{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "commercetools",
    "name": "commercetools",
    "vendor": "commercetools GmbH",
    "vendorUrl": "https://commercetools.com",
    "kind": "http-api",
    "category": "commerce",
    "summary": "Headless commerce platform from commercetools GmbH in Munich, with HTTP and GraphQL APIs for catalogue, carts, checkout, orders and customers. Agents reach it through the API, four SDKs or a managed MCP server per project.",
    "url": "https://www.anchorterminal.com/tools/commercetools",
    "markdownUrl": "https://www.anchorterminal.com/tools/commercetools.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/commercetools.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/commercetools.json",
    "repo": "https://github.com/commercetools/commercetools-api-reference",
    "license": "Proprietary service under the commercetools Master Service Agreement. The API specifications are public, the SDKs are MIT (TypeScript, PHP) or Apache 2.0 (Java, .NET) and Commerce MCP is MIT",
    "transports": [
      "http",
      "streamable-http",
      "stdio"
    ],
    "remoteUrl": "https://api.{region}.commercetools.com/{projectKey}",
    "packages": [
      {
        "registry": "npm",
        "name": "@commercetools/platform-sdk"
      },
      {
        "registry": "npm",
        "name": "@commercetools/commerce-mcp"
      }
    ],
    "auth": "oauth",
    "authNotes": "OAuth 2.0. A person creates an API Client in the Merchant Centre (or through the API Clients API) with chosen scopes, and the secret is shown once. The client credentials flow at https://auth.{region}.commercetools.com/oauth/token returns a Bearer token valid for 48 hours by default. Scopes are view or manage per resource and per store, and `manage_project` grants everything. Password, anonymous-session and refresh flows exist for shoppers. A managed MCP server takes a token scoped to `mcp:{projectKey}:{mcpServerKey}` (30 days at most), OAuth client credentials discovery, or a browser sign-in with an Identity account. Access is self-serve through the trial sign-up form.",
    "pricing": "paid",
    "pricingNotes": "No public prices. The pricing page describes order-based pricing and sends buyers to sales, and the product is also sold through the AWS and Google Cloud marketplaces. A 60-day trial has every core commerce API and the Merchant Centre, needs no card and does not convert automatically, so an agent can start without a contract. InStore, Frontend and the agent products are not in the trial (https://commercetools.com/free-trial, checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "both",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs, llms.txt or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 221261,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.commercetools.com/api/",
    "llmsTxt": "https://docs.commercetools.com/llms.txt",
    "openapi": "https://raw.githubusercontent.com/commercetools/commercetools-api-reference/main/oas/api/openapi.yaml",
    "capabilities": [
      "commerce.products",
      "commerce.cart",
      "commerce.checkout",
      "commerce.orders",
      "commerce.headless"
    ],
    "tags": [
      "hosted",
      "enterprise",
      "closed-source",
      "mcp",
      "oauth",
      "openapi",
      "graphql",
      "llms-txt",
      "typescript",
      "java",
      "php",
      "dotnet",
      "webhooks",
      "sales-led",
      "status-page",
      "sla",
      "soc2"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 71.3,
      "grade": "BB",
      "agentReady": true,
      "rank": 110,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 83,
        "maintenance": 85,
        "payments": 20,
        "reliability": 73,
        "schema": 86,
        "security": 70,
        "transparency": 81
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 73,
          "points": 14.6,
          "reason": "Graded on the HTTP API with the hosted lines. status.commercetools.com lists seven components across five regions with a dated history (20). From 10 July to 8 October 2026 the API component shows elevated 5xx errors in Europe (Google Cloud) on 10 July from 00:49 to 02:30 UTC and two shorter error spikes there on 30 July (41 and 51 minutes). One region of five was affected each time and all three were marked partial or lower, which we read as between minor and one major (15). The docs say the HTTP API has no single documented platform-wide rate limit. Numbers exist for query size (500 per page, offset 10,000), the Knowledge MCP (100 requests per 15 minutes per IP) and Managed MCP Servers (1,000,000 tool calls a project a month) (5). Retry guidance covers 502 and 503 with exponential backoff, Retry-After, and 409 handling through resource versions. There are no idempotency keys (13). 99.9 per cent monthly availability with service credits of 10 to 50 per cent, though Managed MCP Servers are excluded (10). The API and Managed MCP Servers are not marked beta (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 86,
          "points": 13.98,
          "reason": "OpenAPI 3.0 file of 3.1 MB with 822 operations in commercetools/commercetools-api-reference, updated on 7 October 2026, with RAML and a GraphQL schema beside it (25). llms.txt, and every docs page is served as Markdown at the same path with .md (10). The API reference describes each resource, field and update action, and a Knowledge MCP searches the docs and validates requests. Guidance on when not to use a call is thin (14). Typed drafts and update actions with required fields, enums and length limits (13). Error codes are listed by HTTP status with type definitions, and the guides carry request and response examples. The OpenAPI file itself has few examples (12). The API is versionless by policy, with dated release notes and an RSS feed. The managed MCP server follows semver with pinned major versions (12)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 83,
          "points": 13.49,
          "reason": "REST queries take limit, offset, sort, where predicates and reference expansion, and GraphQL selects fields. Commerce MCP lists 122 tool names, which is heavy, but an administrator picks the tools per server, `read_all` gives a read-only set, fields can be filtered, and the self-hosted package loads tools on demand above 30 (20). Pagination, filtering and limits on every query endpoint (20). JSON errors with named codes per status. Errors from the load balancer can be HTML or empty (17). Updates and deletes need the resource version, which makes a repeated write fail safely, and MCP tools carry readOnlyHint, destructiveHint and openWorldHint from 1 October 2026. No idempotency key for creates (13). SDKs for Java, TypeScript, PHP and .NET. Changes go through typed update actions, which take more parameters than a plain patch (13)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 70,
          "points": 12.25,
          "reason": "OAuth 2.0 client credentials through API Clients with view and manage scopes per resource and per store, tokens that last 48 hours by default, an RFC 7009 revocation endpoint, and no tokens in URL parameters. Each managed MCP server has its own scope, `mcp:{projectKey}:{mcpServerKey}`, with tokens capped at 30 days (28). Read-only scopes and tool sets, per-server tool lists, field redaction, and an Identity mode that filters tools by the signed-in user's permissions. No confirmation step for destructive tools was found (15). Tool results carry merchant and shopper text. The docs explain the confused deputy risk and field redaction but give no prompt-injection guidance (6). Audit Log Basic records Merchant Centre changes only. Changes through the API need the Audit Log Premium add-on, and MCP usage tracking needs the Platform Insights add-on (9). SOC 2, ISO 27001 and Cyber Essentials are listed on the security page, with reports under NDA. The Commerce MCP repository has a SECURITY.md that asks for email reports. No security.txt (404) and no bug bounty found, and the trust centre refused our reader (12)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 20,
          "points": 2.5,
          "reason": "No x402, MPP or L402 in the docs or pricing page (0). The pricing page describes order-based pricing with no figures and sends buyers to sales (0). A 60-day trial with every core commerce API, and the trial FAQ says no credit card or payment is needed (20). A person fills in a web form and follows an emailed link to create the account. API Clients can then be created through the API (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 85,
          "points": 7.44,
          "reason": "Release notes dated 7 October 2026 (30). More than twenty dated entries since 21 September alone (20). Public release notes with RSS, and standard support with published first-response targets of 12 hours for problems and 48 hours for questions. GitHub issue handling wasn't read (12). Four official SDKs on a monthly schedule, with @commercetools/platform-sdk 9.6.0 published on 5 October 2026 (15). The Commerce MCP repository runs quality and release workflows with changesets, and shipped six tagged releases between 3 August and 30 September 2026. Its server.json still names version 4.1.0 while npm has 4.2.2 (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 81,
          "points": 7.09,
          "note": "editorial 75, provenance 86",
          "reason": "Closed service under a public Master Service Agreement and a public 60-day trial agreement. The SDKs are MIT or Apache 2.0 and Commerce MCP is MIT (17). A privacy notice with a section for customers, a public DPA last updated 1 October 2024 and a sub-processor list. The DPA says personal data is deleted promptly at termination without a period in days, and the security page says the DPA is available on request while it is published at commercetools.com/dpa (22). Breaking changes are announced three months ahead and removals six months ahead in release notes, and a deprecations archive gives dates. The policy keeps a right to make larger changes with direct notice (16). Sub-processors listed with purpose, hosting location and product, updated 24 August 2026 (20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "REST queries take limit, offset, sort, where predicates and reference expansion, and GraphQL selects fields. Commerce MCP lists 122 tool names, which is heavy, but an administrator picks the tools per server, `read_all` gives a read-only set, fields can be filtered, and the self-hosted package loads tools on demand above 30 (20). Pagination, filtering and limits on every query endpoint (20). JSON errors with named codes per status. Errors from the load balancer can be HTML or empty (17). Updates and deletes need the resource version, which makes a repeated write fail safely, and MCP tools carry readOnlyHint, destructiveHint and openWorldHint from 1 October 2026. No idempotency key for creates (13). SDKs for Java, TypeScript, PHP and .NET. Changes go through typed update actions, which take more parameters than a plain patch (13).",
          "maintenance": "Release notes dated 7 October 2026 (30). More than twenty dated entries since 21 September alone (20). Public release notes with RSS, and standard support with published first-response targets of 12 hours for problems and 48 hours for questions. GitHub issue handling wasn't read (12). Four official SDKs on a monthly schedule, with @commercetools/platform-sdk 9.6.0 published on 5 October 2026 (15). The Commerce MCP repository runs quality and release workflows with changesets, and shipped six tagged releases between 3 August and 30 September 2026. Its server.json still names version 4.1.0 while npm has 4.2.2 (8).",
          "payments": "No x402, MPP or L402 in the docs or pricing page (0). The pricing page describes order-based pricing with no figures and sends buyers to sales (0). A 60-day trial with every core commerce API, and the trial FAQ says no credit card or payment is needed (20). A person fills in a web form and follows an emailed link to create the account. API Clients can then be created through the API (0).",
          "reliability": "Graded on the HTTP API with the hosted lines. status.commercetools.com lists seven components across five regions with a dated history (20). From 10 July to 8 October 2026 the API component shows elevated 5xx errors in Europe (Google Cloud) on 10 July from 00:49 to 02:30 UTC and two shorter error spikes there on 30 July (41 and 51 minutes). One region of five was affected each time and all three were marked partial or lower, which we read as between minor and one major (15). The docs say the HTTP API has no single documented platform-wide rate limit. Numbers exist for query size (500 per page, offset 10,000), the Knowledge MCP (100 requests per 15 minutes per IP) and Managed MCP Servers (1,000,000 tool calls a project a month) (5). Retry guidance covers 502 and 503 with exponential backoff, Retry-After, and 409 handling through resource versions. There are no idempotency keys (13). 99.9 per cent monthly availability with service credits of 10 to 50 per cent, though Managed MCP Servers are excluded (10). The API and Managed MCP Servers are not marked beta (10).",
          "schema": "OpenAPI 3.0 file of 3.1 MB with 822 operations in commercetools/commercetools-api-reference, updated on 7 October 2026, with RAML and a GraphQL schema beside it (25). llms.txt, and every docs page is served as Markdown at the same path with .md (10). The API reference describes each resource, field and update action, and a Knowledge MCP searches the docs and validates requests. Guidance on when not to use a call is thin (14). Typed drafts and update actions with required fields, enums and length limits (13). Error codes are listed by HTTP status with type definitions, and the guides carry request and response examples. The OpenAPI file itself has few examples (12). The API is versionless by policy, with dated release notes and an RSS feed. The managed MCP server follows semver with pinned major versions (12).",
          "security": "OAuth 2.0 client credentials through API Clients with view and manage scopes per resource and per store, tokens that last 48 hours by default, an RFC 7009 revocation endpoint, and no tokens in URL parameters. Each managed MCP server has its own scope, `mcp:{projectKey}:{mcpServerKey}`, with tokens capped at 30 days (28). Read-only scopes and tool sets, per-server tool lists, field redaction, and an Identity mode that filters tools by the signed-in user's permissions. No confirmation step for destructive tools was found (15). Tool results carry merchant and shopper text. The docs explain the confused deputy risk and field redaction but give no prompt-injection guidance (6). Audit Log Basic records Merchant Centre changes only. Changes through the API need the Audit Log Premium add-on, and MCP usage tracking needs the Platform Insights add-on (9). SOC 2, ISO 27001 and Cyber Essentials are listed on the security page, with reports under NDA. The Commerce MCP repository has a SECURITY.md that asks for email reports. No security.txt (404) and no bug bounty found, and the trust centre refused our reader (12).",
          "transparency": "Closed service under a public Master Service Agreement and a public 60-day trial agreement. The SDKs are MIT or Apache 2.0 and Commerce MCP is MIT (17). A privacy notice with a section for customers, a public DPA last updated 1 October 2024 and a sub-processor list. The DPA says personal data is deleted promptly at termination without a period in days, and the security page says the DPA is available on request while it is published at commercetools.com/dpa (22). Breaking changes are announced three months ahead and removals six months ahead in release notes, and a deprecations archive gives dates. The policy keeps a right to make larger changes with direct notice (16). Sub-processors listed with purpose, hosting location and product, updated 24 August 2026 (20)."
        },
        "sources": [
          {
            "what": "docs index for agents",
            "url": "https://docs.commercetools.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Managed MCP Servers overview",
            "url": "https://docs.commercetools.com/api/managed-mcp-servers-overview.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Managed MCP Servers setup and authentication",
            "url": "https://docs.commercetools.com/api/managed-mcp-servers-get-started.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Commerce MCP tool list",
            "url": "https://docs.commercetools.com/dev-tooling/mcp/commerce-mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "self-hosted Commerce MCP (annotations, dynamic tool loading)",
            "url": "https://docs.commercetools.com/dev-tooling/mcp/self-hosted-commerce-mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Knowledge MCP and its rate limit",
            "url": "https://docs.commercetools.com/dev-tooling/mcp/knowledge-mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "authorisation flows and token revocation",
            "url": "https://docs.commercetools.com/api/authorization.md",
            "seen": "2026-10-08"
          },
          {
            "what": "scopes",
            "url": "https://docs.commercetools.com/api/scopes.md",
            "seen": "2026-10-08"
          },
          {
            "what": "general concepts (client resiliency, versions, pagination)",
            "url": "https://docs.commercetools.com/api/general-concepts.md",
            "seen": "2026-10-08"
          },
          {
            "what": "limits",
            "url": "https://docs.commercetools.com/api/limits.md",
            "seen": "2026-10-08"
          },
          {
            "what": "error handling, timeouts and retries",
            "url": "https://docs.commercetools.com/api/error-handling.md",
            "seen": "2026-10-08"
          },
          {
            "what": "error codes",
            "url": "https://docs.commercetools.com/api/errors.md",
            "seen": "2026-10-08"
          },
          {
            "what": "standard SLA",
            "url": "https://docs.commercetools.com/offering/sla.md",
            "seen": "2026-10-08"
          },
          {
            "what": "compatibility, release life cycle and deprecation",
            "url": "https://docs.commercetools.com/offering/compatibility.md",
            "seen": "2026-10-08"
          },
          {
            "what": "deprecations and removals archive",
            "url": "https://docs.commercetools.com/api/deprecations-and-removals.md",
            "seen": "2026-10-08"
          },
          {
            "what": "standard support",
            "url": "https://docs.commercetools.com/offering/support.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Audit Log overview",
            "url": "https://docs.commercetools.com/api/history/overview.md",
            "seen": "2026-10-08"
          },
          {
            "what": "release notes",
            "url": "https://docs.commercetools.com/docs/release-notes",
            "seen": "2026-10-08"
          },
          {
            "what": "status history",
            "url": "https://status.commercetools.com/pages/history/56e4295370fe4ece420002bb",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://commercetools.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "free trial FAQ",
            "url": "https://commercetools.com/free-trial",
            "seen": "2026-10-08"
          },
          {
            "what": "Master Service Agreement",
            "url": "https://commercetools.com/msa",
            "seen": "2026-10-08"
          },
          {
            "what": "trial agreement",
            "url": "https://commercetools.com/trial-agreement",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy notice",
            "url": "https://commercetools.com/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Processing Agreement",
            "url": "https://commercetools.com/dpa",
            "seen": "2026-10-08"
          },
          {
            "what": "sub-processors",
            "url": "https://commercetools.com/subprocessors",
            "seen": "2026-10-08"
          },
          {
            "what": "security and compliance page",
            "url": "https://commercetools.com/commerce-platform/security-compliance",
            "seen": "2026-10-08"
          },
          {
            "what": "API specifications repository (OpenAPI, clone)",
            "url": "https://github.com/commercetools/commercetools-api-reference",
            "seen": "2026-10-08"
          },
          {
            "what": "Commerce MCP repository (tags, workflows, SECURITY.md, server.json, clone)",
            "url": "https://github.com/commercetools/commerce-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "TypeScript SDK on npm",
            "url": "https://registry.npmjs.org/@commercetools/platform-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=commercetools",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: trust.commercetools.com answered 403 to our reader, so the trust centre's documents and any disclosure policy there were not read",
          "unchecked: GitHub stars and open issues, because the GitHub API refused us for its rate limit",
          "unchecked: the Merchant Centre sign-up flow itself, which redirects to identity.commercetools.com. The trial steps are taken from the docs",
          "unchecked: the wording of individual Commerce MCP tool descriptions and input schemas. The tool list and annotations are taken from the docs",
          "Whether the 10 July 2026 error period in Europe (Google Cloud) counted as downtime under the SLA. The status page marks it a partial service disruption",
          "No price of any kind is public, so cost per order or per call could not be established",
          "The lead was right about the HTTP API, SDKs and managed MCP servers. It did not mention that Managed MCP Servers sit outside the standard SLA"
        ]
      },
      "negative": 0,
      "verdict": "A public OpenAPI file with 822 operations, per-resource OAuth scopes and a managed MCP server whose tools an administrator selects per agent. Prices are quoted by sales only, and the HTTP API publishes no platform-wide rate limit. A 60-day trial needs no card.",
      "bestFor": "Enterprises that already run or plan a composable commerce stack and want agents working across catalogue, pricing, carts and orders under scoped credentials.",
      "strengths": [
        "Public OpenAPI 3.0 file with 822 operations, plus RAML, a GraphQL schema, llms.txt and Markdown copies of every docs page",
        "OAuth 2.0 API Clients with view and manage scopes per resource, a token revocation endpoint, and no tokens accepted in URL parameters",
        "Managed MCP server per agent with a chosen tool list, field filtering and redaction, and readOnlyHint and destructiveHint on every tool since 1 October 2026",
        "99.9 per cent monthly availability SLA with service credits, published in the docs",
        "60-day trial with every core commerce API and no card"
      ],
      "weaknesses": [
        "No public price. The pricing page describes order-based pricing and sends buyers to sales",
        "The docs state that the HTTP API has no single documented platform-wide rate limit",
        "Managed MCP Servers, AI Hub and Platform Insights are excluded from the standard SLA",
        "API-wide change tracking needs the paid Audit Log Premium add-on. Audit Log Basic records Merchant Centre changes only",
        "No security.txt and no bug bounty found, and audit reports are released under NDA"
      ],
      "agentNotes": [
        "Use the auth and API hosts for the project's region, such as auth.europe-west1.gcp.commercetools.com and api.europe-west1.gcp.commercetools.com. There are five regions",
        "Send the resource's current `version` with every update or delete. On 409 ConcurrentModification, re-read the resource and retry only if the change is still needed",
        "Retry 502 and 503 with exponential backoff from 200 ms, honour Retry-After, and check Content-Type before parsing an error body",
        "For MCP, ask for an API Client scoped to `mcp:{projectKey}:{mcpServerKey}` and a server limited to the tools the task needs, not `all`",
        "Keep page size at or under 500 and offset at or under 10,000. Product Search returns at most 100 per request"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 71.3
        }
      ],
      "editorialScores": {
        "ergonomics": 83,
        "maintenance": 85,
        "payments": 20,
        "reliability": 73,
        "schema": 86,
        "security": 70,
        "transparency": 75
      },
      "provenanceScore": 86
    },
    "connect": {
      "install": "npm install @commercetools/platform-sdk",
      "http": "curl https://{auth_host}/oauth/token -X POST \\\n  --basic --user \"{clientId}:{clientSecret}\" \\\n  -d \"grant_type=client_credentials\u0026scope=manage_project:{projectKey}\"\ncurl https://api.{region}.commercetools.com/{projectKey}/ \\\n  -X GET \\\n  -H \"Authorization: Bearer ${BEARER_TOKEN}\"",
      "config": {
        "mcpServers": {
          "managed-mcp-servers": {
            "headers": {
              "Authorization": "Bearer \u003cyour-ctp-token\u003e"
            },
            "type": "http",
            "url": "\u003cyour-mcp-server-url\u003e"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/commerce.products",
      "tool": "https://letme.dev/commercetools"
    },
    "notable": [
      "Managed MCP Servers host Commerce MCP at https://mcp.{region}.commercetools.com/projects/{projectKey}/{mcpServerKey}, up to 500 servers a project, each with its own tool list, and the client can't call the API directly (https://docs.commercetools.com/api/projects/managed-mcp-servers.md)",
      "Commerce MCP lists 122 tool names in the docs, and since 1 October 2026 every tool carries a title, readOnlyHint, destructiveHint and openWorldHint (https://docs.commercetools.com/dev-tooling/mcp/self-hosted-commerce-mcp.md)",
      "The docs say the HTTP API does not document a single platform-wide rate limit, and ask clients to retry 502 and 503 with exponential backoff (https://docs.commercetools.com/api/general-concepts.md)",
      "The standard SLA commits to 99.9 per cent monthly availability with service credits, and excludes Managed MCP Servers, AI Hub, Platform Insights and trial projects (https://docs.commercetools.com/offering/sla.md)",
      "The Knowledge MCP at https://docs.commercetools.com/apis/mcp is free, needs no project, and is limited to 100 requests per 15 minutes per IP (https://docs.commercetools.com/dev-tooling/mcp/knowledge-mcp.md)",
      "The status history shows elevated 5xx errors on the API in Europe (Google Cloud) on 10 July 2026 from 00:49 to 02:30 UTC (https://status.commercetools.com/pages/history/56e4295370fe4ece420002bb)"
    ],
    "area": "business",
    "details": [
      {
        "label": "APIs",
        "value": "HTTP API (OpenAPI 3.0, 822 operations) and GraphQL API on https://api.{region}.commercetools.com/{projectKey}, plus Import, Audit Log (Change History) and Checkout APIs"
      },
      {
        "label": "Regions",
        "value": "North America (Google Cloud, AWS), Europe (Google Cloud, AWS) and Australia (Google Cloud). Each has its own api, auth and mcp host"
      },
      {
        "label": "Managed MCP server",
        "value": "Hosted Commerce MCP at https://mcp.{region}.commercetools.com/projects/{projectKey}/{mcpServerKey}. Up to 500 servers a project and 1,000,000 tool calls a project a month. Tools chosen per server, with field filtering and overridable tool descriptions. Pinned by major version (v4)"
      },
      {
        "label": "MCP tools",
        "value": "122 tool names in the docs, in a create, read, update pattern per resource (products, carts, orders, customers, discounts, inventory, payments and more), with `all` and `read_all` sets. Titles and readOnlyHint, destructiveHint and openWorldHint annotations since 1 October 2026"
      },
      {
        "label": "Self-hosted MCP",
        "value": "@commercetools/commerce-mcp 4.2.2 on npm (MIT, Node.js 20 or later), stdio or Streamable HTTP. Above 30 enabled tools it exposes list_available_tools, inject_tools and execute_tool instead of every tool"
      },
      {
        "label": "Knowledge MCP",
        "value": "https://docs.commercetools.com/apis/mcp, free and without a project. Docs search, OpenAPI and GraphQL schema lookup, and request validation. 100 requests per 15 minutes per IP, with Retry-After on 429"
      },
      {
        "label": "Credentials",
        "value": "OAuth 2.0 API Clients with view and manage scopes per resource and per store. Tokens last 48 hours by default and can be revoked at /oauth/token/revoke. Tokens are not accepted as URL parameters"
      },
      {
        "label": "Rate limits",
        "value": "No platform-wide limit documented for the HTTP API. Queries return at most 500 results with offset up to 10,000, 500 update actions a request, a 14 MB request body, and GraphQL complexity under 20,000"
      },
      {
        "label": "Retries",
        "value": "Retry 502 and 503 with exponential backoff from 200 ms and honour Retry-After. Updates and deletes need the resource `version`, and a mismatch returns 409 ConcurrentModification. No idempotency keys"
      },
      {
        "label": "SLA",
        "value": "99.9 per cent monthly availability, with credits of 10, 25 or 50 per cent. Managed MCP Servers, AI Hub, Platform Insights, beta functions and trial projects are excluded"
      },
      {
        "label": "SDKs",
        "value": "Java (Apache 2.0), TypeScript (MIT), PHP (MIT) and .NET (Apache 2.0), generated from the API specifications and released on the first Monday of each month. @commercetools/platform-sdk 9.6.0 on 5 October 2026"
      },
      {
        "label": "Audit",
        "value": "Audit Log Basic records Merchant Centre changes. Audit Log Premium (add-on) records changes from every source. Platform Insights (add-on) tracks MCP server usage"
      },
      {
        "label": "Change policy",
        "value": "Versionless APIs with continuous delivery. Breaking changes announced three months ahead and removals six months ahead in release notes"
      },
      {
        "label": "Certifications",
        "value": "SOC 2, ISO/IEC 27001 and Cyber Essentials per the security page, with audit reports under NDA. HIPAA and HDS hosting as add-ons"
      },
      {
        "label": "Status",
        "value": "status.commercetools.com, seven components (APIs, Merchant Centre, three Frontend components, Connect, Checkout) across five regions"
      },
      {
        "label": "Sub-processors",
        "value": "List updated 24 August 2026. Google Cloud and AWS for hosting in the customer's chosen region, MongoDB Atlas, CrowdStrike for logs in Belgium, Atlassian for support tickets, and Google, AWS and Langfuse for optional AI functions"
      }
    ],
    "provenance": {
      "legalEntity": "commercetools GmbH",
      "domain": "commercetools.com",
      "domainRegistered": "2002-05-13",
      "endpointOnVendorDomain": true,
      "terms": "https://commercetools.com/msa",
      "privacy": "https://commercetools.com/privacy",
      "statusPage": "https://status.commercetools.com",
      "changelog": "https://docs.commercetools.com/docs/release-notes",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The imprint names commercetools GmbH, Adams-Lehmann-Str. 44, 80797 Munich, Amtsgericht München HRB 161496.",
        "The Master Service Agreement at commercetools.com/msa governs paid use once an Order Form is signed. Trial use falls under the 60 Days Trial Agreement at commercetools.com/trial-agreement, last updated 24 July 2024.",
        "The privacy notice covers the websites in section III and customers' use of the service in section IV. Data that customers store in the platform falls under the DPA at commercetools.com/dpa, last updated 1 October 2024.",
        "commercetools.com/.well-known/security.txt and docs.commercetools.com/.well-known/security.txt both return 404.",
        "API, auth and MCP hosts are subdomains of commercetools.com for each region. RDAP gives a registration date of 2002-05-13 for commercetools.com."
      ],
      "score": 86,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "commercetools GmbH",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "commercetools.com, registered 2002-05-13 (24 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.{region}.commercetools.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 7.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.commercetools.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://commercetools.com/msa",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 6431,
          "points": 7.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "If your physical address as set out in the Order Form is in the European Union or European Economic Area (except Ireland): in accordance with the laws of the Federal Republic of Germany, and the parties irrevocably submit to the exclusive jurisdiction of the courts of Munich.",
              "says": "The law of Federal Republic of Germany, with disputes in the courts of Munich"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…all causes of action and/or any and all theories of liability will be and are hereby limited to and will not exceed the fees paid or payable to commercetools under this Agreement and affected Order Form during the 24 month period immediately preceding the event giving rise to the particular claim or liability.",
              "says": "Capped at the fees paid in the 24 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "commercetools may suspend access to the Service and related services (and the relevant fees for the Service will continue to apply during such period) if: (a) Customer breaches Section 1.7 (Restrictions);"
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "If a modification materially impacts this Agreement, commercetools will use reasonable efforts to notify Customer through the Service and/or in accordance with Section 11.3 (Notices).",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Customer will not (and will not permit anyone else to) do any of the following: (a) use the Service to develop a similar or competing product or service;"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "commercetools will make the Service available in accordance with the Service Level Availability commitments set out in the Documentation."
            }
          ],
          "toKnow": [
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "Customer will not (and will not permit anyone else to) do any of the following: (a) use the Service to develop a similar or competing product or service;",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Each party may name the other on its website during the term, while other public announcements need agreement in advance.",
              "quote": "However, both parties are entitled to name the respective other party on their websites during the Term of this Agreement."
            },
            {
              "date": "2026-10-08",
              "text": "The agreement covers the paid Service only and does not apply to free beta trials, unpaid use, early access or pre-release use.",
              "quote": "Subject to Section 1.6, the terms set out in this Agreement apply to the Service only, and do not apply to any free beta trials, unpaid use of the service, early access, pre-release use of commercetools products or services."
            },
            {
              "date": "2026-10-08",
              "text": "An invoice not disputed in writing within 30 days of receipt is deemed accepted and the customer waives the right to dispute it.",
              "quote": "If written notification is not received by commercetools within such a 30 day period, the invoice shall be deemed accepted by Customer and Customer shall have waived the right to dispute such amounts."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://commercetools.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 5891,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Notice outlines how we collect, use, protect, and share your personal data when you visit our website or interact with our services."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Connection data (access logs) are automatically deleted shortly after use, with anonymized logs stored for 31 days.",
              "says": "Names a period of 31 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "To process personal data for the purposes described, we engage various data processors, including IT and server service providers for website hosting and infrastructure maintenance, as well as marketing and analytics partners and other external vendors."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "commercetools does not sell or share your personal information as defined by these laws.",
              "says": "Says it does not sell personal data"
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Where consent is required, particularly for special categories of data under Article 9(2)(a) of the GDPR, you can withdraw your consent at any time, without providing a reason, by emailing privacy@commercetools.com."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have questions about data protection, please contact privacy@commercetools.com.",
              "says": "privacy@commercetools.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Such transfers only occur if appropriate safeguards are in place, including an adequacy decision by the European Commission, an approved certification mechanism with binding commitments from the recipient, or the use of Standard Contractual Clauses (SCCs) adopted by the European Commission.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "commercetools records and analyses calls and video calls with customers and prospects to improve its sales processes, including by means of artificial intelligence where applicable.",
              "quote": "Recording and analysis of calls and video calls to improve our sales processes and gain insights for enhancing both sales strategies and feedback discussions, incl. with the means of artificial intelligence, where applicable"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/commercetools.json",
    "live": {
      "slug": "commercetools",
      "probe": {
        "target": "https://api.{region}.commercetools.com/{projectKey}",
        "method": "get",
        "lastAt": "2026-10-08T19:08:43.983307366Z",
        "lastOk": false,
        "lastStatus": 0,
        "lastMs": 0,
        "lastNote": "invalid character \"{\" in host name",
        "authRequired": false,
        "uptime24h": 0,
        "uptime30d": 0,
        "p50ms24h": 0,
        "p95ms24h": 0,
        "samples24h": 19,
        "samples30d": 19,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 19,
            "ok": 0
          }
        ],
        "outages": [
          {
            "start": "2026-10-08T17:31:33.341731081Z",
            "end": "0001-01-01T00:00:00Z",
            "note": "invalid character \"{\" in host name"
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.commercetools.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T17:50:31.099632039Z"
      },
      "pages": [
        {
          "url": "https://docs.commercetools.com/docs/release-notes",
          "kind": "changelog",
          "status": 404,
          "checkedAt": "2026-10-08T18:18:30.793646678Z",
          "changedAt": "0001-01-01T00:00:00Z"
        },
        {
          "url": "https://commercetools.com/privacy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:16:37.91248595Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "58be3463d4f5"
        },
        {
          "url": "https://commercetools.com/msa",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:16:35.711051914Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "c72525a36335"
        }
      ],
      "updatedAt": "2026-10-08T19:08:43.983307366Z"
    }
  }
}
