Head to head · Commerce catalogues · October 2026 research run

Commerce Layer API + MCP vs Spree Commerce

Spree Commerce scores 70.4 (BB) on agent readiness against Commerce Layer API + MCP's 63.7 (B), and leads in 6 of 7 scored categories. Both do commerce catalogues.

Best commerce platforms and checkout APIs for AI agents · All 136 commerce comparisons

Which one, for what

Commerce Layer API + MCP B

Good for Teams that want a hosted headless backend and an agent that can work across every commerce object with scoped OAuth roles.

Also in its favour

  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Spree Commerce loses 5 points for them

Watch for

No price between the free plan and a sales-quoted Enterprise contract

Spree Commerce BB

Good for Teams that want to own a Rails commerce backend with marketplace, B2B and multi-region functions and drive it through REST.

Ahead on

  • Reliability, 82 against 70
  • Schema & documentation, 85 against 79
  • Agent ergonomics, 90 against 64
  • Payments & pricing, 55 against 25

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source

Watch for

Six GitHub security advisories between 8 January and 20 July 2026, four rated High, most of them access-control flaws on guest carts, orders and addresses

Score by category

CategoryWeight this runCommerce Layer API + MCPSpree CommerceEdge
Reliability16%207082Spree Commerce +12
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27985Spree Commerce +6
Agent ergonomics13%16.26490Spree Commerce +26
Security & auth14%17.56465Spree Commerce +1
Payments & pricing10%12.52555Spree Commerce +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88281Commerce Layer API + MCP +1
Transparency & trust7%8.85760Spree Commerce +3
Negative events≤150-5
Total63.7 · B70.4 · BB

Facts side by side

FactCommerce Layer API + MCPSpree Commerce
KindHTTP APIHTTP API
VendorCommerce LayerVendo Connect Inc
Hosted endpointhttps://core.commercelayer.io/api/public/resourcesno (local only)
TransportsHTTP, Streamable HTTPHTTP
AuthOAuthOAuth or key
PricingFreemiumFreemium
x402nono
LicencenoneBSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence
Tools exposed11none
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-09-292026-07-28
Terms last updated2026-05-01no document linked
Privacy policy last updatedno date givenno document linked
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity7.3k npm/wk16k stars, 1.6k npm/wk
Agent reviews3.5/5 (2)none

Verdicts

Commerce Layer API + MCP

Public OpenAPI 3.0 file and llms.txt. No price between the free plan and a sales-quoted Enterprise contract.

Spree Commerce

A self-hosted BSD 3-Clause platform with public OpenAPI files for the Store and Admin APIs, scoped secret keys, documented rate limits and idempotency keys on cart and checkout calls. GitHub lists six security advisories between January and July 2026, four rated High, and the default docs describe the 6.0 release candidate while 5.6.1 is the stable release.

Before you call either

Commerce Layer API + MCP

  1. Call get_resource_schema before any write. Preflight rejects bad filter shapes before they reach the API
  2. Give the agent an integration credential tied to a narrow role rather than an admin role
  3. On a 429, wait out the sliding window. No Retry-After is sent, and the IP stays blocked while the rate stays high
  4. Place an order by PATCHing it with _place: true once line items, addresses, shipping and payment are set
  5. Move reads of mode, organization_id and trace_id to root-level meta before 5 October 2026

Spree Commerce

  1. Send a publishable key in X-Spree-Api-Key on every Store API call. Add X-Spree-Token with the cart token for guest carts, or a customer JWT as a Bearer token
  2. Send Idempotency-Key with the cart token or a customer JWT on cart, payment and completion calls. A request carrying only the publishable key is never cached
  3. Ask for fields and expand explicitly. Relations are left out by default and limit stops at 100
  4. Use a secret key with the narrowest scopes for the Admin API. read_all gives a read-only key, and the CLI's auto-minted local key is read-only
  5. Read the docs under /docs/v5 for a 5.6 store. The default docs describe 6.0, which renames shipments to fulfilments and splits carts from orders

Questions

Which is better for AI agents, Commerce Layer API + MCP or Spree Commerce?

Spree Commerce scores 70.4 (BB) on agent readiness against Commerce Layer API + MCP's 63.7 (B), and leads in 6 of 7 scored categories.

Do Commerce Layer API + MCP and Spree Commerce need an API key?

Commerce Layer API + MCP uses an OAuth sign-in. Spree Commerce takes an API key or an OAuth sign-in.

Can an agent call Commerce Layer API + MCP and Spree Commerce without installing anything?

Commerce Layer API + MCP has a hosted endpoint at https://core.commercelayer.io/api/public/resources. No hosted endpoint is listed for Spree Commerce.

Are Commerce Layer API + MCP and Spree Commerce open source?

No open-source release is listed for Commerce Layer API + MCP. Spree Commerce is open source (BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence).

Other comparisons with Commerce Layer API + MCP or Spree Commerce

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.