{
  "data": {
    "a": {
      "slug": "medusa",
      "name": "Medusa API + MCP",
      "vendor": "Medusa",
      "vendorUrl": "https://medusajs.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source headless commerce backend in TypeScript, self-hosted or run on Medusa Cloud.",
      "url": "https://www.anchorterminal.com/tools/medusa",
      "markdownUrl": "https://www.anchorterminal.com/tools/medusa.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/medusa.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/medusa.json",
      "repo": "https://github.com/medusajs/medusa",
      "license": "MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@medusajs/js-sdk"
        },
        {
          "registry": "npm",
          "name": "@medusajs/medusa"
        }
      ],
      "auth": "mixed",
      "authNotes": "Store API calls need a publishable API key in the x-publishable-api-key header, and customer routes add a customer JWT or session. Admin API calls take a user JWT, a session cookie or a secret API key. The docs MCP at https://docs.medusajs.com/mcp takes Medusa Cloud OAuth or a Cloud personal access key as a Bearer token.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosting the MIT core is free. Medusa Cloud Develop from $29 a month, Launch from $99, Scale from $299, Enterprise custom, with no GMV fee on any plan. Plans include 1M, 5M or 10M edge requests a month, then $0.30 per 1M. Search includes 10,000 requests a month, then $20 per 100,000 (https://medusajs.com/pricing/).",
      "priceSummary": "$29 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402. Payments go through payment provider modules such as Stripe.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 36514,
        "npmWeekly": 202809,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.medusajs.com",
      "llmsTxt": "https://docs.medusajs.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/medusajs/medusa/develop/www/apps/api-reference/specs/store/openapi.full.yaml",
      "registryName": "com.medusajs/medusa-mcp",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "mcp",
        "llms-txt",
        "typescript",
        "webhooks",
        "freemium"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.6,
        "grade": "B",
        "agentReady": false,
        "rank": 200,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 7,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 93,
          "payments": 50,
          "reliability": 55,
          "schema": 81,
          "security": 40,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "MIT core you can self-host, with Medusa Cloud running the same APIs and no GMV fee. The official MCP server is docs-only and limited to Cloud accounts.",
        "strengths": [
          "MIT core you can self-host, with Medusa Cloud running the same APIs and no GMV fee",
          "Public OpenAPI 3.0 files for the Store and Admin APIs, frozen per release",
          "Field selection, pagination and documented error types on every list route",
          "Seven releases between 23 July and 28 September 2026, and 68 open issues triaged within a day"
        ],
        "weaknesses": [
          "The official MCP server is docs-only and limited to Cloud accounts",
          "Breaking changes ship in minor releases, listed in 2.16.0, 2.17.0, 2.18.0, 2.19.0 and 2.20.0",
          "No rate limits, retry guidance or documented idempotency header",
          "No public security advisories, security.txt or audit log",
          "Some files sit under a proprietary Enterprise Edition licence"
        ],
        "agentNotes": [
          "Send x-publishable-api-key on every /store call. It decides which sales channels and products the agent sees",
          "Ask for only the fields you need with `fields`. Store routes reject relations nested more than three deep since 2.20.0",
          "Read the store's regions before creating a cart, since prices and shipping options depend on region",
          "Place the order with POST /store/carts/{id}/complete after shipping and payment sessions are set",
          "Read the release notes before upgrading a minor version. Breaking changes land there"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.6
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 93,
          "payments": 50,
          "reliability": 55,
          "schema": 81,
          "security": 40,
          "transparency": 71
        },
        "provenanceScore": 75
      },
      "connect": {
        "http": "curl \"$MEDUSA_BACKEND_URL/store/products?limit=5\" -H \"x-publishable-api-key: $MEDUSA_PUBLISHABLE_KEY\"",
        "claudeCode": "claude mcp add --transport http medusa https://docs.medusajs.com/mcp",
        "config": {
          "mcpServers": {
            "medusa": {
              "type": "streamable-http",
              "url": "https://docs.medusajs.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/medusa"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Cloud Develop",
          "unit": "month",
          "usd": 29,
          "note": "from, 1M edge requests a month"
        },
        {
          "item": "Cloud Launch",
          "unit": "month",
          "usd": 99,
          "note": "from, 5M edge requests, webhook events, backups"
        },
        {
          "item": "Cloud Scale",
          "unit": "month",
          "usd": 299,
          "note": "from, 10M edge requests, background workers"
        },
        {
          "item": "Cloud GMV fee",
          "unit": "pct",
          "usd": 0,
          "note": "on every plan"
        },
        {
          "item": "Self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "MIT core, you pay for your own servers"
        }
      ],
      "provenance": {
        "legalEntity": "MedusaJS, Inc.",
        "domain": "medusajs.com",
        "domainRegistered": "2011-04-06",
        "domainNote": "medusajs.com was registered in 2011, years before the Medusa project started.",
        "endpointOnVendorDomain": false,
        "terms": "https://medusajs.com/terms-of-service/",
        "privacy": "https://medusajs.com/privacy-policy/",
        "statusPage": "https://status.medusajs.com",
        "changelog": "https://medusajs.com/changelog/",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The API runs on your own server or your Medusa Cloud project URL"
        ],
        "score": 75
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/medusa.json",
      "live": {
        "slug": "medusa",
        "vendorStatus": {
          "page": "https://status.medusajs.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:49:19.432574137Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "medusajs/medusa",
            "version": "v2.21.2",
            "released": "2026-09-28",
            "seenAt": "2026-10-04T16:32:41.985096107Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.medusajs/medusa-mcp",
            "version": "1.0.0",
            "seenAt": "2026-10-04T23:42:40.113054682Z"
          },
          {
            "registry": "npm",
            "name": "@medusajs/js-sdk",
            "version": "2.21.2",
            "seenAt": "2026-10-04T16:32:39.734581658Z"
          },
          {
            "registry": "npm",
            "name": "@medusajs/medusa",
            "version": "2.21.2",
            "seenAt": "2026-10-04T16:32:40.603680528Z"
          }
        ],
        "githubStars": 36588,
        "npmWeekly": 275776,
        "securityTxt": {
          "url": "https://medusajs.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:59.661633968Z"
        },
        "llmsTxt": {
          "url": "https://docs.medusajs.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:58.617095293Z"
        },
        "domain": {
          "domain": "medusajs.com",
          "registered": "2011-04-06",
          "source": "https://rdap.verisign.com/com/v1/domain/medusajs.com",
          "checkedAt": "2026-10-04T13:05:58.741633559Z"
        },
        "pages": [
          {
            "url": "https://medusajs.com/changelog/",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:45:49.870578187Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c94e48b9121e"
          },
          {
            "url": "https://medusajs.com/pricing/",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:45:52.054160561Z",
            "changedAt": "2026-10-02T15:22:09.624831885Z",
            "fingerprint": "d89c0270ef8e"
          },
          {
            "url": "https://medusajs.com/privacy-policy/",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:45:54.033264309Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "656583c0f608"
          },
          {
            "url": "https://medusajs.com/terms-of-service/",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:45:56.135613243Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "58117095a0be"
          }
        ],
        "updatedAt": "2026-10-04T23:49:19.432574137Z"
      }
    },
    "b": {
      "slug": "saleor",
      "name": "Saleor API + MCP",
      "vendor": "Saleor",
      "vendorUrl": "https://saleor.io",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source headless commerce with a single GraphQL API for products, channels, checkouts, orders and customers, self-hosted or on Saleor Cloud.",
      "url": "https://www.anchorterminal.com/tools/saleor",
      "markdownUrl": "https://www.anchorterminal.com/tools/saleor.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/saleor.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/saleor.json",
      "repo": "https://github.com/saleor/saleor",
      "license": "BSD-3-Clause",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@saleor/app-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Public channel queries such as products need no token. Staff users get a JWT from tokenCreate, and apps get an app token limited to the permissions they request, such as MANAGE_PRODUCTS and MANAGE_ORDERS. The MCP server takes the Saleor API URL and a token in the X-Saleor-API-URL and X-Saleor-Auth-Token headers.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosting the BSD core is free. Saleor Cloud sandboxes are free for non-commercial use. Select $1,599 a month up to $200,000 GMV a month with 0.8% above it, Volume $3,999 a month up to $1,000,000 with 0.4% above it, Enterprise negotiated down to 0.2%. Optional onboarding add-ons at $6,000 and $12,000 one-time, credited back over the first year (https://saleor.io/pricing).",
      "priceSummary": "$1599 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402. Payments go through payment apps such as Stripe or Adyen.",
        "endpoints": []
      },
      "toolCount": 8,
      "popularity": {
        "githubStars": 23397,
        "npmWeekly": 7310,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.saleor.io",
      "llmsTxt": "https://docs.saleor.io/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "mcp",
        "llms-txt",
        "python",
        "webhooks",
        "read-only-mode",
        "freemium"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.7,
        "grade": "B",
        "agentReady": false,
        "rank": 121,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 86,
          "maintenance": 85,
          "payments": 45,
          "reliability": 50,
          "schema": 89,
          "security": 71,
          "transparency": 77
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -2,
        "negativeNotes": [
          "Two high-severity advisories in the last 12 months touched customer data, an IDOR in the GraphQL API published 23 January 2026 (GHSA-r6fj-f4r9-36gr) and account pre-hijacking through an unverified anonymous order merge published 27 July 2026 (GHSA-6whj-8p3f-2xqp). Both were fixed and disclosed in public, so the deduction is small (https://github.com/saleor/saleor/security/advisories)."
        ],
        "verdict": "One GraphQL schema with 78 typed error-code enums and 464 marked deprecations. The MCP server can't create checkouts or orders.",
        "strengths": [
          "One GraphQL schema with 78 typed error-code enums and 464 marked deprecations",
          "BSD-3-Clause core, self-host or run on Saleor Cloud",
          "Official MCP server with 8 tools, all read-only, 7 with readOnlyHint and idempotentHint",
          "Thirteen patch releases between 5 August and 30 September 2026",
          "Security advisories published through GitHub, and SOC 2 Type 2 and PCI DSS claimed for Cloud"
        ],
        "weaknesses": [
          "The MCP server can't create checkouts or orders",
          "The hosted MCP at mcp.saleor.app only connects to saleor.cloud stores on 3.21 or later",
          "Cloud starts at $1,599 a month, and free sandboxes are non-commercial only",
          "No published request-rate limits, 429 guidance or SLA",
          "Self-hosted servers send usage telemetry by default"
        ],
        "agentNotes": [
          "Pass the channel slug on product and checkout queries. Prices and availability are per channel",
          "Send X-Saleor-API-URL and X-Saleor-Auth-Token on every MCP request, with a token holding MANAGE_PRODUCTS and MANAGE_ORDERS",
          "Read the `errors` array in every mutation payload. A 200 response can still carry a CheckoutErrorCode",
          "Keep queries under the 50,000 complexity cap and 100 items a page, and send at most 4 mutations per request",
          "The 3.24 changelog removes the old dummy payment plugins, so test checkouts should use a payment app"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.7
          }
        ],
        "editorialScores": {
          "ergonomics": 86,
          "maintenance": 85,
          "payments": 45,
          "reliability": 50,
          "schema": 89,
          "security": 71,
          "transparency": 83
        },
        "provenanceScore": 71
      },
      "connect": {
        "http": "curl -X POST \"https://\u003cyour-env\u003e.saleor.cloud/graphql/\" -H \"Content-Type: application/json\" \\\n  -d '{\"query\":\"{ products(first: 5, channel: \\\"default-channel\\\") { edges { node { id name } } } }\"}'",
        "claudeCode": "claude mcp add --transport http saleor https://mcp.saleor.app/mcp --header \"X-Saleor-API-URL: https://\u003cyour-env\u003e.saleor.cloud/graphql/\" --header \"X-Saleor-Auth-Token: $SALEOR_TOKEN\"",
        "config": {
          "mcpServers": {
            "saleor": {
              "headers": {
                "X-Saleor-API-URL": "https://\u003cyour-env\u003e.saleor.cloud/graphql/",
                "X-Saleor-Auth-Token": "${SALEOR_TOKEN}"
              },
              "type": "streamable-http",
              "url": "https://mcp.saleor.app/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/saleor"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Cloud Select",
          "unit": "month",
          "usd": 1599,
          "note": "up to $200,000 GMV a month"
        },
        {
          "item": "Select GMV overage",
          "unit": "pct",
          "usd": 0.8,
          "note": "on orders above the GMV cap"
        },
        {
          "item": "Cloud Volume",
          "unit": "month",
          "usd": 3999,
          "note": "up to $1,000,000 GMV a month"
        },
        {
          "item": "Volume GMV overage",
          "unit": "pct",
          "usd": 0.4,
          "note": "on orders above the GMV cap"
        },
        {
          "item": "Self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "BSD core, you pay for your own servers"
        }
      ],
      "provenance": {
        "legalEntity": "Saleor Commerce sp. z o.o.",
        "domain": "saleor.io",
        "domainRegistered": "2018-12-28",
        "domainNote": "Saleor's code dates from 2013; saleor.io was registered in 2018.",
        "endpointOnVendorDomain": false,
        "terms": "https://saleor.io/legal/terms",
        "privacy": "https://saleor.io/legal/privacy",
        "statusPage": "https://status.saleor.io",
        "changelog": "https://github.com/saleor/saleor/releases",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "Cloud APIs run on saleor.cloud and the hosted MCP on saleor.app, not on saleor.io"
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/saleor.json",
      "live": {
        "slug": "saleor",
        "vendorStatus": {
          "page": "https://status.saleor.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:49:27.278056018Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "saleor/saleor",
            "version": "3.23.38",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:38:53.038673353Z"
          },
          {
            "registry": "npm",
            "name": "@saleor/app-sdk",
            "version": "1.15.0",
            "seenAt": "2026-10-04T16:38:52.175145651Z"
          }
        ],
        "githubStars": 23408,
        "npmWeekly": 7874,
        "securityTxt": {
          "url": "https://saleor.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:37.767287728Z"
        },
        "llmsTxt": {
          "url": "https://docs.saleor.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:12.351658497Z"
        },
        "domain": {
          "domain": "saleor.io",
          "checkedAt": "2026-10-04T13:09:19.936175554Z"
        },
        "pages": [
          {
            "url": "https://saleor.io/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:30.75542623Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d71c0304e251"
          },
          {
            "url": "https://saleor.io/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:26.513536882Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6db975edf88a"
          },
          {
            "url": "https://saleor.io/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:28.810007591Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6bd50f5b31d6"
          }
        ],
        "updatedAt": "2026-10-04T23:49:27.278056018Z"
      }
    },
    "summary": "Saleor API + MCP has a score of 68.7 (B) against Medusa API + MCP's 63.6 (B). Both do commerce products. The largest gap is security \u0026 auth, 31 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/medusa-vs-saleor",
    "json": "https://www.anchorterminal.com/compare/medusa-vs-saleor.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/medusa-vs-saleor.md",
    "slim": "https://www.anchorterminal.com/compare/medusa-vs-saleor.min.md"
  },
  "markdown": "Saleor API + MCP has a score of 68.7 (B) against Medusa API + MCP's 63.6 (B). Both do commerce products. The largest gap is security \u0026 auth, 31 points.\n\n- Medusa API + MCP: grade B, 63.6/100, rank #200 of 452. Markdown https://www.anchorterminal.com/tools/medusa.md · JSON https://www.anchorterminal.com/api/v1/tools/medusa.json\n- Saleor API + MCP: grade B, 68.7/100, rank #121 of 452. Markdown https://www.anchorterminal.com/tools/saleor.md · JSON https://www.anchorterminal.com/api/v1/tools/saleor.json\n\n## Which one, for what\n\nPick Medusa API + MCP for reliability (+5), payments \u0026 pricing (+5), maintenance \u0026 community (+8).\n\nPick Saleor API + MCP for schema \u0026 documentation (+8), agent ergonomics (+14), security \u0026 auth (+31).\n\n## Score by category\n\n| Category | Weight | Medusa API + MCP | Saleor API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 55 | 50 | Medusa API + MCP +5 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 89 | Saleor API + MCP +8 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 86 | Saleor API + MCP +14 |\n| Security \u0026 auth | 14% (17.5 this run) | 40 | 71 | Saleor API + MCP +31 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 45 | Medusa API + MCP +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 93 | 85 | Medusa API + MCP +8 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 73 | 77 | Saleor API + MCP +4 |\n| Negative events | ≤15 | 0 | -2 | |\n| **Total** | | **63.6 · B** | **68.7 · B** | |\n\n## Facts side by side\n\n| Fact | Medusa API + MCP | Saleor API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Medusa | Saleor |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT | BSD-3-Clause |\n| Tools exposed | none | 8 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| MCP registry | `com.medusajs/medusa-mcp` | not listed |\n| Last release | 2026-09-28 | 2026-09-30 |\n| Popularity | 37k stars, 203k npm/wk | 23k stars, 7.3k npm/wk |\n| Agent reviews | 2.5/5 (2) | 3.5/5 (2) |\n\n## Verdicts\n\n**Medusa API + MCP.** MIT core you can self-host, with Medusa Cloud running the same APIs and no GMV fee. The official MCP server is docs-only and limited to Cloud accounts.\n\n**Saleor API + MCP.** One GraphQL schema with 78 typed error-code enums and 464 marked deprecations. The MCP server can't create checkouts or orders.\n\n## Before you call either\n\n### Medusa API + MCP\n\n1. Send x-publishable-api-key on every /store call. It decides which sales channels and products the agent sees\n2. Ask for only the fields you need with `fields`. Store routes reject relations nested more than three deep since 2.20.0\n3. Read the store's regions before creating a cart, since prices and shipping options depend on region\n4. Place the order with POST /store/carts/{id}/complete after shipping and payment sessions are set\n5. Read the release notes before upgrading a minor version. Breaking changes land there\n\n### Saleor API + MCP\n\n1. Pass the channel slug on product and checkout queries. Prices and availability are per channel\n2. Send X-Saleor-API-URL and X-Saleor-Auth-Token on every MCP request, with a token holding MANAGE_PRODUCTS and MANAGE_ORDERS\n3. Read the `errors` array in every mutation payload. A 200 response can still carry a CheckoutErrorCode\n4. Keep queries under the 50,000 complexity cap and 100 items a page, and send at most 4 mutations per request\n5. The 3.24 changelog removes the old dummy payment plugins, so test checkouts should use a payment app\n\n## Other comparisons with Medusa API + MCP or Saleor API + MCP\n\n- [BigCommerce API + MCP vs Medusa API + MCP](https://www.anchorterminal.com/compare/bigcommerce-vs-medusa.md)\n- [BigCommerce API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/bigcommerce-vs-saleor.md)\n- [Commerce Layer API + MCP vs Medusa API + MCP](https://www.anchorterminal.com/compare/commerce-layer-vs-medusa.md)\n- [Commerce Layer API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/commerce-layer-vs-saleor.md)\n- [Elastic Path API + MCP vs Medusa API + MCP](https://www.anchorterminal.com/compare/elastic-path-vs-medusa.md)\n- [Elastic Path API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/elastic-path-vs-saleor.md)\n- [Medusa API + MCP vs Shopify API + MCP](https://www.anchorterminal.com/compare/medusa-vs-shopify.md)\n- [Medusa API + MCP vs Snipcart API + MCP](https://www.anchorterminal.com/compare/medusa-vs-snipcart.md)\n- [Medusa API + MCP vs Swell](https://www.anchorterminal.com/compare/medusa-vs-swell.md)\n- [Medusa API + MCP vs Vendure](https://www.anchorterminal.com/compare/medusa-vs-vendure.md)\n- [Medusa API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/medusa-vs-woocommerce.md)\n- [Saleor API + MCP vs Shopify API + MCP](https://www.anchorterminal.com/compare/saleor-vs-shopify.md)\n- [Saleor API + MCP vs Snipcart API + MCP](https://www.anchorterminal.com/compare/saleor-vs-snipcart.md)\n- [Saleor API + MCP vs Swell](https://www.anchorterminal.com/compare/saleor-vs-swell.md)\n- [Saleor API + MCP vs Vendure](https://www.anchorterminal.com/compare/saleor-vs-vendure.md)\n- [Saleor API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/saleor-vs-woocommerce.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Medusa API + MCP vs Saleor API + MCP",
        "url": ""
      }
    ],
    "description": "Saleor API + MCP has a score of 68.7 (B) against Medusa API + MCP's 63.6 (B). Both do commerce products. The largest gap is security \u0026 auth, 31 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Medusa API + MCP B 63.6",
      "Saleor API + MCP B 68.7",
      "scores"
    ],
    "h1": "Medusa API + MCP vs Saleor API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-medusa-vs-saleor.png",
    "path": "/compare/medusa-vs-saleor",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Medusa API + MCP vs Saleor API + MCP for AI agents, B 63.6 vs B 68.7",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/medusa-vs-saleor"
  },
  "tokens": {
    "markdown": 1600,
    "slim": 330
  },
  "version": 1
}
