{
  "data": {
    "a": {
      "slug": "ecwid",
      "name": "Ecwid by Lightspeed",
      "vendor": "Ecwid, Inc. (Lightspeed Commerce)",
      "vendorUrl": "https://www.ecwid.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Ecwid by Lightspeed is a hosted online store that embeds in any website. Its REST API reads and writes products, categories, orders, customers and discounts for one store, with webhooks and a browser JavaScript API for the cart.",
      "url": "https://www.anchorterminal.com/tools/ecwid",
      "markdownUrl": "https://www.anchorterminal.com/tools/ecwid.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ecwid.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ecwid.json",
      "repo": "https://github.com/Ecwid/ecwid-java-api-client",
      "license": "Proprietary service under the Lightspeed Service Agreement. The `@lightspeed/ecom-headless` npm package is MIT and the Java API client on GitHub is Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://app.ecwid.com/api/v3",
      "packages": [
        {
          "registry": "npm",
          "name": "@lightspeed/ecom-headless"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve for one store. The store admin creates a custom app automatically, with a secret token and a public token sent as `Authorization: Bearer`, and no OAuth flow. Seven of the 40 access scopes are on by default, more are added in the admin, and scopes marked sensitive need a request to API support. Public apps for many stores use OAuth 2.0 and go through app review. Tokens don't expire and are revoked by uninstalling the app.",
      "pricing": "paid",
      "pricingNotes": "Starter $5 a month, Venture $35 ($29 billed yearly), Business $65 ($49) and Unlimited $149 ($119), with no transaction fee from Ecwid. The docs say only paid plans reach the API, and the pricing page does not list API access by plan. No free plan, trial or sandbox was found. Developers can email API support for a free upgrade of a test store (https://www.ecwid.com/pricing, checked 2026-10-08).",
      "priceSummary": "$5 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs or on the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 22,
        "npmWeekly": 307,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.ecwid.com",
      "llmsTxt": "https://docs.ecwid.com/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "api-key",
        "oauth",
        "llms-txt",
        "webhooks",
        "typescript",
        "java",
        "status-page",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.2,
        "grade": "B",
        "agentReady": false,
        "rank": 316,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 79,
          "payments": 15,
          "reliability": 80,
          "schema": 66,
          "security": 61,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The REST API has 40 access scopes, a published limit of 600 requests a minute per token with `Retry-After` on a 429, field selection through `responseFields`, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.",
        "bestFor": "An agent doing back-office work on an existing Ecwid store, such as catalogue edits, order export and discount coupons.",
        "strengths": [
          "40 access scopes split into read, update and create, plus a public token limited to enabled catalogue data and unpaid orders",
          "Published limit of 600 requests a minute per token, and a 429 carries a `Retry-After` header",
          "`responseFields` trims any response to named fields, and searches page with `offset` and `limit` up to 100",
          "Every docs page is served as Markdown, with `llms.txt` and `llms-full.txt` indexes",
          "One incident on status.ecwid.com between 10 July and 8 October 2026, a 48-minute storefront slowdown on 7 August"
        ],
        "weaknesses": [
          "Access tokens never expire and change only when the app is uninstalled and installed again",
          "No test mode. The docs advise a separate test store, and only stores on paid plans can call the API",
          "No idempotency keys on REST writes found in the reviewed documentation",
          "OpenAPI 3.0.3 definitions are published for store profile and orders only, with no complete downloadable spec found",
          "The REST API has no endpoint that builds a live cart or runs checkout. Those sit in the browser JavaScript API",
          "The service agreement disclaims any service level commitment"
        ],
        "agentNotes": [
          "Send the token as `Authorization: Bearer` to `https://app.ecwid.com/api/v3/{storeId}`. Tokens in the query string stopped working in March 2025",
          "Use the secret token server-side only. The public token reads enabled products and places orders that are not marked paid",
          "Add `responseFields`, for example `total,items(id,name,price)`, to keep responses small, and page with `offset` and `limit` (maximum 100)",
          "Stay under 600 requests a minute per token and wait the `Retry-After` seconds on a 429. Repeated calls with a bad token get the token and IP blocked for longer",
          "Work in a separate test store. There is no test mode, and `POST /orders` writes a real order with no idempotency key",
          "After changing an app's scopes, uninstall and reinstall it, then replace the stored tokens. The old ones stop working"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.2
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 79,
          "payments": 15,
          "reliability": 80,
          "schema": 66,
          "security": 61,
          "transparency": 56
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "npm install @lightspeed/ecom-headless",
        "http": "curl \"https://app.ecwid.com/api/v3/$ECWID_STORE_ID/profile?responseFields=generalInfo(storeId,storeUrl)\" \\\n  -H \"Authorization: Bearer $ECWID_SECRET_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/ecwid"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Starter",
          "unit": "month",
          "usd": 5,
          "note": "up to 10 products. The docs say only paid plans reach the API and the pricing page does not list API access by plan"
        },
        {
          "item": "Venture",
          "unit": "month",
          "usd": 35,
          "note": "$29 a month billed yearly, up to 100 products"
        },
        {
          "item": "Business",
          "unit": "month",
          "usd": 65,
          "note": "$49 a month billed yearly, up to 2,500 products"
        },
        {
          "item": "Unlimited",
          "unit": "month",
          "usd": 149,
          "note": "$119 a month billed yearly, unlimited products"
        }
      ],
      "provenance": {
        "legalEntity": "Ecwid, Inc.",
        "domain": "ecwid.com",
        "domainRegistered": "2009-01-08",
        "endpointOnVendorDomain": true,
        "terms": "https://www.lightspeedhq.com/legal/lightspeed-service-agreement/",
        "privacy": "https://www.lightspeedhq.com/legal/privacy-policy/",
        "statusPage": "https://status.ecwid.com",
        "changelog": "https://docs.ecwid.com/changelog/ecwid-api-changelog",
        "securityTxt": "unknown",
        "checked": "2026-10-08",
        "notes": [
          "www.ecwid.com/terms-of-service redirects to the Lightspeed Service Agreement (last updated 26 February 2026), whose contracting-entity table names Ecwid, Inc., Delaware, for Lightspeed eCom (E-Series) worldwide.",
          "The service agreement says API use is governed by Lightspeed's API licence agreement at https://developers.lightspeedhq.com/terms (effective 20 May 2025), which does not name Ecwid or E-Series.",
          "www.ecwid.com/privacy-policy and /eu-privacy-policy redirect to Lightspeed's privacy policy (effective 8 July 2026), which lists Ecwid, Inc. among the entities certified under the Data Privacy Framework.",
          "www.ecwid.com/.well-known/security.txt answered 403 and www.lightspeedhq.com/.well-known/security.txt answered 404, so no security.txt was read.",
          "RDAP for ecwid.com gives a registration date of 2009-01-08.",
          "The REST API answers at app.ecwid.com. Docs are hosted on GitBook at docs.ecwid.com."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ecwid.json",
      "live": {
        "slug": "ecwid",
        "probe": {
          "target": "https://app.ecwid.com/api/v3",
          "method": "get",
          "lastAt": "2026-10-08T21:12:09.334118611Z",
          "lastOk": true,
          "lastStatus": 400,
          "lastMs": 124,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 102,
          "p95ms24h": 127,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.ecwid.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:06:01.196078974Z"
        },
        "updatedAt": "2026-10-08T21:12:09.334118611Z"
      }
    },
    "answer": "Shopware scores 71.4 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in every scored category.",
    "b": {
      "slug": "shopware",
      "name": "Shopware",
      "vendor": "shopware AG",
      "vendorUrl": "https://www.shopware.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source commerce platform from shopware AG in Germany, written in PHP on Symfony. Agents reach a store through its Store API for shopping, its Admin API for back-office work, and a built-in MCP server on both.",
      "url": "https://www.anchorterminal.com/tools/shopware",
      "markdownUrl": "https://www.anchorterminal.com/tools/shopware.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shopware.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shopware.json",
      "repo": "https://github.com/shopware/shopware",
      "license": "MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "packagist",
          "name": "shopware/core"
        },
        {
          "registry": "npm",
          "name": "@shopware/api-client"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access comes from the merchant who runs the store, with no vendor review. The Admin API takes an OAuth 2.0 bearer token from /api/oauth/token, normally by client credentials from an integration created in Settings or with `bin/console integration:create`, and tokens last 10 minutes by default. An integration gets an ACL role, or full access with --admin. The MCP endpoint at /api/_mcp also accepts the integration's `sw-access-key` and `sw-secret-access-key` headers, and each integration and user has an MCP allowlist. The Store API takes the sales channel's `sw-access-key`, which is public in a headless shop, plus an `sw-context-token` for the cart and customer session.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is free under MIT with no account, so an agent's owner can start with `shopware-cli project create` and Docker, with no contract (the docs say no Shopware account is needed to install or run a store). Paid plans start at €600 a month for Rise and €2,400 for Evolve, excluding VAT, with Beyond on request, and the pricing page says the price depends on GMV. Shopware SaaS is priced the same as self-hosted. No trial of the paid plans was found on the pricing page (https://www.shopware.com/en/pricing/, checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the repository or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 14,
      "popularity": {
        "githubStars": 3400,
        "npmWeekly": 30917,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.shopware.com/docs/",
      "llmsTxt": "https://developer.shopware.com/llms.txt",
      "openapi": "https://github.com/shopware/shopware/tree/trunk/src/Core/Framework/Api/ApiDefinition/Generator/Schema",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "mcp",
        "openapi",
        "llms-txt",
        "oauth",
        "php",
        "typescript",
        "webhooks",
        "freemium",
        "eu",
        "bug-bounty",
        "iso27001",
        "beta"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 112,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 87,
          "payments": 50,
          "reliability": 83,
          "schema": 85,
          "security": 73,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -5,
        "negativeNotes": [
          "GitHub lists 20 security advisories for shopware/shopware published between 19 May and 16 September 2026, four of them critical (an app script sandbox escape, stored SQL injection through app manifests, admin account takeover by host-header poisoning and a webhook permission bypass), plus a pre-authentication SQL injection in the Store API (GHSA-p37c-pm9p-7vm5, CVSS 8.6, published 25 August 2026, fixed in 6.7.13.1 and 6.6.10.23). All were disclosed in public with fixed versions, so the deduction is 5 of a possible 15 (https://github.com/shopware/shopware/security/advisories)."
        ],
        "verdict": "MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.",
        "bestFor": "A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.",
        "strengths": [
          "MIT core, free to self-host, with security fixes for the 6.7 line promised until 28 February 2028 in releases.json",
          "Built-in MCP server advertises three discovery tools, and other tools load by toolset for the session",
          "MCP write tools default to dryRun=true, which runs the change in a transaction and rolls it back",
          "Per-integration ACL roles and MCP allowlists, with a 300 a minute limit on /api/_mcp",
          "OpenAPI 3 schemas for the Store API and Admin API in the repository, plus llms.txt and Markdown docs"
        ],
        "weaknesses": [
          "The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint",
          "20 advisories published between 19 May and 16 September 2026, four critical, including a pre-authentication SQL injection in the Store API",
          "MCP tools carry no readOnlyHint or destructiveHint annotations, and criteria and payloads travel as JSON-encoded strings",
          "A 429 from the MCP endpoints carries the wait time in the body, with no Retry-After header",
          "The Store API MCP endpoint ships one domain tool, has no allowlist, and the security.txt file expired on 31 December 2025"
        ],
        "agentNotes": [
          "Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp",
          "Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools",
          "Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once",
          "For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core",
          "Send `includes` in search criteria to cut response size, and read the 429 body for the wait time"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.4
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 87,
          "payments": 50,
          "reliability": 83,
          "schema": 85,
          "security": 73,
          "transparency": 80
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "npx @shopware-ag/shopware-cli project create my-shop",
        "http": "curl -X POST \"http://localhost:8000/api/search/product\" \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{}'",
        "claudeCode": "claude mcp add --transport http shopware http://localhost:8000/api/_mcp --header \"sw-access-key: SWIA...\" --header \"sw-secret-access-key: ...\"",
        "config": {
          "mcpServers": {
            "shopware": {
              "headers": {
                "sw-access-key": "SWIA...",
                "sw-secret-access-key": "..."
              },
              "type": "streamable-http",
              "url": "https://your-shop.example.com/api/_mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/shopware"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Community Edition",
          "unit": "month",
          "usd": 0,
          "note": "MIT core, you pay for your own hosting"
        }
      ],
      "provenance": {
        "legalEntity": "shopware AG",
        "domain": "shopware.com",
        "domainRegistered": "1998-08-08",
        "endpointOnVendorDomain": false,
        "terms": "https://www.shopware.com/en/gtc/",
        "privacy": "https://www.shopware.com/en/privacy/",
        "statusPage": "https://status.shopware.com",
        "changelog": "https://github.com/shopware/shopware/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The legal notice names shopware AG, Ebbinghoff 10, 48624 Schoeppingen, Germany, Amtsgericht Coesfeld HRB 11471.",
          "The general terms cover every product. Part 2 covers the free Community Edition and Part 4 covers SaaS, and only the German version is binding.",
          "The Store API, Admin API and MCP endpoints run on each merchant's own domain or SaaS shop, not on shopware.com.",
          "security.txt at www.shopware.com gives Expires 31 December 2025.",
          "www.shopware.com answered several requests with a 503 first byte timeout on 8 October 2026. The terms loaded on a retry and the privacy page loaded once.",
          "status.shopware.com covers Shopware SaaS, PaaS and vendor services, not self-hosted stores.",
          "Verisign RDAP gives a registration date of 1998-08-08 for shopware.com."
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shopware.json",
      "live": {
        "slug": "shopware",
        "vendorStatus": {
          "page": "https://status.shopware.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:10.49832559Z"
        },
        "pages": [
          {
            "url": "https://www.shopware.com/en/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:28.817122652Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a8eeb1d7324d"
          },
          {
            "url": "https://www.shopware.com/en/privacy/",
            "kind": "privacy",
            "status": 503,
            "checkedAt": "2026-10-08T18:30:30.769152247Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.shopware.com/en/gtc/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:26.06911646Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "034d628e8015"
          }
        ],
        "updatedAt": "2026-10-08T19:39:10.49832559Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Ecwid, Inc. (Lightspeed Commerce)",
        "b": "shopware AG",
        "name": "Vendor"
      },
      {
        "a": "https://app.ecwid.com/api/v3",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Lightspeed Service Agreement. The `@lightspeed/ecom-headless` npm package is MIT and the Java API client on GitHub is Apache-2.0",
        "b": "MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "14",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-10-02",
        "name": "Last release"
      },
      {
        "a": "2026-02-26",
        "b": "2026-06-10",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "22 stars, 307 npm/wk",
        "b": "3.4k stars, 31k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Shopware scores 71.4 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in every scored category.",
        "question": "Which is better for AI agents, Ecwid by Lightspeed or Shopware?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Ecwid by Lightspeed and Shopware need an API key?"
      },
      {
        "answer": "Ecwid by Lightspeed has a hosted endpoint at https://app.ecwid.com/api/v3. No hosted endpoint is listed for Shopware.",
        "question": "Can an agent call Ecwid by Lightspeed and Shopware without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Ecwid by Lightspeed. Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms).",
        "question": "Are Ecwid by Lightspeed and Shopware open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": [
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Shopware loses 5 points for them"
        ],
        "goodFor": "An agent doing back-office work on an existing Ecwid store, such as catalogue edits, order export and discount coupons.",
        "slug": "ecwid",
        "watchFor": "Access tokens never expire and change only when the app is uninstalled and installed again"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 85 against 66",
          "Agent ergonomics, 78 against 66",
          "Security \u0026 auth, 73 against 61",
          "Payments \u0026 pricing, 50 against 15",
          "Maintenance \u0026 community, 87 against 79"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "Open source"
        ],
        "goodFor": "A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.",
        "slug": "shopware",
        "watchFor": "The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint"
      }
    ],
    "job": {
      "capability": "commerce.products",
      "name": "Commerce products"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/adobe-commerce-vs-ecwid.json",
        "title": "Adobe Commerce (Magento) vs Ecwid by Lightspeed",
        "url": "https://www.anchorterminal.com/compare/adobe-commerce-vs-ecwid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/adobe-commerce-vs-shopware.json",
        "title": "Adobe Commerce (Magento) vs Shopware",
        "url": "https://www.anchorterminal.com/compare/adobe-commerce-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-ecwid.json",
        "title": "BigCommerce API + MCP vs Ecwid by Lightspeed",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-ecwid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-shopware.json",
        "title": "BigCommerce API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-ecwid.json",
        "title": "Commerce Layer API + MCP vs Ecwid by Lightspeed",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-ecwid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-shopware.json",
        "title": "Commerce Layer API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-ecwid.json",
        "title": "commercetools vs Ecwid by Lightspeed",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-ecwid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-shopware.json",
        "title": "commercetools vs Shopware",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-elastic-path.json",
        "title": "Ecwid by Lightspeed vs Elastic Path API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-elastic-path"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-medusa.json",
        "title": "Ecwid by Lightspeed vs Medusa API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-medusa"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-saleor.json",
        "title": "Ecwid by Lightspeed vs Saleor API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-saleor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-shopify.json",
        "title": "Ecwid by Lightspeed vs Shopify API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-shopify"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-snipcart.json",
        "title": "Ecwid by Lightspeed vs Snipcart API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-snipcart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-square.json",
        "title": "Ecwid by Lightspeed vs Square",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-swell.json",
        "title": "Ecwid by Lightspeed vs Swell",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-swell"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-vendure.json",
        "title": "Ecwid by Lightspeed vs Vendure",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-wix.json",
        "title": "Ecwid by Lightspeed vs Wix Stores and eCommerce API",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-wix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-woocommerce.json",
        "title": "Ecwid by Lightspeed vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-woocommerce"
      },
      {
        "json": "https://www.anchorterminal.com/compare/elastic-path-vs-shopware.json",
        "title": "Elastic Path API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/elastic-path-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/medusa-vs-shopware.json",
        "title": "Medusa API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/medusa-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-shopware.json",
        "title": "Saleor API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopify-vs-shopware.json",
        "title": "Shopify API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/shopify-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-snipcart.json",
        "title": "Shopware vs Snipcart API + MCP",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-snipcart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-square.json",
        "title": "Shopware vs Square",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-swell.json",
        "title": "Shopware vs Swell",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-swell"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-vendure.json",
        "title": "Shopware vs Vendure",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-wix.json",
        "title": "Shopware vs Wix Stores and eCommerce API",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-wix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-woocommerce.json",
        "title": "Shopware vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-woocommerce"
      }
    ],
    "scores": [
      {
        "by": 3,
        "ecwid": 80,
        "edge": "shopware",
        "key": "reliability",
        "name": "Reliability",
        "shopware": 83,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 19,
        "ecwid": 66,
        "edge": "shopware",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "shopware": 85,
        "weight": 13
      },
      {
        "by": 12,
        "ecwid": 66,
        "edge": "shopware",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "shopware": 78,
        "weight": 13
      },
      {
        "by": 12,
        "ecwid": 61,
        "edge": "shopware",
        "key": "security",
        "name": "Security \u0026 auth",
        "shopware": 73,
        "weight": 14
      },
      {
        "by": 35,
        "ecwid": 15,
        "edge": "shopware",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "shopware": 50,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 8,
        "ecwid": 79,
        "edge": "shopware",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "shopware": 87,
        "weight": 7
      },
      {
        "by": 4,
        "ecwid": 72,
        "edge": "shopware",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "shopware": 76,
        "weight": 7
      }
    ],
    "summary": "Shopware scores 71.4 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in every scored category. Both do commerce products.",
    "verdicts": {
      "ecwid": "The REST API has 40 access scopes, a published limit of 600 requests a minute per token with `Retry-After` on a 429, field selection through `responseFields`, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.",
      "shopware": "MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/ecwid-vs-shopware",
    "json": "https://www.anchorterminal.com/compare/ecwid-vs-shopware.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/ecwid-vs-shopware.md",
    "slim": "https://www.anchorterminal.com/compare/ecwid-vs-shopware.min.md"
  },
  "markdown": "Shopware scores 71.4 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in every scored category. Both do commerce products.\n\n- Ecwid by Lightspeed: grade B, 63.2/100, rank #316 of 722. Markdown https://www.anchorterminal.com/tools/ecwid.md · JSON https://www.anchorterminal.com/api/v1/tools/ecwid.json\n- Shopware: grade BB, 71.4/100, rank #112 of 722. Markdown https://www.anchorterminal.com/tools/shopware.md · JSON https://www.anchorterminal.com/api/v1/tools/shopware.json\n\n## Which one, for what\n\n### Ecwid by Lightspeed (B)\n\nGood for: An agent doing back-office work on an existing Ecwid store, such as catalogue edits, order export and discount coupons.\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Shopware loses 5 points for them\n\nWatch for: Access tokens never expire and change only when the app is uninstalled and installed again\n\n### Shopware (BB)\n\nGood for: A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.\n\nAhead on:\n- Schema \u0026 documentation, 85 against 66\n- Agent ergonomics, 78 against 66\n- Security \u0026 auth, 73 against 61\n- Payments \u0026 pricing, 50 against 15\n- Maintenance \u0026 community, 87 against 79\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- Open source\n\nWatch for: The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint\n\n\n## Score by category\n\n| Category | Weight | Ecwid by Lightspeed | Shopware | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 80 | 83 | Shopware +3 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 66 | 85 | Shopware +19 |\n| Agent ergonomics | 13% (16.2 this run) | 66 | 78 | Shopware +12 |\n| Security \u0026 auth | 14% (17.5 this run) | 61 | 73 | Shopware +12 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 15 | 50 | Shopware +35 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 79 | 87 | Shopware +8 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 76 | Shopware +4 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **63.2 · B** | **71.4 · BB** | |\n\n## Facts side by side\n\n| Fact | Ecwid by Lightspeed | Shopware |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Ecwid, Inc. (Lightspeed Commerce) | shopware AG |\n| Hosted endpoint | `https://app.ecwid.com/api/v3` | no (local only) |\n| Transports | HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under the Lightspeed Service Agreement. The `@lightspeed/ecom-headless` npm package is MIT and the Java API client on GitHub is Apache-2.0 | MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms |\n| Tools exposed | none | 14 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-30 | 2026-10-02 |\n| Terms last updated | 2026-02-26 | 2026-06-10 |\n| Privacy policy last updated | no date given | couldn't be read |\n| Customer content may train models | not found in the text | yes |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 22 stars, 307 npm/wk | 3.4k stars, 31k npm/wk |\n\n## Verdicts\n\n**Ecwid by Lightspeed.** The REST API has 40 access scopes, a published limit of 600 requests a minute per token with `Retry-After` on a 429, field selection through `responseFields`, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.\n\n**Shopware.** MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.\n\n## Before you call either\n\n### Ecwid by Lightspeed\n\n1. Send the token as `Authorization: Bearer` to `https://app.ecwid.com/api/v3/{storeId}`. Tokens in the query string stopped working in March 2025\n2. Use the secret token server-side only. The public token reads enabled products and places orders that are not marked paid\n3. Add `responseFields`, for example `total,items(id,name,price)`, to keep responses small, and page with `offset` and `limit` (maximum 100)\n4. Stay under 600 requests a minute per token and wait the `Retry-After` seconds on a 429. Repeated calls with a bad token get the token and IP blocked for longer\n5. Work in a separate test store. There is no test mode, and `POST /orders` writes a real order with no idempotency key\n6. After changing an app's scopes, uninstall and reinstall it, then replace the stored tokens. The old ones stop working\n\n### Shopware\n\n1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp\n2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools\n3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once\n4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core\n5. Send `includes` in search criteria to cut response size, and read the 429 body for the wait time\n\n## Questions\n\n### Which is better for AI agents, Ecwid by Lightspeed or Shopware?\n\nShopware scores 71.4 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in every scored category.\n\n### Do Ecwid by Lightspeed and Shopware need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Ecwid by Lightspeed and Shopware without installing anything?\n\nEcwid by Lightspeed has a hosted endpoint at https://app.ecwid.com/api/v3. No hosted endpoint is listed for Shopware.\n\n### Are Ecwid by Lightspeed and Shopware open source?\n\nNo open-source release is listed for Ecwid by Lightspeed. Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/ecwid-vs-shopware.json, and with the fewest tokens: https://www.anchorterminal.com/compare/ecwid-vs-shopware.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"ecwid\", \"b\": \"shopware\"}`. From a terminal: `anchor compare ecwid shopware`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/ecwid.json and https://www.anchorterminal.com/api/v1/tools/shopware.json\n\n## Other comparisons with Ecwid by Lightspeed or Shopware\n\n- [Adobe Commerce (Magento) vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/adobe-commerce-vs-ecwid.md)\n- [Adobe Commerce (Magento) vs Shopware](https://www.anchorterminal.com/compare/adobe-commerce-vs-shopware.md)\n- [BigCommerce API + MCP vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/bigcommerce-vs-ecwid.md)\n- [BigCommerce API + MCP vs Shopware](https://www.anchorterminal.com/compare/bigcommerce-vs-shopware.md)\n- [Commerce Layer API + MCP vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/commerce-layer-vs-ecwid.md)\n- [Commerce Layer API + MCP vs Shopware](https://www.anchorterminal.com/compare/commerce-layer-vs-shopware.md)\n- [commercetools vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/commercetools-vs-ecwid.md)\n- [commercetools vs Shopware](https://www.anchorterminal.com/compare/commercetools-vs-shopware.md)\n- [Ecwid by Lightspeed vs Elastic Path API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-elastic-path.md)\n- [Ecwid by Lightspeed vs Medusa API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-medusa.md)\n- [Ecwid by Lightspeed vs Saleor API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-saleor.md)\n- [Ecwid by Lightspeed vs Shopify API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-shopify.md)\n- [Ecwid by Lightspeed vs Snipcart API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-snipcart.md)\n- [Ecwid by Lightspeed vs Square](https://www.anchorterminal.com/compare/ecwid-vs-square.md)\n- [Ecwid by Lightspeed vs Swell](https://www.anchorterminal.com/compare/ecwid-vs-swell.md)\n- [Ecwid by Lightspeed vs Vendure](https://www.anchorterminal.com/compare/ecwid-vs-vendure.md)\n- [Ecwid by Lightspeed vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/ecwid-vs-wix.md)\n- [Ecwid by Lightspeed vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-woocommerce.md)\n- [Elastic Path API + MCP vs Shopware](https://www.anchorterminal.com/compare/elastic-path-vs-shopware.md)\n- [Medusa API + MCP vs Shopware](https://www.anchorterminal.com/compare/medusa-vs-shopware.md)\n- [Saleor API + MCP vs Shopware](https://www.anchorterminal.com/compare/saleor-vs-shopware.md)\n- [Shopify API + MCP vs Shopware](https://www.anchorterminal.com/compare/shopify-vs-shopware.md)\n- [Shopware vs Snipcart API + MCP](https://www.anchorterminal.com/compare/shopware-vs-snipcart.md)\n- [Shopware vs Square](https://www.anchorterminal.com/compare/shopware-vs-square.md)\n- [Shopware vs Swell](https://www.anchorterminal.com/compare/shopware-vs-swell.md)\n- [Shopware vs Vendure](https://www.anchorterminal.com/compare/shopware-vs-vendure.md)\n- [Shopware vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/shopware-vs-wix.md)\n- [Shopware vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/shopware-vs-woocommerce.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Ecwid by Lightspeed vs Shopware",
        "url": ""
      }
    ],
    "description": "Shopware scores 71.4 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in every scored category. Both do commerce products. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Ecwid by Lightspeed B 63.2",
      "Shopware BB 71.4",
      "scores"
    ],
    "h1": "Ecwid by Lightspeed vs Shopware",
    "image": "https://www.anchorterminal.com/assets/og/compare-ecwid-vs-shopware.png",
    "path": "/compare/ecwid-vs-shopware",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Ecwid by Lightspeed vs Shopware for AI agents, B 63.2 vs BB 71.4",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/ecwid-vs-shopware"
  },
  "tokens": {
    "markdown": 2700,
    "slim": 730
  },
  "version": 1
}
