# Best commerce platforms and checkout APIs for AI agents > Shopify API + MCP (BB), WooCommerce API + MCP (BB) and Shopware (BB) lead the 17 ranked commerce platforms and checkout APIs. Picks by need, strengths, weaknesses and prices from the Anchor benchmark. - Canonical: https://www.anchorterminal.com/best/commerce/ - Markdown: https://www.anchorterminal.com/best/commerce/index.md (~5,800 tokens) - Slim: https://www.anchorterminal.com/best/commerce/index.min.md (~1,480 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/best/commerce/index.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 The 10 highest-scoring of 17 commerce platforms and checkout APIs on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change. - Ranked: 17 · agent-ready (BB or better): 6 · accept x402: 0 · hosted endpoints: 10 - Full ranked table: https://www.anchorterminal.com/categories/commerce.md - Head-to-head comparisons: https://www.anchorterminal.com/compare/commerce/index.md (136) - Methodology: https://www.anchorterminal.com/benchmark/index.md ## The shortlist | # | Tool | Grade | Score | Best for | Price | Where | | --- | --- | --- | --- | --- | --- | --- | | 1 | [Shopify API + MCP](https://www.anchorterminal.com/tools/shopify.md) | BB | 75 | Agents that shop on real stores or automate a merchant's back office at scale. | $39 / mo | local | | 2 | [WooCommerce API + MCP](https://www.anchorterminal.com/tools/woocommerce.md) | BB | 72.9 | Merchants already on WordPress and agents that need a cart and checkout without a vendor account. | Free · OSS | local | | 3 | [Shopware](https://www.anchorterminal.com/tools/shopware.md) | BB | 71.4 | A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work. | Freemium | local | | 4 | [commercetools](https://www.anchorterminal.com/tools/commercetools.md) | BB | 71.3 | Enterprises that already run or plan a composable commerce stack and want agents working across catalogue, pricing, carts and orders under scoped credentials. | Paid | hosted and local | | 5 | [Vendure](https://www.anchorterminal.com/tools/vendure.md) | BB | 70.9 | TypeScript teams that want a typed GraphQL commerce server and will host it. | Freemium | hosted | | 6 | [Spree Commerce](https://www.anchorterminal.com/tools/spree-commerce.md) | BB | 70.4 | Teams that want to own a Rails commerce backend with marketplace, B2B and multi-region functions and drive it through REST. | Freemium | local | | 7 | [Square](https://www.anchorterminal.com/tools/square.md) | B | 69.2 | Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person. | 2.9% fee | hosted and local | | 8 | [Saleor API + MCP](https://www.anchorterminal.com/tools/saleor.md) | B | 68.6 | Teams that want an open-source GraphQL backend with multi-channel pricing and an agent that reads store data safely. | $1599 / mo | local | | 9 | [BigCommerce API + MCP](https://www.anchorterminal.com/tools/bigcommerce.md) | B | 64.3 | Agents working with existing BigCommerce stores, for back-office automation through REST or guest shopping through the MCP. | $39 / mo | hosted | | 10 | [Adobe Commerce (Magento)](https://www.anchorterminal.com/tools/adobe-commerce.md) | B | 63.9 | An agent working for a merchant already on Adobe Commerce or Magento, for catalogue, order and B2B back-office work over REST and for carts and checkout over GraphQL. | Freemium | local | ## Picks by need - Highest score overall: [Shopify API + MCP](https://www.anchorterminal.com/tools/shopify.md), BB, 75/100 on the benchmark. Also [WooCommerce API + MCP](https://www.anchorterminal.com/tools/woocommerce.md), BB, 72.9/100. - Reliability: [Vendure](https://www.anchorterminal.com/tools/vendure.md), 89/100 on reliability, against 73 for the overall leader. - Agent ergonomics: [Spree Commerce](https://www.anchorterminal.com/tools/spree-commerce.md), 90/100 on agent ergonomics, against 79 for the overall leader. - Security & auth: [Shopware](https://www.anchorterminal.com/tools/shopware.md), 73/100 on security & auth, against 71 for the overall leader. - Maintenance & community: [Medusa API + MCP](https://www.anchorterminal.com/tools/medusa.md), 93/100 on maintenance & community, against 85 for the overall leader. - Transparency & trust: [Adobe Commerce (Magento)](https://www.anchorterminal.com/tools/adobe-commerce.md), 90/100 on transparency & trust, against 88 for the overall leader. - A hosted MCP endpoint: [commercetools](https://www.anchorterminal.com/tools/commercetools.md), remote MCP server, nothing to install. - Self-hosting under an open licence: [WooCommerce API + MCP](https://www.anchorterminal.com/tools/woocommerce.md), self-hosted, GPL-3 licence. Also [Shopware](https://www.anchorterminal.com/tools/shopware.md), self-hosted, MIT for the Community Edition core licence. ## How to choose - Cart and checkout over the API: Check that an agent can create a cart, add items, apply a discount and complete checkout through the API, not only through a hosted page it cannot read. - Headless access to the catalogue: Check whether products and variants can be read and changed without a storefront theme, since an agent needs structured product data rather than rendered pages. - Discount rules and errors: Check how discounts stack and how failed cart or checkout calls report errors, because an agent has to recover from a rejected coupon without a person stepping in. - Webhooks for order changes: Check that orders trigger webhooks for payment, fulfilment and cancellation, so an agent can react to status changes without polling the order list. - How the benchmark tests this category: The same catalogue and order flow on every platform. An agent searches products, builds a cart, applies a discount and places a test order. We score API coverage, webhooks, error handling, setup effort and platform cost, with no real payments. ## Each one in detail ### 1. Shopify API + MCP, BB 75/100 Hosted commerce platform for online stores. - Verdict: Typed GraphQL schemas with quarterly versions supported at least 12 months. Closed platform. You can't self-host or change checkout internals. - Choose it for: Agents that shop on real stores or automate a merchant's back office at scale. - Strength: Typed GraphQL schemas with quarterly versions supported at least 12 months - Strength: UCP on every store, 13 tools for catalogue, cart, checkout and orders, with idempotency keys on checkout - Strength: Granular read and write access scopes per app - Weakness: Closed platform. You can't self-host or change checkout internals - Weakness: Agent surface changes often. Storefront MCP tools moved to UCP, and AI Toolkit skills were consolidated on 25 September 2026 - Weakness: Checkout calls need signing or authentication, more setup than a plain key - Price: $39 / mo · Auth: OAuth or key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/shopify.md ### 2. WooCommerce API + MCP, BB 72.9/100 Open-source commerce plugin for WordPress that you host yourself. - Verdict: Free GPL software with no platform fee or revenue share. Uptime, speed and security depend on each store's host and plugins. No vendor status page. - Choose it for: Merchants already on WordPress and agents that need a cart and checkout without a vendor account. - Strength: Free GPL software with no platform fee or revenue share - Strength: Store API runs carts, coupons and checkout with a Cart-Token instead of a key - Strength: Code examples in five languages on every REST endpoint, and official JavaScript and Python clients - Weakness: Uptime, speed and security depend on each store's host and plugins. No vendor status page - Weakness: MCP is a developer preview behind the mcp_integration flag, with 7 abilities - Weakness: REST docs allow the consumer key and secret in the query string - Price: Free · OSS · Auth: OAuth or key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/woocommerce.md - Against #1: https://www.anchorterminal.com/compare/shopify-vs-woocommerce.md ### 3. Shopware, BB 71.4/100 Open-source commerce platform from shopware AG in Germany, written in PHP on Symfony. Agents reach a store through its Store API for shopping, its Admin API for back-office work, and a built-in MCP server on both. - Verdict: MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical. - Choose it for: A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work. - Strength: MIT core, free to self-host, with security fixes for the 6.7 line promised until 28 February 2028 in releases.json - Strength: Built-in MCP server advertises three discovery tools, and other tools load by toolset for the session - Strength: MCP write tools default to dryRun=true, which runs the change in a transaction and rolls it back - Weakness: The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint - Weakness: 20 advisories published between 19 May and 16 September 2026, four critical, including a pre-authentication SQL injection in the Store API - Weakness: MCP tools carry no readOnlyHint or destructiveHint annotations, and criteria and payloads travel as JSON-encoded strings - Price: Freemium · Auth: OAuth or key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/shopware.md - Against #1: https://www.anchorterminal.com/compare/shopify-vs-shopware.md ### 4. commercetools, BB 71.3/100 Headless commerce platform from commercetools GmbH in Munich, with HTTP and GraphQL APIs for catalogue, carts, checkout, orders and customers. Agents reach it through the API, four SDKs or a managed MCP server per project. - Verdict: A public OpenAPI file with 822 operations, per-resource OAuth scopes and a managed MCP server whose tools an administrator selects per agent. Prices are quoted by sales only, and the HTTP API publishes no platform-wide rate limit. A 60-day trial needs no card. - Choose it for: Enterprises that already run or plan a composable commerce stack and want agents working across catalogue, pricing, carts and orders under scoped credentials. - Strength: Public OpenAPI 3.0 file with 822 operations, plus RAML, a GraphQL schema, llms.txt and Markdown copies of every docs page - Strength: OAuth 2.0 API Clients with view and manage scopes per resource, a token revocation endpoint, and no tokens accepted in URL parameters - Strength: Managed MCP server per agent with a chosen tool list, field filtering and redaction, and readOnlyHint and destructiveHint on every tool since 1 October 2026 - Weakness: No public price. The pricing page describes order-based pricing and sends buyers to sales - Weakness: The docs state that the HTTP API has no single documented platform-wide rate limit - Weakness: Managed MCP Servers, AI Hub and Platform Insights are excluded from the standard SLA - Price: Paid · Auth: OAuth · x402: no · Where: hosted and local - Full assessment: https://www.anchorterminal.com/tools/commercetools.md - Against #1: https://www.anchorterminal.com/compare/commercetools-vs-shopify.md ### 5. Vendure, BB 70.9/100 Open-source headless commerce framework on TypeScript, NestJS and GraphQL that you self-host. - Verdict: Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available. - Choose it for: TypeScript teams that want a typed GraphQL commerce server and will host it. - Strength: Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on - Strength: API keys scoped to roles and channels, bcrypt-hashed and rotatable - Strength: GPLv3 core, free to self-host, with no GMV or order fees on any tier - Weakness: No vendor-hosted API. Vendure Cloud is only partly available - Weakness: The MCP plugin with 42 tools sits on the minor branch and isn't on npm - Weakness: Eleven advisories fixed in 3.7.3, including unauthenticated SSO account takeover and a cross-channel IDOR - Price: Freemium · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/vendure.md - Against #1: https://www.anchorterminal.com/compare/shopify-vs-vendure.md ### 6. Spree Commerce, BB 70.4/100 Spree Commerce is an open-source commerce platform on Ruby on Rails, maintained by Vendo Connect Inc. A self-hosted store runs a Store API for catalogue, cart and checkout, and an Admin API for back-office work. - Verdict: A self-hosted BSD 3-Clause platform with public OpenAPI files for the Store and Admin APIs, scoped secret keys, documented rate limits and idempotency keys on cart and checkout calls. GitHub lists six security advisories between January and July 2026, four rated High, and the default docs describe the 6.0 release candidate while 5.6.1 is the stable release. - Choose it for: Teams that want to own a Rails commerce backend with marketplace, B2B and multi-region functions and drive it through REST. - Strength: OpenAPI 3.0.3 files for the Store API (81 paths, 99 operations) and Admin API (259 paths, 417 operations), plus llms.txt and a Markdown copy of every docs page - Strength: Secret keys carry `read_*` and `write_*` scopes per resource, are shown once and can be revoked, and a key cannot create a key with wider scopes - Strength: `Idempotency-Key` on eight cart, checkout and payment calls, cached for 24 hours, with `Retry-After` on 429 responses - Weakness: Six GitHub security advisories between 8 January and 20 July 2026, four rated High, most of them access-control flaws on guest carts, orders and addresses - Weakness: The default docs and the main-branch OpenAPI files describe 6.0, a release candidate dated 8 October 2026. The stable release is 5.6.1 of 28 July 2026 - Weakness: The audit trail is in the paid Enterprise Edition only, and Enterprise prices are not published - Price: Freemium · Auth: OAuth or key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/spree-commerce.md - Against #1: https://www.anchorterminal.com/compare/shopify-vs-spree-commerce.md ### 7. Square, B 69.2/100 Square is Block's commerce and payments platform for sellers. Its REST API covers catalogue, orders, payment links, payments, inventory and customers, with seven SDKs and a beta MCP server hosted at mcp.squareup.com. - Verdict: The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026. - Choose it for: Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person. - Strength: Public OpenAPI 3.0 spec with 332 operations and 1,476 schemas, regenerated for API version 2026-09-16 - Strength: OAuth scopes are split by read and write for each resource, and access tokens expire after 30 days - Strength: 78 request schemas carry an `idempotency_key`, and the docs describe backoff with jitter for 429 responses - Weakness: The MCP server is marked beta, and the remote server reaches production data only - Weakness: No numeric rate limits were found for the REST API. Only GraphQL states a figure, 10 queries a second - Weakness: No SLA was found in the developer terms or documentation - Price: 2.9% fee · Auth: OAuth or key · x402: no · Where: hosted and local - Full assessment: https://www.anchorterminal.com/tools/square.md - Against #1: https://www.anchorterminal.com/compare/shopify-vs-square.md ### 8. Saleor API + MCP, B 68.6/100 Open-source headless commerce with a single GraphQL API for products, channels, checkouts, orders and customers, self-hosted or on Saleor Cloud. - Verdict: One GraphQL schema with 78 typed error-code enums and 464 marked deprecations. The MCP server can't create checkouts or orders. - Choose it for: Teams that want an open-source GraphQL backend with multi-channel pricing and an agent that reads store data safely. - Strength: One GraphQL schema with 78 typed error-code enums and 464 marked deprecations - Strength: BSD-3-Clause core, self-host or run on Saleor Cloud - Strength: Official MCP server with 8 tools, all read-only, 7 with readOnlyHint and idempotentHint - Weakness: The MCP server can't create checkouts or orders - Weakness: The hosted MCP at mcp.saleor.app only connects to saleor.cloud stores on 3.21 or later - Weakness: Cloud starts at $1,599 a month, and free sandboxes are non-commercial only - Price: $1599 / mo · Auth: OAuth or key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/saleor.md - Against #1: https://www.anchorterminal.com/compare/saleor-vs-shopify.md ### 9. BigCommerce API + MCP, B 64.3/100 Hosted commerce platform with REST management APIs for catalogue, carts, checkouts, orders and customers, a GraphQL Storefront API, and a beta storefront MCP server that lets an agent search products, build a cart and get a checkout link. - Verdict: Published rate limits per plan, with X-Rate-Limit-Time-Reset-Ms on every 429. Storefront MCP is beta, switched on per store, has no back-office tools and documents no tool annotations. - Choose it for: Agents working with existing BigCommerce stores, for back-office automation through REST or guest shopping through the MCP. - Strength: Published rate limits per plan, with X-Rate-Limit-Time-Reset-Ms on every 429 - Strength: PCI DSS Level 1, SOC 1, 2 and 3, and ISO 27001, 27017, 27018 and 27701 listed in the trust centre - Strength: Guest shopping through the storefront MCP with no key - Weakness: Storefront MCP is beta, switched on per store, has no back-office tools and documents no tool annotations - Weakness: Access tokens never expire and can't be rotated in place - Weakness: No current public OpenAPI file and no error-format reference. The old spec repo was archived in December 2023 - Price: $39 / mo · Auth: OAuth or key · x402: no · Where: hosted - Full assessment: https://www.anchorterminal.com/tools/bigcommerce.md - Against #1: https://www.anchorterminal.com/compare/bigcommerce-vs-shopify.md ### 10. Adobe Commerce (Magento), B 63.9/100 Commerce platform from Adobe, built on the open-source Magento core. It runs as Adobe Commerce as a Cloud Service, on Adobe's cloud infrastructure or on the merchant's own servers, and agents reach a store through its REST and GraphQL APIs. - Verdict: Public Swagger files cover 510 REST operations for the cloud service, the GraphQL schema carries cart, checkout and order mutations, and the cloud service authenticates by OAuth 2 through Adobe IMS. No request rate limit or idempotency key was found in the API documentation, Adobe publishes no MCP server for Commerce, and a licence starts with a sales order. - Choose it for: An agent working for a merchant already on Adobe Commerce or Magento, for catalogue, order and B2B back-office work over REST and for carts and checkout over GraphQL. - Strength: Swagger 2.0 files for the cloud service (510 operations) and for releases 2.4.6 to 2.4.9 sit in the public docs repository - Strength: The cloud service takes OAuth 2 client credentials or user tokens from Adobe IMS, and older bearer integration tokens are off by default on 2.4 stores - Strength: `?fields=` trims any REST response, and `searchCriteria` filters, sorts and pages every list endpoint - Weakness: No request rate limit for the REST or GraphQL APIs was found in the reviewed documentation, and 429 handling appears only in a code sample - Weakness: No idempotency keys were found, so a retried POST can create a second order or cart item - Weakness: status.adobe.com lists three Commerce incidents marked major in September 2026, two of them longer than an hour - Price: Freemium · Auth: OAuth or key · x402: no · Where: local - Full assessment: https://www.anchorterminal.com/tools/adobe-commerce.md - Against #1: https://www.anchorterminal.com/compare/adobe-commerce-vs-shopify.md 7 more are ranked in the full table: https://www.anchorterminal.com/categories/commerce.md ## Head to head - [Shopify API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/shopify-vs-woocommerce.md) - [Shopify API + MCP vs Shopware](https://www.anchorterminal.com/compare/shopify-vs-shopware.md) - [commercetools vs Shopify API + MCP](https://www.anchorterminal.com/compare/commercetools-vs-shopify.md) - [Shopify API + MCP vs Vendure](https://www.anchorterminal.com/compare/shopify-vs-vendure.md) - [Shopware vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/shopware-vs-woocommerce.md) - [commercetools vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/commercetools-vs-woocommerce.md) - [Vendure vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/vendure-vs-woocommerce.md) - [commercetools vs Shopware](https://www.anchorterminal.com/compare/commercetools-vs-shopware.md) - [Shopware vs Vendure](https://www.anchorterminal.com/compare/shopware-vs-vendure.md) - [commercetools vs Vendure](https://www.anchorterminal.com/compare/commercetools-vs-vendure.md) ## Questions ### What are the highest-rated commerce platforms and checkout APIs for AI agents? Shopify API + MCP has the highest benchmark score of the 17 ranked commerce platforms and checkout APIs, 75 (BB). WooCommerce API + MCP is second with 72.9 (BB). ### How many commerce platforms and checkout APIs are agent-ready? 6 of the 17 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark. ### Which commerce platforms and checkout APIs accept x402 payments? None of the ranked listings here accepts x402 for its main call yet. ### How is this list ranked? By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026. ## How this list is made The order is the Anchor benchmark score, the same number as on each listing. Each listing is graded from public evidence against the benchmark checklist, and the picks are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.