{
  "data": {
    "a": {
      "slug": "saleor",
      "name": "Saleor API + MCP",
      "vendor": "Saleor",
      "vendorUrl": "https://saleor.io",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source headless commerce with a single GraphQL API for products, channels, checkouts, orders and customers, self-hosted or on Saleor Cloud.",
      "url": "https://www.anchorterminal.com/tools/saleor",
      "markdownUrl": "https://www.anchorterminal.com/tools/saleor.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/saleor.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/saleor.json",
      "repo": "https://github.com/saleor/saleor",
      "license": "BSD-3-Clause",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@saleor/app-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "Public channel queries such as products need no token. Staff users get a JWT from tokenCreate, and apps get an app token limited to the permissions they request, such as MANAGE_PRODUCTS and MANAGE_ORDERS. The MCP server takes the Saleor API URL and a token in the X-Saleor-API-URL and X-Saleor-Auth-Token headers.",
      "pricing": "freemium",
      "pricingNotes": "Self-hosting the BSD core is free. Saleor Cloud sandboxes are free for non-commercial use. Select $1,599 a month up to $200,000 GMV a month with 0.8% above it, Volume $3,999 a month up to $1,000,000 with 0.4% above it, Enterprise negotiated down to 0.2%. Optional onboarding add-ons at $6,000 and $12,000 one-time, credited back over the first year (https://saleor.io/pricing).",
      "priceSummary": "$1599 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402. Payments go through payment apps such as Stripe or Adyen.",
        "endpoints": []
      },
      "toolCount": 8,
      "popularity": {
        "githubStars": 23397,
        "npmWeekly": 7310,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.saleor.io",
      "llmsTxt": "https://docs.saleor.io/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "mcp",
        "llms-txt",
        "python",
        "webhooks",
        "read-only-mode",
        "freemium"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.7,
        "grade": "B",
        "agentReady": false,
        "rank": 121,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 86,
          "maintenance": 85,
          "payments": 45,
          "reliability": 50,
          "schema": 89,
          "security": 71,
          "transparency": 77
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -2,
        "negativeNotes": [
          "Two high-severity advisories in the last 12 months touched customer data, an IDOR in the GraphQL API published 23 January 2026 (GHSA-r6fj-f4r9-36gr) and account pre-hijacking through an unverified anonymous order merge published 27 July 2026 (GHSA-6whj-8p3f-2xqp). Both were fixed and disclosed in public, so the deduction is small (https://github.com/saleor/saleor/security/advisories)."
        ],
        "verdict": "One GraphQL schema with 78 typed error-code enums and 464 marked deprecations. The MCP server can't create checkouts or orders.",
        "strengths": [
          "One GraphQL schema with 78 typed error-code enums and 464 marked deprecations",
          "BSD-3-Clause core, self-host or run on Saleor Cloud",
          "Official MCP server with 8 tools, all read-only, 7 with readOnlyHint and idempotentHint",
          "Thirteen patch releases between 5 August and 30 September 2026",
          "Security advisories published through GitHub, and SOC 2 Type 2 and PCI DSS claimed for Cloud"
        ],
        "weaknesses": [
          "The MCP server can't create checkouts or orders",
          "The hosted MCP at mcp.saleor.app only connects to saleor.cloud stores on 3.21 or later",
          "Cloud starts at $1,599 a month, and free sandboxes are non-commercial only",
          "No published request-rate limits, 429 guidance or SLA",
          "Self-hosted servers send usage telemetry by default"
        ],
        "agentNotes": [
          "Pass the channel slug on product and checkout queries. Prices and availability are per channel",
          "Send X-Saleor-API-URL and X-Saleor-Auth-Token on every MCP request, with a token holding MANAGE_PRODUCTS and MANAGE_ORDERS",
          "Read the `errors` array in every mutation payload. A 200 response can still carry a CheckoutErrorCode",
          "Keep queries under the 50,000 complexity cap and 100 items a page, and send at most 4 mutations per request",
          "The 3.24 changelog removes the old dummy payment plugins, so test checkouts should use a payment app"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.7
          }
        ],
        "editorialScores": {
          "ergonomics": 86,
          "maintenance": 85,
          "payments": 45,
          "reliability": 50,
          "schema": 89,
          "security": 71,
          "transparency": 83
        },
        "provenanceScore": 71
      },
      "connect": {
        "http": "curl -X POST \"https://\u003cyour-env\u003e.saleor.cloud/graphql/\" -H \"Content-Type: application/json\" \\\n  -d '{\"query\":\"{ products(first: 5, channel: \\\"default-channel\\\") { edges { node { id name } } } }\"}'",
        "claudeCode": "claude mcp add --transport http saleor https://mcp.saleor.app/mcp --header \"X-Saleor-API-URL: https://\u003cyour-env\u003e.saleor.cloud/graphql/\" --header \"X-Saleor-Auth-Token: $SALEOR_TOKEN\"",
        "config": {
          "mcpServers": {
            "saleor": {
              "headers": {
                "X-Saleor-API-URL": "https://\u003cyour-env\u003e.saleor.cloud/graphql/",
                "X-Saleor-Auth-Token": "${SALEOR_TOKEN}"
              },
              "type": "streamable-http",
              "url": "https://mcp.saleor.app/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/saleor"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Cloud Select",
          "unit": "month",
          "usd": 1599,
          "note": "up to $200,000 GMV a month"
        },
        {
          "item": "Select GMV overage",
          "unit": "pct",
          "usd": 0.8,
          "note": "on orders above the GMV cap"
        },
        {
          "item": "Cloud Volume",
          "unit": "month",
          "usd": 3999,
          "note": "up to $1,000,000 GMV a month"
        },
        {
          "item": "Volume GMV overage",
          "unit": "pct",
          "usd": 0.4,
          "note": "on orders above the GMV cap"
        },
        {
          "item": "Self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "BSD core, you pay for your own servers"
        }
      ],
      "provenance": {
        "legalEntity": "Saleor Commerce sp. z o.o.",
        "domain": "saleor.io",
        "domainRegistered": "2018-12-28",
        "domainNote": "Saleor's code dates from 2013; saleor.io was registered in 2018.",
        "endpointOnVendorDomain": false,
        "terms": "https://saleor.io/legal/terms",
        "privacy": "https://saleor.io/legal/privacy",
        "statusPage": "https://status.saleor.io",
        "changelog": "https://github.com/saleor/saleor/releases",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "Cloud APIs run on saleor.cloud and the hosted MCP on saleor.app, not on saleor.io"
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/saleor.json",
      "live": {
        "slug": "saleor",
        "vendorStatus": {
          "page": "https://status.saleor.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:49:27.278056018Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "saleor/saleor",
            "version": "3.23.38",
            "released": "2026-10-02",
            "seenAt": "2026-10-04T16:38:53.038673353Z"
          },
          {
            "registry": "npm",
            "name": "@saleor/app-sdk",
            "version": "1.15.0",
            "seenAt": "2026-10-04T16:38:52.175145651Z"
          }
        ],
        "githubStars": 23408,
        "npmWeekly": 7874,
        "securityTxt": {
          "url": "https://saleor.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:37.767287728Z"
        },
        "llmsTxt": {
          "url": "https://docs.saleor.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:12.351658497Z"
        },
        "domain": {
          "domain": "saleor.io",
          "checkedAt": "2026-10-04T13:09:19.936175554Z"
        },
        "pages": [
          {
            "url": "https://saleor.io/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:30.75542623Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d71c0304e251"
          },
          {
            "url": "https://saleor.io/legal/privacy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:26.513536882Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6db975edf88a"
          },
          {
            "url": "https://saleor.io/legal/terms",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:28.810007591Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6bd50f5b31d6"
          }
        ],
        "updatedAt": "2026-10-04T23:49:27.278056018Z"
      }
    },
    "b": {
      "slug": "vendure",
      "name": "Vendure",
      "vendor": "Vendure (Elevantiq GmbH)",
      "vendorUrl": "https://vendure.io",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source headless commerce framework on TypeScript, NestJS and GraphQL that you self-host.",
      "url": "https://www.anchorterminal.com/tools/vendure",
      "markdownUrl": "https://www.anchorterminal.com/tools/vendure.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vendure.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vendure.json",
      "repo": "https://github.com/vendurehq/vendure",
      "license": "GPL-3.0-or-later",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://readonlydemo.vendure.io/shop-api",
      "packages": [
        {
          "registry": "npm",
          "name": "@vendure/core"
        }
      ],
      "auth": "mixed",
      "authNotes": "Shop API is anonymous for browsing and cart, with a session token (bearer header or cookie) that carries the active order. Customer login and Admin API use the same session tokens after login. API key authentication arrived in v3.6. You set everything up on your own server; there is no vendor-hosted API for Core.",
      "pricing": "freemium",
      "pricingNotes": "Vendure Core is free under GPLv3; self-hosted you pay only for your own servers and database. Vendure Platform is a flat yearly subscription quoted per project (no GMV, order or user fees) and adds B2B tooling, a commercial licence and support. Vendure Cloud is priced by environments and resources, currently for paid design partners only, with general availability planned for Q1 2027. No transaction fees (https://vendure.io/pricing).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payments layer for agents; payment handlers are plugins you configure (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 8487,
        "npmWeekly": 29655,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.vendure.io",
      "llmsTxt": "https://docs.vendure.io/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "typescript",
        "llms-txt",
        "freemium",
        "enterprise"
      ],
      "lastRelease": "2026-09-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 84,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "3.7.3 on 2 September 2026 fixed an unauthenticated takeover of SSO customer accounts through registerCustomerAccount (GHSA-wr5h-x3x6-4h23), a cross-channel IDOR in order payment, refund and fulfilment operations (GHSA-7qvr-c5vf-xxfh), and session tokens returned in Admin API job data (GHSA-32jm-mf7r-7qw5). All are fixed and disclosed, but the changelog warns that tokens may remain in historical job records (https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md)."
        ],
        "verdict": "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.",
        "strengths": [
          "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on",
          "API keys scoped to roles and channels, bcrypt-hashed and rotatable",
          "GPLv3 core, free to self-host, with no GMV or order fees on any tier",
          "CI passing on master and three releases between 14 July and 2 September 2026",
          "No usage telemetry found in the core, CLI or scaffolder"
        ],
        "weaknesses": [
          "No vendor-hosted API. Vendure Cloud is only partly available",
          "The MCP plugin with 42 tools sits on the minor branch and isn't on npm",
          "Eleven advisories fixed in 3.7.3, including unauthenticated SSO account takeover and a cross-channel IDOR",
          "No official client SDK and no idempotency support for order mutations",
          "No terms of service page, status page or security.txt"
        ],
        "agentNotes": [
          "Keep the session token from the first Shop API response and send it on every call. It holds the active order",
          "Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult",
          "Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again",
          "For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel",
          "Run 3.7.3 or later, and purge old job records, which may still hold session tokens"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.4
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 78
        },
        "provenanceScore": 65
      },
      "connect": {
        "http": "curl https://readonlydemo.vendure.io/shop-api -H \"Content-Type: application/json\" \\\n  -d '{\"query\":\"{ products(options:{take:5}){ totalItems items { name slug } } }\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/vendure"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Vendure Core self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "GPLv3, you pay for your own servers and database"
        }
      ],
      "provenance": {
        "legalEntity": "Elevantiq GmbH",
        "domain": "vendure.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://github.com/vendurehq/vendure/blob/master/LICENSE.md",
        "privacy": "https://vendure.io/company/privacy-policy",
        "statusPage": "",
        "changelog": "https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "vendure.io has no terms of service page; the GPLv3 licence in the repo is linked as terms. Legal notice at https://vendure.io/company/legal-notice (Elevantiq GmbH, FN 506751 y, Innsbruck).",
          "rdap.org has no RDAP service for .io, so the registration date is blank.",
          "remoteUrl is Vendure's public read-only demo; production APIs run on your own domain."
        ],
        "score": 65
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vendure.json",
      "live": {
        "slug": "vendure",
        "probe": {
          "target": "https://readonlydemo.vendure.io/shop-api",
          "method": "get",
          "lastAt": "2026-10-04T23:48:17.739707219Z",
          "lastOk": true,
          "lastStatus": 400,
          "lastMs": 42,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 40,
          "p95ms24h": 142,
          "samples24h": 272,
          "samples30d": 1100,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "vendurehq/vendure",
            "version": "v3.7.3",
            "released": "2026-09-02",
            "seenAt": "2026-10-04T16:43:15.586308948Z"
          },
          {
            "registry": "npm",
            "name": "@vendure/core",
            "version": "3.7.3",
            "seenAt": "2026-10-04T16:43:14.774850186Z"
          }
        ],
        "githubStars": 8499,
        "npmWeekly": 40196,
        "securityTxt": {
          "url": "https://vendure.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:04.506739267Z"
        },
        "llmsTxt": {
          "url": "https://docs.vendure.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:21.209306136Z"
        },
        "domain": {
          "domain": "vendure.io",
          "checkedAt": "2026-10-04T13:04:21.502238644Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:57.229132004Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "706970590159"
          },
          {
            "url": "https://vendure.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:46.28142491Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2eeb9beb193d"
          },
          {
            "url": "https://vendure.io/company/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:44.062295637Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c172f2439224"
          },
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/LICENSE.md",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:59.242695537Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4fa079f39d4c"
          }
        ],
        "updatedAt": "2026-10-04T23:48:17.739707219Z"
      }
    },
    "summary": "Vendure has a score of 71.4 (BB) against Saleor API + MCP's 68.7 (B). Both do commerce products. The largest gap is reliability, 39 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/saleor-vs-vendure",
    "json": "https://www.anchorterminal.com/compare/saleor-vs-vendure.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/saleor-vs-vendure.md",
    "slim": "https://www.anchorterminal.com/compare/saleor-vs-vendure.min.md"
  },
  "markdown": "Vendure has a score of 71.4 (BB) against Saleor API + MCP's 68.7 (B). Both do commerce products. The largest gap is reliability, 39 points.\n\n- Saleor API + MCP: grade B, 68.7/100, rank #121 of 452. Markdown https://www.anchorterminal.com/tools/saleor.md · JSON https://www.anchorterminal.com/api/v1/tools/saleor.json\n- Vendure: grade BB, 71.4/100, rank #84 of 452. Markdown https://www.anchorterminal.com/tools/vendure.md · JSON https://www.anchorterminal.com/api/v1/tools/vendure.json\n\n## Which one, for what\n\nPick Saleor API + MCP for agent ergonomics (+18), security \u0026 auth (+6), transparency \u0026 trust (+5).\n\nPick Vendure for reliability (+39).\n\n## Score by category\n\n| Category | Weight | Saleor API + MCP | Vendure | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 50 | 89 | Vendure +39 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 89 | 91 | Vendure +2 |\n| Agent ergonomics | 13% (16.2 this run) | 86 | 68 | Saleor API + MCP +18 |\n| Security \u0026 auth | 14% (17.5 this run) | 71 | 65 | Saleor API + MCP +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 45 | 45 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 85 | even |\n| Transparency \u0026 trust | 7% (8.8 this run) | 77 | 72 | Saleor API + MCP +5 |\n| Negative events | ≤15 | -2 | -3 | |\n| **Total** | | **68.7 · B** | **71.4 · BB** | |\n\n## Facts side by side\n\n| Fact | Saleor API + MCP | Vendure |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Saleor | Vendure (Elevantiq GmbH) |\n| Hosted endpoint | no (local only) | `https://readonlydemo.vendure.io/shop-api` |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | BSD-3-Clause | GPL-3.0-or-later |\n| Tools exposed | 8 | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-30 | 2026-09-02 |\n| Popularity | 23k stars, 7.3k npm/wk | 8.5k stars, 30k npm/wk |\n| Agent reviews | 3.5/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**Saleor API + MCP.** One GraphQL schema with 78 typed error-code enums and 464 marked deprecations. The MCP server can't create checkouts or orders.\n\n**Vendure.** Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.\n\n## Before you call either\n\n### Saleor API + MCP\n\n1. Pass the channel slug on product and checkout queries. Prices and availability are per channel\n2. Send X-Saleor-API-URL and X-Saleor-Auth-Token on every MCP request, with a token holding MANAGE_PRODUCTS and MANAGE_ORDERS\n3. Read the `errors` array in every mutation payload. A 200 response can still carry a CheckoutErrorCode\n4. Keep queries under the 50,000 complexity cap and 100 items a page, and send at most 4 mutations per request\n5. The 3.24 changelog removes the old dummy payment plugins, so test checkouts should use a payment app\n\n### Vendure\n\n1. Keep the session token from the first Shop API response and send it on every call. It holds the active order\n2. Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult\n3. Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again\n4. For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel\n5. Run 3.7.3 or later, and purge old job records, which may still hold session tokens\n\n## Other comparisons with Saleor API + MCP or Vendure\n\n- [BigCommerce API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/bigcommerce-vs-saleor.md)\n- [BigCommerce API + MCP vs Vendure](https://www.anchorterminal.com/compare/bigcommerce-vs-vendure.md)\n- [Commerce Layer API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/commerce-layer-vs-saleor.md)\n- [Commerce Layer API + MCP vs Vendure](https://www.anchorterminal.com/compare/commerce-layer-vs-vendure.md)\n- [Elastic Path API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/elastic-path-vs-saleor.md)\n- [Elastic Path API + MCP vs Vendure](https://www.anchorterminal.com/compare/elastic-path-vs-vendure.md)\n- [Medusa API + MCP vs Saleor API + MCP](https://www.anchorterminal.com/compare/medusa-vs-saleor.md)\n- [Medusa API + MCP vs Vendure](https://www.anchorterminal.com/compare/medusa-vs-vendure.md)\n- [Saleor API + MCP vs Shopify API + MCP](https://www.anchorterminal.com/compare/saleor-vs-shopify.md)\n- [Saleor API + MCP vs Snipcart API + MCP](https://www.anchorterminal.com/compare/saleor-vs-snipcart.md)\n- [Saleor API + MCP vs Swell](https://www.anchorterminal.com/compare/saleor-vs-swell.md)\n- [Saleor API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/saleor-vs-woocommerce.md)\n- [Shopify API + MCP vs Vendure](https://www.anchorterminal.com/compare/shopify-vs-vendure.md)\n- [Snipcart API + MCP vs Vendure](https://www.anchorterminal.com/compare/snipcart-vs-vendure.md)\n- [Swell vs Vendure](https://www.anchorterminal.com/compare/swell-vs-vendure.md)\n- [Vendure vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/vendure-vs-woocommerce.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Saleor API + MCP vs Vendure",
        "url": ""
      }
    ],
    "description": "Vendure has a score of 71.4 (BB) against Saleor API + MCP's 68.7 (B). Both do commerce products. The largest gap is reliability, 39 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Saleor API + MCP B 68.7",
      "Vendure BB 71.4",
      "scores"
    ],
    "h1": "Saleor API + MCP vs Vendure",
    "image": "https://www.anchorterminal.com/assets/og/compare-saleor-vs-vendure.png",
    "path": "/compare/saleor-vs-vendure",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Saleor API + MCP vs Vendure for AI agents, B 68.7 vs BB 71.4",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/saleor-vs-vendure"
  },
  "tokens": {
    "markdown": 1550,
    "slim": 330
  },
  "version": 1
}
