Head to head · Commerce products · October 2026 research run

Ecwid by Lightspeed vs Shopware

Shopware scores 71.4 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in every scored category. Both do commerce products.

Which one, for what

Ecwid by Lightspeed B

Good for An agent doing back-office work on an existing Ecwid store, such as catalogue edits, order export and discount coupons.

Also in its favour

  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Shopware loses 5 points for them

Watch for

Access tokens never expire and change only when the app is uninstalled and installed again

Shopware BB

Good for A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.

Ahead on

  • Schema & documentation, 85 against 66
  • Agent ergonomics, 78 against 66
  • Security & auth, 73 against 61
  • Payments & pricing, 50 against 15
  • Maintenance & community, 87 against 79

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source

Watch for

The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint

Score by category

CategoryWeight this runEcwid by LightspeedShopwareEdge
Reliability16%208083Shopware +3
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26685Shopware +19
Agent ergonomics13%16.26678Shopware +12
Security & auth14%17.56173Shopware +12
Payments & pricing10%12.51550Shopware +35
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87987Shopware +8
Transparency & trust7%8.87276Shopware +4
Negative events≤150-5
Total63.2 · B71.4 · BB

Facts side by side

FactEcwid by LightspeedShopware
KindHTTP APIHTTP API
VendorEcwid, Inc. (Lightspeed Commerce)shopware AG
Hosted endpointhttps://app.ecwid.com/api/v3no (local only)
TransportsHTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingPaidFreemium
x402nono
LicenceProprietary service under the Lightspeed Service Agreement. The @lightspeed/ecom-headless npm package is MIT and the Java API client on GitHub is Apache-2.0MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms
Tools exposednone14
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-302026-10-02
Terms last updated2026-02-262026-06-10
Privacy policy last updatedno date givencouldn't be read
Customer content may train modelsnot found in the textyes
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waiveryesnot found in the text
Popularity22 stars, 307 npm/wk3.4k stars, 31k npm/wk

Verdicts

Ecwid by Lightspeed

The REST API has 40 access scopes, a published limit of 600 requests a minute per token with Retry-After on a 429, field selection through responseFields, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.

Shopware

MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.

Before you call either

Ecwid by Lightspeed

  1. Send the token as Authorization: Bearer to https://app.ecwid.com/api/v3/{storeId}. Tokens in the query string stopped working in March 2025
  2. Use the secret token server-side only. The public token reads enabled products and places orders that are not marked paid
  3. Add responseFields, for example total,items(id,name,price), to keep responses small, and page with offset and limit (maximum 100)
  4. Stay under 600 requests a minute per token and wait the Retry-After seconds on a 429. Repeated calls with a bad token get the token and IP blocked for longer
  5. Work in a separate test store. There is no test mode, and POST /orders writes a real order with no idempotency key
  6. After changing an app's scopes, uninstall and reinstall it, then replace the stored tokens. The old ones stop working

Shopware

  1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp
  2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools
  3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once
  4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core
  5. Send includes in search criteria to cut response size, and read the 429 body for the wait time

Questions

Which is better for AI agents, Ecwid by Lightspeed or Shopware?

Shopware scores 71.4 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in every scored category.

Do Ecwid by Lightspeed and Shopware need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Ecwid by Lightspeed and Shopware without installing anything?

Ecwid by Lightspeed has a hosted endpoint at https://app.ecwid.com/api/v3. No hosted endpoint is listed for Shopware.

Are Ecwid by Lightspeed and Shopware open source?

No open-source release is listed for Ecwid by Lightspeed. Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms).

Other comparisons with Ecwid by Lightspeed or Shopware

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.