{
  "data": {
    "a": {
      "slug": "shopware",
      "name": "Shopware",
      "vendor": "shopware AG",
      "vendorUrl": "https://www.shopware.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source commerce platform from shopware AG in Germany, written in PHP on Symfony. Agents reach a store through its Store API for shopping, its Admin API for back-office work, and a built-in MCP server on both.",
      "url": "https://www.anchorterminal.com/tools/shopware",
      "markdownUrl": "https://www.anchorterminal.com/tools/shopware.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shopware.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shopware.json",
      "repo": "https://github.com/shopware/shopware",
      "license": "MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "packagist",
          "name": "shopware/core"
        },
        {
          "registry": "npm",
          "name": "@shopware/api-client"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access comes from the merchant who runs the store, with no vendor review. The Admin API takes an OAuth 2.0 bearer token from /api/oauth/token, normally by client credentials from an integration created in Settings or with `bin/console integration:create`, and tokens last 10 minutes by default. An integration gets an ACL role, or full access with --admin. The MCP endpoint at /api/_mcp also accepts the integration's `sw-access-key` and `sw-secret-access-key` headers, and each integration and user has an MCP allowlist. The Store API takes the sales channel's `sw-access-key`, which is public in a headless shop, plus an `sw-context-token` for the cart and customer session.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is free under MIT with no account, so an agent's owner can start with `shopware-cli project create` and Docker, with no contract (the docs say no Shopware account is needed to install or run a store). Paid plans start at €600 a month for Rise and €2,400 for Evolve, excluding VAT, with Beyond on request, and the pricing page says the price depends on GMV. Shopware SaaS is priced the same as self-hosted. No trial of the paid plans was found on the pricing page (https://www.shopware.com/en/pricing/, checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the repository or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 14,
      "popularity": {
        "githubStars": 3400,
        "npmWeekly": 30917,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.shopware.com/docs/",
      "llmsTxt": "https://developer.shopware.com/llms.txt",
      "openapi": "https://github.com/shopware/shopware/tree/trunk/src/Core/Framework/Api/ApiDefinition/Generator/Schema",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "mcp",
        "openapi",
        "llms-txt",
        "oauth",
        "php",
        "typescript",
        "webhooks",
        "freemium",
        "eu",
        "bug-bounty",
        "iso27001",
        "beta"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 107,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 87,
          "payments": 50,
          "reliability": 83,
          "schema": 85,
          "security": 73,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -5,
        "negativeNotes": [
          "GitHub lists 20 security advisories for shopware/shopware published between 19 May and 16 September 2026, four of them critical (an app script sandbox escape, stored SQL injection through app manifests, admin account takeover by host-header poisoning and a webhook permission bypass), plus a pre-authentication SQL injection in the Store API (GHSA-p37c-pm9p-7vm5, CVSS 8.6, published 25 August 2026, fixed in 6.7.13.1 and 6.6.10.23). All were disclosed in public with fixed versions, so the deduction is 5 of a possible 15 (https://github.com/shopware/shopware/security/advisories)."
        ],
        "verdict": "MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.",
        "bestFor": "A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.",
        "strengths": [
          "MIT core, free to self-host, with security fixes for the 6.7 line promised until 28 February 2028 in releases.json",
          "Built-in MCP server advertises three discovery tools, and other tools load by toolset for the session",
          "MCP write tools default to dryRun=true, which runs the change in a transaction and rolls it back",
          "Per-integration ACL roles and MCP allowlists, with a 300 a minute limit on /api/_mcp",
          "OpenAPI 3 schemas for the Store API and Admin API in the repository, plus llms.txt and Markdown docs"
        ],
        "weaknesses": [
          "The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint",
          "20 advisories published between 19 May and 16 September 2026, four critical, including a pre-authentication SQL injection in the Store API",
          "MCP tools carry no readOnlyHint or destructiveHint annotations, and criteria and payloads travel as JSON-encoded strings",
          "A 429 from the MCP endpoints carries the wait time in the body, with no Retry-After header",
          "The Store API MCP endpoint ships one domain tool, has no allowlist, and the security.txt file expired on 31 December 2025"
        ],
        "agentNotes": [
          "Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp",
          "Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools",
          "Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once",
          "For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core",
          "Send `includes` in search criteria to cut response size, and read the 429 body for the wait time"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.4
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 87,
          "payments": 50,
          "reliability": 83,
          "schema": 85,
          "security": 73,
          "transparency": 80
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "npx @shopware-ag/shopware-cli project create my-shop",
        "http": "curl -X POST \"http://localhost:8000/api/search/product\" \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{}'",
        "claudeCode": "claude mcp add --transport http shopware http://localhost:8000/api/_mcp --header \"sw-access-key: SWIA...\" --header \"sw-secret-access-key: ...\"",
        "config": {
          "mcpServers": {
            "shopware": {
              "headers": {
                "sw-access-key": "SWIA...",
                "sw-secret-access-key": "..."
              },
              "type": "streamable-http",
              "url": "https://your-shop.example.com/api/_mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/shopware"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Community Edition",
          "unit": "month",
          "usd": 0,
          "note": "MIT core, you pay for your own hosting"
        }
      ],
      "provenance": {
        "legalEntity": "shopware AG",
        "domain": "shopware.com",
        "domainRegistered": "1998-08-08",
        "endpointOnVendorDomain": false,
        "terms": "https://www.shopware.com/en/gtc/",
        "privacy": "https://www.shopware.com/en/privacy/",
        "statusPage": "https://status.shopware.com",
        "changelog": "https://github.com/shopware/shopware/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The legal notice names shopware AG, Ebbinghoff 10, 48624 Schoeppingen, Germany, Amtsgericht Coesfeld HRB 11471.",
          "The general terms cover every product. Part 2 covers the free Community Edition and Part 4 covers SaaS, and only the German version is binding.",
          "The Store API, Admin API and MCP endpoints run on each merchant's own domain or SaaS shop, not on shopware.com.",
          "security.txt at www.shopware.com gives Expires 31 December 2025.",
          "www.shopware.com answered several requests with a 503 first byte timeout on 8 October 2026. The terms loaded on a retry and the privacy page loaded once.",
          "status.shopware.com covers Shopware SaaS, PaaS and vendor services, not self-hosted stores.",
          "Verisign RDAP gives a registration date of 1998-08-08 for shopware.com."
        ],
        "score": 71
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shopware.json",
      "live": {
        "slug": "shopware",
        "vendorStatus": {
          "page": "https://status.shopware.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T17:51:12.427095822Z"
        },
        "pages": [
          {
            "url": "https://www.shopware.com/en/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:28.817122652Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a8eeb1d7324d"
          },
          {
            "url": "https://www.shopware.com/en/privacy/",
            "kind": "privacy",
            "status": 503,
            "checkedAt": "2026-10-08T18:30:30.769152247Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.shopware.com/en/gtc/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:26.06911646Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "034d628e8015"
          }
        ],
        "updatedAt": "2026-10-08T18:30:30.769152247Z"
      }
    },
    "answer": "Shopware and Vendure score within a point of each other on agent readiness, 71.4 (BB) and 70.9 (BB). Vendure leads on reliability and schema \u0026 documentation.",
    "b": {
      "slug": "vendure",
      "name": "Vendure",
      "vendor": "Vendure (Elevantiq GmbH)",
      "vendorUrl": "https://vendure.io",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source headless commerce framework on TypeScript, NestJS and GraphQL that you self-host.",
      "url": "https://www.anchorterminal.com/tools/vendure",
      "markdownUrl": "https://www.anchorterminal.com/tools/vendure.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vendure.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vendure.json",
      "repo": "https://github.com/vendurehq/vendure",
      "license": "GPL-3.0-or-later",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://readonlydemo.vendure.io/shop-api",
      "packages": [
        {
          "registry": "npm",
          "name": "@vendure/core"
        }
      ],
      "auth": "mixed",
      "authNotes": "Shop API is anonymous for browsing and cart, with a session token (bearer header or cookie) that carries the active order. Customer login and Admin API use the same session tokens after login. API key authentication arrived in v3.6. You set everything up on your own server; there is no vendor-hosted API for Core.",
      "pricing": "freemium",
      "pricingNotes": "Vendure Core is free under GPLv3; self-hosted you pay only for your own servers and database. Vendure Platform is a flat yearly subscription quoted per project (no GMV, order or user fees) and adds B2B tooling, a commercial licence and support. Vendure Cloud is priced by environments and resources, currently for paid design partners only, with general availability planned for Q1 2027. No transaction fees (https://vendure.io/pricing).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payments layer for agents; payment handlers are plugins you configure (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 8487,
        "npmWeekly": 29655,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.vendure.io",
      "llmsTxt": "https://docs.vendure.io/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "typescript",
        "llms-txt",
        "freemium",
        "enterprise"
      ],
      "lastRelease": "2026-09-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.9,
        "grade": "BB",
        "agentReady": true,
        "rank": 117,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "3.7.3 on 2 September 2026 fixed an unauthenticated takeover of SSO customer accounts through registerCustomerAccount (GHSA-wr5h-x3x6-4h23), a cross-channel IDOR in order payment, refund and fulfilment operations (GHSA-7qvr-c5vf-xxfh), and session tokens returned in Admin API job data (GHSA-32jm-mf7r-7qw5). All are fixed and disclosed, but the changelog warns that tokens may remain in historical job records (https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md)."
        ],
        "verdict": "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.",
        "bestFor": "TypeScript teams that want a typed GraphQL commerce server and will host it.",
        "strengths": [
          "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on",
          "API keys scoped to roles and channels, bcrypt-hashed and rotatable",
          "GPLv3 core, free to self-host, with no GMV or order fees on any tier",
          "CI passing on master and three releases between 14 July and 2 September 2026",
          "No usage telemetry found in the core, CLI or scaffolder"
        ],
        "weaknesses": [
          "No vendor-hosted API. Vendure Cloud is only partly available",
          "The MCP plugin with 42 tools sits on the minor branch and isn't on npm",
          "Eleven advisories fixed in 3.7.3, including unauthenticated SSO account takeover and a cross-channel IDOR",
          "No official client SDK and no idempotency support for order mutations",
          "No terms of service page, status page or security.txt"
        ],
        "agentNotes": [
          "Keep the session token from the first Shop API response and send it on every call. It holds the active order",
          "Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult",
          "Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again",
          "For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel",
          "Run 3.7.3 or later, and purge old job records, which may still hold session tokens"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.9
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 78
        },
        "provenanceScore": 56
      },
      "connect": {
        "http": "curl https://readonlydemo.vendure.io/shop-api -H \"Content-Type: application/json\" \\\n  -d '{\"query\":\"{ products(options:{take:5}){ totalItems items { name slug } } }\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/vendure"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Vendure Core self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "GPLv3, you pay for your own servers and database"
        }
      ],
      "provenance": {
        "legalEntity": "Elevantiq GmbH",
        "domain": "vendure.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://github.com/vendurehq/vendure/blob/master/LICENSE.md",
        "privacy": "https://vendure.io/company/privacy-policy",
        "statusPage": "",
        "changelog": "https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "vendure.io has no terms of service page; the GPLv3 licence in the repo is linked as terms. Legal notice at https://vendure.io/company/legal-notice (Elevantiq GmbH, FN 506751 y, Innsbruck).",
          "rdap.org has no RDAP service for .io, so the registration date is blank.",
          "remoteUrl is Vendure's public read-only demo; production APIs run on your own domain."
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vendure.json",
      "live": {
        "slug": "vendure",
        "probe": {
          "target": "https://readonlydemo.vendure.io/shop-api",
          "method": "get",
          "lastAt": "2026-10-08T19:09:01.32967552Z",
          "lastOk": true,
          "lastStatus": 400,
          "lastMs": 39,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 42,
          "p95ms24h": 162,
          "samples24h": 272,
          "samples30d": 2135,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 217,
              "ok": 217
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "vendurehq/vendure",
            "version": "v3.7.4",
            "released": "2026-10-05",
            "seenAt": "2026-10-08T16:34:00.219407602Z"
          },
          {
            "registry": "npm",
            "name": "@vendure/core",
            "version": "3.7.4",
            "seenAt": "2026-10-08T16:33:59.406669774Z"
          }
        ],
        "githubStars": 8505,
        "npmWeekly": 39734,
        "securityTxt": {
          "url": "https://vendure.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:55.51273513Z"
        },
        "llmsTxt": {
          "url": "https://docs.vendure.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:59.103928368Z"
        },
        "domain": {
          "domain": "vendure.io",
          "checkedAt": "2026-10-04T13:04:21.502238644Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:47.725516985Z",
            "changedAt": "2026-10-05T16:00:13.686824026Z",
            "fingerprint": "1138502529e2"
          },
          {
            "url": "https://vendure.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:37.530244878Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2eeb9beb193d"
          },
          {
            "url": "https://vendure.io/company/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:35.37388554Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c172f2439224"
          },
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/LICENSE.md",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:49.736344061Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4fa079f39d4c"
          }
        ],
        "updatedAt": "2026-10-08T19:09:01.32967552Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "shopware AG",
        "b": "Vendure (Elevantiq GmbH)",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://readonlydemo.vendure.io/shop-api",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms",
        "b": "GPL-3.0-or-later",
        "name": "Licence"
      },
      {
        "a": "14",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-02",
        "b": "2026-09-02",
        "name": "Last release"
      },
      {
        "a": "2026-06-10",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "3.4k stars, 31k npm/wk",
        "b": "8.5k stars, 30k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Shopware and Vendure score within a point of each other on agent readiness, 71.4 (BB) and 70.9 (BB). Vendure leads on reliability and schema \u0026 documentation.",
        "question": "Which is better for AI agents, Shopware or Vendure?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Shopware and Vendure need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Shopware. Vendure has a hosted endpoint at https://readonlydemo.vendure.io/shop-api.",
        "question": "Can an agent call Shopware and Vendure without installing anything?"
      },
      {
        "answer": "Yes. Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms). Vendure is open source (GPL-3.0-or-later).",
        "question": "Are Shopware and Vendure open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 78 against 68",
          "Security \u0026 auth, 73 against 65",
          "Payments \u0026 pricing, 50 against 45",
          "Transparency \u0026 trust, 76 against 67"
        ],
        "also": null,
        "goodFor": "A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.",
        "slug": "shopware",
        "watchFor": "The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint"
      },
      {
        "aheadOn": [
          "Reliability, 89 against 83",
          "Schema \u0026 documentation, 91 against 85"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "TypeScript teams that want a typed GraphQL commerce server and will host it.",
        "slug": "vendure",
        "watchFor": "No vendor-hosted API. Vendure Cloud is only partly available"
      }
    ],
    "job": {
      "capability": "commerce.products",
      "name": "Commerce products"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-shopware.json",
        "title": "BigCommerce API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-vendure.json",
        "title": "BigCommerce API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-shopware.json",
        "title": "Commerce Layer API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-vendure.json",
        "title": "Commerce Layer API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-shopware.json",
        "title": "commercetools vs Shopware",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-vendure.json",
        "title": "commercetools vs Vendure",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/elastic-path-vs-shopware.json",
        "title": "Elastic Path API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/elastic-path-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/elastic-path-vs-vendure.json",
        "title": "Elastic Path API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/elastic-path-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/medusa-vs-shopware.json",
        "title": "Medusa API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/medusa-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/medusa-vs-vendure.json",
        "title": "Medusa API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/medusa-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-shopware.json",
        "title": "Saleor API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-vendure.json",
        "title": "Saleor API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopify-vs-shopware.json",
        "title": "Shopify API + MCP vs Shopware",
        "url": "https://www.anchorterminal.com/compare/shopify-vs-shopware"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopify-vs-vendure.json",
        "title": "Shopify API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/shopify-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-snipcart.json",
        "title": "Shopware vs Snipcart API + MCP",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-snipcart"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-square.json",
        "title": "Shopware vs Square",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-swell.json",
        "title": "Shopware vs Swell",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-swell"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-woocommerce.json",
        "title": "Shopware vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-woocommerce"
      },
      {
        "json": "https://www.anchorterminal.com/compare/snipcart-vs-vendure.json",
        "title": "Snipcart API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/snipcart-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-vendure.json",
        "title": "Square vs Vendure",
        "url": "https://www.anchorterminal.com/compare/square-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/swell-vs-vendure.json",
        "title": "Swell vs Vendure",
        "url": "https://www.anchorterminal.com/compare/swell-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/vendure-vs-woocommerce.json",
        "title": "Vendure vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/vendure-vs-woocommerce"
      }
    ],
    "scores": [
      {
        "by": 6,
        "edge": "vendure",
        "key": "reliability",
        "name": "Reliability",
        "shopware": 83,
        "vendure": 89,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "edge": "vendure",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "shopware": 85,
        "vendure": 91,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "shopware",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "shopware": 78,
        "vendure": 68,
        "weight": 13
      },
      {
        "by": 8,
        "edge": "shopware",
        "key": "security",
        "name": "Security \u0026 auth",
        "shopware": 73,
        "vendure": 65,
        "weight": 14
      },
      {
        "by": 5,
        "edge": "shopware",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "shopware": 50,
        "vendure": 45,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "shopware",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "shopware": 87,
        "vendure": 85,
        "weight": 7
      },
      {
        "by": 9,
        "edge": "shopware",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "shopware": 76,
        "vendure": 67,
        "weight": 7
      }
    ],
    "summary": "Shopware and Vendure score within a point of each other on agent readiness, 71.4 (BB) and 70.9 (BB). Vendure leads on reliability and schema \u0026 documentation. Both do commerce products.",
    "verdicts": {
      "shopware": "MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.",
      "vendure": "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/shopware-vs-vendure",
    "json": "https://www.anchorterminal.com/compare/shopware-vs-vendure.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/shopware-vs-vendure.md",
    "slim": "https://www.anchorterminal.com/compare/shopware-vs-vendure.min.md"
  },
  "markdown": "Shopware and Vendure score within a point of each other on agent readiness, 71.4 (BB) and 70.9 (BB). Vendure leads on reliability and schema \u0026 documentation. Both do commerce products.\n\n- Shopware: grade BB, 71.4/100, rank #107 of 629. Markdown https://www.anchorterminal.com/tools/shopware.md · JSON https://www.anchorterminal.com/api/v1/tools/shopware.json\n- Vendure: grade BB, 70.9/100, rank #117 of 629. Markdown https://www.anchorterminal.com/tools/vendure.md · JSON https://www.anchorterminal.com/api/v1/tools/vendure.json\n\n## Which one, for what\n\n### Shopware (BB)\n\nGood for: A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.\n\nAhead on:\n- Agent ergonomics, 78 against 68\n- Security \u0026 auth, 73 against 65\n- Payments \u0026 pricing, 50 against 45\n- Transparency \u0026 trust, 76 against 67\n\nWatch for: The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint\n\n### Vendure (BB)\n\nGood for: TypeScript teams that want a typed GraphQL commerce server and will host it.\n\nAhead on:\n- Reliability, 89 against 83\n- Schema \u0026 documentation, 91 against 85\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: No vendor-hosted API. Vendure Cloud is only partly available\n\n\n## Score by category\n\n| Category | Weight | Shopware | Vendure | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 83 | 89 | Vendure +6 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 85 | 91 | Vendure +6 |\n| Agent ergonomics | 13% (16.2 this run) | 78 | 68 | Shopware +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 73 | 65 | Shopware +8 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 45 | Shopware +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 87 | 85 | Shopware +2 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 76 | 67 | Shopware +9 |\n| Negative events | ≤15 | -5 | -3 | |\n| **Total** | | **71.4 · BB** | **70.9 · BB** | |\n\n## Facts side by side\n\n| Fact | Shopware | Vendure |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | shopware AG | Vendure (Elevantiq GmbH) |\n| Hosted endpoint | no (local only) | `https://readonlydemo.vendure.io/shop-api` |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms | GPL-3.0-or-later |\n| Tools exposed | 14 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-02 | 2026-09-02 |\n| Terms last updated | 2026-06-10 | no date given |\n| Privacy policy last updated | couldn't be read | no date given |\n| Customer content may train models | yes | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | not found in the text |\n| Popularity | 3.4k stars, 31k npm/wk | 8.5k stars, 30k npm/wk |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Shopware.** MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.\n\n**Vendure.** Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.\n\n## Before you call either\n\n### Shopware\n\n1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp\n2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools\n3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once\n4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core\n5. Send `includes` in search criteria to cut response size, and read the 429 body for the wait time\n\n### Vendure\n\n1. Keep the session token from the first Shop API response and send it on every call. It holds the active order\n2. Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult\n3. Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again\n4. For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel\n5. Run 3.7.3 or later, and purge old job records, which may still hold session tokens\n\n## Questions\n\n### Which is better for AI agents, Shopware or Vendure?\n\nShopware and Vendure score within a point of each other on agent readiness, 71.4 (BB) and 70.9 (BB). Vendure leads on reliability and schema \u0026 documentation.\n\n### Do Shopware and Vendure need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Shopware and Vendure without installing anything?\n\nNo hosted endpoint is listed for Shopware. Vendure has a hosted endpoint at https://readonlydemo.vendure.io/shop-api.\n\n### Are Shopware and Vendure open source?\n\nYes. Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms). Vendure is open source (GPL-3.0-or-later).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/shopware-vs-vendure.json, and with the fewest tokens: https://www.anchorterminal.com/compare/shopware-vs-vendure.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"shopware\", \"b\": \"vendure\"}`. From a terminal: `anchor compare shopware vendure`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/shopware.json and https://www.anchorterminal.com/api/v1/tools/vendure.json\n\n## Other comparisons with Shopware or Vendure\n\n- [BigCommerce API + MCP vs Shopware](https://www.anchorterminal.com/compare/bigcommerce-vs-shopware.md)\n- [BigCommerce API + MCP vs Vendure](https://www.anchorterminal.com/compare/bigcommerce-vs-vendure.md)\n- [Commerce Layer API + MCP vs Shopware](https://www.anchorterminal.com/compare/commerce-layer-vs-shopware.md)\n- [Commerce Layer API + MCP vs Vendure](https://www.anchorterminal.com/compare/commerce-layer-vs-vendure.md)\n- [commercetools vs Shopware](https://www.anchorterminal.com/compare/commercetools-vs-shopware.md)\n- [commercetools vs Vendure](https://www.anchorterminal.com/compare/commercetools-vs-vendure.md)\n- [Elastic Path API + MCP vs Shopware](https://www.anchorterminal.com/compare/elastic-path-vs-shopware.md)\n- [Elastic Path API + MCP vs Vendure](https://www.anchorterminal.com/compare/elastic-path-vs-vendure.md)\n- [Medusa API + MCP vs Shopware](https://www.anchorterminal.com/compare/medusa-vs-shopware.md)\n- [Medusa API + MCP vs Vendure](https://www.anchorterminal.com/compare/medusa-vs-vendure.md)\n- [Saleor API + MCP vs Shopware](https://www.anchorterminal.com/compare/saleor-vs-shopware.md)\n- [Saleor API + MCP vs Vendure](https://www.anchorterminal.com/compare/saleor-vs-vendure.md)\n- [Shopify API + MCP vs Shopware](https://www.anchorterminal.com/compare/shopify-vs-shopware.md)\n- [Shopify API + MCP vs Vendure](https://www.anchorterminal.com/compare/shopify-vs-vendure.md)\n- [Shopware vs Snipcart API + MCP](https://www.anchorterminal.com/compare/shopware-vs-snipcart.md)\n- [Shopware vs Square](https://www.anchorterminal.com/compare/shopware-vs-square.md)\n- [Shopware vs Swell](https://www.anchorterminal.com/compare/shopware-vs-swell.md)\n- [Shopware vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/shopware-vs-woocommerce.md)\n- [Snipcart API + MCP vs Vendure](https://www.anchorterminal.com/compare/snipcart-vs-vendure.md)\n- [Square vs Vendure](https://www.anchorterminal.com/compare/square-vs-vendure.md)\n- [Swell vs Vendure](https://www.anchorterminal.com/compare/swell-vs-vendure.md)\n- [Vendure vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/vendure-vs-woocommerce.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Shopware vs Vendure",
        "url": ""
      }
    ],
    "description": "Shopware and Vendure score within a point of each other on agent readiness, 71.4 (BB) and 70.9 (BB). Vendure leads on reliability and schema \u0026 documentation. Both do commerce products. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Shopware BB 71.4",
      "Vendure BB 70.9",
      "scores"
    ],
    "h1": "Shopware vs Vendure",
    "image": "https://www.anchorterminal.com/assets/og/compare-shopware-vs-vendure.png",
    "path": "/compare/shopware-vs-vendure",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Shopware vs Vendure for AI agents, BB 71.4 vs BB 70.9",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/shopware-vs-vendure"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 630
  },
  "version": 1
}
