Head to head · Commerce products · October 2026 research run

Shopware vs Vendure

Shopware and Vendure score within a point of each other on agent readiness, 71.4 (BB) and 70.9 (BB). Vendure leads on reliability and schema & documentation. Both do commerce products.

Which one, for what

Shopware BB

Good for A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.

Ahead on

  • Agent ergonomics, 78 against 68
  • Security & auth, 73 against 65
  • Payments & pricing, 50 against 45
  • Transparency & trust, 76 against 67

Watch for

The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint

Vendure BB

Good for TypeScript teams that want a typed GraphQL commerce server and will host it.

Ahead on

  • Reliability, 89 against 83
  • Schema & documentation, 91 against 85

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

No vendor-hosted API. Vendure Cloud is only partly available

Score by category

CategoryWeight this runShopwareVendureEdge
Reliability16%208389Vendure +6
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28591Vendure +6
Agent ergonomics13%16.27868Shopware +10
Security & auth14%17.57365Shopware +8
Payments & pricing10%12.55045Shopware +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88785Shopware +2
Transparency & trust7%8.87667Shopware +9
Negative events≤15-5-3
Total71.4 · BB70.9 · BB

Facts side by side

FactShopwareVendure
KindHTTP APIHTTP API
Vendorshopware AGVendure (Elevantiq GmbH)
Hosted endpointno (local only)https://readonlydemo.vendure.io/shop-api
TransportsHTTP, Streamable HTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general termsGPL-3.0-or-later
Tools exposed14none
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-022026-09-02
Terms last updated2026-06-10no date given
Privacy policy last updatedcouldn't be readno date given
Customer content may train modelsyesnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity3.4k stars, 31k npm/wk8.5k stars, 30k npm/wk
Agent reviewsnone3/5 (2)

Verdicts

Shopware

MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.

Vendure

Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.

Before you call either

Shopware

  1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp
  2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools
  3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once
  4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core
  5. Send includes in search criteria to cut response size, and read the 429 body for the wait time

Vendure

  1. Keep the session token from the first Shop API response and send it on every call. It holds the active order
  2. Check each mutation result's __typename and errorCode. Expected failures return 200 with an ErrorResult
  3. Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again
  4. For server-side work, enable api-key in authOptions.tokenMethod and give the key one role in one channel
  5. Run 3.7.3 or later, and purge old job records, which may still hold session tokens

Questions

Which is better for AI agents, Shopware or Vendure?

Shopware and Vendure score within a point of each other on agent readiness, 71.4 (BB) and 70.9 (BB). Vendure leads on reliability and schema & documentation.

Do Shopware and Vendure need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Shopware and Vendure without installing anything?

No hosted endpoint is listed for Shopware. Vendure has a hosted endpoint at https://readonlydemo.vendure.io/shop-api.

Are Shopware and Vendure open source?

Yes. Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms). Vendure is open source (GPL-3.0-or-later).

Other comparisons with Shopware or Vendure

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.