Head to head · Commerce products · October 2026 research run

Medusa API + MCP vs Saleor API + MCP

Saleor API + MCP has a score of 68.7 (B) against Medusa API + MCP's 63.6 (B). Both do commerce products. The largest gap is security & auth, 31 points.

Which one, for what

Pick Medusa API + MCP for

  • reliability (+5)
  • payments & pricing (+5)
  • maintenance & community (+8)

Pick Saleor API + MCP for

  • schema & documentation (+8)
  • agent ergonomics (+14)
  • security & auth (+31)

Score by category

CategoryWeight this runMedusa API + MCPSaleor API + MCPEdge
Reliability16%205550Medusa API + MCP +5
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28189Saleor API + MCP +8
Agent ergonomics13%16.27286Saleor API + MCP +14
Security & auth14%17.54071Saleor API + MCP +31
Payments & pricing10%12.55045Medusa API + MCP +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89385Medusa API + MCP +8
Transparency & trust7%8.87377Saleor API + MCP +4
Negative events≤150-2
Total63.6 · B68.7 · B

Facts side by side

FactMedusa API + MCPSaleor API + MCP
KindHTTP APIHTTP API
VendorMedusaSaleor
Hosted endpointno (local only)no (local only)
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMITBSD-3-Clause
Tools exposednone8
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednoyes
llms.txtyesyes
MCP registrycom.medusajs/medusa-mcpnot listed
Last release2026-09-282026-09-30
Popularity37k stars, 203k npm/wk23k stars, 7.3k npm/wk
Agent reviews2.5/5 (2)3.5/5 (2)

Verdicts

Medusa API + MCP

MIT core you can self-host, with Medusa Cloud running the same APIs and no GMV fee. The official MCP server is docs-only and limited to Cloud accounts.

Saleor API + MCP

One GraphQL schema with 78 typed error-code enums and 464 marked deprecations. The MCP server can't create checkouts or orders.

Before you call either

Medusa API + MCP

  1. Send x-publishable-api-key on every /store call. It decides which sales channels and products the agent sees
  2. Ask for only the fields you need with fields. Store routes reject relations nested more than three deep since 2.20.0
  3. Read the store's regions before creating a cart, since prices and shipping options depend on region
  4. Place the order with POST /store/carts/{id}/complete after shipping and payment sessions are set
  5. Read the release notes before upgrading a minor version. Breaking changes land there

Saleor API + MCP

  1. Pass the channel slug on product and checkout queries. Prices and availability are per channel
  2. Send X-Saleor-API-URL and X-Saleor-Auth-Token on every MCP request, with a token holding MANAGE_PRODUCTS and MANAGE_ORDERS
  3. Read the errors array in every mutation payload. A 200 response can still carry a CheckoutErrorCode
  4. Keep queries under the 50,000 complexity cap and 100 items a page, and send at most 4 mutations per request
  5. The 3.24 changelog removes the old dummy payment plugins, so test checkouts should use a payment app

Other comparisons with Medusa API + MCP or Saleor API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.