Head to head · Commerce catalogues · October 2026 research run

Ecwid by Lightspeed vs Spree Commerce

Spree Commerce scores 70.4 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 6 of 7 scored categories. Ecwid by Lightspeed leads on transparency & trust. Both do commerce catalogues.

Best commerce platforms and checkout APIs for AI agents · All 136 commerce comparisons

Which one, for what

Ecwid by Lightspeed B

Good for An agent doing back-office work on an existing Ecwid store, such as catalogue edits, order export and discount coupons.

Ahead on

  • Transparency & trust, 72 against 60

Also in its favour

  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Spree Commerce loses 5 points for them

Watch for

Access tokens never expire and change only when the app is uninstalled and installed again

Spree Commerce BB

Good for Teams that want to own a Rails commerce backend with marketplace, B2B and multi-region functions and drive it through REST.

Ahead on

  • Schema & documentation, 85 against 66
  • Agent ergonomics, 90 against 66
  • Payments & pricing, 55 against 15

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source

Watch for

Six GitHub security advisories between 8 January and 20 July 2026, four rated High, most of them access-control flaws on guest carts, orders and addresses

Score by category

CategoryWeight this runEcwid by LightspeedSpree CommerceEdge
Reliability16%208082Spree Commerce +2
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26685Spree Commerce +19
Agent ergonomics13%16.26690Spree Commerce +24
Security & auth14%17.56165Spree Commerce +4
Payments & pricing10%12.51555Spree Commerce +40
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87981Spree Commerce +2
Transparency & trust7%8.87260Ecwid by Lightspeed +12
Negative events≤150-5
Total63.2 · B70.4 · BB

Facts side by side

FactEcwid by LightspeedSpree Commerce
KindHTTP APIHTTP API
VendorEcwid, Inc. (Lightspeed Commerce)Vendo Connect Inc
Hosted endpointhttps://app.ecwid.com/api/v3no (local only)
TransportsHTTPHTTP
AuthOAuth or keyOAuth or key
PricingPaidFreemium
x402nono
LicenceProprietary service under the Lightspeed Service Agreement. The @lightspeed/ecom-headless npm package is MIT and the Java API client on GitHub is Apache-2.0BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-09-302026-07-28
Terms last updated2026-02-26no document linked
Privacy policy last updatedno date givenno document linked
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticeyes
Arbitration or class-action waiveryes
Popularity22 stars, 307 npm/wk16k stars, 1.6k npm/wk

Verdicts

Ecwid by Lightspeed

The REST API has 40 access scopes, a published limit of 600 requests a minute per token with Retry-After on a 429, field selection through responseFields, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.

Spree Commerce

A self-hosted BSD 3-Clause platform with public OpenAPI files for the Store and Admin APIs, scoped secret keys, documented rate limits and idempotency keys on cart and checkout calls. GitHub lists six security advisories between January and July 2026, four rated High, and the default docs describe the 6.0 release candidate while 5.6.1 is the stable release.

Before you call either

Ecwid by Lightspeed

  1. Send the token as Authorization: Bearer to https://app.ecwid.com/api/v3/{storeId}. Tokens in the query string stopped working in March 2025
  2. Use the secret token server-side only. The public token reads enabled products and places orders that are not marked paid
  3. Add responseFields, for example total,items(id,name,price), to keep responses small, and page with offset and limit (maximum 100)
  4. Stay under 600 requests a minute per token and wait the Retry-After seconds on a 429. Repeated calls with a bad token get the token and IP blocked for longer
  5. Work in a separate test store. There is no test mode, and POST /orders writes a real order with no idempotency key
  6. After changing an app's scopes, uninstall and reinstall it, then replace the stored tokens. The old ones stop working

Spree Commerce

  1. Send a publishable key in X-Spree-Api-Key on every Store API call. Add X-Spree-Token with the cart token for guest carts, or a customer JWT as a Bearer token
  2. Send Idempotency-Key with the cart token or a customer JWT on cart, payment and completion calls. A request carrying only the publishable key is never cached
  3. Ask for fields and expand explicitly. Relations are left out by default and limit stops at 100
  4. Use a secret key with the narrowest scopes for the Admin API. read_all gives a read-only key, and the CLI's auto-minted local key is read-only
  5. Read the docs under /docs/v5 for a 5.6 store. The default docs describe 6.0, which renames shipments to fulfilments and splits carts from orders

Questions

Which is better for AI agents, Ecwid by Lightspeed or Spree Commerce?

Spree Commerce scores 70.4 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 6 of 7 scored categories. Ecwid by Lightspeed leads on transparency & trust.

Do Ecwid by Lightspeed and Spree Commerce need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Ecwid by Lightspeed and Spree Commerce without installing anything?

Ecwid by Lightspeed has a hosted endpoint at https://app.ecwid.com/api/v3. No hosted endpoint is listed for Spree Commerce.

Are Ecwid by Lightspeed and Spree Commerce open source?

No open-source release is listed for Ecwid by Lightspeed. Spree Commerce is open source (BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence).

Other comparisons with Ecwid by Lightspeed or Spree Commerce

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.