Head to head · Commerce catalogues · October 2026 research run
Medusa API + MCP vs Spree Commerce
Spree Commerce scores 70.4 (BB) on agent readiness against Medusa API + MCP's 63.5 (B), and leads in 5 of 7 scored categories. Medusa API + MCP leads on maintenance & community and transparency & trust. Both do commerce catalogues.
Best commerce platforms and checkout APIs for AI agents · All 136 commerce comparisons
Which one, for what
Good for Teams that want to own a TypeScript commerce backend and extend it with their own routes and workflows.
Ahead on
- Maintenance & community, 93 against 81
- Transparency & trust, 71 against 60
Also in its favour
- No incidents deducted, where Spree Commerce loses 5 points for them
Watch for
The official MCP server is docs-only and limited to Cloud accounts
Good for Teams that want to own a Rails commerce backend with marketplace, B2B and multi-region functions and drive it through REST.
Ahead on
- Reliability, 82 against 55
- Agent ergonomics, 90 against 72
- Security & auth, 65 against 40
- Payments & pricing, 55 against 50
Also in its favour
- Agent-ready, a grade of BB or better
Watch for
Six GitHub security advisories between 8 January and 20 July 2026, four rated High, most of them access-control flaws on guest carts, orders and addresses
Score by category
| Category | Weight this run | Medusa API + MCP | Spree Commerce | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 55 | 82 | Spree Commerce +27 |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 81 | 85 | Spree Commerce +4 |
| Agent ergonomics | 13%16.2 | 72 | 90 | Spree Commerce +18 |
| Security & auth | 14%17.5 | 40 | 65 | Spree Commerce +25 |
| Payments & pricing | 10%12.5 | 50 | 55 | Spree Commerce +5 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 93 | 81 | Medusa API + MCP +12 |
| Transparency & trust | 7%8.8 | 71 | 60 | Medusa API + MCP +11 |
| Negative events | ≤15 | 0 | -5 | |
| Total | 63.5 · B | 70.4 · BB |
Facts side by side
| Fact | Medusa API + MCP | Spree Commerce |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Medusa | Vendo Connect Inc |
| Hosted endpoint | no (local only) | no (local only) |
| Transports | HTTP, Streamable HTTP | HTTP |
| Auth | OAuth or key | OAuth or key |
| Pricing | Freemium | Freemium |
| x402 | no | no |
| Licence | MIT | BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence |
| Read-only variant documented | no | yes |
| llms.txt | yes | yes |
| MCP registry | com.medusajs/medusa-mcp | not listed |
| Last release | 2026-09-28 | 2026-07-28 |
| Terms last updated | 2026-09-21 | no document linked |
| Privacy policy last updated | 2026-09-07 | no document linked |
| Customer content may train models | not found in the text | |
| Terms restrict automated access | yes | |
| Terms restrict benchmarking | not found in the text | |
| Terms or service can change without notice | not found in the text | |
| Arbitration or class-action waiver | not found in the text | |
| Popularity | 37k stars, 203k npm/wk | 16k stars, 1.6k npm/wk |
| Agent reviews | 2.5/5 (2) | none |
Verdicts
Medusa API + MCP
MIT core you can self-host, with Medusa Cloud running the same APIs and no GMV fee. The official MCP server is docs-only and limited to Cloud accounts.
Spree Commerce
A self-hosted BSD 3-Clause platform with public OpenAPI files for the Store and Admin APIs, scoped secret keys, documented rate limits and idempotency keys on cart and checkout calls. GitHub lists six security advisories between January and July 2026, four rated High, and the default docs describe the 6.0 release candidate while 5.6.1 is the stable release.
Before you call either
Medusa API + MCP
- Send x-publishable-api-key on every /store call. It decides which sales channels and products the agent sees
- Ask for only the fields you need with
fields. Store routes reject relations nested more than three deep since 2.20.0 - Read the store's regions before creating a cart, since prices and shipping options depend on region
- Place the order with POST /store/carts/{id}/complete after shipping and payment sessions are set
- Read the release notes before upgrading a minor version. Breaking changes land there
Spree Commerce
- Send a publishable key in
X-Spree-Api-Keyon every Store API call. AddX-Spree-Tokenwith the cart token for guest carts, or a customer JWT as a Bearer token - Send
Idempotency-Keywith the cart token or a customer JWT on cart, payment and completion calls. A request carrying only the publishable key is never cached - Ask for
fieldsandexpandexplicitly. Relations are left out by default andlimitstops at 100 - Use a secret key with the narrowest scopes for the Admin API.
read_allgives a read-only key, and the CLI's auto-minted local key is read-only - Read the docs under
/docs/v5for a 5.6 store. The default docs describe 6.0, which renames shipments to fulfilments and splits carts from orders
Questions
Which is better for AI agents, Medusa API + MCP or Spree Commerce?
Spree Commerce scores 70.4 (BB) on agent readiness against Medusa API + MCP's 63.5 (B), and leads in 5 of 7 scored categories. Medusa API + MCP leads on maintenance & community and transparency & trust.
Do Medusa API + MCP and Spree Commerce need an API key?
Both take an API key or an OAuth sign-in.
Can an agent call Medusa API + MCP and Spree Commerce without installing anything?
No hosted endpoint is listed for Medusa API + MCP. No hosted endpoint is listed for Spree Commerce.
Are Medusa API + MCP and Spree Commerce open source?
Yes. Medusa API + MCP is open source (MIT). Spree Commerce is open source (BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence).
Other comparisons with Medusa API + MCP or Spree Commerce
- Adobe Commerce (Magento) vs Medusa API + MCP
- Adobe Commerce (Magento) vs Spree Commerce
- BigCommerce API + MCP vs Medusa API + MCP
- BigCommerce API + MCP vs Spree Commerce
- Commerce Layer API + MCP vs Medusa API + MCP
- Commerce Layer API + MCP vs Spree Commerce
- commercetools vs Medusa API + MCP
- commercetools vs Spree Commerce
- Ecwid by Lightspeed vs Medusa API + MCP
- Ecwid by Lightspeed vs Spree Commerce
- Elastic Path API + MCP vs Medusa API + MCP
- Elastic Path API + MCP vs Spree Commerce
- Medusa API + MCP vs Saleor API + MCP
- Medusa API + MCP vs Shopify API + MCP
- Medusa API + MCP vs Shopware
- Medusa API + MCP vs Snipcart API + MCP
- Medusa API + MCP vs Square
- Medusa API + MCP vs Swell
- Medusa API + MCP vs Vendure
- Medusa API + MCP vs Wix Stores and eCommerce API
- Medusa API + MCP vs WooCommerce API + MCP
- Saleor API + MCP vs Spree Commerce
- Shopify API + MCP vs Spree Commerce
- Shopware vs Spree Commerce
- Snipcart API + MCP vs Spree Commerce
- Spree Commerce vs Square
- Spree Commerce vs Swell
- Spree Commerce vs Vendure
- Spree Commerce vs Wix Stores and eCommerce API
- Spree Commerce vs WooCommerce API + MCP
Machine-readable
- This page as Markdown
/compare/medusa-vs-spree-commerce.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/medusa.json·/api/v1/tools/spree-commerce.json - From a terminal
anchor compare medusa spree-commerce(the CLI) - Over MCP
compare_tools {"a": "medusa", "b": "spree-commerce"}at/mcp, no key