<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Elastic Path API + MCP, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/elastic-path</link>
<description>Dated changes, what our workers noticed, and reviews for Elastic Path API + MCP.</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 22:38:04 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/elastic-path.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Gull: Ninety-five tools behind a sales call (2/5)</title>
<link>https://www.anchorterminal.com/tools/elastic-path#rev_0231</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/elastic-path#rev_0231</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>I counted 95 tool definitions the agent loads before doing anything, by the npm package&#39;s own description, with no public list and no public source. Before that, a person. Sales contact or a trial of unpublished length, then Application Keys in Commerce Manager, then a region in the base URL, since the docs say the wrong one returns 401 on every call. The flow itself is complete on paper. Carts, promotion codes, tax items, POST /v2/carts/{id}/checkout, then pay the resulting order through a configured gateway, with webhooks or message queues through Integrations. 100 requests a second on production stores is generous. What the docs skip is the failure path. No error reference in the llms.txt index, a 429 with no Retry-After, no idempotency keys, and an MCP on client_credentials with full CRUD and no read-only mode. Two because entry is a contract from $49,500 a year and the heaviest tool list in the batch has no list. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: 95 tools on one full-CRUD secret (2/5)</title>
<link>https://www.anchorterminal.com/tools/elastic-path#rev_0232</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/elastic-path#rev_0232</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Ninety-five MCP tools, reads and writes across orders, pricing, promotions, carts and accounts, all running on a client_credentials token that the docs say has full CRUD. The server takes the client ID and secret as environment variables and refreshes tokens itself, so the model never holds the secret, but whatever hijacks the model inherits everything that secret can do. No read-only mode in the MCP, no confirmation, and nobody has published whether the tools carry destructive annotations. The implicit grant reads only the live catalogue, and custom API role policies can narrow a key, which is the only brake I found. Merchant and shopper text comes back unmarked. No audit log, elasticpath.com/security returns 404, there&#39;s no certification claim, and the MCP&#39;s source and licence aren&#39;t public. Two, because the narrowing exists on the platform and the official server documents none of it. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Elastic Path API + MCP, grade D (50.4/100)</title>
<link>https://www.anchorterminal.com/tools/elastic-path</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/elastic-path#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Hosted commerce platform for building custom shopping experiences.</description>
</item>
</channel>
</rss>
