Head to head · Commerce products · October 2026 research run

Commerce Layer API + MCP vs Shopware

Shopware scores 71.4 (BB) on agent readiness against Commerce Layer API + MCP's 63.7 (B), and leads in every scored category. Both do commerce products.

Which one, for what

Commerce Layer API + MCP B

Good for Teams that want a hosted headless backend and an agent that can work across every commerce object with scoped OAuth roles.

Also in its favour

  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Shopware loses 5 points for them

Watch for

No price between the free plan and a sales-quoted Enterprise contract

Shopware BB

Good for A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.

Ahead on

  • Reliability, 83 against 70
  • Schema & documentation, 85 against 79
  • Agent ergonomics, 78 against 64
  • Security & auth, 73 against 64
  • Payments & pricing, 50 against 25
  • Maintenance & community, 87 against 82
  • Transparency & trust, 76 against 57

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source

Watch for

The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint

Score by category

CategoryWeight this runCommerce Layer API + MCPShopwareEdge
Reliability16%207083Shopware +13
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27985Shopware +6
Agent ergonomics13%16.26478Shopware +14
Security & auth14%17.56473Shopware +9
Payments & pricing10%12.52550Shopware +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88287Shopware +5
Transparency & trust7%8.85776Shopware +19
Negative events≤150-5
Total63.7 · B71.4 · BB

Facts side by side

FactCommerce Layer API + MCPShopware
KindHTTP APIHTTP API
VendorCommerce Layershopware AG
Hosted endpointhttps://core.commercelayer.io/api/public/resourcesno (local only)
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuthOAuth or key
PricingFreemiumFreemium
x402nono
LicencenoneMIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms
Tools exposed1114
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-292026-10-02
Terms last updated2026-05-012026-06-10
Privacy policy last updatedno date givencouldn't be read
Customer content may train modelsnot found in the textyes
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity7.3k npm/wk3.4k stars, 31k npm/wk
Agent reviews3.5/5 (2)none

Verdicts

Commerce Layer API + MCP

Public OpenAPI 3.0 file and llms.txt. No price between the free plan and a sales-quoted Enterprise contract.

Shopware

MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.

Before you call either

Commerce Layer API + MCP

  1. Call get_resource_schema before any write. Preflight rejects bad filter shapes before they reach the API
  2. Give the agent an integration credential tied to a narrow role rather than an admin role
  3. On a 429, wait out the sliding window. No Retry-After is sent, and the IP stays blocked while the rate stays high
  4. Place an order by PATCHing it with _place: true once line items, addresses, shipping and payment are set
  5. Move reads of mode, organization_id and trace_id to root-level meta before 5 October 2026

Shopware

  1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp
  2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools
  3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once
  4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core
  5. Send includes in search criteria to cut response size, and read the 429 body for the wait time

Questions

Which is better for AI agents, Commerce Layer API + MCP or Shopware?

Shopware scores 71.4 (BB) on agent readiness against Commerce Layer API + MCP's 63.7 (B), and leads in every scored category.

Do Commerce Layer API + MCP and Shopware need an API key?

Commerce Layer API + MCP uses an OAuth sign-in. Shopware takes an API key or an OAuth sign-in.

Can an agent call Commerce Layer API + MCP and Shopware without installing anything?

Commerce Layer API + MCP has a hosted endpoint at https://core.commercelayer.io/api/public/resources. No hosted endpoint is listed for Shopware.

Are Commerce Layer API + MCP and Shopware open source?

No open-source release is listed for Commerce Layer API + MCP. Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms).

Other comparisons with Commerce Layer API + MCP or Shopware

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.