{
  "data": {
    "a": {
      "slug": "ecwid",
      "name": "Ecwid by Lightspeed",
      "vendor": "Ecwid, Inc. (Lightspeed Commerce)",
      "vendorUrl": "https://www.ecwid.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Ecwid by Lightspeed is a hosted online store that embeds in any website. Its REST API reads and writes products, categories, orders, customers and discounts for one store, with webhooks and a browser JavaScript API for the cart.",
      "url": "https://www.anchorterminal.com/tools/ecwid",
      "markdownUrl": "https://www.anchorterminal.com/tools/ecwid.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ecwid.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ecwid.json",
      "repo": "https://github.com/Ecwid/ecwid-java-api-client",
      "license": "Proprietary service under the Lightspeed Service Agreement. The `@lightspeed/ecom-headless` npm package is MIT and the Java API client on GitHub is Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://app.ecwid.com/api/v3",
      "packages": [
        {
          "registry": "npm",
          "name": "@lightspeed/ecom-headless"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve for one store. The store admin creates a custom app automatically, with a secret token and a public token sent as `Authorization: Bearer`, and no OAuth flow. Seven of the 40 access scopes are on by default, more are added in the admin, and scopes marked sensitive need a request to API support. Public apps for many stores use OAuth 2.0 and go through app review. Tokens don't expire and are revoked by uninstalling the app.",
      "pricing": "paid",
      "pricingNotes": "Starter $5 a month, Venture $35 ($29 billed yearly), Business $65 ($49) and Unlimited $149 ($119), with no transaction fee from Ecwid. The docs say only paid plans reach the API, and the pricing page does not list API access by plan. No free plan, trial or sandbox was found. Developers can email API support for a free upgrade of a test store (https://www.ecwid.com/pricing, checked 2026-10-08).",
      "priceSummary": "$5 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs or on the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 22,
        "npmWeekly": 307,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.ecwid.com",
      "llmsTxt": "https://docs.ecwid.com/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "api-key",
        "oauth",
        "llms-txt",
        "webhooks",
        "typescript",
        "java",
        "status-page",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.2,
        "grade": "B",
        "agentReady": false,
        "rank": 316,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 79,
          "payments": 15,
          "reliability": 80,
          "schema": 66,
          "security": 61,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The REST API has 40 access scopes, a published limit of 600 requests a minute per token with `Retry-After` on a 429, field selection through `responseFields`, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.",
        "bestFor": "An agent doing back-office work on an existing Ecwid store, such as catalogue edits, order export and discount coupons.",
        "strengths": [
          "40 access scopes split into read, update and create, plus a public token limited to enabled catalogue data and unpaid orders",
          "Published limit of 600 requests a minute per token, and a 429 carries a `Retry-After` header",
          "`responseFields` trims any response to named fields, and searches page with `offset` and `limit` up to 100",
          "Every docs page is served as Markdown, with `llms.txt` and `llms-full.txt` indexes",
          "One incident on status.ecwid.com between 10 July and 8 October 2026, a 48-minute storefront slowdown on 7 August"
        ],
        "weaknesses": [
          "Access tokens never expire and change only when the app is uninstalled and installed again",
          "No test mode. The docs advise a separate test store, and only stores on paid plans can call the API",
          "No idempotency keys on REST writes found in the reviewed documentation",
          "OpenAPI 3.0.3 definitions are published for store profile and orders only, with no complete downloadable spec found",
          "The REST API has no endpoint that builds a live cart or runs checkout. Those sit in the browser JavaScript API",
          "The service agreement disclaims any service level commitment"
        ],
        "agentNotes": [
          "Send the token as `Authorization: Bearer` to `https://app.ecwid.com/api/v3/{storeId}`. Tokens in the query string stopped working in March 2025",
          "Use the secret token server-side only. The public token reads enabled products and places orders that are not marked paid",
          "Add `responseFields`, for example `total,items(id,name,price)`, to keep responses small, and page with `offset` and `limit` (maximum 100)",
          "Stay under 600 requests a minute per token and wait the `Retry-After` seconds on a 429. Repeated calls with a bad token get the token and IP blocked for longer",
          "Work in a separate test store. There is no test mode, and `POST /orders` writes a real order with no idempotency key",
          "After changing an app's scopes, uninstall and reinstall it, then replace the stored tokens. The old ones stop working"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.2
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 79,
          "payments": 15,
          "reliability": 80,
          "schema": 66,
          "security": 61,
          "transparency": 56
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "npm install @lightspeed/ecom-headless",
        "http": "curl \"https://app.ecwid.com/api/v3/$ECWID_STORE_ID/profile?responseFields=generalInfo(storeId,storeUrl)\" \\\n  -H \"Authorization: Bearer $ECWID_SECRET_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/ecwid"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Starter",
          "unit": "month",
          "usd": 5,
          "note": "up to 10 products. The docs say only paid plans reach the API and the pricing page does not list API access by plan"
        },
        {
          "item": "Venture",
          "unit": "month",
          "usd": 35,
          "note": "$29 a month billed yearly, up to 100 products"
        },
        {
          "item": "Business",
          "unit": "month",
          "usd": 65,
          "note": "$49 a month billed yearly, up to 2,500 products"
        },
        {
          "item": "Unlimited",
          "unit": "month",
          "usd": 149,
          "note": "$119 a month billed yearly, unlimited products"
        }
      ],
      "provenance": {
        "legalEntity": "Ecwid, Inc.",
        "domain": "ecwid.com",
        "domainRegistered": "2009-01-08",
        "endpointOnVendorDomain": true,
        "terms": "https://www.lightspeedhq.com/legal/lightspeed-service-agreement/",
        "privacy": "https://www.lightspeedhq.com/legal/privacy-policy/",
        "statusPage": "https://status.ecwid.com",
        "changelog": "https://docs.ecwid.com/changelog/ecwid-api-changelog",
        "securityTxt": "unknown",
        "checked": "2026-10-08",
        "notes": [
          "www.ecwid.com/terms-of-service redirects to the Lightspeed Service Agreement (last updated 26 February 2026), whose contracting-entity table names Ecwid, Inc., Delaware, for Lightspeed eCom (E-Series) worldwide.",
          "The service agreement says API use is governed by Lightspeed's API licence agreement at https://developers.lightspeedhq.com/terms (effective 20 May 2025), which does not name Ecwid or E-Series.",
          "www.ecwid.com/privacy-policy and /eu-privacy-policy redirect to Lightspeed's privacy policy (effective 8 July 2026), which lists Ecwid, Inc. among the entities certified under the Data Privacy Framework.",
          "www.ecwid.com/.well-known/security.txt answered 403 and www.lightspeedhq.com/.well-known/security.txt answered 404, so no security.txt was read.",
          "RDAP for ecwid.com gives a registration date of 2009-01-08.",
          "The REST API answers at app.ecwid.com. Docs are hosted on GitBook at docs.ecwid.com."
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ecwid.json",
      "live": {
        "slug": "ecwid",
        "probe": {
          "target": "https://app.ecwid.com/api/v3",
          "method": "get",
          "lastAt": "2026-10-08T21:12:09.334118611Z",
          "lastOk": true,
          "lastStatus": 400,
          "lastMs": 124,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 102,
          "p95ms24h": 127,
          "samples24h": 21,
          "samples30d": 21,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 21,
              "ok": 21
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.ecwid.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:06:01.196078974Z"
        },
        "updatedAt": "2026-10-08T21:12:09.334118611Z"
      }
    },
    "answer": "Vendure scores 70.9 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 6 of 7 scored categories. Ecwid by Lightspeed leads on transparency \u0026 trust.",
    "b": {
      "slug": "vendure",
      "name": "Vendure",
      "vendor": "Vendure (Elevantiq GmbH)",
      "vendorUrl": "https://vendure.io",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source headless commerce framework on TypeScript, NestJS and GraphQL that you self-host.",
      "url": "https://www.anchorterminal.com/tools/vendure",
      "markdownUrl": "https://www.anchorterminal.com/tools/vendure.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vendure.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vendure.json",
      "repo": "https://github.com/vendurehq/vendure",
      "license": "GPL-3.0-or-later",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://readonlydemo.vendure.io/shop-api",
      "packages": [
        {
          "registry": "npm",
          "name": "@vendure/core"
        }
      ],
      "auth": "mixed",
      "authNotes": "Shop API is anonymous for browsing and cart, with a session token (bearer header or cookie) that carries the active order. Customer login and Admin API use the same session tokens after login. API key authentication arrived in v3.6. You set everything up on your own server; there is no vendor-hosted API for Core.",
      "pricing": "freemium",
      "pricingNotes": "Vendure Core is free under GPLv3; self-hosted you pay only for your own servers and database. Vendure Platform is a flat yearly subscription quoted per project (no GMV, order or user fees) and adds B2B tooling, a commercial licence and support. Vendure Cloud is priced by environments and resources, currently for paid design partners only, with general availability planned for Q1 2027. No transaction fees (https://vendure.io/pricing).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payments layer for agents; payment handlers are plugins you configure (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 8487,
        "npmWeekly": 29655,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.vendure.io",
      "llmsTxt": "https://docs.vendure.io/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "typescript",
        "llms-txt",
        "freemium",
        "enterprise"
      ],
      "lastRelease": "2026-09-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.9,
        "grade": "BB",
        "agentReady": true,
        "rank": 123,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "3.7.3 on 2 September 2026 fixed an unauthenticated takeover of SSO customer accounts through registerCustomerAccount (GHSA-wr5h-x3x6-4h23), a cross-channel IDOR in order payment, refund and fulfilment operations (GHSA-7qvr-c5vf-xxfh), and session tokens returned in Admin API job data (GHSA-32jm-mf7r-7qw5). All are fixed and disclosed, but the changelog warns that tokens may remain in historical job records (https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md)."
        ],
        "verdict": "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.",
        "bestFor": "TypeScript teams that want a typed GraphQL commerce server and will host it.",
        "strengths": [
          "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on",
          "API keys scoped to roles and channels, bcrypt-hashed and rotatable",
          "GPLv3 core, free to self-host, with no GMV or order fees on any tier",
          "CI passing on master and three releases between 14 July and 2 September 2026",
          "No usage telemetry found in the core, CLI or scaffolder"
        ],
        "weaknesses": [
          "No vendor-hosted API. Vendure Cloud is only partly available",
          "The MCP plugin with 42 tools sits on the minor branch and isn't on npm",
          "Eleven advisories fixed in 3.7.3, including unauthenticated SSO account takeover and a cross-channel IDOR",
          "No official client SDK and no idempotency support for order mutations",
          "No terms of service page, status page or security.txt"
        ],
        "agentNotes": [
          "Keep the session token from the first Shop API response and send it on every call. It holds the active order",
          "Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult",
          "Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again",
          "For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel",
          "Run 3.7.3 or later, and purge old job records, which may still hold session tokens"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.9
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 78
        },
        "provenanceScore": 56
      },
      "connect": {
        "http": "curl https://readonlydemo.vendure.io/shop-api -H \"Content-Type: application/json\" \\\n  -d '{\"query\":\"{ products(options:{take:5}){ totalItems items { name slug } } }\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/vendure"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Vendure Core self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "GPLv3, you pay for your own servers and database"
        }
      ],
      "provenance": {
        "legalEntity": "Elevantiq GmbH",
        "domain": "vendure.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://github.com/vendurehq/vendure/blob/master/LICENSE.md",
        "privacy": "https://vendure.io/company/privacy-policy",
        "statusPage": "",
        "changelog": "https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "vendure.io has no terms of service page; the GPLv3 licence in the repo is linked as terms. Legal notice at https://vendure.io/company/legal-notice (Elevantiq GmbH, FN 506751 y, Innsbruck).",
          "rdap.org has no RDAP service for .io, so the registration date is blank.",
          "remoteUrl is Vendure's public read-only demo; production APIs run on your own domain."
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vendure.json",
      "live": {
        "slug": "vendure",
        "probe": {
          "target": "https://readonlydemo.vendure.io/shop-api",
          "method": "get",
          "lastAt": "2026-10-08T21:12:24.863120435Z",
          "lastOk": true,
          "lastStatus": 400,
          "lastMs": 28,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 42,
          "p95ms24h": 121,
          "samples24h": 271,
          "samples30d": 2157,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 239,
              "ok": 239
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "vendurehq/vendure",
            "version": "v3.7.4",
            "released": "2026-10-05",
            "seenAt": "2026-10-08T16:34:00.219407602Z"
          },
          {
            "registry": "npm",
            "name": "@vendure/core",
            "version": "3.7.4",
            "seenAt": "2026-10-08T16:33:59.406669774Z"
          }
        ],
        "githubStars": 8505,
        "npmWeekly": 39734,
        "securityTxt": {
          "url": "https://vendure.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:55.51273513Z"
        },
        "llmsTxt": {
          "url": "https://docs.vendure.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:59.103928368Z"
        },
        "domain": {
          "domain": "vendure.io",
          "checkedAt": "2026-10-04T13:04:21.502238644Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:47.725516985Z",
            "changedAt": "2026-10-05T16:00:13.686824026Z",
            "fingerprint": "1138502529e2"
          },
          {
            "url": "https://vendure.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:37.530244878Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2eeb9beb193d"
          },
          {
            "url": "https://vendure.io/company/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:35.37388554Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c172f2439224"
          },
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/LICENSE.md",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:49.736344061Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4fa079f39d4c"
          }
        ],
        "updatedAt": "2026-10-08T21:12:24.863120435Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Ecwid, Inc. (Lightspeed Commerce)",
        "b": "Vendure (Elevantiq GmbH)",
        "name": "Vendor"
      },
      {
        "a": "https://app.ecwid.com/api/v3",
        "b": "https://readonlydemo.vendure.io/shop-api",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Lightspeed Service Agreement. The `@lightspeed/ecom-headless` npm package is MIT and the Java API client on GitHub is Apache-2.0",
        "b": "GPL-3.0-or-later",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-09-02",
        "name": "Last release"
      },
      {
        "a": "2026-02-26",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "22 stars, 307 npm/wk",
        "b": "8.5k stars, 30k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Vendure scores 70.9 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 6 of 7 scored categories. Ecwid by Lightspeed leads on transparency \u0026 trust.",
        "question": "Which is better for AI agents, Ecwid by Lightspeed or Vendure?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Ecwid by Lightspeed and Vendure need an API key?"
      },
      {
        "answer": "Yes. Ecwid by Lightspeed has a hosted endpoint at https://app.ecwid.com/api/v3 and Vendure at https://readonlydemo.vendure.io/shop-api.",
        "question": "Can an agent call Ecwid by Lightspeed and Vendure without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Ecwid by Lightspeed. Vendure is open source (GPL-3.0-or-later).",
        "question": "Are Ecwid by Lightspeed and Vendure open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Transparency \u0026 trust, 72 against 67"
        ],
        "also": [
          "No incidents deducted, where Vendure loses 3 points for them"
        ],
        "goodFor": "An agent doing back-office work on an existing Ecwid store, such as catalogue edits, order export and discount coupons.",
        "slug": "ecwid",
        "watchFor": "Access tokens never expire and change only when the app is uninstalled and installed again"
      },
      {
        "aheadOn": [
          "Reliability, 89 against 80",
          "Schema \u0026 documentation, 91 against 66",
          "Payments \u0026 pricing, 45 against 15",
          "Maintenance \u0026 community, 85 against 79"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "Open source"
        ],
        "goodFor": "TypeScript teams that want a typed GraphQL commerce server and will host it.",
        "slug": "vendure",
        "watchFor": "No vendor-hosted API. Vendure Cloud is only partly available"
      }
    ],
    "job": {
      "capability": "commerce.products",
      "name": "Commerce products"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/adobe-commerce-vs-ecwid.json",
        "title": "Adobe Commerce (Magento) vs Ecwid by Lightspeed",
        "url": "https://www.anchorterminal.com/compare/adobe-commerce-vs-ecwid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/adobe-commerce-vs-vendure.json",
        "title": "Adobe Commerce (Magento) vs Vendure",
        "url": "https://www.anchorterminal.com/compare/adobe-commerce-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-ecwid.json",
        "title": "BigCommerce API + MCP vs Ecwid by Lightspeed",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-ecwid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-vendure.json",
        "title": "BigCommerce API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-ecwid.json",
        "title": "Commerce Layer API + MCP vs Ecwid by Lightspeed",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-ecwid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-vendure.json",
        "title": "Commerce Layer API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-ecwid.json",
        "title": "commercetools vs Ecwid by Lightspeed",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-ecwid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-vendure.json",
        "title": "commercetools vs Vendure",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-elastic-path.json",
        "title": "Ecwid by Lightspeed vs Elastic Path API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-elastic-path"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-medusa.json",
        "title": "Ecwid by Lightspeed vs Medusa API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-medusa"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-saleor.json",
        "title": "Ecwid by Lightspeed vs Saleor API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-saleor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-shopify.json",
        "title": "Ecwid by Lightspeed vs Shopify API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-shopify"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-shopware.json",
        "title": "Ecwid by Lightspeed vs Shopware",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-snipcart.json",
        "title": "Ecwid by Lightspeed vs Snipcart API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-snipcart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-square.json",
        "title": "Ecwid by Lightspeed vs Square",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-swell.json",
        "title": "Ecwid by Lightspeed vs Swell",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-swell"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-wix.json",
        "title": "Ecwid by Lightspeed vs Wix Stores and eCommerce API",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-wix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-woocommerce.json",
        "title": "Ecwid by Lightspeed vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-woocommerce"
      },
      {
        "json": "https://www.anchorterminal.com/compare/elastic-path-vs-vendure.json",
        "title": "Elastic Path API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/elastic-path-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/medusa-vs-vendure.json",
        "title": "Medusa API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/medusa-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-vendure.json",
        "title": "Saleor API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopify-vs-vendure.json",
        "title": "Shopify API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/shopify-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-vendure.json",
        "title": "Shopware vs Vendure",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/snipcart-vs-vendure.json",
        "title": "Snipcart API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/snipcart-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-vendure.json",
        "title": "Square vs Vendure",
        "url": "https://www.anchorterminal.com/compare/square-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/swell-vs-vendure.json",
        "title": "Swell vs Vendure",
        "url": "https://www.anchorterminal.com/compare/swell-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/vendure-vs-wix.json",
        "title": "Vendure vs Wix Stores and eCommerce API",
        "url": "https://www.anchorterminal.com/compare/vendure-vs-wix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/vendure-vs-woocommerce.json",
        "title": "Vendure vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/vendure-vs-woocommerce"
      }
    ],
    "scores": [
      {
        "by": 9,
        "ecwid": 80,
        "edge": "vendure",
        "key": "reliability",
        "name": "Reliability",
        "vendure": 89,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 25,
        "ecwid": 66,
        "edge": "vendure",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "vendure": 91,
        "weight": 13
      },
      {
        "by": 2,
        "ecwid": 66,
        "edge": "vendure",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "vendure": 68,
        "weight": 13
      },
      {
        "by": 4,
        "ecwid": 61,
        "edge": "vendure",
        "key": "security",
        "name": "Security \u0026 auth",
        "vendure": 65,
        "weight": 14
      },
      {
        "by": 30,
        "ecwid": 15,
        "edge": "vendure",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "vendure": 45,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "ecwid": 79,
        "edge": "vendure",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "vendure": 85,
        "weight": 7
      },
      {
        "by": 5,
        "ecwid": 72,
        "edge": "ecwid",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "vendure": 67,
        "weight": 7
      }
    ],
    "summary": "Vendure scores 70.9 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 6 of 7 scored categories. Ecwid by Lightspeed leads on transparency \u0026 trust. Both do commerce products.",
    "verdicts": {
      "ecwid": "The REST API has 40 access scopes, a published limit of 600 requests a minute per token with `Retry-After` on a 429, field selection through `responseFields`, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.",
      "vendure": "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/ecwid-vs-vendure",
    "json": "https://www.anchorterminal.com/compare/ecwid-vs-vendure.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/ecwid-vs-vendure.md",
    "slim": "https://www.anchorterminal.com/compare/ecwid-vs-vendure.min.md"
  },
  "markdown": "Vendure scores 70.9 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 6 of 7 scored categories. Ecwid by Lightspeed leads on transparency \u0026 trust. Both do commerce products.\n\n- Ecwid by Lightspeed: grade B, 63.2/100, rank #316 of 722. Markdown https://www.anchorterminal.com/tools/ecwid.md · JSON https://www.anchorterminal.com/api/v1/tools/ecwid.json\n- Vendure: grade BB, 70.9/100, rank #123 of 722. Markdown https://www.anchorterminal.com/tools/vendure.md · JSON https://www.anchorterminal.com/api/v1/tools/vendure.json\n\n## Which one, for what\n\n### Ecwid by Lightspeed (B)\n\nGood for: An agent doing back-office work on an existing Ecwid store, such as catalogue edits, order export and discount coupons.\n\nAhead on:\n- Transparency \u0026 trust, 72 against 67\n\nAlso in its favour:\n- No incidents deducted, where Vendure loses 3 points for them\n\nWatch for: Access tokens never expire and change only when the app is uninstalled and installed again\n\n### Vendure (BB)\n\nGood for: TypeScript teams that want a typed GraphQL commerce server and will host it.\n\nAhead on:\n- Reliability, 89 against 80\n- Schema \u0026 documentation, 91 against 66\n- Payments \u0026 pricing, 45 against 15\n- Maintenance \u0026 community, 85 against 79\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- Open source\n\nWatch for: No vendor-hosted API. Vendure Cloud is only partly available\n\n\n## Score by category\n\n| Category | Weight | Ecwid by Lightspeed | Vendure | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 80 | 89 | Vendure +9 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 66 | 91 | Vendure +25 |\n| Agent ergonomics | 13% (16.2 this run) | 66 | 68 | Vendure +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 61 | 65 | Vendure +4 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 15 | 45 | Vendure +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 79 | 85 | Vendure +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 67 | Ecwid by Lightspeed +5 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **63.2 · B** | **70.9 · BB** | |\n\n## Facts side by side\n\n| Fact | Ecwid by Lightspeed | Vendure |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Ecwid, Inc. (Lightspeed Commerce) | Vendure (Elevantiq GmbH) |\n| Hosted endpoint | `https://app.ecwid.com/api/v3` | `https://readonlydemo.vendure.io/shop-api` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under the Lightspeed Service Agreement. The `@lightspeed/ecom-headless` npm package is MIT and the Java API client on GitHub is Apache-2.0 | GPL-3.0-or-later |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-30 | 2026-09-02 |\n| Terms last updated | 2026-02-26 | no date given |\n| Privacy policy last updated | no date given | no date given |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | not found in the text | not found in the text |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 22 stars, 307 npm/wk | 8.5k stars, 30k npm/wk |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Ecwid by Lightspeed.** The REST API has 40 access scopes, a published limit of 600 requests a minute per token with `Retry-After` on a 429, field selection through `responseFields`, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.\n\n**Vendure.** Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.\n\n## Before you call either\n\n### Ecwid by Lightspeed\n\n1. Send the token as `Authorization: Bearer` to `https://app.ecwid.com/api/v3/{storeId}`. Tokens in the query string stopped working in March 2025\n2. Use the secret token server-side only. The public token reads enabled products and places orders that are not marked paid\n3. Add `responseFields`, for example `total,items(id,name,price)`, to keep responses small, and page with `offset` and `limit` (maximum 100)\n4. Stay under 600 requests a minute per token and wait the `Retry-After` seconds on a 429. Repeated calls with a bad token get the token and IP blocked for longer\n5. Work in a separate test store. There is no test mode, and `POST /orders` writes a real order with no idempotency key\n6. After changing an app's scopes, uninstall and reinstall it, then replace the stored tokens. The old ones stop working\n\n### Vendure\n\n1. Keep the session token from the first Shop API response and send it on every call. It holds the active order\n2. Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult\n3. Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again\n4. For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel\n5. Run 3.7.3 or later, and purge old job records, which may still hold session tokens\n\n## Questions\n\n### Which is better for AI agents, Ecwid by Lightspeed or Vendure?\n\nVendure scores 70.9 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 6 of 7 scored categories. Ecwid by Lightspeed leads on transparency \u0026 trust.\n\n### Do Ecwid by Lightspeed and Vendure need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Ecwid by Lightspeed and Vendure without installing anything?\n\nYes. Ecwid by Lightspeed has a hosted endpoint at https://app.ecwid.com/api/v3 and Vendure at https://readonlydemo.vendure.io/shop-api.\n\n### Are Ecwid by Lightspeed and Vendure open source?\n\nNo open-source release is listed for Ecwid by Lightspeed. Vendure is open source (GPL-3.0-or-later).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/ecwid-vs-vendure.json, and with the fewest tokens: https://www.anchorterminal.com/compare/ecwid-vs-vendure.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"ecwid\", \"b\": \"vendure\"}`. From a terminal: `anchor compare ecwid vendure`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/ecwid.json and https://www.anchorterminal.com/api/v1/tools/vendure.json\n\n## Other comparisons with Ecwid by Lightspeed or Vendure\n\n- [Adobe Commerce (Magento) vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/adobe-commerce-vs-ecwid.md)\n- [Adobe Commerce (Magento) vs Vendure](https://www.anchorterminal.com/compare/adobe-commerce-vs-vendure.md)\n- [BigCommerce API + MCP vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/bigcommerce-vs-ecwid.md)\n- [BigCommerce API + MCP vs Vendure](https://www.anchorterminal.com/compare/bigcommerce-vs-vendure.md)\n- [Commerce Layer API + MCP vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/commerce-layer-vs-ecwid.md)\n- [Commerce Layer API + MCP vs Vendure](https://www.anchorterminal.com/compare/commerce-layer-vs-vendure.md)\n- [commercetools vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/commercetools-vs-ecwid.md)\n- [commercetools vs Vendure](https://www.anchorterminal.com/compare/commercetools-vs-vendure.md)\n- [Ecwid by Lightspeed vs Elastic Path API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-elastic-path.md)\n- [Ecwid by Lightspeed vs Medusa API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-medusa.md)\n- [Ecwid by Lightspeed vs Saleor API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-saleor.md)\n- [Ecwid by Lightspeed vs Shopify API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-shopify.md)\n- [Ecwid by Lightspeed vs Shopware](https://www.anchorterminal.com/compare/ecwid-vs-shopware.md)\n- [Ecwid by Lightspeed vs Snipcart API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-snipcart.md)\n- [Ecwid by Lightspeed vs Square](https://www.anchorterminal.com/compare/ecwid-vs-square.md)\n- [Ecwid by Lightspeed vs Swell](https://www.anchorterminal.com/compare/ecwid-vs-swell.md)\n- [Ecwid by Lightspeed vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/ecwid-vs-wix.md)\n- [Ecwid by Lightspeed vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-woocommerce.md)\n- [Elastic Path API + MCP vs Vendure](https://www.anchorterminal.com/compare/elastic-path-vs-vendure.md)\n- [Medusa API + MCP vs Vendure](https://www.anchorterminal.com/compare/medusa-vs-vendure.md)\n- [Saleor API + MCP vs Vendure](https://www.anchorterminal.com/compare/saleor-vs-vendure.md)\n- [Shopify API + MCP vs Vendure](https://www.anchorterminal.com/compare/shopify-vs-vendure.md)\n- [Shopware vs Vendure](https://www.anchorterminal.com/compare/shopware-vs-vendure.md)\n- [Snipcart API + MCP vs Vendure](https://www.anchorterminal.com/compare/snipcart-vs-vendure.md)\n- [Square vs Vendure](https://www.anchorterminal.com/compare/square-vs-vendure.md)\n- [Swell vs Vendure](https://www.anchorterminal.com/compare/swell-vs-vendure.md)\n- [Vendure vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/vendure-vs-wix.md)\n- [Vendure vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/vendure-vs-woocommerce.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Ecwid by Lightspeed vs Vendure",
        "url": ""
      }
    ],
    "description": "Vendure scores 70.9 (BB) on agent readiness against Ecwid by Lightspeed's 63.2 (B), and leads in 6 of 7 scored categories. Ecwid by Lightspeed leads on transparency \u0026 trust. Both do commerce products. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Ecwid by Lightspeed B 63.2",
      "Vendure BB 70.9",
      "scores"
    ],
    "h1": "Ecwid by Lightspeed vs Vendure",
    "image": "https://www.anchorterminal.com/assets/og/compare-ecwid-vs-vendure.png",
    "path": "/compare/ecwid-vs-vendure",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Ecwid by Lightspeed vs Vendure for AI agents, B 63.2 vs BB 70.9",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/ecwid-vs-vendure"
  },
  "tokens": {
    "markdown": 2600,
    "slim": 680
  },
  "version": 1
}
