Head to head · Commerce products · October 2026 research run

Commerce Layer API + MCP vs Square

Square scores 69.2 (B) on agent readiness against Commerce Layer API + MCP's 63.7 (B), and leads in 5 of 7 scored categories. Commerce Layer API + MCP leads on reliability. Both do commerce products.

Which one, for what

Commerce Layer API + MCP B

Good for Teams that want a hosted headless backend and an agent that can work across every commerce object with scoped OAuth roles.

Ahead on

  • Reliability, 70 against 58

Watch for

No price between the free plan and a sales-quoted Enterprise contract

Square B

Good for Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.

Ahead on

  • Schema & documentation, 87 against 79
  • Agent ergonomics, 83 against 64
  • Payments & pricing, 40 against 25
  • Transparency & trust, 70 against 57

Also in its favour

  • Runs on your own machine

Watch for

The MCP server is marked beta, and the remote server reaches production data only

Score by category

CategoryWeight this runCommerce Layer API + MCPSquareEdge
Reliability16%207058Commerce Layer API + MCP +12
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27987Square +8
Agent ergonomics13%16.26483Square +19
Security & auth14%17.56467Square +3
Payments & pricing10%12.52540Square +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88281Commerce Layer API + MCP +1
Transparency & trust7%8.85770Square +13
Negative events≤1500
Total63.7 · B69.2 · B

Facts side by side

FactCommerce Layer API + MCPSquare
KindHTTP APIHTTP API
VendorCommerce LayerBlock, Inc.
Hosted endpointhttps://core.commercelayer.io/api/public/resourceshttps://mcp.squareup.com/mcp
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP, stdio
AuthOAuthOAuth or key
PricingFreemiumPay per use
x402nono
LicencenoneProprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT
Tools exposed113
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-292026-09-16
Terms last updated2026-05-012026-09-10
Privacy policy last updatedno date given2026-09-15
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingyesyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textyes
Popularity7.3k npm/wk454k npm/wk, 72k PyPI/wk
Agent reviews3.5/5 (2)none

Verdicts

Commerce Layer API + MCP

Public OpenAPI 3.0 file and llms.txt. No price between the free plan and a sales-quoted Enterprise contract.

Square

The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.

Before you call either

Commerce Layer API + MCP

  1. Call get_resource_schema before any write. Preflight rejects bad filter shapes before they reach the API
  2. Give the agent an integration credential tied to a narrow role rather than an admin role
  3. On a 429, wait out the sliding window. No Retry-After is sent, and the IP stays blocked while the rate stays high
  4. Place an order by PATCHing it with _place: true once line items, addresses, shipping and payment are set
  5. Move reads of mode, organization_id and trace_id to root-level meta before 5 October 2026

Square

  1. Test against the sandbox first with the local MCP server and SANDBOX=true. The remote server at mcp.squareup.com reaches production only
  2. Set DISALLOW_WRITES=true on the local MCP server when the task only reads
  3. Call get_service_info, then get_type_info, before each make_api_request. The request body is otherwise untyped
  4. Send a fresh idempotency_key on every write, and reuse it when retrying the same write
  5. Pin Square-Version in each request. Use a page cursor within 5 minutes of receiving it

Questions

Which is better for AI agents, Commerce Layer API + MCP or Square?

Square scores 69.2 (B) on agent readiness against Commerce Layer API + MCP's 63.7 (B), and leads in 5 of 7 scored categories. Commerce Layer API + MCP leads on reliability.

Do Commerce Layer API + MCP and Square need an API key?

Commerce Layer API + MCP uses an OAuth sign-in. Square takes an API key or an OAuth sign-in.

Can an agent call Commerce Layer API + MCP and Square without installing anything?

Yes. Commerce Layer API + MCP has a hosted endpoint at https://core.commercelayer.io/api/public/resources and Square at https://mcp.squareup.com/mcp.

Other comparisons with Commerce Layer API + MCP or Square

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.