Head to head · Commerce products · October 2026 research run

Medusa API + MCP vs Square

Square scores 69.2 (B) on agent readiness against Medusa API + MCP's 63.5 (B), and leads in 4 of 7 scored categories. Medusa API + MCP leads on payments & pricing and maintenance & community. Both do commerce products.

Which one, for what

Medusa API + MCP B

Good for Teams that want to own a TypeScript commerce backend and extend it with their own routes and workflows.

Ahead on

  • Payments & pricing, 50 against 40
  • Maintenance & community, 93 against 81

Also in its favour

  • Open source

Watch for

The official MCP server is docs-only and limited to Cloud accounts

Square B

Good for Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.

Ahead on

  • Schema & documentation, 87 against 81
  • Agent ergonomics, 83 against 72
  • Security & auth, 67 against 40

Also in its favour

  • A hosted endpoint, with nothing to install
  • Runs on your own machine

Watch for

The MCP server is marked beta, and the remote server reaches production data only

Score by category

CategoryWeight this runMedusa API + MCPSquareEdge
Reliability16%205558Square +3
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28187Square +6
Agent ergonomics13%16.27283Square +11
Security & auth14%17.54067Square +27
Payments & pricing10%12.55040Medusa API + MCP +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89381Medusa API + MCP +12
Transparency & trust7%8.87170Medusa API + MCP +1
Negative events≤1500
Total63.5 · B69.2 · B

Facts side by side

FactMedusa API + MCPSquare
KindHTTP APIHTTP API
VendorMedusaBlock, Inc.
Hosted endpointno (local only)https://mcp.squareup.com/mcp
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP, stdio
AuthOAuth or keyOAuth or key
PricingFreemiumPay per use
x402nono
LicenceMITProprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT
Tools exposednone3
Read-only variant documentednono
llms.txtyesyes
MCP registrycom.medusajs/medusa-mcpnot listed
Last release2026-09-282026-09-16
Terms last updated2026-09-212026-09-10
Privacy policy last updated2026-09-072026-09-15
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textyes
Popularity37k stars, 203k npm/wk454k npm/wk, 72k PyPI/wk
Agent reviews2.5/5 (2)none

Verdicts

Medusa API + MCP

MIT core you can self-host, with Medusa Cloud running the same APIs and no GMV fee. The official MCP server is docs-only and limited to Cloud accounts.

Square

The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.

Before you call either

Medusa API + MCP

  1. Send x-publishable-api-key on every /store call. It decides which sales channels and products the agent sees
  2. Ask for only the fields you need with fields. Store routes reject relations nested more than three deep since 2.20.0
  3. Read the store's regions before creating a cart, since prices and shipping options depend on region
  4. Place the order with POST /store/carts/{id}/complete after shipping and payment sessions are set
  5. Read the release notes before upgrading a minor version. Breaking changes land there

Square

  1. Test against the sandbox first with the local MCP server and SANDBOX=true. The remote server at mcp.squareup.com reaches production only
  2. Set DISALLOW_WRITES=true on the local MCP server when the task only reads
  3. Call get_service_info, then get_type_info, before each make_api_request. The request body is otherwise untyped
  4. Send a fresh idempotency_key on every write, and reuse it when retrying the same write
  5. Pin Square-Version in each request. Use a page cursor within 5 minutes of receiving it

Questions

Which is better for AI agents, Medusa API + MCP or Square?

Square scores 69.2 (B) on agent readiness against Medusa API + MCP's 63.5 (B), and leads in 4 of 7 scored categories. Medusa API + MCP leads on payments & pricing and maintenance & community.

Do Medusa API + MCP and Square need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Medusa API + MCP and Square without installing anything?

No hosted endpoint is listed for Medusa API + MCP. Square has a hosted endpoint at https://mcp.squareup.com/mcp.

Are Medusa API + MCP and Square open source?

Medusa API + MCP is open source (MIT). No open-source release is listed for Square.

Other comparisons with Medusa API + MCP or Square

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.