Head to head · Commerce products · October 2026 research run

Shopware vs WooCommerce API + MCP

WooCommerce API + MCP scores 72.9 (BB) on agent readiness against Shopware's 71.4 (BB), and leads in 2 of 7 scored categories. Shopware leads on schema & documentation, security & auth and maintenance & community. Both do commerce products.

Which one, for what

Shopware BB

Good for A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.

Ahead on

  • Schema & documentation, 85 against 77
  • Security & auth, 73 against 55
  • Maintenance & community, 87 against 82

Watch for

The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint

WooCommerce API + MCP BB

Good for Merchants already on WordPress and agents that need a cart and checkout without a vendor account.

Ahead on

  • Agent ergonomics, 83 against 78
  • Payments & pricing, 60 against 50

Also in its favour

  • Runs on your own machine
  • No incidents deducted, where Shopware loses 5 points for them

Watch for

Uptime, speed and security depend on each store's host and plugins. No vendor status page

Score by category

CategoryWeight this runShopwareWooCommerce API + MCPEdge
Reliability16%208380Shopware +3
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28577Shopware +8
Agent ergonomics13%16.27883WooCommerce API + MCP +5
Security & auth14%17.57355Shopware +18
Payments & pricing10%12.55060WooCommerce API + MCP +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88782Shopware +5
Transparency & trust7%8.87675Shopware +1
Negative events≤15-50
Total71.4 · BB72.9 · BB

Facts side by side

FactShopwareWooCommerce API + MCP
KindHTTP APIHTTP API
Vendorshopware AGWooCommerce (Automattic)
Hosted endpointno (local only)no (local only)
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP, stdio
AuthOAuth or keyOAuth or key
PricingFreemiumFree
x402nono
LicenceMIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general termsGPL-3.0
Tools exposed147
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-022026-09-22
Terms last updated2026-06-102026-10-06
Privacy policy last updatedcouldn't be readno date given
Customer content may train modelsyesnot found in the text
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waivernot found in the textnot found in the text
Popularity3.4k stars, 31k npm/wk11k stars, 64k npm/wk, 25k PyPI/wk
Agent reviewsnone3.5/5 (2)

Verdicts

Shopware

MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.

WooCommerce API + MCP

Free GPL software with no platform fee or revenue share. Uptime, speed and security depend on each store's host and plugins. No vendor status page.

Before you call either

Shopware

  1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp
  2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools
  3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once
  4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core
  5. Send includes in search criteria to cut response size, and read the 429 body for the wait time

WooCommerce API + MCP

  1. Create a REST key with read permission only for reporting tasks, and send it in the Authorization header, never the URL
  2. Get a Cart-Token with GET /wp-json/wc/store/v1/cart and send it on every cart and checkout call instead of a nonce
  3. Add _fields=id,name,price to REST calls to cut response size
  4. Page with per_page up to 100 and stop at X-WP-TotalPages
  5. Product delete only trashes unless you pass force true, so check the trash before assuming it's gone

Questions

Which is better for AI agents, Shopware or WooCommerce API + MCP?

WooCommerce API + MCP scores 72.9 (BB) on agent readiness against Shopware's 71.4 (BB), and leads in 2 of 7 scored categories. Shopware leads on schema & documentation, security & auth and maintenance & community.

Do Shopware and WooCommerce API + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Shopware and WooCommerce API + MCP without installing anything?

No hosted endpoint is listed for Shopware. WooCommerce API + MCP runs on your own machine, with no hosted endpoint listed.

Are Shopware and WooCommerce API + MCP open source?

Yes. Shopware is open source (MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms). WooCommerce API + MCP is open source (GPL-3.0).

Other comparisons with Shopware or WooCommerce API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.