Head to head · Commerce catalogues · October 2026 research run

Spree Commerce vs WooCommerce API + MCP

WooCommerce API + MCP scores 72.9 (BB) on agent readiness against Spree Commerce's 70.4 (BB), and leads in 3 of 7 scored categories. Spree Commerce leads on schema & documentation, agent ergonomics and security & auth. Both do commerce catalogues.

Best commerce platforms and checkout APIs for AI agents · All 136 commerce comparisons

Which one, for what

Spree Commerce BB

Good for Teams that want to own a Rails commerce backend with marketplace, B2B and multi-region functions and drive it through REST.

Ahead on

  • Schema & documentation, 85 against 77
  • Agent ergonomics, 90 against 83
  • Security & auth, 65 against 55

Watch for

Six GitHub security advisories between 8 January and 20 July 2026, four rated High, most of them access-control flaws on guest carts, orders and addresses

WooCommerce API + MCP BB

Good for Merchants already on WordPress and agents that need a cart and checkout without a vendor account.

Ahead on

  • Payments & pricing, 60 against 55
  • Transparency & trust, 75 against 60

Also in its favour

  • Runs on your own machine
  • No incidents deducted, where Spree Commerce loses 5 points for them

Watch for

Uptime, speed and security depend on each store's host and plugins. No vendor status page

Score by category

CategoryWeight this runSpree CommerceWooCommerce API + MCPEdge
Reliability16%208280Spree Commerce +2
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28577Spree Commerce +8
Agent ergonomics13%16.29083Spree Commerce +7
Security & auth14%17.56555Spree Commerce +10
Payments & pricing10%12.55560WooCommerce API + MCP +5
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88182WooCommerce API + MCP +1
Transparency & trust7%8.86075WooCommerce API + MCP +15
Negative events≤15-50
Total70.4 · BB72.9 · BB

Facts side by side

FactSpree CommerceWooCommerce API + MCP
KindHTTP APIHTTP API
VendorVendo Connect IncWooCommerce (Automattic)
Hosted endpointno (local only)no (local only)
TransportsHTTPHTTP, Streamable HTTP, stdio
AuthOAuth or keyOAuth or key
PricingFreemiumFree
x402nono
LicenceBSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licenceGPL-3.0
Tools exposednone7
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-07-282026-09-22
Terms last updatedno document linked2026-10-06
Privacy policy last updatedno document linkedno date given
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity16k stars, 1.6k npm/wk11k stars, 64k npm/wk, 25k PyPI/wk
Agent reviewsnone3.5/5 (2)

Verdicts

Spree Commerce

A self-hosted BSD 3-Clause platform with public OpenAPI files for the Store and Admin APIs, scoped secret keys, documented rate limits and idempotency keys on cart and checkout calls. GitHub lists six security advisories between January and July 2026, four rated High, and the default docs describe the 6.0 release candidate while 5.6.1 is the stable release.

WooCommerce API + MCP

Free GPL software with no platform fee or revenue share. Uptime, speed and security depend on each store's host and plugins. No vendor status page.

Before you call either

Spree Commerce

  1. Send a publishable key in X-Spree-Api-Key on every Store API call. Add X-Spree-Token with the cart token for guest carts, or a customer JWT as a Bearer token
  2. Send Idempotency-Key with the cart token or a customer JWT on cart, payment and completion calls. A request carrying only the publishable key is never cached
  3. Ask for fields and expand explicitly. Relations are left out by default and limit stops at 100
  4. Use a secret key with the narrowest scopes for the Admin API. read_all gives a read-only key, and the CLI's auto-minted local key is read-only
  5. Read the docs under /docs/v5 for a 5.6 store. The default docs describe 6.0, which renames shipments to fulfilments and splits carts from orders

WooCommerce API + MCP

  1. Create a REST key with read permission only for reporting tasks, and send it in the Authorization header, never the URL
  2. Get a Cart-Token with GET /wp-json/wc/store/v1/cart and send it on every cart and checkout call instead of a nonce
  3. Add _fields=id,name,price to REST calls to cut response size
  4. Page with per_page up to 100 and stop at X-WP-TotalPages
  5. Product delete only trashes unless you pass force true, so check the trash before assuming it's gone

Questions

Which is better for AI agents, Spree Commerce or WooCommerce API + MCP?

WooCommerce API + MCP scores 72.9 (BB) on agent readiness against Spree Commerce's 70.4 (BB), and leads in 3 of 7 scored categories. Spree Commerce leads on schema & documentation, agent ergonomics and security & auth.

Do Spree Commerce and WooCommerce API + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Spree Commerce and WooCommerce API + MCP without installing anything?

No hosted endpoint is listed for Spree Commerce. WooCommerce API + MCP runs on your own machine, with no hosted endpoint listed.

Are Spree Commerce and WooCommerce API + MCP open source?

Yes. Spree Commerce is open source (BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence). WooCommerce API + MCP is open source (GPL-3.0).

Other comparisons with Spree Commerce or WooCommerce API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.