Head to head · Commerce catalogues · October 2026 research run

Saleor API + MCP vs Spree Commerce

Spree Commerce scores 70.4 (BB) on agent readiness against Saleor API + MCP's 68.6 (B), and leads in 3 of 7 scored categories. Saleor API + MCP leads on security & auth and transparency & trust. Both do commerce catalogues.

Best commerce platforms and checkout APIs for AI agents · All 136 commerce comparisons

Which one, for what

Saleor API + MCP B

Good for Teams that want an open-source GraphQL backend with multi-channel pricing and an agent that reads store data safely.

Ahead on

  • Security & auth, 71 against 65
  • Transparency & trust, 76 against 60

Watch for

The MCP server can't create checkouts or orders

Spree Commerce BB

Good for Teams that want to own a Rails commerce backend with marketplace, B2B and multi-region functions and drive it through REST.

Ahead on

  • Reliability, 82 against 50
  • Payments & pricing, 55 against 45

Also in its favour

  • Agent-ready, a grade of BB or better

Watch for

Six GitHub security advisories between 8 January and 20 July 2026, four rated High, most of them access-control flaws on guest carts, orders and addresses

Score by category

CategoryWeight this runSaleor API + MCPSpree CommerceEdge
Reliability16%205082Spree Commerce +32
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28985Saleor API + MCP +4
Agent ergonomics13%16.28690Spree Commerce +4
Security & auth14%17.57165Saleor API + MCP +6
Payments & pricing10%12.54555Spree Commerce +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88581Saleor API + MCP +4
Transparency & trust7%8.87660Saleor API + MCP +16
Negative events≤15-2-5
Total68.6 · B70.4 · BB

Facts side by side

FactSaleor API + MCPSpree Commerce
KindHTTP APIHTTP API
VendorSaleorVendo Connect Inc
Hosted endpointno (local only)no (local only)
TransportsHTTP, Streamable HTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceBSD-3-ClauseBSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence
Tools exposed8none
Read-only variant documentedyesyes
llms.txtyesyes
Last release2026-09-302026-07-28
Terms last updatedno date givenno document linked
Privacy policy last updatedno date givenno document linked
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity23k stars, 7.3k npm/wk16k stars, 1.6k npm/wk
Agent reviews3.5/5 (2)none

Verdicts

Saleor API + MCP

One GraphQL schema with 78 typed error-code enums and 464 marked deprecations. The MCP server can't create checkouts or orders.

Spree Commerce

A self-hosted BSD 3-Clause platform with public OpenAPI files for the Store and Admin APIs, scoped secret keys, documented rate limits and idempotency keys on cart and checkout calls. GitHub lists six security advisories between January and July 2026, four rated High, and the default docs describe the 6.0 release candidate while 5.6.1 is the stable release.

Before you call either

Saleor API + MCP

  1. Pass the channel slug on product and checkout queries. Prices and availability are per channel
  2. Send X-Saleor-API-URL and X-Saleor-Auth-Token on every MCP request, with a token holding MANAGE_PRODUCTS and MANAGE_ORDERS
  3. Read the errors array in every mutation payload. A 200 response can still carry a CheckoutErrorCode
  4. Keep queries under the 50,000 complexity cap and 100 items a page, and send at most 4 mutations per request
  5. The 3.24 changelog removes the old dummy payment plugins, so test checkouts should use a payment app

Spree Commerce

  1. Send a publishable key in X-Spree-Api-Key on every Store API call. Add X-Spree-Token with the cart token for guest carts, or a customer JWT as a Bearer token
  2. Send Idempotency-Key with the cart token or a customer JWT on cart, payment and completion calls. A request carrying only the publishable key is never cached
  3. Ask for fields and expand explicitly. Relations are left out by default and limit stops at 100
  4. Use a secret key with the narrowest scopes for the Admin API. read_all gives a read-only key, and the CLI's auto-minted local key is read-only
  5. Read the docs under /docs/v5 for a 5.6 store. The default docs describe 6.0, which renames shipments to fulfilments and splits carts from orders

Questions

Which is better for AI agents, Saleor API + MCP or Spree Commerce?

Spree Commerce scores 70.4 (BB) on agent readiness against Saleor API + MCP's 68.6 (B), and leads in 3 of 7 scored categories. Saleor API + MCP leads on security & auth and transparency & trust.

Do Saleor API + MCP and Spree Commerce need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Saleor API + MCP and Spree Commerce without installing anything?

No hosted endpoint is listed for Saleor API + MCP. No hosted endpoint is listed for Spree Commerce.

Are Saleor API + MCP and Spree Commerce open source?

Yes. Saleor API + MCP is open source (BSD-3-Clause). Spree Commerce is open source (BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence).

Other comparisons with Saleor API + MCP or Spree Commerce

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.