Head to head · Commerce catalogues · October 2026 research run

Shopware vs Spree Commerce

Shopware scores 71.4 (BB) on agent readiness against Spree Commerce's 70.4 (BB), and leads in 4 of 7 scored categories. Spree Commerce leads on agent ergonomics and payments & pricing. Both do commerce catalogues.

Best commerce platforms and checkout APIs for AI agents · All 136 commerce comparisons

Which one, for what

Shopware BB

Good for A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.

Ahead on

  • Security & auth, 73 against 65
  • Maintenance & community, 87 against 81
  • Transparency & trust, 76 against 60

Watch for

The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint

Spree Commerce BB

Good for Teams that want to own a Rails commerce backend with marketplace, B2B and multi-region functions and drive it through REST.

Ahead on

  • Agent ergonomics, 90 against 78
  • Payments & pricing, 55 against 50

Watch for

Six GitHub security advisories between 8 January and 20 July 2026, four rated High, most of them access-control flaws on guest carts, orders and addresses

Score by category

CategoryWeight this runShopwareSpree CommerceEdge
Reliability16%208382Shopware +1
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28585even
Agent ergonomics13%16.27890Spree Commerce +12
Security & auth14%17.57365Shopware +8
Payments & pricing10%12.55055Spree Commerce +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88781Shopware +6
Transparency & trust7%8.87660Shopware +16
Negative events≤15-5-5
Total71.4 · BB70.4 · BB

Facts side by side

FactShopwareSpree Commerce
KindHTTP APIHTTP API
Vendorshopware AGVendo Connect Inc
Hosted endpointno (local only)no (local only)
TransportsHTTP, Streamable HTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general termsBSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence
Tools exposed14none
Read-only variant documentednoyes
llms.txtyesyes
Last release2026-10-022026-07-28
Terms last updated2026-06-10no document linked
Privacy policy last updatedcouldn't be readno document linked
Customer content may train modelsyes
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity3.4k stars, 31k npm/wk16k stars, 1.6k npm/wk

Verdicts

Shopware

MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.

Spree Commerce

A self-hosted BSD 3-Clause platform with public OpenAPI files for the Store and Admin APIs, scoped secret keys, documented rate limits and idempotency keys on cart and checkout calls. GitHub lists six security advisories between January and July 2026, four rated High, and the default docs describe the 6.0 release candidate while 5.6.1 is the stable release.

Before you call either

Shopware

  1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp
  2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools
  3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once
  4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core
  5. Send includes in search criteria to cut response size, and read the 429 body for the wait time

Spree Commerce

  1. Send a publishable key in X-Spree-Api-Key on every Store API call. Add X-Spree-Token with the cart token for guest carts, or a customer JWT as a Bearer token
  2. Send Idempotency-Key with the cart token or a customer JWT on cart, payment and completion calls. A request carrying only the publishable key is never cached
  3. Ask for fields and expand explicitly. Relations are left out by default and limit stops at 100
  4. Use a secret key with the narrowest scopes for the Admin API. read_all gives a read-only key, and the CLI's auto-minted local key is read-only
  5. Read the docs under /docs/v5 for a 5.6 store. The default docs describe 6.0, which renames shipments to fulfilments and splits carts from orders

Questions

Which is better for AI agents, Shopware or Spree Commerce?

Shopware scores 71.4 (BB) on agent readiness against Spree Commerce's 70.4 (BB), and leads in 4 of 7 scored categories. Spree Commerce leads on agent ergonomics and payments & pricing.

Do Shopware and Spree Commerce need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Shopware and Spree Commerce without installing anything?

No hosted endpoint is listed for Shopware. No hosted endpoint is listed for Spree Commerce.

Are Shopware and Spree Commerce open source?

Yes. Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms). Spree Commerce is open source (BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence).

Other comparisons with Shopware or Spree Commerce

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.