{
  "data": {
    "a": {
      "slug": "vendure",
      "name": "Vendure",
      "vendor": "Vendure (Elevantiq GmbH)",
      "vendorUrl": "https://vendure.io",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source headless commerce framework on TypeScript, NestJS and GraphQL that you self-host.",
      "url": "https://www.anchorterminal.com/tools/vendure",
      "markdownUrl": "https://www.anchorterminal.com/tools/vendure.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vendure.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vendure.json",
      "repo": "https://github.com/vendurehq/vendure",
      "license": "GPL-3.0-or-later",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://readonlydemo.vendure.io/shop-api",
      "packages": [
        {
          "registry": "npm",
          "name": "@vendure/core"
        }
      ],
      "auth": "mixed",
      "authNotes": "Shop API is anonymous for browsing and cart, with a session token (bearer header or cookie) that carries the active order. Customer login and Admin API use the same session tokens after login. API key authentication arrived in v3.6. You set everything up on your own server; there is no vendor-hosted API for Core.",
      "pricing": "freemium",
      "pricingNotes": "Vendure Core is free under GPLv3; self-hosted you pay only for your own servers and database. Vendure Platform is a flat yearly subscription quoted per project (no GMV, order or user fees) and adds B2B tooling, a commercial licence and support. Vendure Cloud is priced by environments and resources, currently for paid design partners only, with general availability planned for Q1 2027. No transaction fees (https://vendure.io/pricing).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No payments layer for agents; payment handlers are plugins you configure (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 8487,
        "npmWeekly": 29655,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.vendure.io",
      "llmsTxt": "https://docs.vendure.io/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "typescript",
        "llms-txt",
        "freemium",
        "enterprise"
      ],
      "lastRelease": "2026-09-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 84,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 3,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "3.7.3 on 2 September 2026 fixed an unauthenticated takeover of SSO customer accounts through registerCustomerAccount (GHSA-wr5h-x3x6-4h23), a cross-channel IDOR in order payment, refund and fulfilment operations (GHSA-7qvr-c5vf-xxfh), and session tokens returned in Admin API job data (GHSA-32jm-mf7r-7qw5). All are fixed and disclosed, but the changelog warns that tokens may remain in historical job records (https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md)."
        ],
        "verdict": "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.",
        "strengths": [
          "Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on",
          "API keys scoped to roles and channels, bcrypt-hashed and rotatable",
          "GPLv3 core, free to self-host, with no GMV or order fees on any tier",
          "CI passing on master and three releases between 14 July and 2 September 2026",
          "No usage telemetry found in the core, CLI or scaffolder"
        ],
        "weaknesses": [
          "No vendor-hosted API. Vendure Cloud is only partly available",
          "The MCP plugin with 42 tools sits on the minor branch and isn't on npm",
          "Eleven advisories fixed in 3.7.3, including unauthenticated SSO account takeover and a cross-channel IDOR",
          "No official client SDK and no idempotency support for order mutations",
          "No terms of service page, status page or security.txt"
        ],
        "agentNotes": [
          "Keep the session token from the first Shop API response and send it on every call. It holds the active order",
          "Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult",
          "Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again",
          "For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel",
          "Run 3.7.3 or later, and purge old job records, which may still hold session tokens"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.4
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 85,
          "payments": 45,
          "reliability": 89,
          "schema": 91,
          "security": 65,
          "transparency": 78
        },
        "provenanceScore": 65
      },
      "connect": {
        "http": "curl https://readonlydemo.vendure.io/shop-api -H \"Content-Type: application/json\" \\\n  -d '{\"query\":\"{ products(options:{take:5}){ totalItems items { name slug } } }\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/vendure"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Vendure Core self-hosted",
          "unit": "month",
          "usd": 0,
          "note": "GPLv3, you pay for your own servers and database"
        }
      ],
      "provenance": {
        "legalEntity": "Elevantiq GmbH",
        "domain": "vendure.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://github.com/vendurehq/vendure/blob/master/LICENSE.md",
        "privacy": "https://vendure.io/company/privacy-policy",
        "statusPage": "",
        "changelog": "https://github.com/vendurehq/vendure/blob/master/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "vendure.io has no terms of service page; the GPLv3 licence in the repo is linked as terms. Legal notice at https://vendure.io/company/legal-notice (Elevantiq GmbH, FN 506751 y, Innsbruck).",
          "rdap.org has no RDAP service for .io, so the registration date is blank.",
          "remoteUrl is Vendure's public read-only demo; production APIs run on your own domain."
        ],
        "score": 65
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vendure.json",
      "live": {
        "slug": "vendure",
        "probe": {
          "target": "https://readonlydemo.vendure.io/shop-api",
          "method": "get",
          "lastAt": "2026-10-05T02:30:04.659237635Z",
          "lastOk": true,
          "lastStatus": 400,
          "lastMs": 34,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 40,
          "p95ms24h": 142,
          "samples24h": 273,
          "samples30d": 1131,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 29,
              "ok": 29
            }
          ]
        },
        "versions": [
          {
            "registry": "github",
            "name": "vendurehq/vendure",
            "version": "v3.7.3",
            "released": "2026-09-02",
            "seenAt": "2026-10-04T16:43:15.586308948Z"
          },
          {
            "registry": "npm",
            "name": "@vendure/core",
            "version": "3.7.3",
            "seenAt": "2026-10-04T16:43:14.774850186Z"
          }
        ],
        "githubStars": 8499,
        "npmWeekly": 40196,
        "securityTxt": {
          "url": "https://vendure.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:16:04.506739267Z"
        },
        "llmsTxt": {
          "url": "https://docs.vendure.io/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:21.209306136Z"
        },
        "domain": {
          "domain": "vendure.io",
          "checkedAt": "2026-10-04T13:04:21.502238644Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/CHANGELOG.md",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:57.229132004Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "706970590159"
          },
          {
            "url": "https://vendure.io/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:46.28142491Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "2eeb9beb193d"
          },
          {
            "url": "https://vendure.io/company/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:44.062295637Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c172f2439224"
          },
          {
            "url": "https://raw.githubusercontent.com/vendurehq/vendure/master/LICENSE.md",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:59.242695537Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4fa079f39d4c"
          }
        ],
        "updatedAt": "2026-10-05T02:30:04.659237635Z"
      }
    },
    "b": {
      "slug": "woocommerce",
      "name": "WooCommerce API + MCP",
      "vendor": "WooCommerce (Automattic)",
      "vendorUrl": "https://woocommerce.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source commerce plugin for WordPress that you host yourself.",
      "url": "https://www.anchorterminal.com/tools/woocommerce",
      "markdownUrl": "https://www.anchorterminal.com/tools/woocommerce.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/woocommerce.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/woocommerce.json",
      "repo": "https://github.com/woocommerce/woocommerce",
      "license": "GPL-3.0",
      "transports": [
        "http",
        "streamable-http",
        "stdio"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@woocommerce/woocommerce-rest-api"
        },
        {
          "registry": "pypi",
          "name": "woocommerce"
        },
        {
          "registry": "npm",
          "name": "@automattic/mcp-wordpress-remote"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST API keys (consumer key and secret) with read, write or read_write permission, sent as HTTP Basic over HTTPS. The Store API needs no key for browsing and uses a nonce or Cart-Token for cart and checkout calls. The MCP adapter takes a WordPress Application Password and acts with that user's capabilities. The deprecated /wp-json/woocommerce/mcp endpoint used REST keys.",
      "pricing": "free",
      "pricingNotes": "The plugin is free under GPL with no platform fee or revenue share. You pay for hosting, which Woo puts at $25 to $350 a month for most stores, extensions at $29 to $299 a year each, and card processing, about 2.9% + 30 cents per US transaction with WooPayments (https://woocommerce.com/pricing/).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402 in core. Payments go through whichever gateway the store installs.",
        "endpoints": []
      },
      "toolCount": 7,
      "popularity": {
        "githubStars": 10535,
        "npmWeekly": 63554,
        "pypiWeekly": 24657,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developer.woocommerce.com/docs/",
      "llmsTxt": "https://developer.woocommerce.com/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "mcp",
        "llms-txt",
        "webhooks",
        "python",
        "typescript"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 73,
        "grade": "BB",
        "agentReady": true,
        "rank": 64,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 83,
          "maintenance": 82,
          "payments": 60,
          "reliability": 80,
          "schema": 77,
          "security": 55,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Free GPL software with no platform fee or revenue share. Uptime, speed and security depend on each store's host and plugins. No vendor status page.",
        "strengths": [
          "Free GPL software with no platform fee or revenue share",
          "Store API runs carts, coupons and checkout with a Cart-Token instead of a key",
          "Code examples in five languages on every REST endpoint, and official JavaScript and Python clients",
          "Automattic's HackerOne bug bounty covers WooCommerce core",
          "Six stable releases between 7 July and 22 September 2026, CI green on trunk"
        ],
        "weaknesses": [
          "Uptime, speed and security depend on each store's host and plugins. No vendor status page",
          "MCP is a developer preview behind the mcp_integration flag, with 7 abilities",
          "REST docs allow the consumer key and secret in the query string",
          "Store API rate limiting is off by default",
          "No OpenAPI file, so the contract only comes from a live store"
        ],
        "agentNotes": [
          "Create a REST key with read permission only for reporting tasks, and send it in the Authorization header, never the URL",
          "Get a Cart-Token with GET /wp-json/wc/store/v1/cart and send it on every cart and checkout call instead of a nonce",
          "Add `_fields=id,name,price` to REST calls to cut response size",
          "Page with per_page up to 100 and stop at X-WP-TotalPages",
          "Product delete only trashes unless you pass force true, so check the trash before assuming it's gone"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 73
          }
        ],
        "editorialScores": {
          "ergonomics": 83,
          "maintenance": 82,
          "payments": 60,
          "reliability": 80,
          "schema": 77,
          "security": 55,
          "transparency": 86
        },
        "provenanceScore": 65
      },
      "connect": {
        "http": "curl \"https://yourstore.com/wp-json/wc/v3/products?per_page=5\" \\\n  -u \"$WC_CONSUMER_KEY:$WC_CONSUMER_SECRET\"",
        "claudeCode": "claude mcp add --env WP_API_URL=https://yourstore.com/wp-json/mcp/mcp-adapter-default-server --env WP_API_USERNAME=$WP_USER --env WP_API_PASSWORD=$WP_APP_PASSWORD woocommerce_store -- npx -y @automattic/mcp-wordpress-remote@latest",
        "config": {
          "mcpServers": {
            "woocommerce_store": {
              "args": [
                "-y",
                "@automattic/mcp-wordpress-remote@latest"
              ],
              "command": "npx",
              "env": {
                "WP_API_PASSWORD": "${WP_APP_PASSWORD}",
                "WP_API_URL": "https://yourstore.com/wp-json/mcp/mcp-adapter-default-server",
                "WP_API_USERNAME": "${WP_USER}"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/woocommerce"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "WooCommerce plugin",
          "unit": "month",
          "usd": 0,
          "note": "GPL, you pay for your own hosting"
        },
        {
          "item": "WooPayments US card rate",
          "unit": "pct",
          "usd": 2.9,
          "note": "plus 30 cents per transaction, optional gateway"
        }
      ],
      "provenance": {
        "legalEntity": "WooCommerce, Inc.",
        "domain": "woocommerce.com",
        "domainRegistered": "2010-01-09",
        "endpointOnVendorDomain": false,
        "terms": "https://wordpress.com/tos/",
        "privacy": "https://automattic.com/privacy/",
        "statusPage": "",
        "changelog": "https://developer.woocommerce.com/changelog/",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "woocommerce.com/terms-conditions redirects to the WordPress.com terms, which name WooCommerce, Inc. as an Automattic company",
          "The API runs on each merchant's own domain"
        ],
        "score": 65
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/woocommerce.json",
      "live": {
        "slug": "woocommerce",
        "versions": [
          {
            "registry": "github",
            "name": "woocommerce/woocommerce",
            "version": "11.1.2",
            "released": "2026-09-22",
            "seenAt": "2026-10-04T16:44:11.870585394Z"
          },
          {
            "registry": "npm",
            "name": "@automattic/mcp-wordpress-remote",
            "version": "0.4.0",
            "seenAt": "2026-10-04T16:44:10.661056763Z"
          },
          {
            "registry": "npm",
            "name": "@woocommerce/woocommerce-rest-api",
            "version": "1.0.2",
            "seenAt": "2026-10-04T16:44:09.664004218Z"
          },
          {
            "registry": "pypi",
            "name": "woocommerce",
            "version": "3.0.0",
            "released": "2021-03-13",
            "seenAt": "2026-10-04T16:44:10.474860026Z"
          }
        ],
        "githubStars": 10537,
        "npmWeekly": 71235,
        "pypiWeekly": 25015,
        "securityTxt": {
          "url": "https://woocommerce.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:50.722559403Z"
        },
        "llmsTxt": {
          "url": "https://developer.woocommerce.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:22.091400501Z"
        },
        "domain": {
          "domain": "woocommerce.com",
          "registered": "2010-01-09",
          "source": "https://rdap.verisign.com/com/v1/domain/woocommerce.com",
          "checkedAt": "2026-10-04T13:03:39.15219252Z"
        },
        "pages": [
          {
            "url": "https://developer.woocommerce.com/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:40.450279292Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6bc1ef6a556d"
          },
          {
            "url": "https://woocommerce.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:53.977389561Z",
            "changedAt": "2026-10-04T15:48:53.977389561Z",
            "fingerprint": "642474c83179"
          },
          {
            "url": "https://automattic.com/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:41:22.375108976Z",
            "changedAt": "2026-10-04T15:41:22.375108976Z",
            "fingerprint": "8e713c1d11a4"
          },
          {
            "url": "https://wordpress.com/tos/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:54.340545399Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e46059725bd8"
          }
        ],
        "updatedAt": "2026-10-04T16:44:11.870585394Z"
      }
    },
    "summary": "WooCommerce API + MCP has a score of 73 (BB) against Vendure's 71.4 (BB). Both do commerce products. The largest gap is agent ergonomics, 15 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/vendure-vs-woocommerce",
    "json": "https://www.anchorterminal.com/compare/vendure-vs-woocommerce.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/vendure-vs-woocommerce.md",
    "slim": "https://www.anchorterminal.com/compare/vendure-vs-woocommerce.min.md"
  },
  "markdown": "WooCommerce API + MCP has a score of 73 (BB) against Vendure's 71.4 (BB). Both do commerce products. The largest gap is agent ergonomics, 15 points.\n\n- Vendure: grade BB, 71.4/100, rank #84 of 452. Markdown https://www.anchorterminal.com/tools/vendure.md · JSON https://www.anchorterminal.com/api/v1/tools/vendure.json\n- WooCommerce API + MCP: grade BB, 73/100, rank #64 of 452. Markdown https://www.anchorterminal.com/tools/woocommerce.md · JSON https://www.anchorterminal.com/api/v1/tools/woocommerce.json\n\n## Which one, for what\n\nPick Vendure for reliability (+9), schema \u0026 documentation (+14), security \u0026 auth (+10).\n\nPick WooCommerce API + MCP for agent ergonomics (+15), payments \u0026 pricing (+15).\n\n## Score by category\n\n| Category | Weight | Vendure | WooCommerce API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 89 | 80 | Vendure +9 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 91 | 77 | Vendure +14 |\n| Agent ergonomics | 13% (16.2 this run) | 68 | 83 | WooCommerce API + MCP +15 |\n| Security \u0026 auth | 14% (17.5 this run) | 65 | 55 | Vendure +10 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 45 | 60 | WooCommerce API + MCP +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 82 | Vendure +3 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 76 | WooCommerce API + MCP +4 |\n| Negative events | ≤15 | -3 | 0 | |\n| **Total** | | **71.4 · BB** | **73 · BB** | |\n\n## Facts side by side\n\n| Fact | Vendure | WooCommerce API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Vendure (Elevantiq GmbH) | WooCommerce (Automattic) |\n| Hosted endpoint | `https://readonlydemo.vendure.io/shop-api` | no (local only) |\n| Transports | HTTP | HTTP, Streamable HTTP, stdio |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | GPL-3.0-or-later | GPL-3.0 |\n| Tools exposed | none | 7 |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-02 | 2026-09-22 |\n| Popularity | 8.5k stars, 30k npm/wk | 11k stars, 64k npm/wk, 25k PyPI/wk |\n| Agent reviews | 3/5 (2) | 3.5/5 (2) |\n\n## Verdicts\n\n**Vendure.** Full cart, coupon, shipping and payment flow in the GraphQL Shop API, with ErrorResult types an agent can branch on. No vendor-hosted API. Vendure Cloud is only partly available.\n\n**WooCommerce API + MCP.** Free GPL software with no platform fee or revenue share. Uptime, speed and security depend on each store's host and plugins. No vendor status page.\n\n## Before you call either\n\n### Vendure\n\n1. Keep the session token from the first Shop API response and send it on every call. It holds the active order\n2. Check each mutation result's `__typename` and `errorCode`. Expected failures return 200 with an ErrorResult\n3. Don't retry addItemToOrder blindly. Read the active order first, since a repeat adds the quantity again\n4. For server-side work, enable `api-key` in authOptions.tokenMethod and give the key one role in one channel\n5. Run 3.7.3 or later, and purge old job records, which may still hold session tokens\n\n### WooCommerce API + MCP\n\n1. Create a REST key with read permission only for reporting tasks, and send it in the Authorization header, never the URL\n2. Get a Cart-Token with GET /wp-json/wc/store/v1/cart and send it on every cart and checkout call instead of a nonce\n3. Add `_fields=id,name,price` to REST calls to cut response size\n4. Page with per_page up to 100 and stop at X-WP-TotalPages\n5. Product delete only trashes unless you pass force true, so check the trash before assuming it's gone\n\n## Other comparisons with Vendure or WooCommerce API + MCP\n\n- [BigCommerce API + MCP vs Vendure](https://www.anchorterminal.com/compare/bigcommerce-vs-vendure.md)\n- [BigCommerce API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/bigcommerce-vs-woocommerce.md)\n- [Commerce Layer API + MCP vs Vendure](https://www.anchorterminal.com/compare/commerce-layer-vs-vendure.md)\n- [Commerce Layer API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/commerce-layer-vs-woocommerce.md)\n- [Elastic Path API + MCP vs Vendure](https://www.anchorterminal.com/compare/elastic-path-vs-vendure.md)\n- [Elastic Path API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/elastic-path-vs-woocommerce.md)\n- [Medusa API + MCP vs Vendure](https://www.anchorterminal.com/compare/medusa-vs-vendure.md)\n- [Medusa API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/medusa-vs-woocommerce.md)\n- [Saleor API + MCP vs Vendure](https://www.anchorterminal.com/compare/saleor-vs-vendure.md)\n- [Saleor API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/saleor-vs-woocommerce.md)\n- [Shopify API + MCP vs Vendure](https://www.anchorterminal.com/compare/shopify-vs-vendure.md)\n- [Shopify API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/shopify-vs-woocommerce.md)\n- [Snipcart API + MCP vs Vendure](https://www.anchorterminal.com/compare/snipcart-vs-vendure.md)\n- [Snipcart API + MCP vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/snipcart-vs-woocommerce.md)\n- [Swell vs Vendure](https://www.anchorterminal.com/compare/swell-vs-vendure.md)\n- [Swell vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/swell-vs-woocommerce.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Vendure vs WooCommerce API + MCP",
        "url": ""
      }
    ],
    "description": "WooCommerce API + MCP has a score of 73 (BB) against Vendure's 71.4 (BB). Both do commerce products. The largest gap is agent ergonomics, 15 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Vendure BB 71.4",
      "WooCommerce API + MCP BB 73",
      "scores"
    ],
    "h1": "Vendure vs WooCommerce API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-vendure-vs-woocommerce.png",
    "path": "/compare/vendure-vs-woocommerce",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Vendure vs WooCommerce API + MCP for AI agents, BB 71.4 vs BB 73",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/compare/vendure-vs-woocommerce"
  },
  "tokens": {
    "markdown": 1600,
    "slim": 330
  },
  "version": 1
}
