Head to head · Commerce products · October 2026 research run

Shopware vs Square

Shopware scores 71.4 (BB) on agent readiness against Square's 69.2 (B), and leads in 5 of 7 scored categories. Square leads on agent ergonomics. Both do commerce products.

Which one, for what

Shopware BB

Good for A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.

Ahead on

  • Reliability, 83 against 58
  • Security & auth, 73 against 67
  • Payments & pricing, 50 against 40
  • Maintenance & community, 87 against 81
  • Transparency & trust, 76 against 70

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source

Watch for

The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint

Square B

Good for Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.

Ahead on

  • Agent ergonomics, 83 against 78

Also in its favour

  • A hosted endpoint, with nothing to install
  • Runs on your own machine
  • No incidents deducted, where Shopware loses 5 points for them

Watch for

The MCP server is marked beta, and the remote server reaches production data only

Score by category

CategoryWeight this runShopwareSquareEdge
Reliability16%208358Shopware +25
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28587Square +2
Agent ergonomics13%16.27883Square +5
Security & auth14%17.57367Shopware +6
Payments & pricing10%12.55040Shopware +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88781Shopware +6
Transparency & trust7%8.87670Shopware +6
Negative events≤15-50
Total71.4 · BB69.2 · B

Facts side by side

FactShopwareSquare
KindHTTP APIHTTP API
Vendorshopware AGBlock, Inc.
Hosted endpointno (local only)https://mcp.squareup.com/mcp
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP, stdio
AuthOAuth or keyOAuth or key
PricingFreemiumPay per use
x402nono
LicenceMIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general termsProprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT
Tools exposed143
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-022026-09-16
Terms last updated2026-06-102026-09-10
Privacy policy last updatedcouldn't be read2026-09-15
Customer content may train modelsyesnot found in the text
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingyesyes
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textyes
Popularity3.4k stars, 31k npm/wk454k npm/wk, 72k PyPI/wk

Verdicts

Shopware

MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.

Square

The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.

Before you call either

Shopware

  1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp
  2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools
  3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once
  4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core
  5. Send includes in search criteria to cut response size, and read the 429 body for the wait time

Square

  1. Test against the sandbox first with the local MCP server and SANDBOX=true. The remote server at mcp.squareup.com reaches production only
  2. Set DISALLOW_WRITES=true on the local MCP server when the task only reads
  3. Call get_service_info, then get_type_info, before each make_api_request. The request body is otherwise untyped
  4. Send a fresh idempotency_key on every write, and reuse it when retrying the same write
  5. Pin Square-Version in each request. Use a page cursor within 5 minutes of receiving it

Questions

Which is better for AI agents, Shopware or Square?

Shopware scores 71.4 (BB) on agent readiness against Square's 69.2 (B), and leads in 5 of 7 scored categories. Square leads on agent ergonomics.

Do Shopware and Square need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Shopware and Square without installing anything?

No hosted endpoint is listed for Shopware. Square has a hosted endpoint at https://mcp.squareup.com/mcp.

Are Shopware and Square open source?

Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms). No open-source release is listed for Square.

Other comparisons with Shopware or Square

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.