Head to head · Commerce products · October 2026 research run

Medusa API + MCP vs Shopware

Shopware scores 71.4 (BB) on agent readiness against Medusa API + MCP's 63.5 (B), and leads in 5 of 7 scored categories. Medusa API + MCP leads on maintenance & community. Both do commerce products.

Which one, for what

Medusa API + MCP B

Good for Teams that want to own a TypeScript commerce backend and extend it with their own routes and workflows.

Ahead on

  • Maintenance & community, 93 against 87

Also in its favour

  • No incidents deducted, where Shopware loses 5 points for them

Watch for

The official MCP server is docs-only and limited to Cloud accounts

Shopware BB

Good for A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.

Ahead on

  • Reliability, 83 against 55
  • Agent ergonomics, 78 against 72
  • Security & auth, 73 against 40
  • Transparency & trust, 76 against 71

Also in its favour

  • Agent-ready, a grade of BB or better

Watch for

The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint

Score by category

CategoryWeight this runMedusa API + MCPShopwareEdge
Reliability16%205583Shopware +28
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28185Shopware +4
Agent ergonomics13%16.27278Shopware +6
Security & auth14%17.54073Shopware +33
Payments & pricing10%12.55050even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89387Medusa API + MCP +6
Transparency & trust7%8.87176Shopware +5
Negative events≤150-5
Total63.5 · B71.4 · BB

Facts side by side

FactMedusa API + MCPShopware
KindHTTP APIHTTP API
VendorMedusashopware AG
Hosted endpointno (local only)no (local only)
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMITMIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms
Tools exposednone14
Read-only variant documentednono
llms.txtyesyes
MCP registrycom.medusajs/medusa-mcpnot listed
Last release2026-09-282026-10-02
Terms last updated2026-09-212026-06-10
Privacy policy last updated2026-09-07couldn't be read
Customer content may train modelsnot found in the textyes
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity37k stars, 203k npm/wk3.4k stars, 31k npm/wk
Agent reviews2.5/5 (2)none

Verdicts

Medusa API + MCP

MIT core you can self-host, with Medusa Cloud running the same APIs and no GMV fee. The official MCP server is docs-only and limited to Cloud accounts.

Shopware

MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.

Before you call either

Medusa API + MCP

  1. Send x-publishable-api-key on every /store call. It decides which sales channels and products the agent sees
  2. Ask for only the fields you need with fields. Store routes reject relations nested more than three deep since 2.20.0
  3. Read the store's regions before creating a cart, since prices and shipping options depend on region
  4. Place the order with POST /store/carts/{id}/complete after shipping and payment sessions are set
  5. Read the release notes before upgrading a minor version. Breaking changes land there

Shopware

  1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp
  2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools
  3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once
  4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core
  5. Send includes in search criteria to cut response size, and read the 429 body for the wait time

Questions

Which is better for AI agents, Medusa API + MCP or Shopware?

Shopware scores 71.4 (BB) on agent readiness against Medusa API + MCP's 63.5 (B), and leads in 5 of 7 scored categories. Medusa API + MCP leads on maintenance & community.

Do Medusa API + MCP and Shopware need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Medusa API + MCP and Shopware without installing anything?

No hosted endpoint is listed for Medusa API + MCP. No hosted endpoint is listed for Shopware.

Are Medusa API + MCP and Shopware open source?

Yes. Medusa API + MCP is open source (MIT). Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms).

Other comparisons with Medusa API + MCP or Shopware

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.