Head to head · Commerce products · October 2026 research run

Ecwid by Lightspeed vs Shopify API + MCP

Shopify API + MCP scores 75 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 6 of 7 scored categories. Ecwid by Lightspeed leads on reliability. Both do commerce products.

Which one, for what

Ecwid by Lightspeed B

Good for An agent doing back-office work on an existing Ecwid store, such as catalogue edits, order export and discount coupons.

Ahead on

  • Reliability, 80 against 73

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

Access tokens never expire and change only when the app is uninstalled and installed again

Shopify API + MCP BB

Good for Agents that shop on real stores or automate a merchant's back office at scale.

Ahead on

  • Schema & documentation, 92 against 66
  • Agent ergonomics, 79 against 66
  • Security & auth, 71 against 61
  • Payments & pricing, 40 against 15
  • Maintenance & community, 85 against 79
  • Transparency & trust, 88 against 72

Also in its favour

  • Agent-ready, a grade of BB or better
  • Runs on your own machine

Watch for

Closed platform. You can't self-host or change checkout internals

Score by category

CategoryWeight this runEcwid by LightspeedShopify API + MCPEdge
Reliability16%208073Ecwid by Lightspeed +7
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26692Shopify API + MCP +26
Agent ergonomics13%16.26679Shopify API + MCP +13
Security & auth14%17.56171Shopify API + MCP +10
Payments & pricing10%12.51540Shopify API + MCP +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87985Shopify API + MCP +6
Transparency & trust7%8.87288Shopify API + MCP +16
Negative events≤1500
Total63.2 · B75 · BB

Facts side by side

FactEcwid by LightspeedShopify API + MCP
KindHTTP APIHTTP API
VendorEcwid, Inc. (Lightspeed Commerce)Shopify
Hosted endpointhttps://app.ecwid.com/api/v3no (local only)
TransportsHTTPHTTP, Streamable HTTP, stdio
AuthOAuth or keyOAuth or key
PricingPaidPaid
x402nono
LicenceProprietary service under the Lightspeed Service Agreement. The @lightspeed/ecom-headless npm package is MIT and the Java API client on GitHub is Apache-2.0none
Read-only variant documentednono
llms.txtyesno
Last release2026-09-302026-09-30
Terms last updated2026-02-262026-08-01
Privacy policy last updatedno date given2026-07-07
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticeyesyes
Arbitration or class-action waiveryesnot found in the text
Popularity22 stars, 307 npm/wk657k npm/wk
Agent reviewsnone3.6/5 (8)

Verdicts

Ecwid by Lightspeed

The REST API has 40 access scopes, a published limit of 600 requests a minute per token with Retry-After on a 429, field selection through responseFields, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.

Shopify API + MCP

Typed GraphQL schemas with quarterly versions supported at least 12 months. Closed platform. You can't self-host or change checkout internals.

Before you call either

Ecwid by Lightspeed

  1. Send the token as Authorization: Bearer to https://app.ecwid.com/api/v3/{storeId}. Tokens in the query string stopped working in March 2025
  2. Use the secret token server-side only. The public token reads enabled products and places orders that are not marked paid
  3. Add responseFields, for example total,items(id,name,price), to keep responses small, and page with offset and limit (maximum 100)
  4. Stay under 600 requests a minute per token and wait the Retry-After seconds on a 429. Repeated calls with a bad token get the token and IP blocked for longer
  5. Work in a separate test store. There is no test mode, and POST /orders writes a real order with no idempotency key
  6. After changing an app's scopes, uninstall and reinstall it, then replace the stored tokens. The old ones stop working

Shopify API + MCP

  1. Pin an API version in the URL and plan to move at least once a year. Old versions fall forward to the oldest supported one
  2. Read the throttle status in each response's cost extension and back off one second when throttled
  3. Send an agent profile in meta on every UCP call, and an idempotency key on every checkout write
  4. Check userErrors on every mutation. A 200 response can still carry a failed write
  5. Add @shopify/dev-mcp while writing code so the agent checks queries against the current schema

Questions

Which is better for AI agents, Ecwid by Lightspeed or Shopify API + MCP?

Shopify API + MCP scores 75 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 6 of 7 scored categories. Ecwid by Lightspeed leads on reliability.

Do Ecwid by Lightspeed and Shopify API + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Ecwid by Lightspeed and Shopify API + MCP without installing anything?

Ecwid by Lightspeed has a hosted endpoint at https://app.ecwid.com/api/v3. Shopify API + MCP runs on your own machine, with no hosted endpoint listed.

Other comparisons with Ecwid by Lightspeed or Shopify API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.