{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/shopify.json",
        "name": "Shopify API + MCP",
        "score": 75,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "shopify"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/woocommerce.json",
        "name": "WooCommerce API + MCP",
        "score": 72.9,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "woocommerce"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/shopware.json",
        "name": "Shopware",
        "score": 71.4,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "shopware"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/commercetools.json",
        "name": "commercetools",
        "score": 71.3,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "commercetools"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/vendure.json",
        "name": "Vendure",
        "score": 70.9,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "vendure"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/square.json",
        "name": "Square",
        "score": 69.2,
        "shared": [
          "commerce.products",
          "commerce.orders",
          "commerce.cart",
          "commerce.headless"
        ],
        "slug": "square"
      }
    ],
    "tool": {
      "slug": "ecwid",
      "name": "Ecwid by Lightspeed",
      "vendor": "Ecwid, Inc. (Lightspeed Commerce)",
      "vendorUrl": "https://www.ecwid.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Ecwid by Lightspeed is a hosted online store that embeds in any website. Its REST API reads and writes products, categories, orders, customers and discounts for one store, with webhooks and a browser JavaScript API for the cart.",
      "url": "https://www.anchorterminal.com/tools/ecwid",
      "markdownUrl": "https://www.anchorterminal.com/tools/ecwid.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/ecwid.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/ecwid.json",
      "repo": "https://github.com/Ecwid/ecwid-java-api-client",
      "license": "Proprietary service under the Lightspeed Service Agreement. The `@lightspeed/ecom-headless` npm package is MIT and the Java API client on GitHub is Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://app.ecwid.com/api/v3",
      "packages": [
        {
          "registry": "npm",
          "name": "@lightspeed/ecom-headless"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve for one store. The store admin creates a custom app automatically, with a secret token and a public token sent as `Authorization: Bearer`, and no OAuth flow. Seven of the 40 access scopes are on by default, more are added in the admin, and scopes marked sensitive need a request to API support. Public apps for many stores use OAuth 2.0 and go through app review. Tokens don't expire and are revoked by uninstalling the app.",
      "pricing": "paid",
      "pricingNotes": "Starter $5 a month, Venture $35 ($29 billed yearly), Business $65 ($49) and Unlimited $149 ($119), with no transaction fee from Ecwid. The docs say only paid plans reach the API, and the pricing page does not list API access by plan. No free plan, trial or sandbox was found. Developers can email API support for a free upgrade of a test store (https://www.ecwid.com/pricing, checked 2026-10-08).",
      "priceSummary": "$5 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs or on the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 22,
        "npmWeekly": 307,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.ecwid.com",
      "llmsTxt": "https://docs.ecwid.com/llms.txt",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "api-key",
        "oauth",
        "llms-txt",
        "webhooks",
        "typescript",
        "java",
        "status-page",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 63.2,
        "grade": "B",
        "agentReady": false,
        "rank": 316,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 79,
          "payments": 15,
          "reliability": 80,
          "schema": 66,
          "security": 61,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 80,
            "points": 16,
            "reason": "Graded as a hosted service, on the REST API. Atlassian Statuspage at status.ecwid.com with six components, API among them, and a full incident history (20). The incident feed shows one incident between 10 July and 8 October 2026, storefronts slowed for 48 minutes on 7 August, marked minor and not on the API component. We score that between clean and minor (25). 600 requests a minute per token is published (15). A 429 carries `Retry-After`, but no backoff guidance and no idempotency keys for REST writes were found (10). The Lightspeed Service Agreement disclaims any service level commitment (0). The REST API is generally available at `/api/v3` (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 66,
            "points": 10.73,
            "reason": "OpenAPI 3.0.3 definitions are embedded in the reference for store profile, store logo, orders and order extra fields only, marked version 0.0.1. No complete downloadable spec was found (10). `llms.txt`, `llms-full.txt` and a Markdown twin of every page (10). Reference pages state what each call does and which scopes it needs, with little on when not to use one (12). Parameters are typed in tables, and the published OpenAPI fragments carry almost no enums or required markers (9). Request and response examples on reference pages and a page of named error codes by area (12). The version sits in the path as `/api/v3` and a dated changelog marks breaking changes, though it was silent from 30 April to 30 September 2026 (13)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 66,
            "points": 10.73,
            "reason": "`responseFields` cuts any response to named fields, including nested ones, and `limit` caps list size (20). Searches page with `offset` and `limit` up to 100 and take filters such as keyword, date ranges and status (18). A published list of named error codes with HTTP status, including scope and plan errors an agent can act on (15). No idempotency keys on REST writes were found. The only idempotency key in the docs belongs to app billing charges (2). A GET needs only the store ID and a token. The official TypeScript package covers GET calls only and the official Java and Kotlin client is on GitHub. No official Python client (11)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 61,
            "points": 10.68,
            "reason": "40 access scopes fixed per app, with tokens revoked by uninstalling the app. Tokens never expire and can't be rotated in place. Tokens in the query string were switched off in March 2025 (24). Scopes split read, update and create, and the public token reads only enabled catalogue data and places unpaid orders. No confirmation step for deletes (13). The API returns merchant and shopper text, and no prompt-injection guidance was found (5). No audit log or per-call log for API use was found in the developer docs. A deleted-items history endpoint exists (3). SOC 2 Type II and a PCI attestation listed for E-Series, a public bug bounty and yearly penetration tests per Lightspeed's security page. No security.txt was read (16)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 15,
            "points": 1.88,
            "reason": "No x402, MPP or L402 (0). Plan prices are public, Starter $5, Venture $35, Business $65 and Unlimited $149 a month, with nothing per call (10). No free plan or trial was found on the pricing page, and the docs say only paid plans reach the API. Developers can email API support for a free upgrade of a test store, which earns part of the line (5). A person signs up in a browser and copies the token from the admin (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 79,
            "points": 6.91,
            "reason": "The API changelog's newest entry is 30 September 2026 (30). That is its only dated entry in 90 days, but the official `@lightspeed/ecom-headless` package had five npm releases since 10 July, 1.2.0 on 2 September and 1.2.1 on 1 October among them, so we count the line as met on SDK releases (20). Public changelog, API support that states a reply within 24 hours on business days, and a Slack community. Replies were not tested (10). Official TypeScript package current, Java and Kotlin client last committed 15 September 2026, no official Python, Ruby or PHP client (12). The Java client runs pull-request and push workflows on GitHub (7)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 72,
            "points": 6.3,
            "note": "editorial 56, provenance 87",
            "reason": "Closed service with a published service agreement, updated 26 February 2026, that names Ecwid, Inc. as the contracting entity for E-Series (15). Privacy policy effective 8 July 2026 and a public DPA, both written for the whole Lightspeed group. Retention is stated as for as long as reasonably needed, with no periods (18). No deprecation policy was found. The changelog marks breaking changes, and the March 2025 entry on query-string tokens announces a change already made (5). The sub-processor list, updated 30 September 2026, gives purpose, product line and country for each provider, with E-Series rows (18)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "`responseFields` cuts any response to named fields, including nested ones, and `limit` caps list size (20). Searches page with `offset` and `limit` up to 100 and take filters such as keyword, date ranges and status (18). A published list of named error codes with HTTP status, including scope and plan errors an agent can act on (15). No idempotency keys on REST writes were found. The only idempotency key in the docs belongs to app billing charges (2). A GET needs only the store ID and a token. The official TypeScript package covers GET calls only and the official Java and Kotlin client is on GitHub. No official Python client (11).",
            "maintenance": "The API changelog's newest entry is 30 September 2026 (30). That is its only dated entry in 90 days, but the official `@lightspeed/ecom-headless` package had five npm releases since 10 July, 1.2.0 on 2 September and 1.2.1 on 1 October among them, so we count the line as met on SDK releases (20). Public changelog, API support that states a reply within 24 hours on business days, and a Slack community. Replies were not tested (10). Official TypeScript package current, Java and Kotlin client last committed 15 September 2026, no official Python, Ruby or PHP client (12). The Java client runs pull-request and push workflows on GitHub (7).",
            "payments": "No x402, MPP or L402 (0). Plan prices are public, Starter $5, Venture $35, Business $65 and Unlimited $149 a month, with nothing per call (10). No free plan or trial was found on the pricing page, and the docs say only paid plans reach the API. Developers can email API support for a free upgrade of a test store, which earns part of the line (5). A person signs up in a browser and copies the token from the admin (0).",
            "reliability": "Graded as a hosted service, on the REST API. Atlassian Statuspage at status.ecwid.com with six components, API among them, and a full incident history (20). The incident feed shows one incident between 10 July and 8 October 2026, storefronts slowed for 48 minutes on 7 August, marked minor and not on the API component. We score that between clean and minor (25). 600 requests a minute per token is published (15). A 429 carries `Retry-After`, but no backoff guidance and no idempotency keys for REST writes were found (10). The Lightspeed Service Agreement disclaims any service level commitment (0). The REST API is generally available at `/api/v3` (10).",
            "schema": "OpenAPI 3.0.3 definitions are embedded in the reference for store profile, store logo, orders and order extra fields only, marked version 0.0.1. No complete downloadable spec was found (10). `llms.txt`, `llms-full.txt` and a Markdown twin of every page (10). Reference pages state what each call does and which scopes it needs, with little on when not to use one (12). Parameters are typed in tables, and the published OpenAPI fragments carry almost no enums or required markers (9). Request and response examples on reference pages and a page of named error codes by area (12). The version sits in the path as `/api/v3` and a dated changelog marks breaking changes, though it was silent from 30 April to 30 September 2026 (13).",
            "security": "40 access scopes fixed per app, with tokens revoked by uninstalling the app. Tokens never expire and can't be rotated in place. Tokens in the query string were switched off in March 2025 (24). Scopes split read, update and create, and the public token reads only enabled catalogue data and places unpaid orders. No confirmation step for deletes (13). The API returns merchant and shopper text, and no prompt-injection guidance was found (5). No audit log or per-call log for API use was found in the developer docs. A deleted-items history endpoint exists (3). SOC 2 Type II and a PCI attestation listed for E-Series, a public bug bounty and yearly penetration tests per Lightspeed's security page. No security.txt was read (16).",
            "transparency": "Closed service with a published service agreement, updated 26 February 2026, that names Ecwid, Inc. as the contracting entity for E-Series (15). Privacy policy effective 8 July 2026 and a public DPA, both written for the whole Lightspeed group. Retention is stated as for as long as reasonably needed, with no periods (18). No deprecation policy was found. The changelog marks breaking changes, and the March 2025 entry on query-string tokens announces a change already made (5). The sub-processor list, updated 30 September 2026, gives purpose, product line and country for each provider, with E-Series rows (18)."
          },
          "sources": [
            {
              "what": "developer docs index",
              "url": "https://docs.ecwid.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "REST API overview and rate limits",
              "url": "https://docs.ecwid.com/api-reference/rest-api/rest-api-overview",
              "seen": "2026-10-08"
            },
            {
              "what": "REST API error codes",
              "url": "https://docs.ecwid.com/api-reference/rest-api/rest-api-error-codes",
              "seen": "2026-10-08"
            },
            {
              "what": "app settings, tokens and access scopes",
              "url": "https://docs.ecwid.com/develop-apps/app-settings",
              "seen": "2026-10-08"
            },
            {
              "what": "dev environment and plan requirement",
              "url": "https://docs.ecwid.com/get-started/set-up-your-dev-environment-in-ecwid",
              "seen": "2026-10-08"
            },
            {
              "what": "first API request, no test mode",
              "url": "https://docs.ecwid.com/get-started/make-your-first-api-request",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI fragments for orders",
              "url": "https://docs.ecwid.com/api-reference/openapi/orders",
              "seen": "2026-10-08"
            },
            {
              "what": "search products reference",
              "url": "https://docs.ecwid.com/api-reference/rest-api/products/search-products",
              "seen": "2026-10-08"
            },
            {
              "what": "place an order with the API",
              "url": "https://docs.ecwid.com/guides/orders/create-orders/place-new-order-with-api",
              "seen": "2026-10-08"
            },
            {
              "what": "webhook handling and retries",
              "url": "https://docs.ecwid.com/webhook-automations/setup-webhooks/how-to-process-webhooks",
              "seen": "2026-10-08"
            },
            {
              "what": "API changelog",
              "url": "https://docs.ecwid.com/changelog/ecwid-api-changelog",
              "seen": "2026-10-08"
            },
            {
              "what": "query-string tokens switched off",
              "url": "https://docs.ecwid.com/changelog/march-2025/march-20/discontinued-tokens-passing-in-query-params-of-api-calls",
              "seen": "2026-10-08"
            },
            {
              "what": "API support",
              "url": "https://docs.ecwid.com/contact-ecwid-api-support-team",
              "seen": "2026-10-08"
            },
            {
              "what": "status page",
              "url": "https://status.ecwid.com/",
              "seen": "2026-10-08"
            },
            {
              "what": "status incident feed",
              "url": "https://status.ecwid.com/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://www.ecwid.com/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "service agreement",
              "url": "https://www.lightspeedhq.com/legal/lightspeed-service-agreement/",
              "seen": "2026-10-08"
            },
            {
              "what": "API licence agreement",
              "url": "https://developers.lightspeedhq.com/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.lightspeedhq.com/legal/privacy-policy/",
              "seen": "2026-10-08"
            },
            {
              "what": "data processing agreement",
              "url": "https://www.lightspeedhq.com/legal/data-processing-agreement/",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processors",
              "url": "https://www.lightspeedhq.com/legal/subprocessors/",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://www.lightspeedhq.com/security/",
              "seen": "2026-10-08"
            },
            {
              "what": "npm package",
              "url": "https://registry.npmjs.org/@lightspeed/ecom-headless",
              "seen": "2026-10-08"
            },
            {
              "what": "Java API client",
              "url": "https://github.com/Ecwid/ecwid-java-api-client",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.org/domain/ecwid.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: which plans include API access. The docs say paid plans only, the pricing page does not list the API, and the help centre at support.ecwid.com answered with a bot check",
            "unchecked: whether signing up for a store needs a card, and whether any trial exists beyond the test-store upgrade developers request by email",
            "unchecked: security.txt. www.ecwid.com/.well-known/security.txt answered 403 and the lightspeedhq.com path 404",
            "Lightspeed's API licence agreement does not name Ecwid or E-Series, so its application to the Ecwid API rests on the service agreement's API clause",
            "No audit log, deprecation policy or MCP server was found in the developer docs. The store admin was not inspected",
            "The lead described APIs for carts and checkout. The REST API reads abandoned carts and creates orders directly, and live cart and checkout calls exist only in the browser JavaScript API"
          ]
        },
        "negative": 0,
        "verdict": "The REST API has 40 access scopes, a published limit of 600 requests a minute per token with `Retry-After` on a 429, field selection through `responseFields`, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.",
        "bestFor": "An agent doing back-office work on an existing Ecwid store, such as catalogue edits, order export and discount coupons.",
        "strengths": [
          "40 access scopes split into read, update and create, plus a public token limited to enabled catalogue data and unpaid orders",
          "Published limit of 600 requests a minute per token, and a 429 carries a `Retry-After` header",
          "`responseFields` trims any response to named fields, and searches page with `offset` and `limit` up to 100",
          "Every docs page is served as Markdown, with `llms.txt` and `llms-full.txt` indexes",
          "One incident on status.ecwid.com between 10 July and 8 October 2026, a 48-minute storefront slowdown on 7 August"
        ],
        "weaknesses": [
          "Access tokens never expire and change only when the app is uninstalled and installed again",
          "No test mode. The docs advise a separate test store, and only stores on paid plans can call the API",
          "No idempotency keys on REST writes found in the reviewed documentation",
          "OpenAPI 3.0.3 definitions are published for store profile and orders only, with no complete downloadable spec found",
          "The REST API has no endpoint that builds a live cart or runs checkout. Those sit in the browser JavaScript API",
          "The service agreement disclaims any service level commitment"
        ],
        "agentNotes": [
          "Send the token as `Authorization: Bearer` to `https://app.ecwid.com/api/v3/{storeId}`. Tokens in the query string stopped working in March 2025",
          "Use the secret token server-side only. The public token reads enabled products and places orders that are not marked paid",
          "Add `responseFields`, for example `total,items(id,name,price)`, to keep responses small, and page with `offset` and `limit` (maximum 100)",
          "Stay under 600 requests a minute per token and wait the `Retry-After` seconds on a 429. Repeated calls with a bad token get the token and IP blocked for longer",
          "Work in a separate test store. There is no test mode, and `POST /orders` writes a real order with no idempotency key",
          "After changing an app's scopes, uninstall and reinstall it, then replace the stored tokens. The old ones stop working"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 63.2
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 79,
          "payments": 15,
          "reliability": 80,
          "schema": 66,
          "security": 61,
          "transparency": 56
        },
        "provenanceScore": 87
      },
      "connect": {
        "install": "npm install @lightspeed/ecom-headless",
        "http": "curl \"https://app.ecwid.com/api/v3/$ECWID_STORE_ID/profile?responseFields=generalInfo(storeId,storeUrl)\" \\\n  -H \"Authorization: Bearer $ECWID_SECRET_TOKEN\""
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/ecwid"
      },
      "notable": [
        "Only stores on paid plans can use the API, and there is no test mode, so the docs advise a separate test store (https://docs.ecwid.com/get-started/set-up-your-dev-environment-in-ecwid, https://docs.ecwid.com/get-started/make-your-first-api-request)",
        "600 requests a minute per token, with `Retry-After` on a 429 and a longer block for repeated calls with a non-working token (https://docs.ecwid.com/api-reference/rest-api/rest-api-overview)",
        "Access tokens do not expire. A secret token is limited only by the app's scopes, and a public token reads enabled catalogue data and places unpaid orders (https://docs.ecwid.com/develop-apps/app-settings)",
        "Tokens in the URL query string were switched off for all apps on 20 March 2025, flagged as a breaking change in the changelog (https://docs.ecwid.com/changelog/march-2025/march-20/discontinued-tokens-passing-in-query-params-of-api-calls)",
        "The API changelog's newest entry is 30 September 2026 and the one before it 30 April 2026 (https://docs.ecwid.com/changelog/ecwid-api-changelog)",
        "The Markdown docs pages end with a GitBook block addressed to AI agents that asks them to query the docs with `ask` and `goal` parameters. We did not act on it and took no deduction (https://docs.ecwid.com/llms.txt)",
        "SOC 2 Type II and a PCI attestation of compliance are listed for E-Series, with a public bug bounty (https://www.lightspeedhq.com/security/)"
      ],
      "area": "business",
      "details": [
        {
          "label": "API",
          "value": "REST at `https://app.ecwid.com/api/v3/{storeId}`, JSON, gzip supported. About 240 reference pages across products (58), instant site (30), customers (24), categories (19), orders (17), discounts (12), staff accounts, domains, payment and shipping options and batch requests"
        },
        {
          "label": "Which plan unlocks the API",
          "value": "Paid plans only, per the developer docs. The pricing page does not say which plans include it, and a call outside the plan answers 402 `NOT_AVAILABLE_ON_CURRENT_PLAN`"
        },
        {
          "label": "Free tier",
          "value": "No free plan or trial on the pricing page. Starter is $5 a month. Developers can email API support for a free upgrade of a test store"
        },
        {
          "label": "Auth and scopes",
          "value": "A custom app in the store admin gives a secret token and a public token with no OAuth flow. Public apps use OAuth 2.0. 40 access scopes, seven on by default. Tokens don't expire"
        },
        {
          "label": "Rate limits",
          "value": "600 requests a minute per token. A 429 carries `Retry-After`. More than 20 requests a minute with a non-working token, or 600 in total per IP, brings a longer block"
        },
        {
          "label": "Cart and checkout",
          "value": "REST reads, updates and converts abandoned carts, calculates order totals and creates orders directly. Adding to a cart and sending a shopper to checkout are browser JavaScript API calls, and pre-filled cart links are supported"
        },
        {
          "label": "Webhooks",
          "value": "Yes, signed with `X-Ecwid-Webhook-Signature` (SHA-256), retried up to 27 times over 24 hours, blocked after two weeks of failures. Needs the app's `webhookUrl`"
        },
        {
          "label": "Errors",
          "value": "A published list of named codes with HTTP status, such as `WRONG_PARAMETER` (400), `INSUFFICIENT_APP_SCOPE` (403) and `PRODUCT_NOT_FOUND` (404)"
        },
        {
          "label": "SDKs",
          "value": "`@lightspeed/ecom-headless` 1.2.1 on npm (1 October 2026, MIT), a typed TypeScript client whose REST functions are GET only with the public token. Java and Kotlin client `ecwid-java-api-client` on GitHub (Apache-2.0, last commit 15 September 2026). Ruby, PHP and C# libraries are community work"
        },
        {
          "label": "MCP server",
          "value": "None found in the developer docs or the Ecwid GitHub organisation"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type II and a PCI attestation of compliance listed for E-Series (Ecwid) on Lightspeed's security page, with a public bug bounty and yearly penetration tests"
        },
        {
          "label": "Status",
          "value": "status.ecwid.com on Atlassian Statuspage, six components (Storefront, Checkout, Admin, API, Third-party services, Billing)"
        },
        {
          "label": "Sub-processors",
          "value": "Lightspeed's list, updated 30 September 2026, names each provider's purpose, product line and country. For E-Series it includes Amazon Web Services and Google as cloud hosts"
        }
      ],
      "unitPrices": [
        {
          "item": "Starter",
          "unit": "month",
          "usd": 5,
          "note": "up to 10 products. The docs say only paid plans reach the API and the pricing page does not list API access by plan"
        },
        {
          "item": "Venture",
          "unit": "month",
          "usd": 35,
          "note": "$29 a month billed yearly, up to 100 products"
        },
        {
          "item": "Business",
          "unit": "month",
          "usd": 65,
          "note": "$49 a month billed yearly, up to 2,500 products"
        },
        {
          "item": "Unlimited",
          "unit": "month",
          "usd": 149,
          "note": "$119 a month billed yearly, unlimited products"
        }
      ],
      "provenance": {
        "legalEntity": "Ecwid, Inc.",
        "domain": "ecwid.com",
        "domainRegistered": "2009-01-08",
        "endpointOnVendorDomain": true,
        "terms": "https://www.lightspeedhq.com/legal/lightspeed-service-agreement/",
        "privacy": "https://www.lightspeedhq.com/legal/privacy-policy/",
        "statusPage": "https://status.ecwid.com",
        "changelog": "https://docs.ecwid.com/changelog/ecwid-api-changelog",
        "securityTxt": "unknown",
        "checked": "2026-10-08",
        "notes": [
          "www.ecwid.com/terms-of-service redirects to the Lightspeed Service Agreement (last updated 26 February 2026), whose contracting-entity table names Ecwid, Inc., Delaware, for Lightspeed eCom (E-Series) worldwide.",
          "The service agreement says API use is governed by Lightspeed's API licence agreement at https://developers.lightspeedhq.com/terms (effective 20 May 2025), which does not name Ecwid or E-Series.",
          "www.ecwid.com/privacy-policy and /eu-privacy-policy redirect to Lightspeed's privacy policy (effective 8 July 2026), which lists Ecwid, Inc. among the entities certified under the Data Privacy Framework.",
          "www.ecwid.com/.well-known/security.txt answered 403 and www.lightspeedhq.com/.well-known/security.txt answered 404, so no security.txt was read.",
          "RDAP for ecwid.com gives a registration date of 2009-01-08.",
          "The REST API answers at app.ecwid.com. Docs are hosted on GitBook at docs.ecwid.com."
        ],
        "score": 87,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Ecwid, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "ecwid.com, registered 2009-01-08 (17 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "app.ecwid.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 7 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.ecwid.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "could not be fetched",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.lightspeedhq.com/legal/lightspeed-service-agreement/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-02-26",
            "words": 13230,
            "points": 8,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated: February 26, 2026",
                "says": "Last updated 2026-02-26"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The arbitration will be conducted pursuant to the Rules of the International Court of Arbitration of the International Chamber of Commerce that are in effect on the date of the receipt of the Dispute Notice (the “Rules”)."
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "TO THE FULLEST EXTENT PERMISSIBLE BY APPLICABLE LAW, LIGHTSPEED’S AGGREGATE LIABILITY UNDER THIS AGREEMENT SHALL BE LIMITED TO THE FEES PAID BY CUSTOMER DURING THE THREE-MONTH PERIOD IMMEDIATELY PRECEDING THE DATE THE CLAIM GIVING RISE TO SUCH LIABILITY WAS FIRST ASSERTED.",
                "says": "Capped at the fees paid in the 3 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Except as otherwise specified herein, Customer may not terminate this Agreement prior to the expiration of the Term."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "Lightspeed reserves the right, at any time and upon thirty (30) days’ written notice, to amend this Agreement, including making changes to the Fees and scope of the Products.",
                "says": "Gives thirty days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Except as otherwise specified herein, Customer may not terminate this Agreement prior to the expiration of the Term."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "LIGHTSPEED EXPRESSLY DISCLAIMS ANY SPECIFIC SERVICE LEVEL WARRANTIES OR COMMITMENTS."
              }
            ],
            "toKnow": [
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "Lightspeed and the Social Media Networks are continually making changes and improvements to this feature, and therefore the available features, and information that is shared, may change from time to time and without notice.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "Notwithstanding the foregoing, Lightspeed reserves the right, at any time and without notice, to suspend or terminate this Agreement if Customer or any User violates the license restrictions under Section 3 of the Agreement."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "Customer agrees to waive any right Customer may have to commence or participate in any class action or representative proceeding against Lightspeed related to any Dispute and, where applicable, Customer also agrees to opt out of any class or representative proceedings against Lightspeed."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Lightspeed's total liability is limited to the fees the customer paid in the three months before the claim was first asserted.",
                "quote": "TO THE FULLEST EXTENT PERMISSIBLE BY APPLICABLE LAW, LIGHTSPEED’S AGGREGATE LIABILITY UNDER THIS AGREEMENT SHALL BE LIMITED TO THE FEES PAID BY CUSTOMER DURING THE THREE-MONTH PERIOD IMMEDIATELY PRECEDING THE DATE THE CLAIM GIVING RISE TO SUCH LIABILITY WAS FIRST ASSERTED."
              },
              {
                "date": "2026-10-08",
                "text": "API access falls under a separate API License Agreement, which lets Lightspeed limit or revoke that access at any time in its sole discretion.",
                "quote": "Customer acknowledges that the API Agreement provides Lightspeed with the latitude to limit or revoke Customer’s access to the Lightspeed APIs at any time in its sole discretion."
              },
              {
                "date": "2026-10-08",
                "text": "After the account or use of the product ends, Lightspeed may deactivate the account and delete customer content immediately.",
                "quote": "Customer agrees that following termination of Customer’s account and/or use of the Product, Lightspeed may immediately deactivate Customer’s account and delete Customer Content."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.lightspeedhq.com/legal/privacy-policy/",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 6325,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "In addition, we collect your payment details to be able to process the payment of your subscription fee or purchase price."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "If de-identification is not possible (for example, because your Personal Data has been stored in backup archives), then we will securely store your Personal Data and isolate it from any further processing until deletion is possible."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Customers may provide Personal Data of End-Users and other third parties by inputting that Personal Data into the Services, for example, when they process a transaction."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We do not sell Personal Data of children under the age of 16.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Right to Know about the Collection, Disclosure and Sale of Personal Data"
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "You can email our Privacy Officer at [email protected] or send a letter to the attention of the Legal Department to either of the following addresses:",
                "says": "Gives an email address, hidden from our reader by the page"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "…appropriate transfer mechanism and appropriate safeguards with any recipient or sub-processor, such as Standard Contractual Clauses as adopted by the European Commission or Data Processing Agreements ensuring an adequate level of data protection.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "While Lightspeed does not “sell” your Personal Data in the conventional sense, we use certain cookies and tracking technologies that may be considered “selling” or “sharing” under certain state laws."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Lightspeed may sell information derived from aggregated and de-identified personal data where it cannot be used to re-identify individuals.",
                "quote": "Lightspeed may also sell non-personally identifiable information that has been derived from aggregated and de-identified Personal Data, provided such information cannot be used to re-identify individual Visitors or Customers."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/ecwid.json",
      "live": {
        "slug": "ecwid",
        "probe": {
          "target": "https://app.ecwid.com/api/v3",
          "method": "get",
          "lastAt": "2026-10-08T21:53:21.175492509Z",
          "lastOk": true,
          "lastStatus": 400,
          "lastMs": 68,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 100,
          "p95ms24h": 154,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.ecwid.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T21:57:51.749610897Z"
        },
        "updatedAt": "2026-10-08T21:57:51.749610897Z"
      }
    },
    "verify": {
      "accepts": "a page on ecwid.com or one of its subdomains, or the README of github.com/Ecwid/ecwid-java-api-client",
      "badgeUrl": "https://www.anchorterminal.com/badges/ecwid.svg",
      "body": {
        "slug": "ecwid",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/ecwid",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/ecwid\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/ecwid.svg\" alt=\"Ecwid by Lightspeed on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Ecwid by Lightspeed on Anchor Terminal](https://www.anchorterminal.com/badges/ecwid.svg)](https://www.anchorterminal.com/tools/ecwid)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/ecwid\"\u003eEcwid by Lightspeed on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/ecwid",
    "json": "https://www.anchorterminal.com/tools/ecwid.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/ecwid.md",
    "slim": "https://www.anchorterminal.com/tools/ecwid.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 63.2/100 · rank #316 of 722 · #12 in Commerce \u0026 checkout · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe REST API has 40 access scopes, a published limit of 600 requests a minute per token with `Retry-After` on a 429, field selection through `responseFields`, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Ecwid, Inc. (Lightspeed Commerce) (https://www.ecwid.com) |\n| Kind | HTTP API |\n| Category | Commerce \u0026 checkout (https://www.anchorterminal.com/categories/commerce) |\n| Transport | HTTP |\n| Endpoint | `https://app.ecwid.com/api/v3` |\n| Auth | OAuth or key · Self-serve for one store. The store admin creates a custom app automatically, with a secret token and a public token sent as `Authorization: Bearer`, and no OAuth flow. Seven of the 40 access scopes are on by default, more are added in the admin, and scopes marked sensitive need a request to API support. Public apps for many stores use OAuth 2.0 and go through app review. Tokens don't expire and are revoked by uninstalling the app. |\n| Pricing | Paid ($5 / mo) · Starter $5 a month, Venture $35 ($29 billed yearly), Business $65 ($49) and Unlimited $149 ($119), with no transaction fee from Ecwid. The docs say only paid plans reach the API, and the pricing page does not list API access by plan. No free plan, trial or sandbox was found. Developers can email API support for a free upgrade of a test store (https://www.ecwid.com/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the developer docs or on the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under the Lightspeed Service Agreement. The `@lightspeed/ecom-headless` npm package is MIT and the Java API client on GitHub is Apache-2.0 |\n| Packages | npm: `@lightspeed/ecom-headless` |\n| Source | https://github.com/Ecwid/ecwid-java-api-client |\n| Docs | https://docs.ecwid.com |\n| llms.txt | https://docs.ecwid.com/llms.txt |\n| Last release | 2026-09-30 |\n| GitHub stars | 22 (as of 2026-10-08) |\n| npm downloads / week | 307 |\n| API | REST at `https://app.ecwid.com/api/v3/{storeId}`, JSON, gzip supported. About 240 reference pages across products (58), instant site (30), customers (24), categories (19), orders (17), discounts (12), staff accounts, domains, payment and shipping options and batch requests |\n| Which plan unlocks the API | Paid plans only, per the developer docs. The pricing page does not say which plans include it, and a call outside the plan answers 402 `NOT_AVAILABLE_ON_CURRENT_PLAN` |\n| Free tier | No free plan or trial on the pricing page. Starter is $5 a month. Developers can email API support for a free upgrade of a test store |\n| Auth and scopes | A custom app in the store admin gives a secret token and a public token with no OAuth flow. Public apps use OAuth 2.0. 40 access scopes, seven on by default. Tokens don't expire |\n| Rate limits | 600 requests a minute per token. A 429 carries `Retry-After`. More than 20 requests a minute with a non-working token, or 600 in total per IP, brings a longer block |\n| Cart and checkout | REST reads, updates and converts abandoned carts, calculates order totals and creates orders directly. Adding to a cart and sending a shopper to checkout are browser JavaScript API calls, and pre-filled cart links are supported |\n| Webhooks | Yes, signed with `X-Ecwid-Webhook-Signature` (SHA-256), retried up to 27 times over 24 hours, blocked after two weeks of failures. Needs the app's `webhookUrl` |\n| Errors | A published list of named codes with HTTP status, such as `WRONG_PARAMETER` (400), `INSUFFICIENT_APP_SCOPE` (403) and `PRODUCT_NOT_FOUND` (404) |\n| SDKs | `@lightspeed/ecom-headless` 1.2.1 on npm (1 October 2026, MIT), a typed TypeScript client whose REST functions are GET only with the public token. Java and Kotlin client `ecwid-java-api-client` on GitHub (Apache-2.0, last commit 15 September 2026). Ruby, PHP and C# libraries are community work |\n| MCP server | None found in the developer docs or the Ecwid GitHub organisation |\n| Certifications | SOC 2 Type II and a PCI attestation of compliance listed for E-Series (Ecwid) on Lightspeed's security page, with a public bug bounty and yearly penetration tests |\n| Status | status.ecwid.com on Atlassian Statuspage, six components (Storefront, Checkout, Admin, API, Third-party services, Billing) |\n| Sub-processors | Lightspeed's list, updated 30 September 2026, names each provider's purpose, product line and country. For E-Series it includes Amazon Web Services and Google as cloud hosts |\n| Capabilities | commerce.products, commerce.cart, commerce.orders, commerce.headless |\n| Tags | hosted, closed-source, api-key, oauth, llms-txt, webhooks, typescript, java, status-page, bug-bounty, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/ecwid.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 80 | 16.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 66 | 10.7 |\n| Agent ergonomics | 13% | 16.2 | 66 | 10.7 |\n| Security \u0026 auth | 14% | 17.5 | 61 | 10.7 |\n| Payments \u0026 pricing | 10% | 12.5 | 15 | 1.9 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 79 | 6.9 |\n| Transparency \u0026 trust (editorial 56, provenance 87) | 7% | 8.8 | 72 | 6.3 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **63.2 → B** |\n\n### Why each score\n\n- Reliability 80: Graded as a hosted service, on the REST API. Atlassian Statuspage at status.ecwid.com with six components, API among them, and a full incident history (20). The incident feed shows one incident between 10 July and 8 October 2026, storefronts slowed for 48 minutes on 7 August, marked minor and not on the API component. We score that between clean and minor (25). 600 requests a minute per token is published (15). A 429 carries `Retry-After`, but no backoff guidance and no idempotency keys for REST writes were found (10). The Lightspeed Service Agreement disclaims any service level commitment (0). The REST API is generally available at `/api/v3` (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 66: OpenAPI 3.0.3 definitions are embedded in the reference for store profile, store logo, orders and order extra fields only, marked version 0.0.1. No complete downloadable spec was found (10). `llms.txt`, `llms-full.txt` and a Markdown twin of every page (10). Reference pages state what each call does and which scopes it needs, with little on when not to use one (12). Parameters are typed in tables, and the published OpenAPI fragments carry almost no enums or required markers (9). Request and response examples on reference pages and a page of named error codes by area (12). The version sits in the path as `/api/v3` and a dated changelog marks breaking changes, though it was silent from 30 April to 30 September 2026 (13).\n- Agent ergonomics 66: `responseFields` cuts any response to named fields, including nested ones, and `limit` caps list size (20). Searches page with `offset` and `limit` up to 100 and take filters such as keyword, date ranges and status (18). A published list of named error codes with HTTP status, including scope and plan errors an agent can act on (15). No idempotency keys on REST writes were found. The only idempotency key in the docs belongs to app billing charges (2). A GET needs only the store ID and a token. The official TypeScript package covers GET calls only and the official Java and Kotlin client is on GitHub. No official Python client (11).\n- Security \u0026 auth 61: 40 access scopes fixed per app, with tokens revoked by uninstalling the app. Tokens never expire and can't be rotated in place. Tokens in the query string were switched off in March 2025 (24). Scopes split read, update and create, and the public token reads only enabled catalogue data and places unpaid orders. No confirmation step for deletes (13). The API returns merchant and shopper text, and no prompt-injection guidance was found (5). No audit log or per-call log for API use was found in the developer docs. A deleted-items history endpoint exists (3). SOC 2 Type II and a PCI attestation listed for E-Series, a public bug bounty and yearly penetration tests per Lightspeed's security page. No security.txt was read (16).\n- Payments \u0026 pricing 15: No x402, MPP or L402 (0). Plan prices are public, Starter $5, Venture $35, Business $65 and Unlimited $149 a month, with nothing per call (10). No free plan or trial was found on the pricing page, and the docs say only paid plans reach the API. Developers can email API support for a free upgrade of a test store, which earns part of the line (5). A person signs up in a browser and copies the token from the admin (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 79: The API changelog's newest entry is 30 September 2026 (30). That is its only dated entry in 90 days, but the official `@lightspeed/ecom-headless` package had five npm releases since 10 July, 1.2.0 on 2 September and 1.2.1 on 1 October among them, so we count the line as met on SDK releases (20). Public changelog, API support that states a reply within 24 hours on business days, and a Slack community. Replies were not tested (10). Official TypeScript package current, Java and Kotlin client last committed 15 September 2026, no official Python, Ruby or PHP client (12). The Java client runs pull-request and push workflows on GitHub (7).\n- Transparency \u0026 trust 72: Closed service with a published service agreement, updated 26 February 2026, that names Ecwid, Inc. as the contracting entity for E-Series (15). Privacy policy effective 8 July 2026 and a public DPA, both written for the whole Lightspeed group. Retention is stated as for as long as reasonably needed, with no periods (18). No deprecation policy was found. The changelog marks breaking changes, and the March 2025 entry on query-string tokens announces a change already made (5). The sub-processor list, updated 30 September 2026, gives purpose, product line and country for each provider, with E-Series rows (18).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (16 items): https://www.anchorterminal.com/fixes/ecwid.md (JSON https://www.anchorterminal.com/fixes/ecwid.json)\n\n### What we couldn't check\n\n- unchecked: which plans include API access. The docs say paid plans only, the pricing page does not list the API, and the help centre at support.ecwid.com answered with a bot check\n- unchecked: whether signing up for a store needs a card, and whether any trial exists beyond the test-store upgrade developers request by email\n- unchecked: security.txt. www.ecwid.com/.well-known/security.txt answered 403 and the lightspeedhq.com path 404\n- Lightspeed's API licence agreement does not name Ecwid or E-Series, so its application to the Ecwid API rests on the service agreement's API clause\n- No audit log, deprecation policy or MCP server was found in the developer docs. The store admin was not inspected\n- The lead described APIs for carts and checkout. The REST API reads abandoned carts and creates orders directly, and live cart and checkout calls exist only in the browser JavaScript API\n\n### Sources\n\n- developer docs index: \u003chttps://docs.ecwid.com/llms.txt\u003e (seen 2026-10-08)\n- REST API overview and rate limits: \u003chttps://docs.ecwid.com/api-reference/rest-api/rest-api-overview\u003e (seen 2026-10-08)\n- REST API error codes: \u003chttps://docs.ecwid.com/api-reference/rest-api/rest-api-error-codes\u003e (seen 2026-10-08)\n- app settings, tokens and access scopes: \u003chttps://docs.ecwid.com/develop-apps/app-settings\u003e (seen 2026-10-08)\n- dev environment and plan requirement: \u003chttps://docs.ecwid.com/get-started/set-up-your-dev-environment-in-ecwid\u003e (seen 2026-10-08)\n- first API request, no test mode: \u003chttps://docs.ecwid.com/get-started/make-your-first-api-request\u003e (seen 2026-10-08)\n- OpenAPI fragments for orders: \u003chttps://docs.ecwid.com/api-reference/openapi/orders\u003e (seen 2026-10-08)\n- search products reference: \u003chttps://docs.ecwid.com/api-reference/rest-api/products/search-products\u003e (seen 2026-10-08)\n- place an order with the API: \u003chttps://docs.ecwid.com/guides/orders/create-orders/place-new-order-with-api\u003e (seen 2026-10-08)\n- webhook handling and retries: \u003chttps://docs.ecwid.com/webhook-automations/setup-webhooks/how-to-process-webhooks\u003e (seen 2026-10-08)\n- API changelog: \u003chttps://docs.ecwid.com/changelog/ecwid-api-changelog\u003e (seen 2026-10-08)\n- query-string tokens switched off: \u003chttps://docs.ecwid.com/changelog/march-2025/march-20/discontinued-tokens-passing-in-query-params-of-api-calls\u003e (seen 2026-10-08)\n- API support: \u003chttps://docs.ecwid.com/contact-ecwid-api-support-team\u003e (seen 2026-10-08)\n- status page: \u003chttps://status.ecwid.com/\u003e (seen 2026-10-08)\n- status incident feed: \u003chttps://status.ecwid.com/api/v2/incidents.json\u003e (seen 2026-10-08)\n- pricing: \u003chttps://www.ecwid.com/pricing\u003e (seen 2026-10-08)\n- service agreement: \u003chttps://www.lightspeedhq.com/legal/lightspeed-service-agreement/\u003e (seen 2026-10-08)\n- API licence agreement: \u003chttps://developers.lightspeedhq.com/terms\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.lightspeedhq.com/legal/privacy-policy/\u003e (seen 2026-10-08)\n- data processing agreement: \u003chttps://www.lightspeedhq.com/legal/data-processing-agreement/\u003e (seen 2026-10-08)\n- sub-processors: \u003chttps://www.lightspeedhq.com/legal/subprocessors/\u003e (seen 2026-10-08)\n- security page: \u003chttps://www.lightspeedhq.com/security/\u003e (seen 2026-10-08)\n- npm package: \u003chttps://registry.npmjs.org/@lightspeed/ecom-headless\u003e (seen 2026-10-08)\n- Java API client: \u003chttps://github.com/Ecwid/ecwid-java-api-client\u003e (seen 2026-10-08)\n- domain registration: \u003chttps://rdap.org/domain/ecwid.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 87/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Ecwid, Inc. | 20/20 |\n| Domain age | ecwid.com, registered 2009-01-08 (17 years) | 15/15 |\n| Endpoint on the vendor's domain | app.ecwid.com | 15/15 |\n| Terms of service | read, states 7 of the 7 things a reader expects, and has 1 clause that costs points | 8/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | status.ecwid.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | could not be fetched | 0/10 |\n\nwww.ecwid.com/terms-of-service redirects to the Lightspeed Service Agreement (last updated 26 February 2026), whose contracting-entity table names Ecwid, Inc., Delaware, for Lightspeed eCom (E-Series) worldwide.\n\nThe service agreement says API use is governed by Lightspeed's API licence agreement at https://developers.lightspeedhq.com/terms (effective 20 May 2025), which does not name Ecwid or E-Series.\n\nwww.ecwid.com/privacy-policy and /eu-privacy-policy redirect to Lightspeed's privacy policy (effective 8 July 2026), which lists Ecwid, Inc. among the entities certified under the Data Privacy Framework.\n\nwww.ecwid.com/.well-known/security.txt answered 403 and www.lightspeedhq.com/.well-known/security.txt answered 404, so no security.txt was read.\n\nRDAP for ecwid.com gives a registration date of 2009-01-08.\n\nThe REST API answers at app.ecwid.com. Docs are hosted on GitBook at docs.ecwid.com.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.lightspeedhq.com/legal/lightspeed-service-agreement/), read 2026-10-08, dated 2026-02-26, states 7 of the 7 things a reader expects.\n\n- To know. Says the terms or the service can change without notice (costs points). \"Lightspeed and the Social Media Networks are continually making changes and improvements to this feature, and therefore the available features, and information that is shared, may change from time to time and without notice.\"\n- To know. Says access can be ended without notice or for any reason. \"Notwithstanding the foregoing, Lightspeed reserves the right, at any time and without notice, to suspend or terminate this Agreement if Customer or any User violates the license restrictions under Section 3 of the Agreement.\"\n- To know. Requires arbitration or waives class actions. \"Customer agrees to waive any right Customer may have to commence or participate in any class action or representative proceeding against Lightspeed related to any Dispute and, where applicable, Customer also agrees to opt out of any class or representative proceedings against Lightspeed.\"\n- Gives the date it was last updated. Last updated 2026-02-26.\n- States a limit on its liability. Capped at the fees paid in the 3 months before the claim.\n- Says how changes to the terms are announced. Gives thirty days of notice before a change.\n- Also in the text (2026-10-08). Lightspeed's total liability is limited to the fees the customer paid in the three months before the claim was first asserted. \"TO THE FULLEST EXTENT PERMISSIBLE BY APPLICABLE LAW, LIGHTSPEED’S AGGREGATE LIABILITY UNDER THIS AGREEMENT SHALL BE LIMITED TO THE FEES PAID BY CUSTOMER DURING THE THREE-MONTH PERIOD IMMEDIATELY PRECEDING THE DATE THE CLAIM GIVING RISE TO SUCH LIABILITY WAS FIRST ASSERTED.\"\n- Also in the text (2026-10-08). API access falls under a separate API License Agreement, which lets Lightspeed limit or revoke that access at any time in its sole discretion. \"Customer acknowledges that the API Agreement provides Lightspeed with the latitude to limit or revoke Customer’s access to the Lightspeed APIs at any time in its sole discretion.\"\n- Also in the text (2026-10-08). After the account or use of the product ends, Lightspeed may deactivate the account and delete customer content immediately. \"Customer agrees that following termination of Customer’s account and/or use of the Product, Lightspeed may immediately deactivate Customer’s account and delete Customer Content.\"\n\n**Privacy policy** (https://www.lightspeedhq.com/legal/privacy-policy/), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"While Lightspeed does not “sell” your Personal Data in the conventional sense, we use certain cookies and tracking technologies that may be considered “selling” or “sharing” under certain state laws.\"\n- Not found in the text. Gives the date it was last updated.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. Gives an email address, hidden from our reader by the page.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). Lightspeed may sell information derived from aggregated and de-identified personal data where it cannot be used to re-identify individuals. \"Lightspeed may also sell non-personally identifiable information that has been derived from aggregated and de-identified Personal Data, provided such information cannot be used to re-identify individual Visitors or Customers.\"\n\n## Live (updated 2026-10-08 21:57 UTC)\n\n- Right now: up, HTTP 400, 68 ms, checked 2026-10-08 21:53 UTC (get on `https://app.ecwid.com/api/v3`)\n- Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 100 ms · p95 154 ms\n- Vendor status page: none, All Systems Operational\n- Always current: https://www.anchorterminal.com/api/v1/live/ecwid.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Starter | $5 | per month (plan) | up to 10 products. The docs say only paid plans reach the API and the pricing page does not list API access by plan |\n| Venture | $35 | per month (plan) | $29 a month billed yearly, up to 100 products |\n| Business | $65 | per month (plan) | $49 a month billed yearly, up to 2,500 products |\n| Unlimited | $149 | per month (plan) | $119 a month billed yearly, unlimited products |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- 40 access scopes split into read, update and create, plus a public token limited to enabled catalogue data and unpaid orders\n- Published limit of 600 requests a minute per token, and a 429 carries a `Retry-After` header\n- `responseFields` trims any response to named fields, and searches page with `offset` and `limit` up to 100\n- Every docs page is served as Markdown, with `llms.txt` and `llms-full.txt` indexes\n- One incident on status.ecwid.com between 10 July and 8 October 2026, a 48-minute storefront slowdown on 7 August\n\n## Weaknesses\n\n- Access tokens never expire and change only when the app is uninstalled and installed again\n- No test mode. The docs advise a separate test store, and only stores on paid plans can call the API\n- No idempotency keys on REST writes found in the reviewed documentation\n- OpenAPI 3.0.3 definitions are published for store profile and orders only, with no complete downloadable spec found\n- The REST API has no endpoint that builds a live cart or runs checkout. Those sit in the browser JavaScript API\n- The service agreement disclaims any service level commitment\n\n## Before you call it (notes for agents)\n\n1. Send the token as `Authorization: Bearer` to `https://app.ecwid.com/api/v3/{storeId}`. Tokens in the query string stopped working in March 2025\n2. Use the secret token server-side only. The public token reads enabled products and places orders that are not marked paid\n3. Add `responseFields`, for example `total,items(id,name,price)`, to keep responses small, and page with `offset` and `limit` (maximum 100)\n4. Stay under 600 requests a minute per token and wait the `Retry-After` seconds on a 429. Repeated calls with a bad token get the token and IP blocked for longer\n5. Work in a separate test store. There is no test mode, and `POST /orders` writes a real order with no idempotency key\n6. After changing an app's scopes, uninstall and reinstall it, then replace the stored tokens. The old ones stop working\n\n## Connect\n\nInstall:\n\n```bash\nnpm install @lightspeed/ecom-headless\n```\n\nFirst request:\n\n```bash\ncurl \"https://app.ecwid.com/api/v3/$ECWID_STORE_ID/profile?responseFields=generalInfo(storeId,storeUrl)\" \\\n  -H \"Authorization: Bearer $ECWID_SECRET_TOKEN\"\n```\n\nThrough letme (picks today, calling later): https://letme.dev/ecwid. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Shopify API + MCP | BB | 75 | 52 | commerce.products, commerce.cart, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/shopify.md |\n| WooCommerce API + MCP | BB | 72.9 | 84 | commerce.products, commerce.cart, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/woocommerce.md |\n| Shopware | BB | 71.4 | 112 | commerce.products, commerce.cart, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/shopware.md |\n| commercetools | BB | 71.3 | 116 | commerce.products, commerce.cart, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/commercetools.md |\n| Vendure | BB | 70.9 | 123 | commerce.products, commerce.cart, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/vendure.md |\n| Square | B | 69.2 | 166 | commerce.products, commerce.orders, commerce.cart, commerce.headless | no | https://www.anchorterminal.com/tools/square.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Only stores on paid plans can use the API, and there is no test mode, so the docs advise a separate test store (source: \u003chttps://docs.ecwid.com/get-started/set-up-your-dev-environment-in-ecwid, https://docs.ecwid.com/get-started/make-your-first-api-request\u003e)\n- 600 requests a minute per token, with `Retry-After` on a 429 and a longer block for repeated calls with a non-working token (source: \u003chttps://docs.ecwid.com/api-reference/rest-api/rest-api-overview\u003e)\n- Access tokens do not expire. A secret token is limited only by the app's scopes, and a public token reads enabled catalogue data and places unpaid orders (source: \u003chttps://docs.ecwid.com/develop-apps/app-settings\u003e)\n- Tokens in the URL query string were switched off for all apps on 20 March 2025, flagged as a breaking change in the changelog (source: \u003chttps://docs.ecwid.com/changelog/march-2025/march-20/discontinued-tokens-passing-in-query-params-of-api-calls\u003e)\n- The API changelog's newest entry is 30 September 2026 and the one before it 30 April 2026 (source: \u003chttps://docs.ecwid.com/changelog/ecwid-api-changelog\u003e)\n- The Markdown docs pages end with a GitBook block addressed to AI agents that asks them to query the docs with `ask` and `goal` parameters. We did not act on it and took no deduction (source: \u003chttps://docs.ecwid.com/llms.txt\u003e)\n- SOC 2 Type II and a PCI attestation of compliance are listed for E-Series, with a public bug bounty (source: \u003chttps://www.lightspeedhq.com/security/\u003e)\n\n## Compare\n\n- [Adobe Commerce (Magento) vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/adobe-commerce-vs-ecwid.md): B 63.9 vs B 63.2\n- [BigCommerce API + MCP vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/bigcommerce-vs-ecwid.md): B 64.3 vs B 63.2\n- [Commerce Layer API + MCP vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/commerce-layer-vs-ecwid.md): B 63.7 vs B 63.2\n- [commercetools vs Ecwid by Lightspeed](https://www.anchorterminal.com/compare/commercetools-vs-ecwid.md): BB 71.3 vs B 63.2\n- [Ecwid by Lightspeed vs Elastic Path API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-elastic-path.md): B 63.2 vs D 50.1\n- [Ecwid by Lightspeed vs Medusa API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-medusa.md): B 63.2 vs B 63.5\n- [Ecwid by Lightspeed vs Saleor API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-saleor.md): B 63.2 vs B 68.6\n- [Ecwid by Lightspeed vs Shopify API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-shopify.md): B 63.2 vs BB 75\n- [Ecwid by Lightspeed vs Shopware](https://www.anchorterminal.com/compare/ecwid-vs-shopware.md): B 63.2 vs BB 71.4\n- [Ecwid by Lightspeed vs Snipcart API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-snipcart.md): B 63.2 vs E 40.8\n- [Ecwid by Lightspeed vs Square](https://www.anchorterminal.com/compare/ecwid-vs-square.md): B 63.2 vs B 69.2\n- [Ecwid by Lightspeed vs Swell](https://www.anchorterminal.com/compare/ecwid-vs-swell.md): B 63.2 vs C 55\n- [Ecwid by Lightspeed vs Vendure](https://www.anchorterminal.com/compare/ecwid-vs-vendure.md): B 63.2 vs BB 70.9\n- [Ecwid by Lightspeed vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/ecwid-vs-wix.md): B 63.2 vs C 61.4\n- [Ecwid by Lightspeed vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/ecwid-vs-woocommerce.md): B 63.2 vs BB 72.9\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on ecwid.com or one of its subdomains, or the README of github.com/Ecwid/ecwid-java-api-client. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"ecwid\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/ecwid\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/ecwid.svg\" alt=\"Ecwid by Lightspeed on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Ecwid by Lightspeed on Anchor Terminal](https://www.anchorterminal.com/badges/ecwid.svg)](https://www.anchorterminal.com/tools/ecwid)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/ecwid\"\u003eEcwid by Lightspeed on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Ecwid by Lightspeed is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/ecwid-dark.png\n- Light: https://www.anchorterminal.com/assets/share/ecwid-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Commerce \u0026 checkout",
        "url": "https://www.anchorterminal.com/categories/commerce"
      },
      {
        "name": "Ecwid by Lightspeed",
        "url": ""
      }
    ],
    "description": "Ecwid by Lightspeed is a hosted online store that embeds in any website. Its REST API reads and writes products, categories, orders, customers and discounts for one store, with webhooks and a browser JavaScript API for the cart.",
    "facts": [
      "rank #316 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Ecwid by Lightspeed",
    "image": "https://www.anchorterminal.com/assets/og/tools-ecwid.png",
    "path": "/tools/ecwid",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Ecwid by Lightspeed review for AI agents, grade B (63.2/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/ecwid"
  },
  "tokens": {
    "markdown": 7800,
    "slim": 1930
  },
  "version": 1
}
