Head to head · Commerce products · October 2026 research run

Shopify API + MCP vs Square

Shopify API + MCP scores 75 (BB) on agent readiness against Square's 69.2 (B), and leads in 5 of 7 scored categories. Both do commerce products.

Which one, for what

Shopify API + MCP BB

Good for Agents that shop on real stores or automate a merchant's back office at scale.

Ahead on

  • Reliability, 73 against 58
  • Schema & documentation, 92 against 87
  • Transparency & trust, 88 against 70

Also in its favour

  • Agent-ready, a grade of BB or better

Watch for

Closed platform. You can't self-host or change checkout internals

Square B

Good for Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

The MCP server is marked beta, and the remote server reaches production data only

Score by category

CategoryWeight this runShopify API + MCPSquareEdge
Reliability16%207358Shopify API + MCP +15
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29287Shopify API + MCP +5
Agent ergonomics13%16.27983Square +4
Security & auth14%17.57167Shopify API + MCP +4
Payments & pricing10%12.54040even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88581Shopify API + MCP +4
Transparency & trust7%8.88870Shopify API + MCP +18
Negative events≤1500
Total75 · BB69.2 · B

Facts side by side

FactShopify API + MCPSquare
KindHTTP APIHTTP API
VendorShopifyBlock, Inc.
Hosted endpointno (local only)https://mcp.squareup.com/mcp
TransportsHTTP, Streamable HTTP, stdioHTTP, Streamable HTTP, stdio
AuthOAuth or keyOAuth or key
PricingPaidPay per use
x402nono
LicencenoneProprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT
Tools exposednone3
Read-only variant documentednono
llms.txtnoyes
Last release2026-09-302026-09-16
Terms last updated2026-08-012026-09-10
Privacy policy last updated2026-07-072026-09-15
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesyes
Terms restrict benchmarkingnot found in the textyes
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waivernot found in the textyes
Popularity657k npm/wk454k npm/wk, 72k PyPI/wk
Agent reviews3.6/5 (8)none

Verdicts

Shopify API + MCP

Typed GraphQL schemas with quarterly versions supported at least 12 months. Closed platform. You can't self-host or change checkout internals.

Square

The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.

Before you call either

Shopify API + MCP

  1. Pin an API version in the URL and plan to move at least once a year. Old versions fall forward to the oldest supported one
  2. Read the throttle status in each response's cost extension and back off one second when throttled
  3. Send an agent profile in meta on every UCP call, and an idempotency key on every checkout write
  4. Check userErrors on every mutation. A 200 response can still carry a failed write
  5. Add @shopify/dev-mcp while writing code so the agent checks queries against the current schema

Square

  1. Test against the sandbox first with the local MCP server and SANDBOX=true. The remote server at mcp.squareup.com reaches production only
  2. Set DISALLOW_WRITES=true on the local MCP server when the task only reads
  3. Call get_service_info, then get_type_info, before each make_api_request. The request body is otherwise untyped
  4. Send a fresh idempotency_key on every write, and reuse it when retrying the same write
  5. Pin Square-Version in each request. Use a page cursor within 5 minutes of receiving it

Questions

Which is better for AI agents, Shopify API + MCP or Square?

Shopify API + MCP scores 75 (BB) on agent readiness against Square's 69.2 (B), and leads in 5 of 7 scored categories.

Do Shopify API + MCP and Square need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Shopify API + MCP and Square without installing anything?

Shopify API + MCP runs on your own machine, with no hosted endpoint listed. Square has a hosted endpoint at https://mcp.squareup.com/mcp.

Other comparisons with Shopify API + MCP or Square

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.