Head to head · Commerce catalogues · October 2026 research run

Spree Commerce vs Square

Spree Commerce scores 70.4 (BB) on agent readiness against Square's 69.2 (B), and leads in 3 of 7 scored categories. Square leads on transparency & trust. Both do commerce catalogues.

Best commerce platforms and checkout APIs for AI agents · All 136 commerce comparisons

Which one, for what

Spree Commerce BB

Good for Teams that want to own a Rails commerce backend with marketplace, B2B and multi-region functions and drive it through REST.

Ahead on

  • Reliability, 82 against 58
  • Agent ergonomics, 90 against 83
  • Payments & pricing, 55 against 40

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source

Watch for

Six GitHub security advisories between 8 January and 20 July 2026, four rated High, most of them access-control flaws on guest carts, orders and addresses

Square B

Good for Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.

Ahead on

  • Transparency & trust, 70 against 60

Also in its favour

  • A hosted endpoint, with nothing to install
  • Runs on your own machine
  • No incidents deducted, where Spree Commerce loses 5 points for them

Watch for

The MCP server is marked beta, and the remote server reaches production data only

Score by category

CategoryWeight this runSpree CommerceSquareEdge
Reliability16%208258Spree Commerce +24
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28587Square +2
Agent ergonomics13%16.29083Spree Commerce +7
Security & auth14%17.56567Square +2
Payments & pricing10%12.55540Spree Commerce +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88181even
Transparency & trust7%8.86070Square +10
Negative events≤15-50
Total70.4 · BB69.2 · B

Facts side by side

FactSpree CommerceSquare
KindHTTP APIHTTP API
VendorVendo Connect IncBlock, Inc.
Hosted endpointno (local only)https://mcp.squareup.com/mcp
TransportsHTTPHTTP, Streamable HTTP, stdio
AuthOAuth or keyOAuth or key
PricingFreemiumPay per use
x402nono
LicenceBSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licenceProprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT
Tools exposednone3
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-07-282026-09-16
Terms last updatedno document linked2026-09-10
Privacy policy last updatedno document linked2026-09-15
Customer content may train modelsnot found in the text
Terms restrict automated accessyes
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waiveryes
Popularity16k stars, 1.6k npm/wk454k npm/wk, 72k PyPI/wk

Verdicts

Spree Commerce

A self-hosted BSD 3-Clause platform with public OpenAPI files for the Store and Admin APIs, scoped secret keys, documented rate limits and idempotency keys on cart and checkout calls. GitHub lists six security advisories between January and July 2026, four rated High, and the default docs describe the 6.0 release candidate while 5.6.1 is the stable release.

Square

The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.

Before you call either

Spree Commerce

  1. Send a publishable key in X-Spree-Api-Key on every Store API call. Add X-Spree-Token with the cart token for guest carts, or a customer JWT as a Bearer token
  2. Send Idempotency-Key with the cart token or a customer JWT on cart, payment and completion calls. A request carrying only the publishable key is never cached
  3. Ask for fields and expand explicitly. Relations are left out by default and limit stops at 100
  4. Use a secret key with the narrowest scopes for the Admin API. read_all gives a read-only key, and the CLI's auto-minted local key is read-only
  5. Read the docs under /docs/v5 for a 5.6 store. The default docs describe 6.0, which renames shipments to fulfilments and splits carts from orders

Square

  1. Test against the sandbox first with the local MCP server and SANDBOX=true. The remote server at mcp.squareup.com reaches production only
  2. Set DISALLOW_WRITES=true on the local MCP server when the task only reads
  3. Call get_service_info, then get_type_info, before each make_api_request. The request body is otherwise untyped
  4. Send a fresh idempotency_key on every write, and reuse it when retrying the same write
  5. Pin Square-Version in each request. Use a page cursor within 5 minutes of receiving it

Questions

Which is better for AI agents, Spree Commerce or Square?

Spree Commerce scores 70.4 (BB) on agent readiness against Square's 69.2 (B), and leads in 3 of 7 scored categories. Square leads on transparency & trust.

Do Spree Commerce and Square need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Spree Commerce and Square without installing anything?

No hosted endpoint is listed for Spree Commerce. Square has a hosted endpoint at https://mcp.squareup.com/mcp.

Are Spree Commerce and Square open source?

Spree Commerce is open source (BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence). No open-source release is listed for Square.

Other comparisons with Spree Commerce or Square

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.