for each deployment, all public (22). The privacy policy of 24 October 2025 says Adobe is the processor for enterprise products and that the policy doesn't cover data its customers collect. The cloud service terms keep customer data for the licence term and allow 30 days to export after it ends. A data processing addendum is published, which we didn't read (22). The lifecycle policy gives three years of standard support and end dates for every release from 2.4.4 to 2.4.9, and says Cloud environments on unsupported versions lose traffic from 1 June 2027. No notice period for API changes on the cloud service was found (18). The sub-processor list, updated 28 September 2026, names seven for Adobe Commerce with countries or regions, among them Microsoft, Platform.sh, Fastly and New Relic (18)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`?fields=` trims any REST response and GraphQL returns only the fields asked for. The surface is large, at 510 REST operations and 246 GraphQL queries and mutations on the cloud service (23). `searchCriteria` gives filters with comparison operators such as `eq`, `in` and `like`, sort orders, `pageSize` and `currentPage`, and GraphQL lists page the same way (20). REST errors are an HTTP code and a message with parameters. GraphQL answers 200 for business errors with a message and a category, and no stable list of codes was found (12). No idempotency keys found. Asynchronous and bulk endpoints return a bulk UUID whose status can be read back, and PUT by SKU updates in place (6). List calls need the long `searchCriteria` syntax, 2.4 stores need OAuth 1.0a signing, and the only official client library is `@adobe/aio-commerce-sdk` for JavaScript (6).",
          "maintenance": "The cloud service's latest production release is dated 7 October 2026 (30). Four cloud service releases since August 2026, in August, twice in September and in October. The 2.4 line last shipped on 12 May 2026 with 2.4.9 and security patches for 2.4.6 to 2.4.8 (20). The API docs repository merged pull requests on 8 October 2026. magento/magento2 has 1,230 open issues and we couldn't read how recent the replies are, because the GitHub API refused us for its rate limit (12). `@adobe/aio-commerce-sdk` is at 2.0.0 with alpha builds published on 8 October 2026. It is for App Builder and JavaScript only, and no Adobe Commerce server is in the official MCP registry (8). The docs repository carries tests and link checks. CI on the core repository wasn't read (5).",
          "payments": "No x402, MPP or L402 in the API docs or the schemas (0). business.adobe.com timed out on every request on 8 October 2026, so the pricing page is unread and scored as absent. The cloud service licensing terms define an account as one opened under a sales order (0). Magento Open Source, the core with the same REST and GraphQL framework, is free under OSL 3.0 with no card (20). Its Composer install needs authentication keys from a Commerce Marketplace account, which a person creates. The public Git repository can be cloned with no account and the install guide points contributors to it, so half the points (10).",
          "reliability": "Graded with the hosted lines, because Adobe runs the cloud service and Adobe Commerce on Cloud. status.adobe.com lists Adobe Commerce with its components and regions (20). Its event feed shows eight Commerce events between 1 and 23 September 2026, three marked major. Catalogue Service, Live Search and the Admin panel had 2 hours 10 minutes of availability and performance trouble on 1 September, Live Search 45 minutes on 2 September, and Commerce Admin and provisioning on the cloud service 1 hour 39 minutes on 18 September. None names the REST or GraphQL endpoint itself, so 5 of 30 where several majors would score 0 (5). Input limits are published with numbers (20 items in a list input, 5,000 for asynchronous calls, 300 a page, GraphQL complexity 300 and depth 20), but no request rate limit was found (5). The server-to-server sample retries on 429 after `retry-after`, with no written guidance and no idempotency keys found (5). The Unified SLA's Actionability Addendum of 23 July 2026 covers Adobe Commerce. We didn't read the percentage (10). Generally available (10).",
          "schema": "Swagger 2.0 YAML files in the public docs repository for the cloud service (510 operations, version September 2026) and for the admin, customer and guest APIs of 2.4.6 to 2.4.9, plus GraphQL introspection JSON for each (25). Every page on developer.adobe.com is also served as Markdown at the same path with `.md`. No llms.txt there, and Experience League has one for the operations and admin guides (10). All 510 cloud service operations carry a description, with a median length of 39 characters and 147 under 30, and 239 of 246 GraphQL queries and mutations have one. None says when not to use a call (11). Definitions are typed and GraphQL uses enums, while `searchCriteria` parameters are plain strings and `custom_attributes` and `extension_attributes` are open (10). Tutorials with full requests and responses, a status code table, and 400, 401 and 500 responses in the spec, with no list of error codes (11). A schema per release, monthly cloud service release notes and release notes for each 2.4 version (15).",
          "security": "The cloud service takes OAuth 2 tokens from Adobe IMS, by client credentials with the `commerce.accs` scope or by a user flow tied to an Admin role. A 2.4 store issues integrations whose requests are signed by OAuth 1.0a, admin tokens that last 4 hours and customer tokens that last 1 hour, and bare integration tokens as bearer tokens are off by default. No secret in a URL was found. Scopes stop at the product level, so finer limits come from roles (26). Each integration or admin role is limited to chosen ACL resources. No read-only switch or confirmation step for writes was found (12). The APIs return shopper-written text such as names, order comments and reviews, and no prompt-injection guidance was found (0). Action Logs record admin users' changes with user, IP address and date on Adobe Commerce, not on Magento Open Source. Whether integration calls are logged wasn't established (8). security.txt is valid to 30 July 2027 and names a public Intigriti programme and PSIRT, and security patches are tied to numbered bulletins. The compliance list didn't show its Commerce rows to our reader (14).",
          "transparency": "Magento Open Source is OSL 3.0. Adobe Commerce is proprietary under Adobe's General Terms (2025v1, 3 October 2025) and a product-specific document for each deployment, all public (22). The privacy policy of 24 October 2025 says Adobe is the processor for enterprise products and that the policy doesn't cover data its customers collect. The cloud service terms keep customer data for the licence term and allow 30 days to export after it ends. A data processing addendum is published, which we didn't read (22). The lifecycle policy gives three years of standard support and end dates for every release from 2.4.4 to 2.4.9, and says Cloud environments on unsupported versions lose traffic from 1 June 2027. No notice period for API changes on the cloud service was found (18). The sub-processor list, updated 28 September 2026, names seven for Adobe Commerce with countries or regions, among them Microsoft, Platform.sh, Fastly and New Relic (18)."
        },
        "sources": [
          {
            "what": "Commerce web API docs index, as Markdown",
            "url": "https://developer.adobe.com/commerce/webapi/index.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API docs repository at its commit of 8 October 2026 (Swagger files in `src/openapi`, GraphQL schema JSON in `spectaql`, REST, GraphQL and authentication pages)",
            "url": "https://github.com/AdobeDocs/commerce-webapi",
            "seen": "2026-10-08"
          },
          {
            "what": "REST overview (deployments, URL structure, first request)",
            "url": "https://developer.adobe.com/commerce/webapi/rest/",
            "seen": "2026-10-08"
          },
          {
            "what": "cloud service REST authentication",
            "url": "https://developer.adobe.com/commerce/webapi/rest/authentication/",
            "seen": "2026-10-08"
          },
          {
            "what": "server-to-server authentication",
            "url": "https://developer.adobe.com/commerce/webapi/rest/authentication/server-to-server/",
            "seen": "2026-10-08"
          },
          {
            "what": "token-based authentication on 2.4 stores",
            "url": "https://developer.adobe.com/commerce/webapi/get-started/authentication/gs-authentication-token/",
            "seen": "2026-10-08"
          },
          {
            "what": "input limiting",
            "url": "https://developer.adobe.com/commerce/webapi/get-started/api-security/",
            "seen": "2026-10-08"
          },
          {
            "what": "payment rate limiting",
            "url": "https://developer.adobe.com/commerce/webapi/get-started/rate-limiting/",
            "seen": "2026-10-08"
          },
          {
            "what": "GraphQL security configuration",
            "url": "https://developer.adobe.com/commerce/webapi/graphql/usage/security-configuration/",
            "seen": "2026-10-08"
          },
          {
            "what": "status codes and responses",
            "url": "https://developer.adobe.com/commerce/webapi/get-started/gs-web-api-response/",
            "seen": "2026-10-08"
          },
          {
            "what": "filtered responses",
            "url": "https://developer.adobe.com/commerce/webapi/rest/use-rest/retrieve-filtered-responses/",
            "seen": "2026-10-08"
          },
          {
            "what": "cloud service release notes",
            "url": "https://experienceleague.adobe.com/en/docs/commerce/cloud-service/release-notes",
            "seen": "2026-10-08"
          },
          {
            "what": "cloud service overview",
            "url": "https://experienceleague.adobe.com/en/docs/commerce/cloud-service/overview",
            "seen": "2026-10-08"
          },
          {
            "what": "shared responsibility model",
            "url": "https://experienceleague.adobe.com/en/docs/commerce/cloud-service/shared-responsibility",
            "seen": "2026-10-08"
          },
          {
            "what": "released versions",
            "url": "https://experienceleague.adobe.com/en/docs/commerce-operations/release/versions",
            "seen": "2026-10-08"
          },
          {
            "what": "lifecycle policy",
            "url": "https://experienceleague.adobe.com/en/docs/commerce-operations/release/planning/lifecycle-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "patch release schedule",
            "url": "https://experienceleague.adobe.com/en/docs/commerce-operations/release/planning/schedule",
            "seen": "2026-10-08"
          },
          {
            "what": "security patch notes for 2.4.8",
            "url": "https://experienceleague.adobe.com/en/docs/commerce-operations/release/notes/security-patches/2-4-8-patches",
            "seen": "2026-10-08"
          },
          {
            "what": "Composer install guide",
            "url": "https://experienceleague.adobe.com/en/docs/commerce-operations/installation-guide/composer",
            "seen": "2026-10-08"
          },
          {
            "what": "Action Logs",
            "url": "https://experienceleague.adobe.com/en/docs/commerce-admin/systems/action-logs/action-log",
            "seen": "2026-10-08"
          },
          {
            "what": "Experience League llms.txt",
            "url": "https://experienceleague.adobe.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "status page",
            "url": "https://status.adobe.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "status event feed the status page loads",
            "url": "https://data.status.adobe.com/adobestatus/StatusEvents",
            "seen": "2026-10-08"
          },
          {
            "what": "product terms index",
            "url": "https://www.adobe.com/legal/terms/enterprise-licensing/all-product-terms.html",
            "seen": "2026-10-08"
          },
          {
            "what": "General Terms page",
            "url": "https://www.adobe.com/legal/terms/enterprise-licensing/overview.html",
            "seen": "2026-10-08"
          },
          {
            "what": "licensing terms for Adobe Commerce as a Cloud Service (2025v1)",
            "url": "https://www.adobe.com/cc-shared/assets/pdf/legal/terms/enterprise/pdfs/pslt-adobecommerce-cloudservice-2025v1.pdf",
            "seen": "2026-10-08"
          },
          {
            "what": "service commitments (SLA documents)",
            "url": "https://www.adobe.com/legal/service-commitments.html",
            "seen": "2026-10-08"
          },
          {
            "what": "data protection terms page",
            "url": "https://www.adobe.com/legal/terms/enterprise-licensing/data-protection.html",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.adobe.com/privacy/policy.html",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processor list",
            "url": "https://www.adobe.com/privacy/sub-processors.html",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.adobe.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "core repository (licence, stars, releases)",
            "url": "https://github.com/magento/magento2",
            "seen": "2026-10-08"
          },
          {
            "what": "npm package",
            "url": "https://registry.npmjs.org/@adobe/aio-commerce-sdk/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=adobe",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.verisign.com/com/v1/domain/adobe.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the pricing page at business.adobe.com/products/commerce/pricing.html, which timed out on every request, so no price, trial or sandbox offer was read and Payments scores it as absent",
          "unchecked: the security bulletins at helpx.adobe.com (APSB26-05 and APSB26-49 among them), which answered 403, so severities and any exploitation in the last 12 months weren't read and no deduction was considered",
          "unchecked: which certifications Adobe lists for Adobe Commerce. The compliance list didn't show its product rows to our reader",
          "unchecked: the uptime percentage and credits in the Unified SLA and its Actionability Addendum, and the text of the General Terms and the data processing addendum",
          "unchecked: how quickly issues on magento/magento2 get a reply, and whether its CI passes. The GitHub API refused us for its rate limit",
          "No request rate limit for the cloud service's REST or GraphQL APIs was found in the reviewed documentation",
          "Whether calls made by an integration appear in Action Logs wasn't established",
          "The sub-processor list names Microsoft for hosting, while the status page's registry lists Commerce Cloud regions on AWS, Azure and GCP"
        ]
      },
      "negative": 0,
      "verdict": "Public Swagger files cover 510 REST operations for the cloud service, the GraphQL schema carries cart, checkout and order mutations, and the cloud service authenticates by OAuth 2 through Adobe IMS. No request rate limit or idempotency key was found in the API documentation, Adobe publishes no MCP server for Commerce, and a licence starts with a sales order.",
      "bestFor": "An agent working for a merchant already on Adobe Commerce or Magento, for catalogue, order and B2B back-office work over REST and for carts and checkout over GraphQL.",
      "strengths": [
        "Swagger 2.0 files for the cloud service (510 operations) and for releases 2.4.6 to 2.4.9 sit in the public docs repository",
        "The cloud service takes OAuth 2 client credentials or user tokens from Adobe IMS, and older bearer integration tokens are off by default on 2.4 stores",
        "`?fields=` trims any REST response, and `searchCriteria` filters, sorts and pages every list endpoint",
        "Cloud service release notes list four production releases between August and 7 October 2026, each naming new endpoints",
        "A lifecycle policy gives end-of-support dates for every 2.4 release line, and the sub-processor list was updated on 28 September 2026"
      ],
      "weaknesses": [
        "No request rate limit for the REST or GraphQL APIs was found in the reviewed documentation, and 429 handling appears only in a code sample",
        "No idempotency keys were found, so a retried POST can create a second order or cart item",
        "status.adobe.com lists three Commerce incidents marked major in September 2026, two of them longer than an hour",
        "The cloud service drops the customer and guest REST APIs, so shopping flows there go through GraphQL only",
        "No Adobe MCP server for Commerce was found, and the only official client library is a JavaScript package for App Builder"
      ],
      "agentNotes": [
        "Ask which deployment the store is. The cloud service answers at `https://\u003cserver\u003e.api.commerce.adobe.com/\u003ctenant-id\u003e/` with no `/rest` prefix, and other stores at `https://\u003chost\u003e/rest/\u003cstore-view-code\u003e/`",
        "On the cloud service, request an IMS token with the `commerce.accs` scope and send the `Store` header to pick the store view",
        "On a 2.4 store, sign requests with all four integration credentials by OAuth 1.0a. A bare integration token is refused unless the merchant has switched that on",
        "Add `?fields=` to REST calls and set `searchCriteria[pageSize]`. Stores with input limits on cap a page at 300 items",
        "Don't retry `placeOrder` or a POST blindly. Read the cart or order back first, because no idempotency key was found"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 63.9
        }
      ],
      "editorialScores": {
        "ergonomics": 67,
        "maintenance": 75,
        "payments": 30,
        "reliability": 55,
        "schema": 82,
        "security": 60,
        "transparency": 80
      },
      "provenanceScore": 99
    },
    "connect": {
      "http": "curl --location 'https://\u003cserver\u003e.api.commerce.adobe.com/\u003ctenant-id\u003e/\u003cendpoint\u003e' \\\n  --header 'Authorization: Bearer \u003ctoken\u003e' \\\n  --header 'Content-Type: application/json' \\\n  --header 'Store: \u003call | default | \u003cstore_view_code\u003e\u003e'"
    },
    "letme": {
      "capability": "https://letme.dev/commerce.products",
      "tool": "https://letme.dev/adobe-commerce"
    },
    "sameCompany": [
      "adobe-firefly",
      "adobe-pdf-extract",
      "adobe-photoshop-api"
    ],
    "notable": [
      "Three deployments share one API framework. The cloud service answers at `https://\u003cserver\u003e.api.commerce.adobe.com/\u003ctenant-id\u003e/` and drops the customer and guest REST APIs, which stay available through GraphQL (https://developer.adobe.com/commerce/webapi/rest/)",
      "The cloud service release of 7 October 2026 added REST endpoints for catalogue price rules, custom cart item prices and shipping discounts (https://experienceleague.adobe.com/en/docs/commerce/cloud-service/release-notes)",
      "Input limits are off by default on 2.4 stores. When on, a list input takes 20 items, an asynchronous one 5,000, and a page 300 (https://developer.adobe.com/commerce/webapi/get-started/api-security/)",
      "GraphQL queries are capped at a complexity of 300 and a depth of 20 by default (https://developer.adobe.com/commerce/webapi/graphql/usage/security-configuration/)",
      "status.adobe.com's event feed shows eight Adobe Commerce events between 1 and 23 September 2026, three marked major (https://status.adobe.com/)",
      "Adobe Commerce 2.4.9 was released on 12 May 2026 with standard support to 31 May 2029, and Cloud environments on unsupported versions lose traffic from 1 June 2027 (https://experienceleague.adobe.com/en/docs/commerce-operations/release/planning/lifecycle-policy)",
      "No Adobe Commerce server from Adobe is in the official MCP registry. The entries that name it are third parties' (https://registry.modelcontextprotocol.io/v0/servers?search=adobe)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Deployments",
        "value": "Adobe Commerce as a Cloud Service (run by Adobe), Adobe Commerce on Cloud, Adobe Commerce on-premises, and the free Magento Open Source core. All use the same web API framework"
      },
      {
        "label": "REST API",
        "value": "Cloud service 510 operations under `/V1` (Swagger 2.0, version September 2026), admin and integration access only. Release 2.4.9 has 614 admin, 117 customer and 78 guest operations at `https://\u003chost\u003e/rest/\u003cstore-view-code\u003e/V1/`"
      },
      {
        "label": "GraphQL API",
        "value": "Cloud service 62 queries and 184 mutations at `https://\u003cregion\u003e-\u003cenvironment\u003e.api.commerce.adobe.com/\u003ctenantId\u003e/graphql`, among them `addProductsToCart`, `applyCouponToCart` and `placeOrder`. Other deployments at `https://\u003chost\u003e/graphql`"
      },
      {
        "label": "Auth",
        "value": "Cloud service by OAuth 2 through Adobe IMS (client credentials with the `commerce.accs` scope, or a user flow). Other deployments by integration with OAuth 1.0a signing, admin tokens (4 hours) and customer tokens (1 hour)"
      },
      {
        "label": "Permissions",
        "value": "ACL resources chosen per integration or Admin role. No read-only mode found"
      },
      {
        "label": "Limits",
        "value": "Input limits (20 items in a list input, 5,000 asynchronous, 300 a page) are off by default on 2.4 stores. GraphQL complexity 300 and depth 20. No request rate limit found. Payment endpoints can be rate limited from 2.4.7"
      },
      {
        "label": "Response size",
        "value": "`?fields=` on REST, field selection in GraphQL, `searchCriteria[pageSize]` and `searchCriteria[currentPage]` on lists"
      },
      {
        "label": "Bulk and async",
        "value": "Asynchronous and bulk endpoints for POST, PUT and DELETE return a bulk UUID, with status at `/V1/bulk/:bulkUuid/status`"
      },
      {
        "label": "SDKs",
        "value": "`@adobe/aio-commerce-sdk` 2.0.0 on npm (Apache-2.0) for App Builder apps. No client library in a second language found"
      },
      {
        "label": "MCP server",
        "value": "None from Adobe for Commerce found. Experience League's llms.txt lists MCP servers for AEM only"
      },
      {
        "label": "Releases",
        "value": "Cloud service releases in August, twice in September and on 7 October 2026. 2.4.9 on 12 May 2026, with a patch each May and security patches between"
      },
      {
        "label": "Support window",
        "value": "Three years of standard support for each release. 2.4.9 to 31 May 2029, 2.4.8 to 31 May 2028, 2.4.7 to 31 May 2027"
      },
      {
        "label": "Status",
        "value": "status.adobe.com lists Adobe Commerce with components by deployment and region. A self-hosted store has no vendor status"
      },
      {
        "label": "SLA",
        "value": "The Unified SLA's Actionability Addendum (23 July 2026) covers Adobe Commerce. Percentage not read"
      },
      {
        "label": "Data on termination",
        "value": "Cloud service customer data is kept for the licence term, with 30 days to export after it ends, per the 2025v1 licensing terms"
      },
      {
        "label": "Sub-processors",
        "value": "Seven named for Adobe Commerce on the list updated 28 September 2026, among them Microsoft, Snowflake, MongoDB, New Relic, Platform.sh, SendGrid and Fastly, in the USA, EU and other regions"
      }
    ],
    "unitPrices": [
      {
        "item": "Magento Open Source",
        "unit": "month",
        "usd": 0,
        "note": "OSL 3.0 core, you pay for your own hosting. Adobe Commerce prices weren't read"
      }
    ],
    "provenance": {
      "legalEntity": "Adobe Inc.",
      "domain": "adobe.com",
      "domainRegistered": "1986-11-17",
      "endpointOnVendorDomain": true,
      "terms": "https://www.adobe.com/cc-shared/assets/pdf/legal/terms/enterprise/pdfs/generalterms-na-2025v1.pdf",
      "privacy": "https://www.adobe.com/privacy/policy.html",
      "statusPage": "https://status.adobe.com",
      "changelog": "https://experienceleague.adobe.com/en/docs/commerce/cloud-service/release-notes",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The privacy policy, last updated 24 October 2025, names Adobe Inc. as controller in the US, Adobe KK in Japan and Adobe Systems Software Ireland Limited elsewhere.",
        "The terms link is Adobe's General Terms 2025v1, effective 3 October 2025, as given on the enterprise licensing page. We read that page and the product-specific terms for Adobe Commerce as a Cloud Service (2025v1, 13 October 2025), not the General Terms PDF itself.",
        "Separate product-specific terms cover Adobe Commerce on Cloud (18 February 2025), on Managed Services (18 March 2025) and on-premise software (9 January 2023).",
        "The privacy policy says Adobe is the processor for enterprise products and that it doesn't apply to data enterprise customers collect. A data processing addendum is published at www.adobe.com/cc-shared/assets/pdf/legal/terms/enterprise/pdfs/dpa-ww.pdf.",
        "Cloud service endpoints are on api.commerce.adobe.com. Stores on Adobe Commerce on Cloud, on-premises and Magento Open Source answer on the merchant's own domain.",
        "security.txt at www.adobe.com is PGP-signed, expires 30 July 2027 and names an Intigriti programme and psirt@adobe.com.",
        "www.adobe.com and helpx.adobe.com answered curl with 403. The legal pages were read through WebFetch, and the helpx security bulletins weren't read at all.",
        "Verisign RDAP gives a registration date of 1986-11-17 for adobe.com."
      ],
      "score": 99,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Adobe Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "adobe.com, registered 1986-11-17 (39 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "adobe.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.adobe.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.adobe.com/cc-shared/assets/pdf/legal/terms/enterprise/pdfs/generalterms-na-2025v1.pdf",
          "state": "not-read",
          "points": 10,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://www.adobe.com/privacy/policy.html",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-10-24",
          "words": 6546,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: October 24, 2025",
              "says": "Last updated 2025-10-24"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "To help keep our databases current and to provide you the most relevant content and experiences, we may infer or generate information based on the information we collect or combine information provided by you with information from third party sources, in accordance with applicable law."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "When you register for an account and create an Adobe ID, we process and keep most personal information we process on your behalf for as long as you are an active user of our Services and Software."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "We also disclose information with third parties we engage to process personal information on our behalf or when such sharing is required by law, or in certain other situations."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Learn more about your rights and how you can exercise them."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "To exercise any of these rights (including deactivating your Adobe ID account), you can get in touch with us – or our data protection officer – using the details set out below.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "…these third parties restricting their access, use and disclosure of personal data in compliance with our Data Privacy Framework obligations, including the onward transfer provisions, and Adobe remains liable if they fail to meet those obligations and Adobe is responsible for the event giving rise to the damage).",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "In some cases, in order to show you more relevant ads, we disclose with social media platforms and other advertising partners, information about actions you take on our websites and apps, such as which pages you visit and which ads you saw."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Insights from analytics on cloud content may inform Adobe marketing to the user, subject to opt-out rights.",
              "quote": "Insights from Content Analytics may be used to inform our marketing to you, subject to your opt-out rights regarding our marketing."
            },
            {
              "date": "2026-10-08",
              "text": "Cloud content may be scanned automatically for illegal or abusive material, with human review when content is flagged or reported.",
              "quote": "Human review may occur when your Cloud Content is flagged or reported as illegal or abusive."
            },
            {
              "date": "2026-10-08",
              "text": "Adobe may give personal information to a business when the user signs in with that business email domain or was invited by that business.",
              "quote": "If you are using an email address that is associated with a business domain (e.g., yourname@businessname.com) to access Adobe's Services and Software, or if you were invited to use the Services and Software by a business, we may provide your personal information to that business."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/adobe-commerce.json",
    "live": {
      "slug": "adobe-commerce",
      "vendorStatus": {
        "page": "https://status.adobe.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:38:11.618214553Z"
      },
      "updatedAt": "2026-10-08T19:38:11.618214553Z"
    }
  }
}
