{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "shopware",
    "name": "Shopware",
    "vendor": "shopware AG",
    "vendorUrl": "https://www.shopware.com",
    "kind": "http-api",
    "category": "commerce",
    "summary": "Open-source commerce platform from shopware AG in Germany, written in PHP on Symfony. Agents reach a store through its Store API for shopping, its Admin API for back-office work, and a built-in MCP server on both.",
    "url": "https://www.anchorterminal.com/tools/shopware",
    "markdownUrl": "https://www.anchorterminal.com/tools/shopware.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shopware.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shopware.json",
    "repo": "https://github.com/shopware/shopware",
    "license": "MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms",
    "transports": [
      "http",
      "streamable-http"
    ],
    "packages": [
      {
        "registry": "packagist",
        "name": "shopware/core"
      },
      {
        "registry": "npm",
        "name": "@shopware/api-client"
      }
    ],
    "auth": "mixed",
    "authNotes": "Access comes from the merchant who runs the store, with no vendor review. The Admin API takes an OAuth 2.0 bearer token from /api/oauth/token, normally by client credentials from an integration created in Settings or with `bin/console integration:create`, and tokens last 10 minutes by default. An integration gets an ACL role, or full access with --admin. The MCP endpoint at /api/_mcp also accepts the integration's `sw-access-key` and `sw-secret-access-key` headers, and each integration and user has an MCP allowlist. The Store API takes the sales channel's `sw-access-key`, which is public in a headless shop, plus an `sw-context-token` for the cart and customer session.",
    "pricing": "freemium",
    "pricingNotes": "The Community Edition is free under MIT with no account, so an agent's owner can start with `shopware-cli project create` and Docker, with no contract (the docs say no Shopware account is needed to install or run a store). Paid plans start at €600 a month for Rise and €2,400 for Evolve, excluding VAT, with Beyond on request, and the pricing page says the price depends on GMV. Shopware SaaS is priced the same as self-hosted. No trial of the paid plans was found on the pricing page (https://www.shopware.com/en/pricing/, checked 2026-10-08).",
    "priceSummary": "Freemium",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the repository or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": 14,
    "popularity": {
      "githubStars": 3400,
      "npmWeekly": 30917,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developer.shopware.com/docs/",
    "llmsTxt": "https://developer.shopware.com/llms.txt",
    "openapi": "https://github.com/shopware/shopware/tree/trunk/src/Core/Framework/Api/ApiDefinition/Generator/Schema",
    "capabilities": [
      "commerce.products",
      "commerce.cart",
      "commerce.checkout",
      "commerce.orders",
      "commerce.headless"
    ],
    "tags": [
      "open-source",
      "self-hosted",
      "local",
      "hosted",
      "mcp",
      "openapi",
      "llms-txt",
      "oauth",
      "php",
      "typescript",
      "webhooks",
      "freemium",
      "eu",
      "bug-bounty",
      "iso27001",
      "beta"
    ],
    "lastRelease": "2026-10-02",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 71.4,
      "grade": "BB",
      "agentReady": true,
      "rank": 107,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 3,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 78,
        "maintenance": 87,
        "payments": 50,
        "reliability": 83,
        "schema": 85,
        "security": 73,
        "transparency": 76
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 83,
          "points": 16.6,
          "reason": "Graded with the self-hosted package lines, because each store's APIs run on the merchant's own server or SaaS shop. Composer packages on Packagist with PHP 8.2 to 8.5 stated in composer.json (20). Nightly workflow on trunk, the last 10 scheduled runs all passing (25). 1,169 open issues, with bugs opened on 8 October 2026 already answered the same day and a triage labeller in the workflows (10). Semantic versioning with a written backward compatibility promise and UPGRADE and RELEASE_INFO files, but 6.7.14.0 changed what tools/list returns on the experimental Store API MCP endpoint in a minor release (13). 6.7 is stable, while the MCP server is experimental until 6.8 (15). Shopware SaaS has a status page at status.shopware.com, which lists a 36 minute outage of storefront and administration on 6 August 2026 and 1 hour 49 minutes of raised errors on 17 August. That isn't scored here."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 85,
          "points": 13.81,
          "reason": "OpenAPI 3 for both APIs, as JSON in the repository, on a hosted Stoplight reference and from each instance at /_info/openapi3.json in dev mode. MCP tools have typed inputs (25). llms.txt with every docs page as Markdown (10). 109 of 116 Store API operations and 105 of 108 Admin API operations in the repository schema carry a description, and the MCP tool reference says when to use search, read or aggregate (16). Types and required fields are set, but the MCP tools take criteria, payload, aggregations and ids as JSON-encoded strings, and Admin API entity routes accept open criteria objects (9). Request examples in the guides, a JSON:API error schema and a fixed success and error envelope for MCP tools (12). No API version in the path since 2020, so the contract follows the product version, with release notes on GitHub and RELEASE_INFO files (13)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "A fresh MCP session advertises three discovery tools and loads the rest by toolset. `includes` selects fields, and MCP results over 100 KB come back as a resource reference (25). page, limit, total-count-mode, filters, sorting and aggregations in one criteria object (20). MCP errors are a message written to say what to do next, and the APIs return JSON:API errors with codes. A 429 on MCP has no Retry-After header (16). No idempotency keys found. Write tools default to dryRun=true, but no MCP tool carries readOnlyHint or destructiveHint in the source (8). Few required parameters and sensible defaults (limit 25, maxResults 3). One official API client, @shopware/api-client for TypeScript, and none found in a second language (9)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 73,
          "points": 12.78,
          "reason": "Admin API by OAuth 2.0 client credentials from a revocable integration with an ACL role and 10 minute tokens, or the integration's key and secret in headers on MCP. No secret in a URL was found in the docs. No OAuth scopes beyond ACL roles, and key rotation wasn't found (25). ACL checks on every MCP call, allowlists per integration and per user, a global allowed_tools switch and dry run by default on write tools. shopware-media-upload has no dry run and the Store API MCP endpoint has no allowlist (17). The MCP best practices page has a section on prompt injection through order notes, names and product text and advises read-only integrations for such data (11). An integration records when it was last used, and no audit log of API or MCP calls was found (4). Bug bounty through the security reporting form per SECURITY.md, ISO/IEC 27001:2022 on the trust centre, and advisories published on GitHub. The security.txt file expired on 31 December 2025 (16)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 50,
          "points": 6.25,
          "reason": "No x402, MPP or L402 (0). The paid plans have public starting prices, Rise from €600 and Evolve from €2,400 a month, with the real price set by GMV and Beyond on request (10). The MIT Community Edition is free with no card (20). An agent's owner can install it with Shopware CLI and Docker, and the install guide says no Shopware account is needed. A paid plan or SaaS shop needs a browser signup or sales (20)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 87,
          "points": 7.61,
          "reason": "6.7.15.1 tagged on 2 October 2026 (30). Seven releases between 19 August and 2 October 2026, from 6.7.13.1 to 6.7.15.1 (20). Issues opened on 8 October 2026 had same-day replies, against 1,169 open issues and 322 open pull requests (17). @shopware/api-client 1.7.0 was published on 6 October 2026. The MCP server is built in and has no entry in the official registry, where the only Shopware server is a third party's (10). Nightly, integration, acceptance, static analysis and npm audit workflows in the repository (10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 76,
          "points": 6.65,
          "note": "editorial 80, provenance 71",
          "reason": "MIT licence for the core (30). A self-hosted store keeps its data on the merchant's server. The privacy page, updated 18 August 2026, names shopware AG and links a data processing agreement, but no retention periods or sub-processors were found on it (18). A backward compatibility promise, `@deprecated` markers that name the major version of removal, and releases.json with an end date for security fixes on every version (18). A telemetry page lists what Shopware CLI, the Deployment Helper and the web installer send, by unencrypted UDP to a server in Frankfurt, with DO_NOT_TRACK as the opt-out. The core has a usage data module with consent that we didn't read (14)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "A fresh MCP session advertises three discovery tools and loads the rest by toolset. `includes` selects fields, and MCP results over 100 KB come back as a resource reference (25). page, limit, total-count-mode, filters, sorting and aggregations in one criteria object (20). MCP errors are a message written to say what to do next, and the APIs return JSON:API errors with codes. A 429 on MCP has no Retry-After header (16). No idempotency keys found. Write tools default to dryRun=true, but no MCP tool carries readOnlyHint or destructiveHint in the source (8). Few required parameters and sensible defaults (limit 25, maxResults 3). One official API client, @shopware/api-client for TypeScript, and none found in a second language (9).",
          "maintenance": "6.7.15.1 tagged on 2 October 2026 (30). Seven releases between 19 August and 2 October 2026, from 6.7.13.1 to 6.7.15.1 (20). Issues opened on 8 October 2026 had same-day replies, against 1,169 open issues and 322 open pull requests (17). @shopware/api-client 1.7.0 was published on 6 October 2026. The MCP server is built in and has no entry in the official registry, where the only Shopware server is a third party's (10). Nightly, integration, acceptance, static analysis and npm audit workflows in the repository (10).",
          "payments": "No x402, MPP or L402 (0). The paid plans have public starting prices, Rise from €600 and Evolve from €2,400 a month, with the real price set by GMV and Beyond on request (10). The MIT Community Edition is free with no card (20). An agent's owner can install it with Shopware CLI and Docker, and the install guide says no Shopware account is needed. A paid plan or SaaS shop needs a browser signup or sales (20).",
          "reliability": "Graded with the self-hosted package lines, because each store's APIs run on the merchant's own server or SaaS shop. Composer packages on Packagist with PHP 8.2 to 8.5 stated in composer.json (20). Nightly workflow on trunk, the last 10 scheduled runs all passing (25). 1,169 open issues, with bugs opened on 8 October 2026 already answered the same day and a triage labeller in the workflows (10). Semantic versioning with a written backward compatibility promise and UPGRADE and RELEASE_INFO files, but 6.7.14.0 changed what tools/list returns on the experimental Store API MCP endpoint in a minor release (13). 6.7 is stable, while the MCP server is experimental until 6.8 (15). Shopware SaaS has a status page at status.shopware.com, which lists a 36 minute outage of storefront and administration on 6 August 2026 and 1 hour 49 minutes of raised errors on 17 August. That isn't scored here.",
          "schema": "OpenAPI 3 for both APIs, as JSON in the repository, on a hosted Stoplight reference and from each instance at /_info/openapi3.json in dev mode. MCP tools have typed inputs (25). llms.txt with every docs page as Markdown (10). 109 of 116 Store API operations and 105 of 108 Admin API operations in the repository schema carry a description, and the MCP tool reference says when to use search, read or aggregate (16). Types and required fields are set, but the MCP tools take criteria, payload, aggregations and ids as JSON-encoded strings, and Admin API entity routes accept open criteria objects (9). Request examples in the guides, a JSON:API error schema and a fixed success and error envelope for MCP tools (12). No API version in the path since 2020, so the contract follows the product version, with release notes on GitHub and RELEASE_INFO files (13).",
          "security": "Admin API by OAuth 2.0 client credentials from a revocable integration with an ACL role and 10 minute tokens, or the integration's key and secret in headers on MCP. No secret in a URL was found in the docs. No OAuth scopes beyond ACL roles, and key rotation wasn't found (25). ACL checks on every MCP call, allowlists per integration and per user, a global allowed_tools switch and dry run by default on write tools. shopware-media-upload has no dry run and the Store API MCP endpoint has no allowlist (17). The MCP best practices page has a section on prompt injection through order notes, names and product text and advises read-only integrations for such data (11). An integration records when it was last used, and no audit log of API or MCP calls was found (4). Bug bounty through the security reporting form per SECURITY.md, ISO/IEC 27001:2022 on the trust centre, and advisories published on GitHub. The security.txt file expired on 31 December 2025 (16).",
          "transparency": "MIT licence for the core (30). A self-hosted store keeps its data on the merchant's server. The privacy page, updated 18 August 2026, names shopware AG and links a data processing agreement, but no retention periods or sub-processors were found on it (18). A backward compatibility promise, `@deprecated` markers that name the major version of removal, and releases.json with an end date for security fixes on every version (18). A telemetry page lists what Shopware CLI, the Deployment Helper and the web installer send, by unencrypted UDP to a server in Frankfurt, with DO_NOT_TRACK as the opt-out. The core has a usage data module with consent that we didn't read (14)."
        },
        "sources": [
          {
            "what": "core repository at commit of 8 October 2026 (LICENSE, composer.json, releases.json, SECURITY.md, workflows, MCP source, OpenAPI schema files, rate limiter config)",
            "url": "https://github.com/shopware/shopware",
            "seen": "2026-10-08"
          },
          {
            "what": "docs index for agents",
            "url": "https://developer.shopware.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP overview and status",
            "url": "https://developer.shopware.com/docs/products/tools/mcp-server.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP getting started (auth, client config, discovery)",
            "url": "https://developer.shopware.com/docs/products/tools/mcp-server/getting-started.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP configuration (allowlists, sessions, rate limits)",
            "url": "https://developer.shopware.com/docs/products/tools/mcp-server/configuration.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tools reference",
            "url": "https://developer.shopware.com/docs/products/tools/mcp-server/tools-reference.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Store API MCP endpoint",
            "url": "https://developer.shopware.com/docs/products/tools/mcp-server/store-api.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP best practices (prompt injection)",
            "url": "https://developer.shopware.com/docs/products/tools/mcp-server/best-practices.md",
            "seen": "2026-10-08"
          },
          {
            "what": "API authentication and OpenAPI endpoints",
            "url": "https://developer.shopware.com/docs/guides/development/integrations-api/auth-api-requests.md",
            "seen": "2026-10-08"
          },
          {
            "what": "search criteria",
            "url": "https://developer.shopware.com/docs/guides/development/integrations-api/search-criteria.md",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limiter defaults",
            "url": "https://developer.shopware.com/docs/guides/hosting/infrastructure/rate-limiter.md",
            "seen": "2026-10-08"
          },
          {
            "what": "backward compatibility promise",
            "url": "https://developer.shopware.com/docs/resources/guidelines/code/backward-compatibility.md",
            "seen": "2026-10-08"
          },
          {
            "what": "installation guide",
            "url": "https://developer.shopware.com/docs/guides/installation.md",
            "seen": "2026-10-08"
          },
          {
            "what": "tools telemetry",
            "url": "https://developer.shopware.com/docs/resources/references/telemetry.md",
            "seen": "2026-10-08"
          },
          {
            "what": "security advisories, pages 1 and 2",
            "url": "https://github.com/shopware/shopware/security/advisories",
            "seen": "2026-10-08"
          },
          {
            "what": "advisory for the Store API SQL injection",
            "url": "https://github.com/shopware/shopware/security/advisories/GHSA-p37c-pm9p-7vm5",
            "seen": "2026-10-08"
          },
          {
            "what": "open issues",
            "url": "https://github.com/shopware/shopware/issues?q=is%3Aissue+is%3Aopen+sort%3Acreated-desc",
            "seen": "2026-10-08"
          },
          {
            "what": "nightly workflow runs",
            "url": "https://github.com/shopware/shopware/actions/workflows/nightly.yml?query=event%3Aschedule+branch%3Atrunk",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://www.shopware.com/en/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "general terms",
            "url": "https://www.shopware.com/en/gtc/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy page",
            "url": "https://www.shopware.com/en/privacy/",
            "seen": "2026-10-08"
          },
          {
            "what": "legal notice",
            "url": "https://www.shopware.com/en/legal-notice/",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre",
            "url": "https://www.shopware.com/en/shopware-trust-center/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.shopware.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "status history",
            "url": "https://status.shopware.com/history",
            "seen": "2026-10-08"
          },
          {
            "what": "npm package",
            "url": "https://registry.npmjs.org/@shopware/api-client/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=shopware",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.verisign.com/com/v1/domain/shopware.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the security reporting page at www.shopware.com/en/contact/security-reporting/ answered 503, so the bug bounty's scope and rewards weren't read",
          "unchecked: the data processing agreement at www.shopware.com/en/privacy/dpa and any sub-processor list",
          "unchecked: the core's usage data module and what consent it asks for",
          "unchecked: the exact GitHub star count. The repository page showed 3.4k and the API refused us for its rate limit",
          "unchecked: whether an official API client exists in a second language",
          "The pricing page shows the plan prices in euros. US dollar prices for Rise and Evolve weren't in the page as fetched",
          "Whether the Store API MCP endpoint gains cart and checkout tools when it leaves experimental status in 6.8"
        ]
      },
      "negative": -5,
      "negativeNotes": [
        "GitHub lists 20 security advisories for shopware/shopware published between 19 May and 16 September 2026, four of them critical (an app script sandbox escape, stored SQL injection through app manifests, admin account takeover by host-header poisoning and a webhook permission bypass), plus a pre-authentication SQL injection in the Store API (GHSA-p37c-pm9p-7vm5, CVSS 8.6, published 25 August 2026, fixed in 6.7.13.1 and 6.6.10.23). All were disclosed in public with fixed versions, so the deduction is 5 of a possible 15 (https://github.com/shopware/shopware/security/advisories)."
      ],
      "verdict": "MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.",
      "bestFor": "A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.",
      "strengths": [
        "MIT core, free to self-host, with security fixes for the 6.7 line promised until 28 February 2028 in releases.json",
        "Built-in MCP server advertises three discovery tools, and other tools load by toolset for the session",
        "MCP write tools default to dryRun=true, which runs the change in a transaction and rolls it back",
        "Per-integration ACL roles and MCP allowlists, with a 300 a minute limit on /api/_mcp",
        "OpenAPI 3 schemas for the Store API and Admin API in the repository, plus llms.txt and Markdown docs"
      ],
      "weaknesses": [
        "The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint",
        "20 advisories published between 19 May and 16 September 2026, four critical, including a pre-authentication SQL injection in the Store API",
        "MCP tools carry no readOnlyHint or destructiveHint annotations, and criteria and payloads travel as JSON-encoded strings",
        "A 429 from the MCP endpoints carries the wait time in the body, with no Retry-After header",
        "The Store API MCP endpoint ships one domain tool, has no allowlist, and the security.txt file expired on 31 December 2025"
      ],
      "agentNotes": [
        "Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp",
        "Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools",
        "Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once",
        "For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core",
        "Send `includes` in search criteria to cut response size, and read the 429 body for the wait time"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "BB",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 71.4
        }
      ],
      "editorialScores": {
        "ergonomics": 78,
        "maintenance": 87,
        "payments": 50,
        "reliability": 83,
        "schema": 85,
        "security": 73,
        "transparency": 80
      },
      "provenanceScore": 71
    },
    "connect": {
      "install": "npx @shopware-ag/shopware-cli project create my-shop",
      "http": "curl -X POST \"http://localhost:8000/api/search/product\" \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{}'",
      "claudeCode": "claude mcp add --transport http shopware http://localhost:8000/api/_mcp --header \"sw-access-key: SWIA...\" --header \"sw-secret-access-key: ...\"",
      "config": {
        "mcpServers": {
          "shopware": {
            "headers": {
              "sw-access-key": "SWIA...",
              "sw-secret-access-key": "..."
            },
            "type": "streamable-http",
            "url": "https://your-shop.example.com/api/_mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/commerce.products",
      "tool": "https://letme.dev/shopware"
    },
    "notable": [
      "The MCP server is part of the core since 6.7.11.0 at /api/_mcp and /store-api/_mcp, with the feature flag removed in 6.7.14.0 and the classes marked experimental until 6.8.0 (https://developer.shopware.com/docs/products/tools/mcp-server.md)",
      "A fresh MCP session advertises only shopware-tool-search, shopware-toolsets-list and shopware-toolset-enable. Core toolsets are entity, system-config, media, order, theme and store-api (https://developer.shopware.com/docs/products/tools/mcp-server/tools-reference.md)",
      "MCP rate limits are 300 a minute and 1,000 per 10 minutes on the Admin API endpoint, 120 and 600 on the Store API endpoint, and a 429 has no Retry-After header (https://developer.shopware.com/docs/products/tools/mcp-server/configuration.md)",
      "GitHub lists 20 advisories published between 19 May and 16 September 2026, four critical. GHSA-p37c-pm9p-7vm5, a pre-authentication SQL injection in the Store API, was fixed in 6.7.13.1 and 6.6.10.23 (https://github.com/shopware/shopware/security/advisories)",
      "6.7.15.1 was tagged on 2 October 2026, and minor versions have shipped monthly, 6.7.13.0 on 3 August, 6.7.14.0 on 7 September and 6.7.15.0 on 5 October per releases.json (https://github.com/shopware/shopware/blob/trunk/releases.json)",
      "www.shopware.com/.well-known/security.txt gives alert@shopware.com and an Expires date of 31 December 2025 (https://www.shopware.com/.well-known/security.txt)",
      "The only Shopware entry in the official MCP registry is a third-party server, io.github.bnymnDev/shopware-mcp (https://registry.modelcontextprotocol.io/v0/servers?search=shopware)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Free tier",
        "value": "Community Edition is free under MIT. Hosting is the merchant's cost"
      },
      {
        "label": "Paid plans",
        "value": "Rise from €600 a month, Evolve from €2,400 a month, Beyond on request, all excluding VAT and priced on GMV. SaaS costs the same as self-hosted per the pricing page (https://www.shopware.com/en/pricing/)"
      },
      {
        "label": "APIs",
        "value": "Store API under /store-api (cart, checkout, orders, products, search, account) and Admin API under /api (entity CRUD, search, sync, order states). OpenAPI 3 at /(api|store-api)/_info/openapi3.json when APP_ENV is dev"
      },
      {
        "label": "MCP server",
        "value": "Built into core since 6.7.11.0, streamable HTTP at /api/_mcp and /store-api/_mcp, experimental until 6.8.0. 14 Admin API tools in core and the Storefront bundle, of which 3 are advertised at the start of a session"
      },
      {
        "label": "Auth and scopes",
        "value": "Admin API takes OAuth 2.0 client credentials from an integration, or the integration's key and secret as headers on MCP. ACL roles per integration. Store API takes a sales channel access key and a context token"
      },
      {
        "label": "Rate limits",
        "value": "MCP 300 a minute and 1,000 per 10 minutes (Admin), 120 and 600 (Store). Login, password reset and form routes are limited by default. No general request limit on the other API routes"
      },
      {
        "label": "Write safety",
        "value": "MCP write tools default to dryRun=true and roll the transaction back. shopware-media-upload has no dry run"
      },
      {
        "label": "Response size",
        "value": "`includes` selects fields, page and limit paginate, and an MCP result over 100 KB comes back as a shopware://tool-result/{id} resource"
      },
      {
        "label": "SDKs",
        "value": "@shopware/api-client 1.7.0 on npm (MIT, published 6 October 2026), generated from the OpenAPI schemas"
      },
      {
        "label": "Support window",
        "value": "releases.json gives 28 February 2028 as the end of security fixes for 6.7 and 28 February 2027 for 6.6"
      },
      {
        "label": "Certifications",
        "value": "ISO/IEC 27001:2022 per the trust centre, which says hosted environments align with SOC 2 Type II principles (vendor claims)"
      },
      {
        "label": "Status",
        "value": "status.shopware.com covers Shopware SaaS, PaaS and vendor services. A self-hosted store has no vendor status"
      }
    ],
    "unitPrices": [
      {
        "item": "Community Edition",
        "unit": "month",
        "usd": 0,
        "note": "MIT core, you pay for your own hosting"
      }
    ],
    "provenance": {
      "legalEntity": "shopware AG",
      "domain": "shopware.com",
      "domainRegistered": "1998-08-08",
      "endpointOnVendorDomain": false,
      "terms": "https://www.shopware.com/en/gtc/",
      "privacy": "https://www.shopware.com/en/privacy/",
      "statusPage": "https://status.shopware.com",
      "changelog": "https://github.com/shopware/shopware/releases",
      "securityTxt": "expired",
      "checked": "2026-10-08",
      "notes": [
        "The legal notice names shopware AG, Ebbinghoff 10, 48624 Schoeppingen, Germany, Amtsgericht Coesfeld HRB 11471.",
        "The general terms cover every product. Part 2 covers the free Community Edition and Part 4 covers SaaS, and only the German version is binding.",
        "The Store API, Admin API and MCP endpoints run on each merchant's own domain or SaaS shop, not on shopware.com.",
        "security.txt at www.shopware.com gives Expires 31 December 2025.",
        "www.shopware.com answered several requests with a 503 first byte timeout on 8 October 2026. The terms loaded on a retry and the privacy page loaded once.",
        "status.shopware.com covers Shopware SaaS, PaaS and vendor services, not self-hosted stores.",
        "Verisign RDAP gives a registration date of 1998-08-08 for shopware.com."
      ],
      "score": 71,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "shopware AG",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "shopware.com, registered 1998-08-08 (28 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": " is not on shopware.com",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 4.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.shopware.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "published but past its Expires date",
          "points": 5,
          "max": 10,
          "state": "part"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.shopware.com/en/gtc/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-06-10",
          "words": 17397,
          "points": 4.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last update: 2026-06-10 10:06:16",
              "says": "Last updated 2026-06-10"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": false
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…payment and simple negligence (einfache Fahrlässigkeit) occurs in this context, liability shall be limited to cases of non-compliance with obligations the fulfilment of which is indispensable for using the services owed by shopware and on the compliance with which Customer usually relies or is reasonably allowed to re…"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "The agreement can be terminated at any time without giving reasons and without observing a notice period."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Without the express written consent of shopware, Customer shall not make any declarations to third parties regarding the infringement of proprietary rights, in particular, without limitation, Customer shall not acknowledge any rights or facts or otherwise assume any liability."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Customer and shopware may specify in a Service Level Agreement the times within which and, if applicable, the other quantitative or qualitative parameters with which the support services are to be provided."
            }
          ],
          "toKnow": [
            {
              "key": "training",
              "label": "Says it may use customer content to train or improve models, and no opt-out was found",
              "found": true,
              "quote": "shopware shall insofar not be subject to any restrictions regarding also the commercial use of such work results for its own purposes and for the purposes of third parties (e. g. benchmarking, quality improvement, training and validation of AI models).",
              "costsPoints": true
            },
            {
              "key": "terms.benchmark",
              "label": "Restricts benchmarking or competitive use",
              "found": true,
              "quote": "Under no circumstances shall Customer use the shopware software to directly or indirectly develop or improve a comparable product itself or through third parties.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "In the case of a contract for the performance of continuing obligations (Dauerschuldverhältnis), shopware is also entitled to terminate the contract by ordinary termination without an objective ground as provided for by these GTC and the contract."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The Rise, Evolve and Beyond plans carry a 24 month minimum term, which renews for up to 24 months unless ended in writing with six months' notice.",
              "quote": "In the case of provision of shopware Rise, shopware Evolve or shopware Beyond, the minimum term of the contract shall be initially 24 months, unless otherwise specified in the contract."
            },
            {
              "date": "2026-10-08",
              "text": "After the minimum term, shopware may raise the price by up to 20 per cent at the start of each new contract term, with four months' notice.",
              "quote": "shopware is entitled, after expiry of the minimum contract term, to increase the remuneration by up to 20% at the beginning of each new contract term, subject to four months’ prior notice."
            },
            {
              "date": "2026-10-08",
              "text": "The customer alone is responsible for its use of shopware's AI assistant functions and for the content they generate.",
              "quote": "Customer shall be solely responsible for the use of AI Systems and for the use of the content generated by AI Systems (output)."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.shopware.com/en/privacy/",
          "state": "unreadable",
          "reason": "the page has 181 words of text without a browser, so the document is drawn by script or sits elsewhere",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/shopware.json",
    "live": {
      "slug": "shopware",
      "vendorStatus": {
        "page": "https://status.shopware.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T17:51:12.427095822Z"
      },
      "pages": [
        {
          "url": "https://www.shopware.com/en/pricing/",
          "kind": "pricing",
          "status": 200,
          "checkedAt": "2026-10-08T18:30:28.817122652Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "a8eeb1d7324d"
        },
        {
          "url": "https://www.shopware.com/en/privacy/",
          "kind": "privacy",
          "status": 503,
          "checkedAt": "2026-10-08T18:30:30.769152247Z",
          "changedAt": "0001-01-01T00:00:00Z"
        },
        {
          "url": "https://www.shopware.com/en/gtc/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:30:26.06911646Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "034d628e8015"
        }
      ],
      "updatedAt": "2026-10-08T18:30:30.769152247Z"
    }
  }
}
