{
  "data": {
    "a": {
      "slug": "saleor",
      "name": "Saleor API + MCP",
      "vendor": "Saleor",
      "vendorUrl": "https://saleor.io",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source headless commerce with a single GraphQL API for products, channels, checkouts, orders and customers, self-hosted or on Saleor Cloud.",
      "url": "https://www.anchorterminal.com/tools/saleor",
      "markdownUrl": "https://www.anchorterminal.com/tools/saleor.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/saleor.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/saleor.json",
      "repo": "https://github.com/saleor/saleor",
      "license": "BSD-3-Clause",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@saleor/app-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Public channel queries such as products need no token. Staff users get a JWT from tokenCreate, and apps get an app token limited to the permissions they request, such as MANAGE_PRODUCTS and MANAGE_ORDERS. The MCP server takes the Saleor API URL and a token in the X-Saleor-API-URL and X-Saleor-Auth-Token headers.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosting the BSD core is free. Saleor Cloud sandboxes are free for non-commercial use. Select $1,599 a month up to $200,000 GMV a month with 0.8% above it, Volume $3,999 a month up to $1,000,000 with 0.4% above it, Enterprise negotiated down to 0.2%. Optional onboarding add-ons at $6,000 and $12,000 one-time, credited back over the first year (https://saleor.io/pricing).",
      "priceSummary": "$1599 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402. Payments go through payment apps such as Stripe or Adyen.",
        "endpoints": []
      },
      "toolCount": 8,
      "popularity": {
        "githubStars": 23397,
        "npmWeekly": 7310,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.saleor.io",
      "llmsTxt": "https://docs.saleor.io/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "mcp",
        "llms-txt",
        "python",
        "webhooks",
        "read-only-mode",
        "freemium"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.6,
        "grade": "B",
        "agentReady": false,
        "rank": 175,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 86,
          "maintenance": 85,
          "payments": 45,
          "reliability": 50,
          "schema": 89,
          "security": 71,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -2,
        "negativeNotes": [
          "Two high-severity advisories in the last 12 months touched customer data, an IDOR in the GraphQL API published 23 January 2026 (GHSA-r6fj-f4r9-36gr) and account pre-hijacking through an unverified anonymous order merge published 27 July 2026 (GHSA-6whj-8p3f-2xqp). Both were fixed and disclosed in public, so the deduction is small (https://github.com/saleor/saleor/security/advisories)."
        ],
        "verdict": "One GraphQL schema with 78 typed error-code enums and 464 marked deprecations. The MCP server can't create checkouts or orders.",
        "bestFor": "Teams that want an open-source GraphQL backend with multi-channel pricing and an agent that reads store data safely.",
        "strengths": [
          "One GraphQL schema with 78 typed error-code enums and 464 marked deprecations",
          "BSD-3-Clause core, self-host or run on Saleor Cloud",
          "Official MCP server with 8 tools, all read-only, 7 with readOnlyHint and idempotentHint",
          "Thirteen patch releases between 5 August and 30 September 2026",
          "Security advisories published through GitHub, and SOC 2 Type 2 and PCI DSS claimed for Cloud"
        ],
        "weaknesses": [
          "The MCP server can't create checkouts or orders",
          "The hosted MCP at mcp.saleor.app only connects to saleor.cloud stores on 3.21 or later",
          "Cloud starts at $1,599 a month, and free sandboxes are non-commercial only",
          "No published request-rate limits, 429 guidance or SLA",
          "Self-hosted servers send usage telemetry by default"
        ],
        "agentNotes": [
          "Pass the channel slug on product and checkout queries. Prices and availability are per channel",
          "Send X-Saleor-API-URL and X-Saleor-Auth-Token on every MCP request, with a token holding MANAGE_PRODUCTS and MANAGE_ORDERS",
          "Read the `errors` array in every mutation payload. A 200 response can still carry a CheckoutErrorCode",
          "Keep queries under the 50,000 complexity cap and 100 items a page, and send at most 4 mutations per request",
          "The 3.24 changelog removes the old dummy payment plugins, so test checkouts should use a payment app"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.6
          }
        ],
        "editorialScores": {
          "ergonomics": 86,
          "maintenance": 85,
          "payments": 45,
          "reliability": 50,
          "schema": 89,
          "security": 71,
          "transparency": 83
        },
        "provenanceScore": 68
      },
      "connect": {
        "http": "curl -X POST \"https://\u003cyour-env\u003e.saleor.cloud/graphql/\" -H \"Content-Type: application/json\" \\\n  -d '{\"query\":\"{ products(first: 5, channel: \\\"default-channel\\\") { edges { node { id name } } } }\"}'",
        "claudeCode": "claude mcp add --transport http saleor https://mcp.saleor.app/mcp --header \"X-Saleor-API-URL: https://\u003cyour-env\u003e.saleor.cloud/graphql/\" --header \"X-Saleor-Auth-Token: $SALEOR_TOKEN\"",
        "config": {
          "mcpServers": {
            "saleor": {
              "headers": {
                "X-Saleor-API-URL": "https://\u003cyour-env\u003e.saleor.cloud/graphql/",
                "X-Saleor-Auth-Token": "${SALEOR_TOKEN}"
              },
              "type": "streamable-http",
              "url": "https://mcp.saleor.app/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/saleor"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Cloud Select",
          "unit": "month",
          "usd": 1599,
          "note": "up to $200,000 GMV a month"
        },
        {
          "item": "Select GMV overage",
          "unit": "pct",
          "usd": 0.8,
          "note": "on orders above the GMV cap"
        },
        {
          "item": "Cloud Volume",
          "unit": "month",
          "usd": 3999,
          "note": "up to $1,000,000 GMV a month"
        },
        {
          "item": "Volume GMV overage",
          "unit": "pct",
          "usd": 0.4,
          "note": "on orders above the GMV cap"
        },
        {
          "item": "Self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "BSD core, you pay for your own servers"
        }
      ],
      "provenance": {
        "legalEntity": "Saleor Commerce sp. z o.o.",
        "domain": "saleor.io",
        "domainRegistered": "2018-12-28",
        "domainNote": "Saleor's code dates from 2013; saleor.io was registered in 2018.",
        "endpointOnVendorDomain": false,
        "terms": "https://saleor.io/legal/terms",
        "privacy": "https://saleor.io/legal/privacy",
        "statusPage": "https://status.saleor.io",
        "changelog": "https://github.com/saleor/saleor/releases",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "Cloud APIs run on saleor.cloud and the hosted MCP on saleor.app, not on saleor.io"
        ],
        "score": 68
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/saleor.json",
      "live": {
        "slug": "saleor",
        "vendorStatus": {
          "page": "https://status.saleor.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:51:01.976376981Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "saleor/saleor",
            "version": "3.23.40",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:27:59.482588719Z"
          },
          {
            "registry": "npm",
            "name": "@saleor/app-sdk",
            "version": "1.16.0",
            "seenAt": "2026-10-08T16:27:58.942693742Z"
          }
        ],
        "githubStars": 23420,
        "npmWeekly": 8054,
        "securityTxt": {
          "url": "https://saleor.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:54.513008536Z"
        },
        "llmsTxt": {
          "url": "https://docs.saleor.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:51.421728964Z"
        },
        "domain": {
          "domain": "saleor.io",
          "checkedAt": "2026-10-04T13:09:19.936175554Z"
        },
        "pages": [
          {
            "url": "https://saleor.io/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-08T18:23:57.767826297Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d71c0304e251"
          },
          {
            "url": "https://saleor.io/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-08T18:23:53.553316248Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6db975edf88a"
          },
          {
            "url": "https://saleor.io/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:23:55.781519018Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6bd50f5b31d6"
          }
        ],
        "updatedAt": "2026-10-08T19:51:01.976376981Z"
      }
    },
    "answer": "Square and Saleor API + MCP score within a point of each other on agent readiness, 69.2 (B) and 68.6 (B). Saleor API + MCP leads on payments \u0026 pricing and transparency \u0026 trust.",
    "b": {
      "slug": "square",
      "name": "Square",
      "vendor": "Block, Inc.",
      "vendorUrl": "https://squareup.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Square is Block's commerce and payments platform for sellers. Its REST API covers catalogue, orders, payment links, payments, inventory and customers, with seven SDKs and a beta MCP server hosted at mcp.squareup.com.",
      "url": "https://www.anchorterminal.com/tools/square",
      "markdownUrl": "https://www.anchorterminal.com/tools/square.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/square.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/square.json",
      "repo": "https://github.com/square/square-mcp-server",
      "license": "Proprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://mcp.squareup.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "square"
        },
        {
          "registry": "npm",
          "name": "square-mcp-server"
        },
        {
          "registry": "pypi",
          "name": "squareup"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access needs a Square account and an application created in the Developer Console, both self-serve. Two token types go in the `Authorization: Bearer` header. A personal access token gives unrestricted access to the owner's own account, with a separate sandbox token. OAuth access tokens are limited to the scopes a seller grants, expire after 30 days and can be refreshed and revoked. The remote MCP server signs in through OAuth, and Square keeps an allowlist of MCP clients that may register.",
      "pricing": "usage",
      "pricingNotes": "The API and sandbox carry no charge. Sellers pay processing fees, 2.9% + 30 cents for card payments through the payments APIs in the US. Square Free is $0 a month, Plus $49 and Premium $149 per location. The sandbox lets an agent start without a contract (https://squareup.com/us/en/payments/our-fees, checked 2026-10-08).",
      "priceSummary": "2.9% fee",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index at developer.squareup.com/llms.txt or the OpenAPI spec (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 453743,
        "pypiWeekly": 72138,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.squareup.com/docs",
      "llmsTxt": "https://developer.squareup.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/square/connect-api-specification/master/api.json",
      "capabilities": [
        "commerce.products",
        "commerce.orders",
        "commerce.checkout",
        "commerce.cart",
        "commerce.headless",
        "payments.card",
        "payments.checkout"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "graphql",
        "typescript",
        "python",
        "status-page",
        "bug-bounty"
      ],
      "lastRelease": "2026-09-16",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.2,
        "grade": "B",
        "agentReady": false,
        "rank": 166,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 81,
          "payments": 40,
          "reliability": 58,
          "schema": 87,
          "security": 67,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.",
        "bestFor": "Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.",
        "strengths": [
          "Public OpenAPI 3.0 spec with 332 operations and 1,476 schemas, regenerated for API version 2026-09-16",
          "OAuth scopes are split by read and write for each resource, and access tokens expire after 30 days",
          "78 request schemas carry an `idempotency_key`, and the docs describe backoff with jitter for 429 responses",
          "Free sandbox at connect.squareupsandbox.com with test cards, and API Logs kept for 28 days",
          "Deprecated APIs are typically retired at least 12 months after deprecation, with dated release notes each month"
        ],
        "weaknesses": [
          "The MCP server is marked beta, and the remote server reaches production data only",
          "No numeric rate limits were found for the REST API. Only GraphQL states a figure, 10 queries a second",
          "No SLA was found in the developer terms or documentation",
          "The status page recorded widespread latency and errors on 27 September 2026, including payment authorisation",
          "A personal access token grants unrestricted access to the whole Square account",
          "97 of the 332 operations in the spec are marked beta"
        ],
        "agentNotes": [
          "Test against the sandbox first with the local MCP server and `SANDBOX=true`. The remote server at mcp.squareup.com reaches production only",
          "Set `DISALLOW_WRITES=true` on the local MCP server when the task only reads",
          "Call `get_service_info`, then `get_type_info`, before each `make_api_request`. The request body is otherwise untyped",
          "Send a fresh `idempotency_key` on every write, and reuse it when retrying the same write",
          "Pin `Square-Version` in each request. Use a page cursor within 5 minutes of receiving it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.2
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 81,
          "payments": 40,
          "reliability": 58,
          "schema": 87,
          "security": 67,
          "transparency": 56
        },
        "provenanceScore": 84
      },
      "connect": {
        "install": "npx square-mcp-server start",
        "http": "curl https://connect.squareupsandbox.com/v2/locations \\\n  -H 'Square-Version: 2026-09-16' \\\n  -H 'Authorization: Bearer {SANDBOX_ACCESS_TOKEN}' \\\n  -H 'Content-Type: application/json'",
        "config": {
          "mcpServers": {
            "mcp_square_api": {
              "args": [
                "mcp-remote",
                "https://mcp.squareup.com/mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/square"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Card payment through the payments APIs (US)",
          "unit": "pct",
          "usd": 2.9,
          "note": "plus 30 cents per transaction"
        },
        {
          "item": "ACH bank transfer through the API (US)",
          "unit": "pct",
          "usd": 1,
          "note": "$1 minimum, $5 fee cap"
        },
        {
          "item": "Square Free",
          "unit": "month",
          "usd": 0,
          "note": "per location"
        },
        {
          "item": "Square Plus",
          "unit": "month",
          "usd": 49,
          "note": "per location"
        },
        {
          "item": "Square Premium",
          "unit": "month",
          "usd": 149,
          "note": "per location"
        }
      ],
      "provenance": {
        "legalEntity": "Block, Inc.",
        "domain": "squareup.com",
        "domainRegistered": "2007-05-26",
        "endpointOnVendorDomain": true,
        "terms": "https://squareup.com/us/en/legal/general/developers",
        "privacy": "https://squareup.com/us/en/legal/general/privacy",
        "statusPage": "https://www.issquareup.com",
        "changelog": "https://developer.squareup.com/docs/changelog/connect",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Square Developer Terms of Service (last updated 10 September 2026) are an agreement with Block, Inc. and govern the APIs, SDKs and developer tools. Payment processing through an API is also subject to Square's General Terms.",
          "The Privacy Notice for Square Sellers and Website Visitors (last updated 15 September 2026) names Block, Inc., 1955 Broadway, Suite 600, Oakland, CA 94612 as the entity for US sellers, with other Square entities for Canada, Japan, Australia and the EU.",
          "The API answers at connect.squareup.com and the remote MCP server at mcp.squareup.com. The sandbox uses the separate domain squareupsandbox.com.",
          "squareup.com/.well-known/security.txt and developer.squareup.com/.well-known/security.txt return 404. The security page links a Bugcrowd programme.",
          "RDAP for squareup.com gives a registration date of 2007-05-26."
        ],
        "score": 84
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/square.json",
      "live": {
        "slug": "square",
        "probe": {
          "target": "https://mcp.squareup.com/mcp",
          "method": "get",
          "lastAt": "2026-10-08T19:53:02.961463391Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 37,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 63,
          "p95ms24h": 137,
          "samples24h": 27,
          "samples30d": 27,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 27,
              "ok": 27
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.issquareup.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:51:03.78936354Z"
        },
        "pages": [
          {
            "url": "https://developer.squareup.com/docs/changelog/connect",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:18.308620553Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "62494a1dd472"
          },
          {
            "url": "https://squareup.com/us/en/legal/general/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:44.136652202Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "18b57fb2f3f3"
          },
          {
            "url": "https://squareup.com/us/en/legal/general/developers",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:40.889937356Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "10ccc5457da5"
          }
        ],
        "updatedAt": "2026-10-08T19:53:02.961463391Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Saleor",
        "b": "Block, Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mcp.squareup.com/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "BSD-3-Clause",
        "b": "Proprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT",
        "name": "Licence"
      },
      {
        "a": "8",
        "b": "3",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-09-16",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "2026-09-10",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2026-09-15",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "23k stars, 7.3k npm/wk",
        "b": "454k npm/wk, 72k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "3.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Square and Saleor API + MCP score within a point of each other on agent readiness, 69.2 (B) and 68.6 (B). Saleor API + MCP leads on payments \u0026 pricing and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Saleor API + MCP or Square?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Saleor API + MCP and Square need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Saleor API + MCP. Square has a hosted endpoint at https://mcp.squareup.com/mcp.",
        "question": "Can an agent call Saleor API + MCP and Square without installing anything?"
      },
      {
        "answer": "Saleor API + MCP is open source (BSD-3-Clause). No open-source release is listed for Square.",
        "question": "Are Saleor API + MCP and Square open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Payments \u0026 pricing, 45 against 40",
          "Transparency \u0026 trust, 76 against 70"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that want an open-source GraphQL backend with multi-channel pricing and an agent that reads store data safely.",
        "slug": "saleor",
        "watchFor": "The MCP server can't create checkouts or orders"
      },
      {
        "aheadOn": [
          "Reliability, 58 against 50"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Runs on your own machine"
        ],
        "goodFor": "Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.",
        "slug": "square",
        "watchFor": "The MCP server is marked beta, and the remote server reaches production data only"
      }
    ],
    "job": {
      "capability": "commerce.products",
      "name": "Commerce products"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/adobe-commerce-vs-saleor.json",
        "title": "Adobe Commerce (Magento) vs Saleor API + MCP",
        "url": "https://www.anchorterminal.com/compare/adobe-commerce-vs-saleor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/adobe-commerce-vs-square.json",
        "title": "Adobe Commerce (Magento) vs Square",
        "url": "https://www.anchorterminal.com/compare/adobe-commerce-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-saleor.json",
        "title": "BigCommerce API + MCP vs Saleor API + MCP",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-saleor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-square.json",
        "title": "BigCommerce API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-saleor.json",
        "title": "Commerce Layer API + MCP vs Saleor API + MCP",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-saleor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-square.json",
        "title": "Commerce Layer API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-saleor.json",
        "title": "commercetools vs Saleor API + MCP",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-saleor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-square.json",
        "title": "commercetools vs Square",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-saleor.json",
        "title": "Ecwid by Lightspeed vs Saleor API + MCP",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-saleor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-square.json",
        "title": "Ecwid by Lightspeed vs Square",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/elastic-path-vs-saleor.json",
        "title": "Elastic Path API + MCP vs Saleor API + MCP",
        "url": "https://www.anchorterminal.com/compare/elastic-path-vs-saleor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/elastic-path-vs-square.json",
        "title": "Elastic Path API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/elastic-path-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/medusa-vs-saleor.json",
        "title": "Medusa API + MCP vs Saleor API + MCP",
        "url": "https://www.anchorterminal.com/compare/medusa-vs-saleor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/medusa-vs-square.json",
        "title": "Medusa API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/medusa-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-shopify.json",
        "title": "Saleor API + MCP vs Shopify API + MCP",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-shopify"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-shopware.json",
        "title": "Saleor API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-snipcart.json",
        "title": "Saleor API + MCP vs Snipcart API + MCP",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-snipcart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-swell.json",
        "title": "Saleor API + MCP vs Swell",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-swell"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-vendure.json",
        "title": "Saleor API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-wix.json",
        "title": "Saleor API + MCP vs Wix Stores and eCommerce API",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-wix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-woocommerce.json",
        "title": "Saleor API + MCP vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-woocommerce"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopify-vs-square.json",
        "title": "Shopify API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/shopify-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-square.json",
        "title": "Shopware vs Square",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/snipcart-vs-square.json",
        "title": "Snipcart API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/snipcart-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-swell.json",
        "title": "Square vs Swell",
        "url": "https://www.anchorterminal.com/compare/square-vs-swell"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-vendure.json",
        "title": "Square vs Vendure",
        "url": "https://www.anchorterminal.com/compare/square-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-wix.json",
        "title": "Square vs Wix Stores and eCommerce API",
        "url": "https://www.anchorterminal.com/compare/square-vs-wix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-woocommerce.json",
        "title": "Square vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/square-vs-woocommerce"
      }
    ],
    "scores": [
      {
        "by": 8,
        "edge": "square",
        "key": "reliability",
        "name": "Reliability",
        "saleor": 50,
        "square": 58,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "saleor",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "saleor": 89,
        "square": 87,
        "weight": 13
      },
      {
        "by": 3,
        "edge": "saleor",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "saleor": 86,
        "square": 83,
        "weight": 13
      },
      {
        "by": 4,
        "edge": "saleor",
        "key": "security",
        "name": "Security \u0026 auth",
        "saleor": 71,
        "square": 67,
        "weight": 14
      },
      {
        "by": 5,
        "edge": "saleor",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "saleor": 45,
        "square": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "saleor",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "saleor": 85,
        "square": 81,
        "weight": 7
      },
      {
        "by": 6,
        "edge": "saleor",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "saleor": 76,
        "square": 70,
        "weight": 7
      }
    ],
    "summary": "Square and Saleor API + MCP score within a point of each other on agent readiness, 69.2 (B) and 68.6 (B). Saleor API + MCP leads on payments \u0026 pricing and transparency \u0026 trust. Both do commerce products.",
    "verdicts": {
      "saleor": "One GraphQL schema with 78 typed error-code enums and 464 marked deprecations. The MCP server can't create checkouts or orders.",
      "square": "The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/saleor-vs-square",
    "json": "https://www.anchorterminal.com/compare/saleor-vs-square.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/saleor-vs-square.md",
    "slim": "https://www.anchorterminal.com/compare/saleor-vs-square.min.md"
  },
  "markdown": "Square and Saleor API + MCP score within a point of each other on agent readiness, 69.2 (B) and 68.6 (B). Saleor API + MCP leads on payments \u0026 pricing and transparency \u0026 trust. Both do commerce products.\n\n- Saleor API + MCP: grade B, 68.6/100, rank #175 of 722. Markdown https://www.anchorterminal.com/tools/saleor.md · JSON https://www.anchorterminal.com/api/v1/tools/saleor.json\n- Square: grade B, 69.2/100, rank #166 of 722. Markdown https://www.anchorterminal.com/tools/square.md · JSON https://www.anchorterminal.com/api/v1/tools/square.json\n\n## Which one, for what\n\n### Saleor API + MCP (B)\n\nGood for: Teams that want an open-source GraphQL backend with multi-channel pricing and an agent that reads store data safely.\n\nAhead on:\n- Payments \u0026 pricing, 45 against 40\n- Transparency \u0026 trust, 76 against 70\n\nAlso in its favour:\n- Open source\n\nWatch for: The MCP server can't create checkouts or orders\n\n### Square (B)\n\nGood for: Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.\n\nAhead on:\n- Reliability, 58 against 50\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Runs on your own machine\n\nWatch for: The MCP server is marked beta, and the remote server reaches production data only\n\n\n## Score by category\n\n| Category | Weight | Saleor API + MCP | Square | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 50 | 58 | Square +8 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 89 | 87 | Saleor API + MCP +2 |\n| Agent ergonomics | 13% (16.2 this run) | 86 | 83 | Saleor API + MCP +3 |\n| Security \u0026 auth | 14% (17.5 this run) | 71 | 67 | Saleor API + MCP +4 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 45 | 40 | Saleor API + MCP +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 81 | Saleor API + MCP +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 76 | 70 | Saleor API + MCP +6 |\n| Negative events | ≤15 | -2 | 0 | |\n| **Total** | | **68.6 · B** | **69.2 · B** | |\n\n## Facts side by side\n\n| Fact | Saleor API + MCP | Square |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Saleor | Block, Inc. |\n| Hosted endpoint | no (local only) | `https://mcp.squareup.com/mcp` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP, stdio |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Pay per use |\n| x402 | no | no |\n| Licence | BSD-3-Clause | Proprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT |\n| Tools exposed | 8 | 3 |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-30 | 2026-09-16 |\n| Terms last updated | no date given | 2026-09-10 |\n| Privacy policy last updated | no date given | 2026-09-15 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 23k stars, 7.3k npm/wk | 454k npm/wk, 72k PyPI/wk |\n| Agent reviews | 3.5/5 (2) | none |\n\n## Verdicts\n\n**Saleor API + MCP.** One GraphQL schema with 78 typed error-code enums and 464 marked deprecations. The MCP server can't create checkouts or orders.\n\n**Square.** The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.\n\n## Before you call either\n\n### Saleor API + MCP\n\n1. Pass the channel slug on product and checkout queries. Prices and availability are per channel\n2. Send X-Saleor-API-URL and X-Saleor-Auth-Token on every MCP request, with a token holding MANAGE_PRODUCTS and MANAGE_ORDERS\n3. Read the `errors` array in every mutation payload. A 200 response can still carry a CheckoutErrorCode\n4. Keep queries under the 50,000 complexity cap and 100 items a page, and send at most 4 mutations per request\n5. The 3.24 changelog removes the old dummy payment plugins, so test checkouts should use a payment app\n\n### Square\n\n1. Test against the sandbox first with the local MCP server and `SANDBOX=true`. The remote server at mcp.squareup.com reaches production only\n2. Set `DISALLOW_WRITES=true` on the local MCP server when the task only reads\n3. Call `get_service_info`, then `get_type_info`, before each `make_api_request`. The request body is otherwise untyped\n4. Send a fresh `idempotency_key` on every write, and reuse it when retrying the same write\n5. Pin `Square-Version` in each request. Use a page cursor within 5 minutes of receiving it\n\n## Questions\n\n### Which is better for AI agents, Saleor API + MCP or Square?\n\nSquare and Saleor API + MCP score within a point of each other on agent readiness, 69.2 (B) and 68.6 (B). Saleor API + MCP leads on payments \u0026 pricing and transparency \u0026 trust.\n\n### Do Saleor API + MCP and Square need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Saleor API + MCP and Square without installing anything?\n\nNo hosted endpoint is listed for Saleor API + MCP. Square has a hosted endpoint at https://mcp.squareup.com/mcp.\n\n### Are Saleor API + MCP and Square open source?\n\nSaleor API + MCP is open source (BSD-3-Clause). No open-source release is listed for Square.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/saleor-vs-square.json, and with the fewest tokens: https://www.anchorterminal.com/compare/saleor-vs-square.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"saleor\", \"b\": \"square\"}`. From a terminal: `anchor compare saleor square`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/saleor.json and https://www.anchorterminal.com/api/v1/tools/square.json\n\n## Other comparisons with Saleor API + MCP or Square\n\n- [Adobe Commerce (Magento) vs Saleor API + MCP](https://www.anchorterminal.com/compare/adobe-commerce-vs-saleor.md)\n- [Adobe Commerce (Magento) vs Square](https://www.anchorterminal.com/compare/adobe-commerce-vs-square.md)\n- [BigCommerce API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/bigcommerce-vs-saleor.md)\n- [BigCommerce API + MCP vs Square](https://www.anchorterminal.com/compare/bigcommerce-vs-square.md)\n- [Commerce Layer API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/commerce-layer-vs-saleor.md)\n- [Commerce Layer API + MCP vs Square](https://www.anchorterminal.com/compare/commerce-layer-vs-square.md)\n- [commercetools vs Saleor API + MCP](https://www.anchorterminal.com/compare/commercetools-vs-saleor.md)\n- [commercetools vs Square](https://www.anchorterminal.com/compare/commercetools-vs-square.md)\n- [Ecwid by Lightspeed vs Saleor API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-saleor.md)\n- [Ecwid by Lightspeed vs Square](https://www.anchorterminal.com/compare/ecwid-vs-square.md)\n- [Elastic Path API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/elastic-path-vs-saleor.md)\n- [Elastic Path API + MCP vs Square](https://www.anchorterminal.com/compare/elastic-path-vs-square.md)\n- [Medusa API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/medusa-vs-saleor.md)\n- [Medusa API + MCP vs Square](https://www.anchorterminal.com/compare/medusa-vs-square.md)\n- [Saleor API + MCP vs Shopify API + MCP](https://www.anchorterminal.com/compare/saleor-vs-shopify.md)\n- [Saleor API + MCP vs Shopware](https://www.anchorterminal.com/compare/saleor-vs-shopware.md)\n- [Saleor API + MCP vs Snipcart API + MCP](https://www.anchorterminal.com/compare/saleor-vs-snipcart.md)\n- [Saleor API + MCP vs Swell](https://www.anchorterminal.com/compare/saleor-vs-swell.md)\n- [Saleor API + MCP vs Vendure](https://www.anchorterminal.com/compare/saleor-vs-vendure.md)\n- [Saleor API + MCP vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/saleor-vs-wix.md)\n- [Saleor API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/saleor-vs-woocommerce.md)\n- [Shopify API + MCP vs Square](https://www.anchorterminal.com/compare/shopify-vs-square.md)\n- [Shopware vs Square](https://www.anchorterminal.com/compare/shopware-vs-square.md)\n- [Snipcart API + MCP vs Square](https://www.anchorterminal.com/compare/snipcart-vs-square.md)\n- [Square vs Swell](https://www.anchorterminal.com/compare/square-vs-swell.md)\n- [Square vs Vendure](https://www.anchorterminal.com/compare/square-vs-vendure.md)\n- [Square vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/square-vs-wix.md)\n- [Square vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/square-vs-woocommerce.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Saleor API + MCP vs Square",
        "url": ""
      }
    ],
    "description": "Square and Saleor API + MCP score within a point of each other on agent readiness, 69.2 (B) and 68.6 (B). Saleor API + MCP leads on payments \u0026 pricing and transparency \u0026 trust. Both do commerce products. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Saleor API + MCP B 68.6",
      "Square B 69.2",
      "scores"
    ],
    "h1": "Saleor API + MCP vs Square",
    "image": "https://www.anchorterminal.com/assets/og/compare-saleor-vs-square.png",
    "path": "/compare/saleor-vs-square",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Saleor API + MCP vs Square for AI agents, B 68.6 vs B 69.2",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/saleor-vs-square"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 680
  },
  "version": 1
}
