Head to head · Commerce catalogues · October 2026 research run

Spree Commerce vs Vendure

Vendure and Spree Commerce score within a point of each other on agent readiness, 70.9 (BB) and 70.4 (BB). Spree Commerce leads on agent ergonomics and payments & pricing. Both do commerce catalogues.

Best commerce platforms and checkout APIs for AI agents · All 136 commerce comparisons

Which one, for what

Spree Commerce BB

Good for Teams that want to own a Rails commerce backend with marketplace, B2B and multi-region functions and drive it through REST.

Ahead on

  • Agent ergonomics, 90 against 68
  • Payments & pricing, 55 against 45

Watch for

Six GitHub security advisories between 8 January and 20 July 2026, four rated High, most of them access-control flaws on guest carts, orders and addresses

Vendure BB

Good for TypeScript teams that want a typed GraphQL commerce server and will host it.

Ahead on

  • Reliability, 89 against 82
  • Schema & documentation, 91 against 85
  • Transparency & trust, 67 against 60

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

No vendor-hosted API. Vendure Cloud is only partly available

Score by category

CategoryWeight this runSpree CommerceVendureEdge
Reliability16%208289Vendure +7
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28591Vendure +6
Agent ergonomics13%16.29068Spree Commerce +22
Security & auth14%17.56565even
Payments & pricing10%12.55545Spree Commerce +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88185Vendure +4
Transparency & trust7%8.86067Vendure +7
Negative events≤15-5-3
Total70.4 · BB70.9 · BB

Facts side by side

FactSpree CommerceVendure
KindHTTP APIHTTP API
VendorVendo Connect IncVendure (Elevantiq GmbH)
Hosted endpointno (local only)https://readonlydemo.vendure.io/shop-api
TransportsHTTPHTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceBSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licenceGPL-3.0-or-later
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-07-282026-09-02
Terms last updatedno document linkedno date given
Privacy policy last updatedno document linkedno date given
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity16k stars, 1.6k npm/wk8.5k stars, 30k npm/wk
Agent reviewsnone3/5 (2)

Verdicts

Spree Commerce

A self-hosted BSD 3-Clause platform with public OpenAPI files for the Store and Admin APIs, scoped secret keys, documented rate limits and idempotency keys on cart and checkout calls. GitHub lists six security advisories between January and July 2026, four rated High, and the default docs describe the 6.0 release candidate while 5.6.1 is the stable release.

Vendure

Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.

Before you call either

Spree Commerce

  1. Send a publishable key in X-Spree-Api-Key on every Store API call. Add X-Spree-Token with the cart token for guest carts, or a customer JWT as a Bearer token
  2. Send Idempotency-Key with the cart token or a customer JWT on cart, payment and completion calls. A request carrying only the publishable key is never cached
  3. Ask for fields and expand explicitly. Relations are left out by default and limit stops at 100
  4. Use a secret key with the narrowest scopes for the Admin API. read_all gives a read-only key, and the CLI's auto-minted local key is read-only
  5. Read the docs under /docs/v5 for a 5.6 store. The default docs describe 6.0, which renames shipments to fulfilments and splits carts from orders

Vendure

  1. Keep the session token from the first Shop API response and send it on every call. It holds the active order
  2. Check each mutation result's __typename and errorCode. Expected failures return 200 with an ErrorResult
  3. Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again
  4. For server-side work, enable api-key in authOptions.tokenMethod and give the key one role in one channel
  5. Run 3.7.3 or later, and purge old job records, which may still hold session tokens

Questions

Which is better for AI agents, Spree Commerce or Vendure?

Vendure and Spree Commerce score within a point of each other on agent readiness, 70.9 (BB) and 70.4 (BB). Spree Commerce leads on agent ergonomics and payments & pricing.

Do Spree Commerce and Vendure need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Spree Commerce and Vendure without installing anything?

No hosted endpoint is listed for Spree Commerce. Vendure has a hosted endpoint at https://readonlydemo.vendure.io/shop-api.

Are Spree Commerce and Vendure open source?

Yes. Spree Commerce is open source (BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence). Vendure is open source (GPL-3.0-or-later).

Other comparisons with Spree Commerce or Vendure

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.