Head to head · Commerce products · October 2026 research run

Medusa API + MCP vs Vendure

Vendure has a score of 71.4 (BB) against Medusa API + MCP's 63.6 (B). Both do commerce products. The largest gap is reliability, 34 points.

Which one, for what

Pick Medusa API + MCP for

  • payments & pricing (+5)
  • maintenance & community (+8)

Pick Vendure for

  • reliability (+34)
  • schema & documentation (+10)
  • security & auth (+25)

Score by category

CategoryWeight this runMedusa API + MCPVendureEdge
Reliability16%205589Vendure +34
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28191Vendure +10
Agent ergonomics13%16.27268Medusa API + MCP +4
Security & auth14%17.54065Vendure +25
Payments & pricing10%12.55045Medusa API + MCP +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89385Medusa API + MCP +8
Transparency & trust7%8.87372Medusa API + MCP +1
Negative events≤150-3
Total63.6 · B71.4 · BB

Facts side by side

FactMedusa API + MCPVendure
KindHTTP APIHTTP API
VendorMedusaVendure (Elevantiq GmbH)
Hosted endpointno (local only)https://readonlydemo.vendure.io/shop-api
TransportsHTTP, Streamable HTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMITGPL-3.0-or-later
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentednono
llms.txtyesyes
MCP registrycom.medusajs/medusa-mcpnot listed
Last release2026-09-282026-09-02
Popularity37k stars, 203k npm/wk8.5k stars, 30k npm/wk
Agent reviews2.5/5 (2)3/5 (2)

Verdicts

Medusa API + MCP

MIT core you can self-host, with Medusa Cloud running the same APIs and no GMV fee. The official MCP server is docs-only and limited to Cloud accounts.

Vendure

Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.

Before you call either

Medusa API + MCP

  1. Send x-publishable-api-key on every /store call. It decides which sales channels and products the agent sees
  2. Ask for only the fields you need with fields. Store routes reject relations nested more than three deep since 2.20.0
  3. Read the store's regions before creating a cart, since prices and shipping options depend on region
  4. Place the order with POST /store/carts/{id}/complete after shipping and payment sessions are set
  5. Read the release notes before upgrading a minor version. Breaking changes land there

Vendure

  1. Keep the session token from the first Shop API response and send it on every call. It holds the active order
  2. Check each mutation result's __typename and errorCode. Expected failures return 200 with an ErrorResult
  3. Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again
  4. For server-side work, enable api-key in authOptions.tokenMethod and give the key one role in one channel
  5. Run 3.7.3 or later, and purge old job records, which may still hold session tokens

Other comparisons with Medusa API + MCP or Vendure

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.