{
  "data": {
    "a": {
      "slug": "square",
      "name": "Square",
      "vendor": "Block, Inc.",
      "vendorUrl": "https://squareup.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Square is Block's commerce and payments platform for sellers. Its REST API covers catalogue, orders, payment links, payments, inventory and customers, with seven SDKs and a beta MCP server hosted at mcp.squareup.com.",
      "url": "https://www.anchorterminal.com/tools/square",
      "markdownUrl": "https://www.anchorterminal.com/tools/square.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/square.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/square.json",
      "repo": "https://github.com/square/square-mcp-server",
      "license": "Proprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://mcp.squareup.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "square"
        },
        {
          "registry": "npm",
          "name": "square-mcp-server"
        },
        {
          "registry": "pypi",
          "name": "squareup"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access needs a Square account and an application created in the Developer Console, both self-serve. Two token types go in the `Authorization: Bearer` header. A personal access token gives unrestricted access to the owner's own account, with a separate sandbox token. OAuth access tokens are limited to the scopes a seller grants, expire after 30 days and can be refreshed and revoked. The remote MCP server signs in through OAuth, and Square keeps an allowlist of MCP clients that may register.",
      "pricing": "usage",
      "pricingNotes": "The API and sandbox carry no charge. Sellers pay processing fees, 2.9% + 30 cents for card payments through the payments APIs in the US. Square Free is $0 a month, Plus $49 and Premium $149 per location. The sandbox lets an agent start without a contract (https://squareup.com/us/en/payments/our-fees, checked 2026-10-08).",
      "priceSummary": "2.9% fee",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index at developer.squareup.com/llms.txt or the OpenAPI spec (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 3,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 453743,
        "pypiWeekly": 72138,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.squareup.com/docs",
      "llmsTxt": "https://developer.squareup.com/llms.txt",
      "openapi": "https://raw.githubusercontent.com/square/connect-api-specification/master/api.json",
      "capabilities": [
        "commerce.products",
        "commerce.orders",
        "commerce.checkout",
        "commerce.cart",
        "commerce.headless",
        "payments.card",
        "payments.checkout"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "sandbox",
        "graphql",
        "typescript",
        "python",
        "status-page",
        "bug-bounty"
      ],
      "lastRelease": "2026-09-16",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.2,
        "grade": "B",
        "agentReady": false,
        "rank": 166,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 81,
          "payments": 40,
          "reliability": 58,
          "schema": 87,
          "security": 67,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.",
        "bestFor": "Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.",
        "strengths": [
          "Public OpenAPI 3.0 spec with 332 operations and 1,476 schemas, regenerated for API version 2026-09-16",
          "OAuth scopes are split by read and write for each resource, and access tokens expire after 30 days",
          "78 request schemas carry an `idempotency_key`, and the docs describe backoff with jitter for 429 responses",
          "Free sandbox at connect.squareupsandbox.com with test cards, and API Logs kept for 28 days",
          "Deprecated APIs are typically retired at least 12 months after deprecation, with dated release notes each month"
        ],
        "weaknesses": [
          "The MCP server is marked beta, and the remote server reaches production data only",
          "No numeric rate limits were found for the REST API. Only GraphQL states a figure, 10 queries a second",
          "No SLA was found in the developer terms or documentation",
          "The status page recorded widespread latency and errors on 27 September 2026, including payment authorisation",
          "A personal access token grants unrestricted access to the whole Square account",
          "97 of the 332 operations in the spec are marked beta"
        ],
        "agentNotes": [
          "Test against the sandbox first with the local MCP server and `SANDBOX=true`. The remote server at mcp.squareup.com reaches production only",
          "Set `DISALLOW_WRITES=true` on the local MCP server when the task only reads",
          "Call `get_service_info`, then `get_type_info`, before each `make_api_request`. The request body is otherwise untyped",
          "Send a fresh `idempotency_key` on every write, and reuse it when retrying the same write",
          "Pin `Square-Version` in each request. Use a page cursor within 5 minutes of receiving it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.2
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 81,
          "payments": 40,
          "reliability": 58,
          "schema": 87,
          "security": 67,
          "transparency": 56
        },
        "provenanceScore": 84
      },
      "connect": {
        "install": "npx square-mcp-server start",
        "http": "curl https://connect.squareupsandbox.com/v2/locations \\\n  -H 'Square-Version: 2026-09-16' \\\n  -H 'Authorization: Bearer {SANDBOX_ACCESS_TOKEN}' \\\n  -H 'Content-Type: application/json'",
        "config": {
          "mcpServers": {
            "mcp_square_api": {
              "args": [
                "mcp-remote",
                "https://mcp.squareup.com/mcp"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/square"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Card payment through the payments APIs (US)",
          "unit": "pct",
          "usd": 2.9,
          "note": "plus 30 cents per transaction"
        },
        {
          "item": "ACH bank transfer through the API (US)",
          "unit": "pct",
          "usd": 1,
          "note": "$1 minimum, $5 fee cap"
        },
        {
          "item": "Square Free",
          "unit": "month",
          "usd": 0,
          "note": "per location"
        },
        {
          "item": "Square Plus",
          "unit": "month",
          "usd": 49,
          "note": "per location"
        },
        {
          "item": "Square Premium",
          "unit": "month",
          "usd": 149,
          "note": "per location"
        }
      ],
      "provenance": {
        "legalEntity": "Block, Inc.",
        "domain": "squareup.com",
        "domainRegistered": "2007-05-26",
        "endpointOnVendorDomain": true,
        "terms": "https://squareup.com/us/en/legal/general/developers",
        "privacy": "https://squareup.com/us/en/legal/general/privacy",
        "statusPage": "https://www.issquareup.com",
        "changelog": "https://developer.squareup.com/docs/changelog/connect",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Square Developer Terms of Service (last updated 10 September 2026) are an agreement with Block, Inc. and govern the APIs, SDKs and developer tools. Payment processing through an API is also subject to Square's General Terms.",
          "The Privacy Notice for Square Sellers and Website Visitors (last updated 15 September 2026) names Block, Inc., 1955 Broadway, Suite 600, Oakland, CA 94612 as the entity for US sellers, with other Square entities for Canada, Japan, Australia and the EU.",
          "The API answers at connect.squareup.com and the remote MCP server at mcp.squareup.com. The sandbox uses the separate domain squareupsandbox.com.",
          "squareup.com/.well-known/security.txt and developer.squareup.com/.well-known/security.txt return 404. The security page links a Bugcrowd programme.",
          "RDAP for squareup.com gives a registration date of 2007-05-26."
        ],
        "score": 84
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/square.json",
      "live": {
        "slug": "square",
        "probe": {
          "target": "https://mcp.squareup.com/mcp",
          "method": "get",
          "lastAt": "2026-10-08T23:09:19.475981708Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 32,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 53,
          "p95ms24h": 137,
          "samples24h": 61,
          "samples30d": 61,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 61,
              "ok": 61
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.issquareup.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T23:13:46.748268039Z"
        },
        "pages": [
          {
            "url": "https://developer.squareup.com/docs/changelog/connect",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:18.308620553Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "62494a1dd472"
          },
          {
            "url": "https://squareup.com/us/en/legal/general/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:44.136652202Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "18b57fb2f3f3"
          },
          {
            "url": "https://squareup.com/us/en/legal/general/developers",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:24:40.889937356Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "10ccc5457da5"
          }
        ],
        "updatedAt": "2026-10-08T23:13:46.748268039Z"
      }
    },
    "answer": "Vendure scores 70.9 (BB) on agent readiness against Square's 69.2 (B), and leads in 4 of 7 scored categories. Square leads on agent ergonomics.",
    "b": {
      "slug": "vendure",
      "name": "Vendure",
      "vendor": "Vendure (Elevantiq GmbH)",
      "vendorUrl": "https://vendure.io",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source headless commerce framework on TypeScript, NestJS and GraphQL that you self-host.",
      "url": "https://www.anchorterminal.com/tools/vendure",
      "markdownUrl": "https://www.anchorterminal.com/tools/vendure.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vendure.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vendure.json",
      "repo": "https://github.com/vendurehq/vendure",
      "license": "GPL-3.0-or-later",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://readonlydemo.vendure.io/shop-api",
      "packages": [
        {
          "registry": "npm",
          "name": "@vendure/core"
        }
      ],
      "auth": "mixed",
      "authNotes": "Shop API is anonymous for browsing and cart, with a session token (bearer header or cookie) that carries the active order. Customer login and Admin API use the same session tokens after login. API key authentication arrived in v3.6. You set everything up on your own server; there is no vendor-hosted API for Core.",
      "pricing": "freemium",
      "pricingNotes": "Vendure Core is free under GPLv3; self-hosted you pay only for your own servers and database. Vendure Platform is a flat yearly subscription quoted per project (no GMV, order or user fees) and adds B2B tooling, a commercial licence and support. Vendure Cloud is priced by environments and resources, currently for paid design partners only, with general availability planned for Q1 2027. No transaction fees (https://vendure.io/pricing).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payments layer for agents; payment handlers are plugins you configure (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 8487,
        "npmWeekly": 29655,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.vendure.io",
      "llmsTxt": "https://docs.vendure.io/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "typescript",
        "llms-txt",
        "freemium",
        "enterprise"
      ],
      "lastRelease": "2026-09-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.9,
        "grade": "BB",
        "agentReady": true,
        "rank": 123,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "3.7.3 on 2 September 2026 fixed an unauthenticated takeover of SSO customer accounts through registerCustomerAccount (GHSA-wr5h-x3x6-4h23), a cross-channel IDOR in order payment, refund and fulfilment operations (GHSA-7qvr-c5vf-xxfh), and session tokens returned in Admin API job data (GHSA-32jm-mf7r-7qw5). All are fixed and disclosed, but the changelog warns that tokens may remain in historical job records (https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md)."
        ],
        "verdict": "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.",
        "bestFor": "TypeScript teams that want a typed GraphQL commerce server and will host it.",
        "strengths": [
          "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on",
          "API keys scoped to roles and channels, bcrypt-hashed and rotatable",
          "GPLv3 core, free to self-host, with no GMV or order fees on any tier",
          "CI passing on master and three releases between 14 July and 2 September 2026",
          "No usage telemetry found in the core, CLI or scaffolder"
        ],
        "weaknesses": [
          "No vendor-hosted API. Vendure Cloud is only partly available",
          "The MCP plugin with 42 tools sits on the minor branch and isn't on npm",
          "Eleven advisories fixed in 3.7.3, including unauthenticated SSO account takeover and a cross-channel IDOR",
          "No official client SDK and no idempotency support for order mutations",
          "No terms of service page, status page or security.txt"
        ],
        "agentNotes": [
          "Keep the session token from the first Shop API response and send it on every call. It holds the active order",
          "Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult",
          "Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again",
          "For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel",
          "Run 3.7.3 or later, and purge old job records, which may still hold session tokens"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.9
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 78
        },
        "provenanceScore": 56
      },
      "connect": {
        "http": "curl https://readonlydemo.vendure.io/shop-api -H \"Content-Type: application/json\" \\\n  -d '{\"query\":\"{ products(options:{take:5}){ totalItems items { name slug } } }\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/vendure"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Vendure Core self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "GPLv3, you pay for your own servers and database"
        }
      ],
      "provenance": {
        "legalEntity": "Elevantiq GmbH",
        "domain": "vendure.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://github.com/vendurehq/vendure/blob/master/LICENSE.md",
        "privacy": "https://vendure.io/company/privacy-policy",
        "statusPage": "",
        "changelog": "https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "vendure.io has no terms of service page; the GPLv3 licence in the repo is linked as terms. Legal notice at https://vendure.io/company/legal-notice (Elevantiq GmbH, FN 506751 y, Innsbruck).",
          "rdap.org has no RDAP service for .io, so the registration date is blank.",
          "remoteUrl is Vendure's public read-only demo; production APIs run on your own domain."
        ],
        "score": 56
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vendure.json",
      "live": {
        "slug": "vendure",
        "probe": {
          "target": "https://readonlydemo.vendure.io/shop-api",
          "method": "get",
          "lastAt": "2026-10-08T23:09:22.133985015Z",
          "lastOk": true,
          "lastStatus": 400,
          "lastMs": 49,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 40,
          "p95ms24h": 124,
          "samples24h": 269,
          "samples30d": 2177,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 259,
              "ok": 259
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "vendurehq/vendure",
            "version": "v3.7.4",
            "released": "2026-10-05",
            "seenAt": "2026-10-08T16:34:00.219407602Z"
          },
          {
            "registry": "npm",
            "name": "@vendure/core",
            "version": "3.7.4",
            "seenAt": "2026-10-08T16:33:59.406669774Z"
          }
        ],
        "githubStars": 8505,
        "npmWeekly": 39734,
        "securityTxt": {
          "url": "https://vendure.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:55.51273513Z"
        },
        "llmsTxt": {
          "url": "https://docs.vendure.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:59.103928368Z"
        },
        "domain": {
          "domain": "vendure.io",
          "checkedAt": "2026-10-04T13:04:21.502238644Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:47.725516985Z",
            "changedAt": "2026-10-05T16:00:13.686824026Z",
            "fingerprint": "1138502529e2"
          },
          {
            "url": "https://vendure.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:37.530244878Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2eeb9beb193d"
          },
          {
            "url": "https://vendure.io/company/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:35.37388554Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c172f2439224"
          },
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/LICENSE.md",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:49.736344061Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4fa079f39d4c"
          }
        ],
        "updatedAt": "2026-10-08T23:09:22.133985015Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Block, Inc.",
        "b": "Vendure (Elevantiq GmbH)",
        "name": "Vendor"
      },
      {
        "a": "https://mcp.squareup.com/mcp",
        "b": "https://readonlydemo.vendure.io/shop-api",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP, stdio",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Pay per use",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT",
        "b": "GPL-3.0-or-later",
        "name": "Licence"
      },
      {
        "a": "3",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-16",
        "b": "2026-09-02",
        "name": "Last release"
      },
      {
        "a": "2026-09-10",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-15",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "454k npm/wk, 72k PyPI/wk",
        "b": "8.5k stars, 30k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Vendure scores 70.9 (BB) on agent readiness against Square's 69.2 (B), and leads in 4 of 7 scored categories. Square leads on agent ergonomics.",
        "question": "Which is better for AI agents, Square or Vendure?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Square and Vendure need an API key?"
      },
      {
        "answer": "Yes. Square has a hosted endpoint at https://mcp.squareup.com/mcp and Vendure at https://readonlydemo.vendure.io/shop-api.",
        "question": "Can an agent call Square and Vendure without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Square. Vendure is open source (GPL-3.0-or-later).",
        "question": "Are Square and Vendure open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 83 against 68"
        ],
        "also": [
          "Runs on your own machine",
          "No incidents deducted, where Vendure loses 3 points for them"
        ],
        "goodFor": "Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.",
        "slug": "square",
        "watchFor": "The MCP server is marked beta, and the remote server reaches production data only"
      },
      {
        "aheadOn": [
          "Reliability, 89 against 58",
          "Payments \u0026 pricing, 45 against 40"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "Open source"
        ],
        "goodFor": "TypeScript teams that want a typed GraphQL commerce server and will host it.",
        "slug": "vendure",
        "watchFor": "No vendor-hosted API. Vendure Cloud is only partly available"
      }
    ],
    "job": {
      "capability": "commerce.products",
      "name": "Commerce products"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/adobe-commerce-vs-square.json",
        "title": "Adobe Commerce (Magento) vs Square",
        "url": "https://www.anchorterminal.com/compare/adobe-commerce-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/adobe-commerce-vs-vendure.json",
        "title": "Adobe Commerce (Magento) vs Vendure",
        "url": "https://www.anchorterminal.com/compare/adobe-commerce-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-square.json",
        "title": "BigCommerce API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bigcommerce-vs-vendure.json",
        "title": "BigCommerce API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/bigcommerce-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-square.json",
        "title": "Commerce Layer API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commerce-layer-vs-vendure.json",
        "title": "Commerce Layer API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/commerce-layer-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-square.json",
        "title": "commercetools vs Square",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/commercetools-vs-vendure.json",
        "title": "commercetools vs Vendure",
        "url": "https://www.anchorterminal.com/compare/commercetools-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-square.json",
        "title": "Ecwid by Lightspeed vs Square",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ecwid-vs-vendure.json",
        "title": "Ecwid by Lightspeed vs Vendure",
        "url": "https://www.anchorterminal.com/compare/ecwid-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/elastic-path-vs-square.json",
        "title": "Elastic Path API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/elastic-path-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/elastic-path-vs-vendure.json",
        "title": "Elastic Path API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/elastic-path-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/medusa-vs-square.json",
        "title": "Medusa API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/medusa-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/medusa-vs-vendure.json",
        "title": "Medusa API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/medusa-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-square.json",
        "title": "Saleor API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/saleor-vs-vendure.json",
        "title": "Saleor API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/saleor-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopify-vs-square.json",
        "title": "Shopify API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/shopify-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopify-vs-vendure.json",
        "title": "Shopify API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/shopify-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-square.json",
        "title": "Shopware vs Square",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shopware-vs-vendure.json",
        "title": "Shopware vs Vendure",
        "url": "https://www.anchorterminal.com/compare/shopware-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/snipcart-vs-square.json",
        "title": "Snipcart API + MCP vs Square",
        "url": "https://www.anchorterminal.com/compare/snipcart-vs-square"
      },
      {
        "json": "https://www.anchorterminal.com/compare/snipcart-vs-vendure.json",
        "title": "Snipcart API + MCP vs Vendure",
        "url": "https://www.anchorterminal.com/compare/snipcart-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-swell.json",
        "title": "Square vs Swell",
        "url": "https://www.anchorterminal.com/compare/square-vs-swell"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-wix.json",
        "title": "Square vs Wix Stores and eCommerce API",
        "url": "https://www.anchorterminal.com/compare/square-vs-wix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/square-vs-woocommerce.json",
        "title": "Square vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/square-vs-woocommerce"
      },
      {
        "json": "https://www.anchorterminal.com/compare/swell-vs-vendure.json",
        "title": "Swell vs Vendure",
        "url": "https://www.anchorterminal.com/compare/swell-vs-vendure"
      },
      {
        "json": "https://www.anchorterminal.com/compare/vendure-vs-wix.json",
        "title": "Vendure vs Wix Stores and eCommerce API",
        "url": "https://www.anchorterminal.com/compare/vendure-vs-wix"
      },
      {
        "json": "https://www.anchorterminal.com/compare/vendure-vs-woocommerce.json",
        "title": "Vendure vs WooCommerce API + MCP",
        "url": "https://www.anchorterminal.com/compare/vendure-vs-woocommerce"
      }
    ],
    "scores": [
      {
        "by": 31,
        "edge": "vendure",
        "key": "reliability",
        "name": "Reliability",
        "square": 58,
        "vendure": 89,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "vendure",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "square": 87,
        "vendure": 91,
        "weight": 13
      },
      {
        "by": 15,
        "edge": "square",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "square": 83,
        "vendure": 68,
        "weight": 13
      },
      {
        "by": 2,
        "edge": "square",
        "key": "security",
        "name": "Security \u0026 auth",
        "square": 67,
        "vendure": 65,
        "weight": 14
      },
      {
        "by": 5,
        "edge": "vendure",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "square": 40,
        "vendure": 45,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "vendure",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "square": 81,
        "vendure": 85,
        "weight": 7
      },
      {
        "by": 3,
        "edge": "square",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "square": 70,
        "vendure": 67,
        "weight": 7
      }
    ],
    "summary": "Vendure scores 70.9 (BB) on agent readiness against Square's 69.2 (B), and leads in 4 of 7 scored categories. Square leads on agent ergonomics. Both do commerce products.",
    "verdicts": {
      "square": "The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.",
      "vendure": "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/square-vs-vendure",
    "json": "https://www.anchorterminal.com/compare/square-vs-vendure.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/square-vs-vendure.md",
    "slim": "https://www.anchorterminal.com/compare/square-vs-vendure.min.md"
  },
  "markdown": "Vendure scores 70.9 (BB) on agent readiness against Square's 69.2 (B), and leads in 4 of 7 scored categories. Square leads on agent ergonomics. Both do commerce products.\n\n- Square: grade B, 69.2/100, rank #166 of 722. Markdown https://www.anchorterminal.com/tools/square.md · JSON https://www.anchorterminal.com/api/v1/tools/square.json\n- Vendure: grade BB, 70.9/100, rank #123 of 722. Markdown https://www.anchorterminal.com/tools/vendure.md · JSON https://www.anchorterminal.com/api/v1/tools/vendure.json\n\n## Which one, for what\n\n### Square (B)\n\nGood for: Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.\n\nAhead on:\n- Agent ergonomics, 83 against 68\n\nAlso in its favour:\n- Runs on your own machine\n- No incidents deducted, where Vendure loses 3 points for them\n\nWatch for: The MCP server is marked beta, and the remote server reaches production data only\n\n### Vendure (BB)\n\nGood for: TypeScript teams that want a typed GraphQL commerce server and will host it.\n\nAhead on:\n- Reliability, 89 against 58\n- Payments \u0026 pricing, 45 against 40\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- Open source\n\nWatch for: No vendor-hosted API. Vendure Cloud is only partly available\n\n\n## Score by category\n\n| Category | Weight | Square | Vendure | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 58 | 89 | Vendure +31 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 87 | 91 | Vendure +4 |\n| Agent ergonomics | 13% (16.2 this run) | 83 | 68 | Square +15 |\n| Security \u0026 auth | 14% (17.5 this run) | 67 | 65 | Square +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 45 | Vendure +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 81 | 85 | Vendure +4 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 70 | 67 | Square +3 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **69.2 · B** | **70.9 · BB** | |\n\n## Facts side by side\n\n| Fact | Square | Vendure |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Block, Inc. | Vendure (Elevantiq GmbH) |\n| Hosted endpoint | `https://mcp.squareup.com/mcp` | `https://readonlydemo.vendure.io/shop-api` |\n| Transports | HTTP, Streamable HTTP, stdio | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Pay per use | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT | GPL-3.0-or-later |\n| Tools exposed | 3 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-16 | 2026-09-02 |\n| Terms last updated | 2026-09-10 | no date given |\n| Privacy policy last updated | 2026-09-15 | no date given |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 454k npm/wk, 72k PyPI/wk | 8.5k stars, 30k npm/wk |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Square.** The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.\n\n**Vendure.** Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.\n\n## Before you call either\n\n### Square\n\n1. Test against the sandbox first with the local MCP server and `SANDBOX=true`. The remote server at mcp.squareup.com reaches production only\n2. Set `DISALLOW_WRITES=true` on the local MCP server when the task only reads\n3. Call `get_service_info`, then `get_type_info`, before each `make_api_request`. The request body is otherwise untyped\n4. Send a fresh `idempotency_key` on every write, and reuse it when retrying the same write\n5. Pin `Square-Version` in each request. Use a page cursor within 5 minutes of receiving it\n\n### Vendure\n\n1. Keep the session token from the first Shop API response and send it on every call. It holds the active order\n2. Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult\n3. Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again\n4. For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel\n5. Run 3.7.3 or later, and purge old job records, which may still hold session tokens\n\n## Questions\n\n### Which is better for AI agents, Square or Vendure?\n\nVendure scores 70.9 (BB) on agent readiness against Square's 69.2 (B), and leads in 4 of 7 scored categories. Square leads on agent ergonomics.\n\n### Do Square and Vendure need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Square and Vendure without installing anything?\n\nYes. Square has a hosted endpoint at https://mcp.squareup.com/mcp and Vendure at https://readonlydemo.vendure.io/shop-api.\n\n### Are Square and Vendure open source?\n\nNo open-source release is listed for Square. Vendure is open source (GPL-3.0-or-later).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/square-vs-vendure.json, and with the fewest tokens: https://www.anchorterminal.com/compare/square-vs-vendure.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"square\", \"b\": \"vendure\"}`. From a terminal: `anchor compare square vendure`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/square.json and https://www.anchorterminal.com/api/v1/tools/vendure.json\n\n## Other comparisons with Square or Vendure\n\n- [Adobe Commerce (Magento) vs Square](https://www.anchorterminal.com/compare/adobe-commerce-vs-square.md)\n- [Adobe Commerce (Magento) vs Vendure](https://www.anchorterminal.com/compare/adobe-commerce-vs-vendure.md)\n- [BigCommerce API + MCP vs Square](https://www.anchorterminal.com/compare/bigcommerce-vs-square.md)\n- [BigCommerce API + MCP vs Vendure](https://www.anchorterminal.com/compare/bigcommerce-vs-vendure.md)\n- [Commerce Layer API + MCP vs Square](https://www.anchorterminal.com/compare/commerce-layer-vs-square.md)\n- [Commerce Layer API + MCP vs Vendure](https://www.anchorterminal.com/compare/commerce-layer-vs-vendure.md)\n- [commercetools vs Square](https://www.anchorterminal.com/compare/commercetools-vs-square.md)\n- [commercetools vs Vendure](https://www.anchorterminal.com/compare/commercetools-vs-vendure.md)\n- [Ecwid by Lightspeed vs Square](https://www.anchorterminal.com/compare/ecwid-vs-square.md)\n- [Ecwid by Lightspeed vs Vendure](https://www.anchorterminal.com/compare/ecwid-vs-vendure.md)\n- [Elastic Path API + MCP vs Square](https://www.anchorterminal.com/compare/elastic-path-vs-square.md)\n- [Elastic Path API + MCP vs Vendure](https://www.anchorterminal.com/compare/elastic-path-vs-vendure.md)\n- [Medusa API + MCP vs Square](https://www.anchorterminal.com/compare/medusa-vs-square.md)\n- [Medusa API + MCP vs Vendure](https://www.anchorterminal.com/compare/medusa-vs-vendure.md)\n- [Saleor API + MCP vs Square](https://www.anchorterminal.com/compare/saleor-vs-square.md)\n- [Saleor API + MCP vs Vendure](https://www.anchorterminal.com/compare/saleor-vs-vendure.md)\n- [Shopify API + MCP vs Square](https://www.anchorterminal.com/compare/shopify-vs-square.md)\n- [Shopify API + MCP vs Vendure](https://www.anchorterminal.com/compare/shopify-vs-vendure.md)\n- [Shopware vs Square](https://www.anchorterminal.com/compare/shopware-vs-square.md)\n- [Shopware vs Vendure](https://www.anchorterminal.com/compare/shopware-vs-vendure.md)\n- [Snipcart API + MCP vs Square](https://www.anchorterminal.com/compare/snipcart-vs-square.md)\n- [Snipcart API + MCP vs Vendure](https://www.anchorterminal.com/compare/snipcart-vs-vendure.md)\n- [Square vs Swell](https://www.anchorterminal.com/compare/square-vs-swell.md)\n- [Square vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/square-vs-wix.md)\n- [Square vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/square-vs-woocommerce.md)\n- [Swell vs Vendure](https://www.anchorterminal.com/compare/swell-vs-vendure.md)\n- [Vendure vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/vendure-vs-wix.md)\n- [Vendure vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/vendure-vs-woocommerce.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Square vs Vendure",
        "url": ""
      }
    ],
    "description": "Vendure scores 70.9 (BB) on agent readiness against Square's 69.2 (B), and leads in 4 of 7 scored categories. Square leads on agent ergonomics. Both do commerce products. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Square B 69.2",
      "Vendure BB 70.9",
      "scores"
    ],
    "h1": "Square vs Vendure",
    "image": "https://www.anchorterminal.com/assets/og/compare-square-vs-vendure.png",
    "path": "/compare/square-vs-vendure",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Square vs Vendure for AI agents, B 69.2 vs BB 70.9 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/square-vs-vendure"
  },
  "tokens": {
    "markdown": 2400,
    "slim": 680
  },
  "version": 1
}
