{
  "data": {
    "a": {
      "slug": "shopware",
      "name": "Shopware",
      "vendor": "shopware AG",
      "vendorUrl": "https://www.shopware.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source commerce platform from shopware AG in Germany, written in PHP on Symfony. Agents reach a store through its Store API for shopping, its Admin API for back-office work, and a built-in MCP server on both.",
      "url": "https://www.anchorterminal.com/tools/shopware",
      "markdownUrl": "https://www.anchorterminal.com/tools/shopware.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shopware.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shopware.json",
      "repo": "https://github.com/shopware/shopware",
      "license": "MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "packagist",
          "name": "shopware/core"
        },
        {
          "registry": "npm",
          "name": "@shopware/api-client"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access comes from the merchant who runs the store, with no vendor review. The Admin API takes an OAuth 2.0 bearer token from /api/oauth/token, normally by client credentials from an integration created in Settings or with `bin/console integration:create`, and tokens last 10 minutes by default. An integration gets an ACL role, or full access with --admin. The MCP endpoint at /api/_mcp also accepts the integration's `sw-access-key` and `sw-secret-access-key` headers, and each integration and user has an MCP allowlist. The Store API takes the sales channel's `sw-access-key`, which is public in a headless shop, plus an `sw-context-token` for the cart and customer session.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is free under MIT with no account, so an agent's owner can start with `shopware-cli project create` and Docker, with no contract (the docs say no Shopware account is needed to install or run a store). Paid plans start at €600 a month for Rise and €2,400 for Evolve, excluding VAT, with Beyond on request, and the pricing page says the price depends on GMV. Shopware SaaS is priced the same as self-hosted. No trial of the paid plans was found on the pricing page (https://www.shopware.com/en/pricing/, checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the repository or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 14,
      "popularity": {
        "githubStars": 3400,
        "npmWeekly": 30917,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.shopware.com/docs/",
      "llmsTxt": "https://developer.shopware.com/llms.txt",
      "openapi": "https://github.com/shopware/shopware/tree/trunk/src/Core/Framework/Api/ApiDefinition/Generator/Schema",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "mcp",
        "openapi",
        "llms-txt",
        "oauth",
        "php",
        "typescript",
        "webhooks",
        "freemium",
        "eu",
        "bug-bounty",
        "iso27001",
        "beta"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 107,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 87,
          "payments": 50,
          "reliability": 83,
          "schema": 85,
          "security": 73,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -5,
        "negativeNotes": [
          "GitHub lists 20 security advisories for shopware/shopware published between 19 May and 16 September 2026, four of them critical (an app script sandbox escape, stored SQL injection through app manifests, admin account takeover by host-header poisoning and a webhook permission bypass), plus a pre-authentication SQL injection in the Store API (GHSA-p37c-pm9p-7vm5, CVSS 8.6, published 25 August 2026, fixed in 6.7.13.1 and 6.6.10.23). All were disclosed in public with fixed versions, so the deduction is 5 of a possible 15 (https://github.com/shopware/shopware/security/advisories)."
        ],
        "verdict": "MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.",
        "bestFor": "A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.",
        "strengths": [
          "MIT core, free to self-host, with security fixes for the 6.7 line promised until 28 February 2028 in releases.json",
          "Built-in MCP server advertises three discovery tools, and other tools load by toolset for the session",
          "MCP write tools default to dryRun=true, which runs the change in a transaction and rolls it back",
          "Per-integration ACL roles and MCP allowlists, with a 300 a minute limit on /api/_mcp",
          "OpenAPI 3 schemas for the Store API and Admin API in the repository, plus llms.txt and Markdown docs"
        ],
        "weaknesses": [
          "The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint",
          "20 advisories published between 19 May and 16 September 2026, four critical, including a pre-authentication SQL injection in the Store API",
          "MCP tools carry no readOnlyHint or destructiveHint annotations, and criteria and payloads travel as JSON-encoded strings",
          "A 429 from the MCP endpoints carries the wait time in the body, with no Retry-After header",
          "The Store API MCP endpoint ships one domain tool, has no allowlist, and the security.txt file expired on 31 December 2025"
        ],
        "agentNotes": [
          "Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp",
          "Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools",
          "Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once",
          "For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core",
          "Send `includes` in search criteria to cut response size, and read the 429 body for the wait time"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.4
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 87,
          "payments": 50,
          "reliability": 83,
          "schema": 85,
          "security": 73,
          "transparency": 80
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "npx @shopware-ag/shopware-cli project create my-shop",
        "http": "curl -X POST \"http://localhost:8000/api/search/product\" \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{}'",
        "claudeCode": "claude mcp add --transport http shopware http://localhost:8000/api/_mcp --header \"sw-access-key: SWIA...\" --header \"sw-secret-access-key: ...\"",
        "config": {
          "mcpServers": {
            "shopware": {
              "headers": {
                "sw-access-key": "SWIA...",
                "sw-secret-access-key": "..."
              },
              "type": "streamable-http",
              "url": "https://your-shop.example.com/api/_mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/shopware"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Community Edition",
          "unit": "month",
          "usd": 0,
          "note": "MIT core, you pay for your own hosting"
        }
      ],
      "provenance": {
        "legalEntity": "shopware AG",
        "domain": "shopware.com",
        "domainRegistered": "1998-08-08",
        "endpointOnVendorDomain": false,
        "terms": "https://www.shopware.com/en/gtc/",
        "privacy": "https://www.shopware.com/en/privacy/",
        "statusPage": "https://status.shopware.com",
        "changelog": "https://github.com/shopware/shopware/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The legal notice names shopware AG, Ebbinghoff 10, 48624 Schoeppingen, Germany, Amtsgericht Coesfeld HRB 11471.",
          "The general terms cover every product. Part 2 covers the free Community Edition and Part 4 covers SaaS, and only the German version is binding.",
          "The Store API, Admin API and MCP endpoints run on each merchant's own domain or SaaS shop, not on shopware.com.",
          "security.txt at www.shopware.com gives Expires 31 December 2025.",
          "www.shopware.com answered several requests with a 503 first byte timeout on 8 October 2026. The terms loaded on a retry and the privacy page loaded once.",
          "status.shopware.com covers Shopware SaaS, PaaS and vendor services, not self-hosted stores.",
          "Verisign RDAP gives a registration date of 1998-08-08 for shopware.com."
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shopware.json",
      "live": {
        "slug": "shopware",
        "vendorStatus": {
          "page": "https://status.shopware.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T17:51:12.427095822Z"
        },
        "pages": [
          {
            "url": "https://www.shopware.com/en/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:28.817122652Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a8eeb1d7324d"
          },
          {
            "url": "https://www.shopware.com/en/privacy/",
            "kind": "privacy",
            "status": 503,
            "checkedAt": "2026-10-08T18:30:30.769152247Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.shopware.com/en/gtc/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:26.06911646Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "034d628e8015"
          }
        ],
        "updatedAt": "2026-10-08T18:30:30.769152247Z"
      }
    },
    "answer": "Shopware scores 71.4 (BB) on agent readiness against Square's 69.2 (B), and leads in 5 of 7 scored categories. Square leads on agent ergonomics.",
    "b": {
      "slug": "square",
      "name": "Square",
      "vendor": "Block, Inc.",
      "vendorUrl": "https://squareup.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Square is Block's commerce and payments platform for sellers. Its REST API covers catalogue, orders, payment links, payments, inventory and customers, with seven SDKs and a beta MCP server hosted at mcp.squareup.com.",
      "url": "https://www.anchorterminal.com/tools/square",
      "markdownUrl": "https://www.anchorterminal.com/tools/square.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/square.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/square.json",
      "repo": "https://github.com/square/square-mcp-server",
      "license": "Proprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://mcp.squareup.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "square"
        },
        {
          "registry": "npm",
          "name": "square-mcp-server"
        },
        {
          "registry": "pypi",
          "name": "squareup"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access needs a Square account and an application created in the Developer Console, both self-serve. Two token types go in the `Authorization: Bearer` header. A personal access token gives unrestricted access to the owner's own account, with a separate sandbox token. OAuth access tokens are limited to the scopes a seller grants, expire after 30 days and can be refreshed and revoked. The remote MCP server signs in through OAuth, and Square keeps an allowlist of MCP clients that may register.",
      "pricing": "usage",
      "pricingNotes": "The API and sandbox carry no charge. Sellers pay processing fees, 2.9% + 30 cents for card payments through the payments APIs in the US. Square Free is $0 a month, Plus $49 and Premium $149 per location. The sandbox lets an agent start without a contract (https://squareup.com/us/en/payments/our-fees, checked 2026-10-08).",
      "priceSummary": "2.9% fee",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index at developer.squareup.com/llms.txt or the OpenAPI spec (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 453743,
        "pypiWeekly": 72138,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.squareup.com/docs",
      "llmsTxt": "https://developer.squareup.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/square/connect-api-specification/master/api.json",
      "capabilities": [
        "commerce.products",
        "commerce.orders",
        "commerce.checkout",
        "commerce.cart",
        "commerce.headless",
        "payments.card",
        "payments.checkout"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "graphql",
        "typescript",
        "python",
        "status-page",
        "bug-bounty"
      ],
      "lastRelease": "2026-09-16",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.2,
        "grade": "B",
        "agentReady": false,
        "rank": 156,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 81,
          "payments": 40,
          "reliability": 58,
          "schema": 87,
          "security": 67,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.",
        "bestFor": "Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.",
        "strengths": [
          "Public OpenAPI 3.0 spec with 332 operations and 1,476 schemas, regenerated for API version 2026-09-16",
          "OAuth scopes are split by read and write for each resource, and access tokens expire after 30 days",
          "78 request schemas carry an `idempotency_key`, and the docs describe backoff with jitter for 429 responses",
          "Free sandbox at connect.squareupsandbox.com with test cards, and API Logs kept for 28 days",
          "Deprecated APIs are typically retired at least 12 months after deprecation, with dated release notes each month"
        ],
        "weaknesses": [
          "The MCP server is marked beta, and the remote server reaches production data only",
          "No numeric rate limits were found for the REST API. Only GraphQL states a figure, 10 queries a second",
          "No SLA was found in the developer terms or documentation",
          "The status page recorded widespread latency and errors on 27 September 2026, including payment authorisation",
          "A personal access token grants unrestricted access to the whole Square account",
          "97 of the 332 operations in the spec are marked beta"
        ],
        "agentNotes": [
          "Test against the sandbox first with the local MCP server and `SANDBOX=true`. The remote server at mcp.squareup.com reaches production only",
          "Set `DISALLOW_WRITES=true` on the local MCP server when the task only reads",
          "Call `get_service_info`, then `get_type_info`, before each `make_api_request`. The request body is otherwise untyped",
          "Send a fresh `idempotency_key` on every write, and reuse it when retrying the same write",
          "Pin `Square-Version` in each request. Use a page cursor within 5 minutes of receiving it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.2
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 81,
          "payments": 40,
          "reliability": 58,
          "schema": 87,
          "security": 67,
          "transparency": 56
        },
        "provenanceScore": 84
      },
      "connect": {
        "install": "npx square-mcp-server start",
        "http": "curl https://connect.squareupsandbox.com/v2/locations \\\n  -H 'Square-Version: 2026-09-16' \\\n  -H 'Authorization: Bearer {SANDBOX_ACCESS_TOKEN}' \\\n  -H 'Content-Type: application/json'",
        "config": {
          "mcpServers": {
            "mcp_square_api": {
              "args": [
                "mcp-remote",
                "https://mcp.squareup.com/mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/square"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Card payment through the payments APIs (US)",
          "unit": "pct",
          "usd": 2.9,
          "note": "plus 30 cents per transaction"
        },
        {
          "item": "ACH bank transfer through the API (US)",
          "unit": "pct",
          "usd": 1,
          "note": "$1 minimum, $5 fee cap"
        },
        {
          "item": "Square Free",
          "unit": "month",
          "usd": 0,
          "note": "per location"
        },
        {
          "item": "Square Plus",
          "unit": "month",
          "usd": 49,
          "note": "per location"
        },
        {
          "item": "Square Premium",
          "unit": "month",
          "usd": 149,
          "note": "per location"
        }
      ],
      "provenance": {
        "legalEntity": "Block, Inc.",
        "domain": "squareup.com",
        "domainRegistered": "2007-05-26",
        "endpointOnVendorDomain": true,
        "terms": "https://squareup.com/us/en/legal/general/developers",
        "privacy": "https://squareup.com/us/en/legal/general/privacy",
        "statusPage": "https://www.issquareup.com",
        "changelog": "https://developer.squareup.com/docs/changelog/connect",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Square Developer Terms of Service (last updated 10 September 2026) are an agreement with Block, Inc. and govern the APIs, SDKs and developer tools. Payment processing through an API is also subject to Square's General Terms.",
          "The Privacy Notice for Square Sellers and Website Visitors (last updated 15 September 2026) names Block, Inc., 1955 Broadway, Suite 600, Oakland, CA 94612 as the entity for US sellers, with other Square entities for Canada, Japan, Australia and the EU.",
          "The API answers at connect.squareup.com and the remote MCP server at mcp.squareup.com. The sandbox uses the separate domain squareupsandbox.com.",
          "squareup.com/.well-known/security.txt and developer.squareup.com/.well-known/security.txt return 404. The security page links a Bugcrowd programme.",
          "RDAP for squareup.com gives a registration date of 2007-05-26."
        ],
        "score": 84
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/square.json",
      "live": {
        "slug": "square",
        "probe": {
          "target": "https://mcp.squareup.com/mcp",
          "method": "get",
          "lastAt": "2026-10-08T19:08:59.27689094Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 59,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 80,
          "p95ms24h": 137,
          "samples24h": 19,
          "samples30d": 19,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 19,
              "ok": 19
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.issquareup.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:59.998723569Z"
        },
        "pages": [
          {
            "url": "https://developer.squareup.com/docs/changelog/connect",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:18.308620553Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "62494a1dd472"
          },
          {
            "url": "https://squareup.com/us/en/legal/general/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:44.136652202Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "18b57fb2f3f3"
          },
          {
            "url": "https://squareup.com/us/en/legal/general/developers",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:40.889937356Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "10ccc5457da5"
          }
        ],
        "updatedAt": "2026-10-08T19:08:59.27689094Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "shopware AG",
        "b": "Block, Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mcp.squareup.com/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms",
        "b": "Proprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT",
        "name": "Licence"
      },
      {
        "a": "14",
        "b": "3",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-02",
        "b": "2026-09-16",
        "name": "Last release"
      },
      {
        "a": "2026-06-10",
        "b": "2026-09-10",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "2026-09-15",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "3.4k stars, 31k npm/wk",
        "b": "454k npm/wk, 72k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Shopware scores 71.4 (BB) on agent readiness against Square's 69.2 (B), and leads in 5 of 7 scored categories. Square leads on agent ergonomics.",
        "question": "Which is better for AI agents, Shopware or Square?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Shopware and Square need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Shopware. Square has a hosted endpoint at https://mcp.squareup.com/mcp.",
        "question": "Can an agent call Shopware and Square without installing anything?"
      },
      {
        "answer": "Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms). No open-source release is listed for Square.",
        "question": "Are Shopware and Square open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 83 against 58",
          "Security \u0026 auth, 73 against 67",
          "Payments \u0026 pricing, 50 against 40",
          "Maintenance \u0026 community, 87 against 81",
          "Transparency \u0026 trust, 76 against 70"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "Open source"
        ],
        "goodFor": "A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.",
        "slug": "shopware",
        "watchFor": "The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint"
      },
      {
        "aheadOn": [
          "Agent ergonomics, 83 against 78"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Runs on your own machine",
          "No incidents deducted, where Shopware loses 5 points for them"
        ],
        "goodFor": "Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.",
        "slug": "square",
        "watchFor": "The MCP server is marked beta, and the remote server reaches production data only"
      }
    ],
    "job": {
      "capability": "commerce.products",
      "name": "Commerce products"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-shopware.json",
        "title": "BigCommerce API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-square.json",
        "title": "BigCommerce API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-shopware.json",
        "title": "Commerce Layer API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-square.json",
        "title": "Commerce Layer API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-shopware.json",
        "title": "commercetools vs Shopware",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-square.json",
        "title": "commercetools vs Square",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/elastic-path-vs-shopware.json",
        "title": "Elastic Path API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/elastic-path-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/elastic-path-vs-square.json",
        "title": "Elastic Path API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/elastic-path-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/medusa-vs-shopware.json",
        "title": "Medusa API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/medusa-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/medusa-vs-square.json",
        "title": "Medusa API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/medusa-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-shopware.json",
        "title": "Saleor API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-square.json",
        "title": "Saleor API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopify-vs-shopware.json",
        "title": "Shopify API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/shopify-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopify-vs-square.json",
        "title": "Shopify API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/shopify-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-snipcart.json",
        "title": "Shopware vs Snipcart API + MCP",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-snipcart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-swell.json",
        "title": "Shopware vs Swell",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-swell"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-vendure.json",
        "title": "Shopware vs Vendure",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-woocommerce.json",
        "title": "Shopware vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-woocommerce"
      },
      {
        "json": "https://www.anchorterminal.com/compare/snipcart-vs-square.json",
        "title": "Snipcart API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/snipcart-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-swell.json",
        "title": "Square vs Swell",
        "url": "https://www.anchorterminal.com/compare/square-vs-swell"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-vendure.json",
        "title": "Square vs Vendure",
        "url": "https://www.anchorterminal.com/compare/square-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-woocommerce.json",
        "title": "Square vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/square-vs-woocommerce"
      }
    ],
    "scores": [
      {
        "by": 25,
        "edge": "shopware",
        "key": "reliability",
        "name": "Reliability",
        "shopware": 83,
        "square": 58,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "square",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "shopware": 85,
        "square": 87,
        "weight": 13
      },
      {
        "by": 5,
        "edge": "square",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "shopware": 78,
        "square": 83,
        "weight": 13
      },
      {
        "by": 6,
        "edge": "shopware",
        "key": "security",
        "name": "Security \u0026 auth",
        "shopware": 73,
        "square": 67,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "shopware",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "shopware": 50,
        "square": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "edge": "shopware",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "shopware": 87,
        "square": 81,
        "weight": 7
      },
      {
        "by": 6,
        "edge": "shopware",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "shopware": 76,
        "square": 70,
        "weight": 7
      }
    ],
    "summary": "Shopware scores 71.4 (BB) on agent readiness against Square's 69.2 (B), and leads in 5 of 7 scored categories. Square leads on agent ergonomics. Both do commerce products.",
    "verdicts": {
      "shopware": "MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.",
      "square": "The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/shopware-vs-square",
    "json": "https://www.anchorterminal.com/compare/shopware-vs-square.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/shopware-vs-square.md",
    "slim": "https://www.anchorterminal.com/compare/shopware-vs-square.min.md"
  },
  "markdown": "Shopware scores 71.4 (BB) on agent readiness against Square's 69.2 (B), and leads in 5 of 7 scored categories. Square leads on agent ergonomics. Both do commerce products.\n\n- Shopware: grade BB, 71.4/100, rank #107 of 629. Markdown https://www.anchorterminal.com/tools/shopware.md · JSON https://www.anchorterminal.com/api/v1/tools/shopware.json\n- Square: grade B, 69.2/100, rank #156 of 629. Markdown https://www.anchorterminal.com/tools/square.md · JSON https://www.anchorterminal.com/api/v1/tools/square.json\n\n## Which one, for what\n\n### Shopware (BB)\n\nGood for: A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.\n\nAhead on:\n- Reliability, 83 against 58\n- Security \u0026 auth, 73 against 67\n- Payments \u0026 pricing, 50 against 40\n- Maintenance \u0026 community, 87 against 81\n- Transparency \u0026 trust, 76 against 70\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- Open source\n\nWatch for: The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint\n\n### Square (B)\n\nGood for: Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.\n\nAhead on:\n- Agent ergonomics, 83 against 78\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Runs on your own machine\n- No incidents deducted, where Shopware loses 5 points for them\n\nWatch for: The MCP server is marked beta, and the remote server reaches production data only\n\n\n## Score by category\n\n| Category | Weight | Shopware | Square | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 83 | 58 | Shopware +25 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 85 | 87 | Square +2 |\n| Agent ergonomics | 13% (16.2 this run) | 78 | 83 | Square +5 |\n| Security \u0026 auth | 14% (17.5 this run) | 73 | 67 | Shopware +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 40 | Shopware +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 87 | 81 | Shopware +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 76 | 70 | Shopware +6 |\n| Negative events | ≤15 | -5 | 0 | |\n| **Total** | | **71.4 · BB** | **69.2 · B** | |\n\n## Facts side by side\n\n| Fact | Shopware | Square |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | shopware AG | Block, Inc. |\n| Hosted endpoint | no (local only) | `https://mcp.squareup.com/mcp` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP, stdio |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Pay per use |\n| x402 | no | no |\n| Licence | MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms | Proprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT |\n| Tools exposed | 14 | 3 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-02 | 2026-09-16 |\n| Terms last updated | 2026-06-10 | 2026-09-10 |\n| Privacy policy last updated | couldn't be read | 2026-09-15 |\n| Customer content may train models | yes | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 3.4k stars, 31k npm/wk | 454k npm/wk, 72k PyPI/wk |\n\n## Verdicts\n\n**Shopware.** MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.\n\n**Square.** The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.\n\n## Before you call either\n\n### Shopware\n\n1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp\n2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools\n3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once\n4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core\n5. Send `includes` in search criteria to cut response size, and read the 429 body for the wait time\n\n### Square\n\n1. Test against the sandbox first with the local MCP server and `SANDBOX=true`. The remote server at mcp.squareup.com reaches production only\n2. Set `DISALLOW_WRITES=true` on the local MCP server when the task only reads\n3. Call `get_service_info`, then `get_type_info`, before each `make_api_request`. The request body is otherwise untyped\n4. Send a fresh `idempotency_key` on every write, and reuse it when retrying the same write\n5. Pin `Square-Version` in each request. Use a page cursor within 5 minutes of receiving it\n\n## Questions\n\n### Which is better for AI agents, Shopware or Square?\n\nShopware scores 71.4 (BB) on agent readiness against Square's 69.2 (B), and leads in 5 of 7 scored categories. Square leads on agent ergonomics.\n\n### Do Shopware and Square need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Shopware and Square without installing anything?\n\nNo hosted endpoint is listed for Shopware. Square has a hosted endpoint at https://mcp.squareup.com/mcp.\n\n### Are Shopware and Square open source?\n\nShopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms). No open-source release is listed for Square.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/shopware-vs-square.json, and with the fewest tokens: https://www.anchorterminal.com/compare/shopware-vs-square.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"shopware\", \"b\": \"square\"}`. From a terminal: `anchor compare shopware square`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/shopware.json and https://www.anchorterminal.com/api/v1/tools/square.json\n\n## Other comparisons with Shopware or Square\n\n- [BigCommerce API + MCP vs Shopware](https://www.anchorterminal.com/compare/bigcommerce-vs-shopware.md)\n- [BigCommerce API + MCP vs Square](https://www.anchorterminal.com/compare/bigcommerce-vs-square.md)\n- [Commerce Layer API + MCP vs Shopware](https://www.anchorterminal.com/compare/commerce-layer-vs-shopware.md)\n- [Commerce Layer API + MCP vs Square](https://www.anchorterminal.com/compare/commerce-layer-vs-square.md)\n- [commercetools vs Shopware](https://www.anchorterminal.com/compare/commercetools-vs-shopware.md)\n- [commercetools vs Square](https://www.anchorterminal.com/compare/commercetools-vs-square.md)\n- [Elastic Path API + MCP vs Shopware](https://www.anchorterminal.com/compare/elastic-path-vs-shopware.md)\n- [Elastic Path API + MCP vs Square](https://www.anchorterminal.com/compare/elastic-path-vs-square.md)\n- [Medusa API + MCP vs Shopware](https://www.anchorterminal.com/compare/medusa-vs-shopware.md)\n- [Medusa API + MCP vs Square](https://www.anchorterminal.com/compare/medusa-vs-square.md)\n- [Saleor API + MCP vs Shopware](https://www.anchorterminal.com/compare/saleor-vs-shopware.md)\n- [Saleor API + MCP vs Square](https://www.anchorterminal.com/compare/saleor-vs-square.md)\n- [Shopify API + MCP vs Shopware](https://www.anchorterminal.com/compare/shopify-vs-shopware.md)\n- [Shopify API + MCP vs Square](https://www.anchorterminal.com/compare/shopify-vs-square.md)\n- [Shopware vs Snipcart API + MCP](https://www.anchorterminal.com/compare/shopware-vs-snipcart.md)\n- [Shopware vs Swell](https://www.anchorterminal.com/compare/shopware-vs-swell.md)\n- [Shopware vs Vendure](https://www.anchorterminal.com/compare/shopware-vs-vendure.md)\n- [Shopware vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/shopware-vs-woocommerce.md)\n- [Snipcart API + MCP vs Square](https://www.anchorterminal.com/compare/snipcart-vs-square.md)\n- [Square vs Swell](https://www.anchorterminal.com/compare/square-vs-swell.md)\n- [Square vs Vendure](https://www.anchorterminal.com/compare/square-vs-vendure.md)\n- [Square vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/square-vs-woocommerce.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Shopware vs Square",
        "url": ""
      }
    ],
    "description": "Shopware scores 71.4 (BB) on agent readiness against Square's 69.2 (B), and leads in 5 of 7 scored categories. Square leads on agent ergonomics. Both do commerce products. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Shopware BB 71.4",
      "Square B 69.2",
      "scores"
    ],
    "h1": "Shopware vs Square",
    "image": "https://www.anchorterminal.com/assets/og/compare-shopware-vs-square.png",
    "path": "/compare/shopware-vs-square",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Shopware vs Square for AI agents, BB 71.4 vs B 69.2 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/shopware-vs-square"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 730
  },
  "version": 1
}
