Head to head · Commerce products · October 2026 research run

Ecwid by Lightspeed vs Square

Square scores 69.2 (B) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 5 of 7 scored categories. Ecwid by Lightspeed leads on reliability. Both do commerce products.

Which one, for what

Ecwid by Lightspeed B

Good for An agent doing back-office work on an existing Ecwid store, such as catalogue edits, order export and discount coupons.

Ahead on

  • Reliability, 80 against 58

Watch for

Access tokens never expire and change only when the app is uninstalled and installed again

Square B

Good for Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.

Ahead on

  • Schema & documentation, 87 against 66
  • Agent ergonomics, 83 against 66
  • Security & auth, 67 against 61
  • Payments & pricing, 40 against 15

Also in its favour

  • Runs on your own machine

Watch for

The MCP server is marked beta, and the remote server reaches production data only

Score by category

CategoryWeight this runEcwid by LightspeedSquareEdge
Reliability16%208058Ecwid by Lightspeed +22
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.26687Square +21
Agent ergonomics13%16.26683Square +17
Security & auth14%17.56167Square +6
Payments & pricing10%12.51540Square +25
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87981Square +2
Transparency & trust7%8.87270Ecwid by Lightspeed +2
Negative events≤1500
Total63.2 · B69.2 · B

Facts side by side

FactEcwid by LightspeedSquare
KindHTTP APIHTTP API
VendorEcwid, Inc. (Lightspeed Commerce)Block, Inc.
Hosted endpointhttps://app.ecwid.com/api/v3https://mcp.squareup.com/mcp
TransportsHTTPHTTP, Streamable HTTP, stdio
AuthOAuth or keyOAuth or key
PricingPaidPay per use
x402nono
LicenceProprietary service under the Lightspeed Service Agreement. The @lightspeed/ecom-headless npm package is MIT and the Java API client on GitHub is Apache-2.0Proprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT
Tools exposednone3
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-302026-09-16
Terms last updated2026-02-262026-09-10
Privacy policy last updatedno date given2026-09-15
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waiveryesyes
Popularity22 stars, 307 npm/wk454k npm/wk, 72k PyPI/wk

Verdicts

Ecwid by Lightspeed

The REST API has 40 access scopes, a published limit of 600 requests a minute per token with Retry-After on a 429, field selection through responseFields, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.

Square

The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.

Before you call either

Ecwid by Lightspeed

  1. Send the token as Authorization: Bearer to https://app.ecwid.com/api/v3/{storeId}. Tokens in the query string stopped working in March 2025
  2. Use the secret token server-side only. The public token reads enabled products and places orders that are not marked paid
  3. Add responseFields, for example total,items(id,name,price), to keep responses small, and page with offset and limit (maximum 100)
  4. Stay under 600 requests a minute per token and wait the Retry-After seconds on a 429. Repeated calls with a bad token get the token and IP blocked for longer
  5. Work in a separate test store. There is no test mode, and POST /orders writes a real order with no idempotency key
  6. After changing an app's scopes, uninstall and reinstall it, then replace the stored tokens. The old ones stop working

Square

  1. Test against the sandbox first with the local MCP server and SANDBOX=true. The remote server at mcp.squareup.com reaches production only
  2. Set DISALLOW_WRITES=true on the local MCP server when the task only reads
  3. Call get_service_info, then get_type_info, before each make_api_request. The request body is otherwise untyped
  4. Send a fresh idempotency_key on every write, and reuse it when retrying the same write
  5. Pin Square-Version in each request. Use a page cursor within 5 minutes of receiving it

Questions

Which is better for AI agents, Ecwid by Lightspeed or Square?

Square scores 69.2 (B) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 5 of 7 scored categories. Ecwid by Lightspeed leads on reliability.

Do Ecwid by Lightspeed and Square need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Ecwid by Lightspeed and Square without installing anything?

Yes. Ecwid by Lightspeed has a hosted endpoint at https://app.ecwid.com/api/v3 and Square at https://mcp.squareup.com/mcp.

Other comparisons with Ecwid by Lightspeed or Square

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.