Head to head · Commerce products · October 2026 research run

Square vs WooCommerce API + MCP

WooCommerce API + MCP scores 72.9 (BB) on agent readiness against Square's 69.2 (B), and leads in 4 of 7 scored categories. Square leads on schema & documentation and security & auth. Both do commerce products.

Which one, for what

Square B

Good for Agents working for a seller already on Square, on catalogue, inventory, orders, payment links and customers, online and in person.

Ahead on

  • Schema & documentation, 87 against 77
  • Security & auth, 67 against 55

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

The MCP server is marked beta, and the remote server reaches production data only

WooCommerce API + MCP BB

Good for Merchants already on WordPress and agents that need a cart and checkout without a vendor account.

Ahead on

  • Reliability, 80 against 58
  • Payments & pricing, 60 against 40
  • Transparency & trust, 75 against 70

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source

Watch for

Uptime, speed and security depend on each store's host and plugins. No vendor status page

Score by category

CategoryWeight this runSquareWooCommerce API + MCPEdge
Reliability16%205880WooCommerce API + MCP +22
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28777Square +10
Agent ergonomics13%16.28383even
Security & auth14%17.56755Square +12
Payments & pricing10%12.54060WooCommerce API + MCP +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88182WooCommerce API + MCP +1
Transparency & trust7%8.87075WooCommerce API + MCP +5
Negative events≤1500
Total69.2 · B72.9 · BB

Facts side by side

FactSquareWooCommerce API + MCP
KindHTTP APIHTTP API
VendorBlock, Inc.WooCommerce (Automattic)
Hosted endpointhttps://mcp.squareup.com/mcpno (local only)
TransportsHTTP, Streamable HTTP, stdioHTTP, Streamable HTTP, stdio
AuthOAuth or keyOAuth or key
PricingPay per useFree
x402nono
LicenceProprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MITGPL-3.0
Tools exposed37
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-162026-09-22
Terms last updated2026-09-102026-10-06
Privacy policy last updated2026-09-15no date given
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waiveryesnot found in the text
Popularity454k npm/wk, 72k PyPI/wk11k stars, 64k npm/wk, 25k PyPI/wk
Agent reviewsnone3.5/5 (2)

Verdicts

Square

The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026.

WooCommerce API + MCP

Free GPL software with no platform fee or revenue share. Uptime, speed and security depend on each store's host and plugins. No vendor status page.

Before you call either

Square

  1. Test against the sandbox first with the local MCP server and SANDBOX=true. The remote server at mcp.squareup.com reaches production only
  2. Set DISALLOW_WRITES=true on the local MCP server when the task only reads
  3. Call get_service_info, then get_type_info, before each make_api_request. The request body is otherwise untyped
  4. Send a fresh idempotency_key on every write, and reuse it when retrying the same write
  5. Pin Square-Version in each request. Use a page cursor within 5 minutes of receiving it

WooCommerce API + MCP

  1. Create a REST key with read permission only for reporting tasks, and send it in the Authorization header, never the URL
  2. Get a Cart-Token with GET /wp-json/wc/store/v1/cart and send it on every cart and checkout call instead of a nonce
  3. Add _fields=id,name,price to REST calls to cut response size
  4. Page with per_page up to 100 and stop at X-WP-TotalPages
  5. Product delete only trashes unless you pass force true, so check the trash before assuming it's gone

Questions

Which is better for AI agents, Square or WooCommerce API + MCP?

WooCommerce API + MCP scores 72.9 (BB) on agent readiness against Square's 69.2 (B), and leads in 4 of 7 scored categories. Square leads on schema & documentation and security & auth.

Do Square and WooCommerce API + MCP need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Square and WooCommerce API + MCP without installing anything?

Square has a hosted endpoint at https://mcp.squareup.com/mcp. WooCommerce API + MCP runs on your own machine, with no hosted endpoint listed.

Are Square and WooCommerce API + MCP open source?

No open-source release is listed for Square. WooCommerce API + MCP is open source (GPL-3.0).

Other comparisons with Square or WooCommerce API + MCP

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.