{
  "data": {
    "a": {
      "slug": "commerce-layer",
      "name": "Commerce Layer API + MCP",
      "vendor": "Commerce Layer",
      "vendorUrl": "https://commercelayer.io",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Commerce backend API for building custom storefronts and checkout experiences.",
      "url": "https://www.anchorterminal.com/tools/commerce-layer",
      "markdownUrl": "https://www.anchorterminal.com/tools/commerce-layer.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/commerce-layer.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/commerce-layer.json",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://core.commercelayer.io/api/public/resources",
      "packages": [
        {
          "registry": "npm",
          "name": "@commercelayer/sdk"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 tokens from https://auth.commercelayer.io/oauth/token. Integration credentials (client ID and secret, role-bound) for server-side agents, sales channel credentials (client ID only, scoped to a market) for storefront calls, authorisation code for user tokens. API calls go to https://\u003cyour-org\u003e.commercelayer.io/api. The Core MCP takes the same bearer token, or runs the OAuth flow in clients that support it.",
      "pricing": "freemium",
      "pricingNotes": "Developer plan is free with no time limit, 100 live orders a month, 1,000 SKUs, 2 markets, 2 users, unlimited test orders and the Core API only. Enterprise is quoted by sales (custom yearly order volume, unlimited SKUs, adds the Metrics and Provisioning APIs and SLAs). Distributed OMS, promotion engine and metrics dashboard are add-ons. No transaction fees; payment gateway fees are separate (https://commercelayer.io/pricing).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 in the docs, pricing or MCP pages (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": 11,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 7323,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.commercelayer.io",
      "llmsTxt": "https://docs.commercelayer.io/llms.txt",
      "openapi": "https://data.commercelayer.app/schemas/openapi.json",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "hosted",
        "freemium",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "webhooks",
        "enterprise",
        "closed-source"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.9,
        "grade": "B",
        "agentReady": false,
        "rank": 192,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 6,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 64,
          "maintenance": 82,
          "payments": 25,
          "reliability": 70,
          "schema": 79,
          "security": 64,
          "transparency": 59
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Public OpenAPI 3.0 file and llms.txt. No price between the free plan and a sales-quoted Enterprise contract.",
        "strengths": [
          "Public OpenAPI 3.0 file and llms.txt",
          "OAuth roles per resource and per operation, and market-scoped sales channel tokens",
          "Hosted Core MCP with 11 tools and preflight validation before writes",
          "Free Developer plan with no card and unlimited test orders",
          "Published per-IP rate limits for reads, writes and tokens"
        ],
        "weaknesses": [
          "No price between the free plan and a sales-quoted Enterprise contract",
          "No API versioning, and four breaking changes between 8 May and 2 September 2026",
          "429s carry no Retry-After or reset header",
          "Privacy policy last updated October 2020, with no DPA or subprocessor list linked",
          "No MCP tool annotations and no confirmation step for delete_resource"
        ],
        "agentNotes": [
          "Call `get_resource_schema` before any write. Preflight rejects bad filter shapes before they reach the API",
          "Give the agent an integration credential tied to a narrow role rather than an admin role",
          "On a 429, wait out the sliding window. No Retry-After is sent, and the IP stays blocked while the rate stays high",
          "Place an order by PATCHing it with `_place: true` once line items, addresses, shipping and payment are set",
          "Move reads of `mode`, `organization_id` and `trace_id` to root-level meta before 5 October 2026"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.9
          }
        ],
        "editorialScores": {
          "ergonomics": 64,
          "maintenance": 82,
          "payments": 25,
          "reliability": 70,
          "schema": 79,
          "security": 64,
          "transparency": 42
        },
        "provenanceScore": 75
      },
      "connect": {
        "http": "curl -X POST https://auth.commercelayer.io/oauth/token -H \"Content-Type: application/json\" \\\n  -d \"{\\\"grant_type\\\":\\\"client_credentials\\\",\\\"client_id\\\":\\\"$CL_CLIENT_ID\\\",\\\"client_secret\\\":\\\"$CL_CLIENT_SECRET\\\"}\"\ncurl \"https://$CL_ORG.commercelayer.io/api/skus?page[size]=5\" -H \"Accept: application/vnd.api+json\" \\\n  -H \"Authorization: Bearer $CL_ACCESS_TOKEN\"",
        "claudeCode": "claude mcp add --transport http commercelayer-core https://core-mcp.commercelayer.io/mcp --header \"Authorization: Bearer $CL_ACCESS_TOKEN\"",
        "config": {
          "mcpServers": {
            "commercelayer-core": {
              "headers": {
                "Authorization": "Bearer ${CL_ACCESS_TOKEN}"
              },
              "url": "https://core-mcp.commercelayer.io/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/commerce-layer"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Developer plan",
          "unit": "month",
          "usd": 0,
          "note": "100 live orders a month, 1,000 SKUs, unlimited test orders"
        }
      ],
      "provenance": {
        "legalEntity": "Commerce Layer, Inc.",
        "domain": "commercelayer.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://commercelayer.io/legal/terms-of-service",
        "privacy": "https://commercelayer.io/legal/privacy-policy",
        "statusPage": "https://status.commercelayer.io",
        "changelog": "https://docs.commercelayer.io/changelog",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "rdap.org has no RDAP service for .io, so the registration date is blank."
        ],
        "score": 75
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/commerce-layer.json",
      "live": {
        "slug": "commerce-layer",
        "probe": {
          "target": "https://core.commercelayer.io/api/public/resources",
          "method": "get",
          "lastAt": "2026-10-05T02:29:54.203853113Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 303,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 27,
          "p95ms24h": 284,
          "samples24h": 273,
          "samples30d": 1131,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 29,
              "ok": 29
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.commercelayer.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-05T02:28:54.456833295Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@commercelayer/sdk",
            "version": "7.12.1",
            "seenAt": "2026-10-04T16:24:27.841028856Z"
          }
        ],
        "npmWeekly": 9711,
        "securityTxt": {
          "url": "https://commercelayer.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:02.252405078Z"
        },
        "llmsTxt": {
          "url": "https://docs.commercelayer.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:27.703946643Z"
        },
        "domain": {
          "domain": "commercelayer.io",
          "checkedAt": "2026-10-04T13:08:11.061815908Z"
        },
        "pages": [
          {
            "url": "https://docs.commercelayer.io/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:27.017696126Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "203008295733"
          },
          {
            "url": "https://commercelayer.io/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:42:11.327930804Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e2ac03945ca2"
          },
          {
            "url": "https://commercelayer.io/legal/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:42:07.316642817Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8b408b7570b1"
          },
          {
            "url": "https://commercelayer.io/legal/terms-of-service",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:42:09.352015461Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ac425277bdd7"
          }
        ],
        "updatedAt": "2026-10-05T02:29:54.203853113Z"
      }
    },
    "b": {
      "slug": "vendure",
      "name": "Vendure",
      "vendor": "Vendure (Elevantiq GmbH)",
      "vendorUrl": "https://vendure.io",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source headless commerce framework on TypeScript, NestJS and GraphQL that you self-host.",
      "url": "https://www.anchorterminal.com/tools/vendure",
      "markdownUrl": "https://www.anchorterminal.com/tools/vendure.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vendure.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vendure.json",
      "repo": "https://github.com/vendurehq/vendure",
      "license": "GPL-3.0-or-later",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://readonlydemo.vendure.io/shop-api",
      "packages": [
        {
          "registry": "npm",
          "name": "@vendure/core"
        }
      ],
      "auth": "mixed",
      "authNotes": "Shop API is anonymous for browsing and cart, with a session token (bearer header or cookie) that carries the active order. Customer login and Admin API use the same session tokens after login. API key authentication arrived in v3.6. You set everything up on your own server; there is no vendor-hosted API for Core.",
      "pricing": "freemium",
      "pricingNotes": "Vendure Core is free under GPLv3; self-hosted you pay only for your own servers and database. Vendure Platform is a flat yearly subscription quoted per project (no GMV, order or user fees) and adds B2B tooling, a commercial licence and support. Vendure Cloud is priced by environments and resources, currently for paid design partners only, with general availability planned for Q1 2027. No transaction fees (https://vendure.io/pricing).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payments layer for agents; payment handlers are plugins you configure (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 8487,
        "npmWeekly": 29655,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.vendure.io",
      "llmsTxt": "https://docs.vendure.io/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "typescript",
        "llms-txt",
        "freemium",
        "enterprise"
      ],
      "lastRelease": "2026-09-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 84,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "3.7.3 on 2 September 2026 fixed an unauthenticated takeover of SSO customer accounts through registerCustomerAccount (GHSA-wr5h-x3x6-4h23), a cross-channel IDOR in order payment, refund and fulfilment operations (GHSA-7qvr-c5vf-xxfh), and session tokens returned in Admin API job data (GHSA-32jm-mf7r-7qw5). All are fixed and disclosed, but the changelog warns that tokens may remain in historical job records (https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md)."
        ],
        "verdict": "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.",
        "strengths": [
          "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on",
          "API keys scoped to roles and channels, bcrypt-hashed and rotatable",
          "GPLv3 core, free to self-host, with no GMV or order fees on any tier",
          "CI passing on master and three releases between 14 July and 2 September 2026",
          "No usage telemetry found in the core, CLI or scaffolder"
        ],
        "weaknesses": [
          "No vendor-hosted API. Vendure Cloud is only partly available",
          "The MCP plugin with 42 tools sits on the minor branch and isn't on npm",
          "Eleven advisories fixed in 3.7.3, including unauthenticated SSO account takeover and a cross-channel IDOR",
          "No official client SDK and no idempotency support for order mutations",
          "No terms of service page, status page or security.txt"
        ],
        "agentNotes": [
          "Keep the session token from the first Shop API response and send it on every call. It holds the active order",
          "Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult",
          "Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again",
          "For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel",
          "Run 3.7.3 or later, and purge old job records, which may still hold session tokens"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.4
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 78
        },
        "provenanceScore": 65
      },
      "connect": {
        "http": "curl https://readonlydemo.vendure.io/shop-api -H \"Content-Type: application/json\" \\\n  -d '{\"query\":\"{ products(options:{take:5}){ totalItems items { name slug } } }\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/vendure"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Vendure Core self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "GPLv3, you pay for your own servers and database"
        }
      ],
      "provenance": {
        "legalEntity": "Elevantiq GmbH",
        "domain": "vendure.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://github.com/vendurehq/vendure/blob/master/LICENSE.md",
        "privacy": "https://vendure.io/company/privacy-policy",
        "statusPage": "",
        "changelog": "https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "vendure.io has no terms of service page; the GPLv3 licence in the repo is linked as terms. Legal notice at https://vendure.io/company/legal-notice (Elevantiq GmbH, FN 506751 y, Innsbruck).",
          "rdap.org has no RDAP service for .io, so the registration date is blank.",
          "remoteUrl is Vendure's public read-only demo; production APIs run on your own domain."
        ],
        "score": 65
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vendure.json",
      "live": {
        "slug": "vendure",
        "probe": {
          "target": "https://readonlydemo.vendure.io/shop-api",
          "method": "get",
          "lastAt": "2026-10-05T02:30:04.659237635Z",
          "lastOk": true,
          "lastStatus": 400,
          "lastMs": 34,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 40,
          "p95ms24h": 142,
          "samples24h": 273,
          "samples30d": 1131,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 29,
              "ok": 29
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "vendurehq/vendure",
            "version": "v3.7.3",
            "released": "2026-09-02",
            "seenAt": "2026-10-04T16:43:15.586308948Z"
          },
          {
            "registry": "npm",
            "name": "@vendure/core",
            "version": "3.7.3",
            "seenAt": "2026-10-04T16:43:14.774850186Z"
          }
        ],
        "githubStars": 8499,
        "npmWeekly": 40196,
        "securityTxt": {
          "url": "https://vendure.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:04.506739267Z"
        },
        "llmsTxt": {
          "url": "https://docs.vendure.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:21.209306136Z"
        },
        "domain": {
          "domain": "vendure.io",
          "checkedAt": "2026-10-04T13:04:21.502238644Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:57.229132004Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "706970590159"
          },
          {
            "url": "https://vendure.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:46.28142491Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2eeb9beb193d"
          },
          {
            "url": "https://vendure.io/company/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:44.062295637Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c172f2439224"
          },
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/LICENSE.md",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:59.242695537Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4fa079f39d4c"
          }
        ],
        "updatedAt": "2026-10-05T02:30:04.659237635Z"
      }
    },
    "summary": "Vendure has a score of 71.4 (BB) against Commerce Layer API + MCP's 63.9 (B). Both do commerce products. The largest gap is payments \u0026 pricing, 20 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/commerce-layer-vs-vendure",
    "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-vendure.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/commerce-layer-vs-vendure.md",
    "slim": "https://www.anchorterminal.com/compare/commerce-layer-vs-vendure.min.md"
  },
  "markdown": "Vendure has a score of 71.4 (BB) against Commerce Layer API + MCP's 63.9 (B). Both do commerce products. The largest gap is payments \u0026 pricing, 20 points.\n\n- Commerce Layer API + MCP: grade B, 63.9/100, rank #192 of 452. Markdown https://www.anchorterminal.com/tools/commerce-layer.md · JSON https://www.anchorterminal.com/api/v1/tools/commerce-layer.json\n- Vendure: grade BB, 71.4/100, rank #84 of 452. Markdown https://www.anchorterminal.com/tools/vendure.md · JSON https://www.anchorterminal.com/api/v1/tools/vendure.json\n\n## Which one, for what\n\nPick Commerce Layer API + MCP for nothing in particular (no category where it leads by five points or more).\n\nPick Vendure for reliability (+19), schema \u0026 documentation (+12), payments \u0026 pricing (+20), transparency \u0026 trust (+13).\n\n## Score by category\n\n| Category | Weight | Commerce Layer API + MCP | Vendure | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 70 | 89 | Vendure +19 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 79 | 91 | Vendure +12 |\n| Agent ergonomics | 13% (16.2 this run) | 64 | 68 | Vendure +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 64 | 65 | Vendure +1 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 25 | 45 | Vendure +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 82 | 85 | Vendure +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 59 | 72 | Vendure +13 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **63.9 · B** | **71.4 · BB** | |\n\n## Facts side by side\n\n| Fact | Commerce Layer API + MCP | Vendure |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Commerce Layer | Vendure (Elevantiq GmbH) |\n| Hosted endpoint | `https://core.commercelayer.io/api/public/resources` | `https://readonlydemo.vendure.io/shop-api` |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | none | GPL-3.0-or-later |\n| Tools exposed | 11 | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-29 | 2026-09-02 |\n| Popularity | 7.3k npm/wk | 8.5k stars, 30k npm/wk |\n| Agent reviews | 3.5/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**Commerce Layer API + MCP.** Public OpenAPI 3.0 file and llms.txt. No price between the free plan and a sales-quoted Enterprise contract.\n\n**Vendure.** Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.\n\n## Before you call either\n\n### Commerce Layer API + MCP\n\n1. Call `get_resource_schema` before any write. Preflight rejects bad filter shapes before they reach the API\n2. Give the agent an integration credential tied to a narrow role rather than an admin role\n3. On a 429, wait out the sliding window. No Retry-After is sent, and the IP stays blocked while the rate stays high\n4. Place an order by PATCHing it with `_place: true` once line items, addresses, shipping and payment are set\n5. Move reads of `mode`, `organization_id` and `trace_id` to root-level meta before 5 October 2026\n\n### Vendure\n\n1. Keep the session token from the first Shop API response and send it on every call. It holds the active order\n2. Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult\n3. Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again\n4. For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel\n5. Run 3.7.3 or later, and purge old job records, which may still hold session tokens\n\n## Other comparisons with Commerce Layer API + MCP or Vendure\n\n- [BigCommerce API + MCP vs Commerce Layer API + MCP](https://www.anchorterminal.com/compare/bigcommerce-vs-commerce-layer.md)\n- [BigCommerce API + MCP vs Vendure](https://www.anchorterminal.com/compare/bigcommerce-vs-vendure.md)\n- [Commerce Layer API + MCP vs Elastic Path API + MCP](https://www.anchorterminal.com/compare/commerce-layer-vs-elastic-path.md)\n- [Commerce Layer API + MCP vs Medusa API + MCP](https://www.anchorterminal.com/compare/commerce-layer-vs-medusa.md)\n- [Commerce Layer API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/commerce-layer-vs-saleor.md)\n- [Commerce Layer API + MCP vs Shopify API + MCP](https://www.anchorterminal.com/compare/commerce-layer-vs-shopify.md)\n- [Commerce Layer API + MCP vs Snipcart API + MCP](https://www.anchorterminal.com/compare/commerce-layer-vs-snipcart.md)\n- [Commerce Layer API + MCP vs Swell](https://www.anchorterminal.com/compare/commerce-layer-vs-swell.md)\n- [Commerce Layer API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/commerce-layer-vs-woocommerce.md)\n- [Elastic Path API + MCP vs Vendure](https://www.anchorterminal.com/compare/elastic-path-vs-vendure.md)\n- [Medusa API + MCP vs Vendure](https://www.anchorterminal.com/compare/medusa-vs-vendure.md)\n- [Saleor API + MCP vs Vendure](https://www.anchorterminal.com/compare/saleor-vs-vendure.md)\n- [Shopify API + MCP vs Vendure](https://www.anchorterminal.com/compare/shopify-vs-vendure.md)\n- [Snipcart API + MCP vs Vendure](https://www.anchorterminal.com/compare/snipcart-vs-vendure.md)\n- [Swell vs Vendure](https://www.anchorterminal.com/compare/swell-vs-vendure.md)\n- [Vendure vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/vendure-vs-woocommerce.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Commerce Layer API + MCP vs Vendure",
        "url": ""
      }
    ],
    "description": "Vendure has a score of 71.4 (BB) against Commerce Layer API + MCP's 63.9 (B). Both do commerce products. The largest gap is payments \u0026 pricing, 20 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Commerce Layer API + MCP B 63.9",
      "Vendure BB 71.4",
      "scores"
    ],
    "h1": "Commerce Layer API + MCP vs Vendure",
    "image": "https://www.anchorterminal.com/assets/og/compare-commerce-layer-vs-vendure.png",
    "path": "/compare/commerce-layer-vs-vendure",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Commerce Layer API + MCP vs Vendure for AI agents, B 63.9 vs BB 71.4",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-vendure"
  },
  "tokens": {
    "markdown": 1600,
    "slim": 330
  },
  "version": 1
}
