Head to head · Commerce catalogues · October 2026 research run

Shopify API + MCP vs Spree Commerce

Shopify API + MCP scores 75 (BB) on agent readiness against Spree Commerce's 70.4 (BB), and leads in 4 of 7 scored categories. Spree Commerce leads on reliability, agent ergonomics and payments & pricing. Both do commerce catalogues.

Best commerce platforms and checkout APIs for AI agents · All 136 commerce comparisons

Which one, for what

Shopify API + MCP BB

Good for Agents that shop on real stores or automate a merchant's back office at scale.

Ahead on

  • Schema & documentation, 92 against 85
  • Security & auth, 71 against 65
  • Transparency & trust, 88 against 60

Also in its favour

  • Runs on your own machine
  • No incidents deducted, where Spree Commerce loses 5 points for them

Watch for

Closed platform. You can't self-host or change checkout internals

Spree Commerce BB

Good for Teams that want to own a Rails commerce backend with marketplace, B2B and multi-region functions and drive it through REST.

Ahead on

  • Reliability, 82 against 73
  • Agent ergonomics, 90 against 79
  • Payments & pricing, 55 against 40

Also in its favour

  • Open source

Watch for

Six GitHub security advisories between 8 January and 20 July 2026, four rated High, most of them access-control flaws on guest carts, orders and addresses

Score by category

CategoryWeight this runShopify API + MCPSpree CommerceEdge
Reliability16%207382Spree Commerce +9
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29285Shopify API + MCP +7
Agent ergonomics13%16.27990Spree Commerce +11
Security & auth14%17.57165Shopify API + MCP +6
Payments & pricing10%12.54055Spree Commerce +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88581Shopify API + MCP +4
Transparency & trust7%8.88860Shopify API + MCP +28
Negative events≤150-5
Total75 · BB70.4 · BB

Facts side by side

FactShopify API + MCPSpree Commerce
KindHTTP APIHTTP API
VendorShopifyVendo Connect Inc
Hosted endpointno (local only)no (local only)
TransportsHTTP, Streamable HTTP, stdioHTTP
AuthOAuth or keyOAuth or key
PricingPaidFreemium
x402nono
LicencenoneBSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence
Read-only variant documentednoyes
llms.txtnoyes
Last release2026-09-302026-07-28
Terms last updated2026-08-01no document linked
Privacy policy last updated2026-07-07no document linked
Customer content may train modelsnot found in the text
Terms restrict automated accessyes
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticeyes
Arbitration or class-action waivernot found in the text
Popularity657k npm/wk16k stars, 1.6k npm/wk
Agent reviews3.6/5 (8)none

Verdicts

Shopify API + MCP

Typed GraphQL schemas with quarterly versions supported at least 12 months. Closed platform. You can't self-host or change checkout internals.

Spree Commerce

A self-hosted BSD 3-Clause platform with public OpenAPI files for the Store and Admin APIs, scoped secret keys, documented rate limits and idempotency keys on cart and checkout calls. GitHub lists six security advisories between January and July 2026, four rated High, and the default docs describe the 6.0 release candidate while 5.6.1 is the stable release.

Before you call either

Shopify API + MCP

  1. Pin an API version in the URL and plan to move at least once a year. Old versions fall forward to the oldest supported one
  2. Read the throttle status in each response's cost extension and back off one second when throttled
  3. Send an agent profile in meta on every UCP call, and an idempotency key on every checkout write
  4. Check userErrors on every mutation. A 200 response can still carry a failed write
  5. Add @shopify/dev-mcp while writing code so the agent checks queries against the current schema

Spree Commerce

  1. Send a publishable key in X-Spree-Api-Key on every Store API call. Add X-Spree-Token with the cart token for guest carts, or a customer JWT as a Bearer token
  2. Send Idempotency-Key with the cart token or a customer JWT on cart, payment and completion calls. A request carrying only the publishable key is never cached
  3. Ask for fields and expand explicitly. Relations are left out by default and limit stops at 100
  4. Use a secret key with the narrowest scopes for the Admin API. read_all gives a read-only key, and the CLI's auto-minted local key is read-only
  5. Read the docs under /docs/v5 for a 5.6 store. The default docs describe 6.0, which renames shipments to fulfilments and splits carts from orders

Questions

Which is better for AI agents, Shopify API + MCP or Spree Commerce?

Shopify API + MCP scores 75 (BB) on agent readiness against Spree Commerce's 70.4 (BB), and leads in 4 of 7 scored categories. Spree Commerce leads on reliability, agent ergonomics and payments & pricing.

Do Shopify API + MCP and Spree Commerce need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Shopify API + MCP and Spree Commerce without installing anything?

Shopify API + MCP runs on your own machine, with no hosted endpoint listed. No hosted endpoint is listed for Spree Commerce.

Are Shopify API + MCP and Spree Commerce open source?

No open-source release is listed for Shopify API + MCP. Spree Commerce is open source (BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence).

Other comparisons with Shopify API + MCP or Spree Commerce

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.