# Ecwid by Lightspeed (slim) > Ecwid by Lightspeed is a hosted online store that embeds in any website. Its REST API reads and writes products, categories, orders, customers and discounts for one store, with webhooks and a browser JavaScript API for the cart. - Full: https://www.anchorterminal.com/tools/ecwid.md (~7,800 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/ecwid.json · canonical https://www.anchorterminal.com/tools/ecwid - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 63.2/100 · rank #316 of 722 · #12 in Commerce & checkout · not agent-ready · confidence medium** Assessment: The REST API has 40 access scopes, a published limit of 600 requests a minute per token with `Retry-After` on a 429, field selection through `responseFields`, and Markdown docs with an llms.txt index. Tokens never expire, there is no test mode or idempotency key, API access needs a paid plan, and carts are built only in the browser. ## Facts - Kind: HTTP API · vendor: Ecwid, Inc. (Lightspeed Commerce) · category: Commerce & checkout · legal entity: Ecwid, Inc. · provenance 87/100 - Endpoint: `https://app.ecwid.com/api/v3` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under the Lightspeed Service Agreement. The `@lightspeed/ecom-headless` npm package is MIT and the Java API client on GitHub is Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - API: REST at `https://app.ecwid.com/api/v3/{storeId}`, JSON, gzip supported. About 240 reference pages across products (58), instant site (30), customers (24), categories (19), orders (17), discounts (12), staff accounts, domains, payment and shipping options and batch requests - Which plan unlocks the API: Paid plans only, per the developer docs. The pricing page does not say which plans include it, and a call outside the plan answers 402 `NOT_AVAILABLE_ON_CURRENT_PLAN` - Free tier: No free plan or trial on the pricing page. Starter is $5 a month. Developers can email API support for a free upgrade of a test store - Auth and scopes: A custom app in the store admin gives a secret token and a public token with no OAuth flow. Public apps use OAuth 2.0. 40 access scopes, seven on by default. Tokens don't expire - Rate limits: 600 requests a minute per token. A 429 carries `Retry-After`. More than 20 requests a minute with a non-working token, or 600 in total per IP, brings a longer block - Cart and checkout: REST reads, updates and converts abandoned carts, calculates order totals and creates orders directly. Adding to a cart and sending a shopper to checkout are browser JavaScript API calls, and pre-filled cart links are supported - Webhooks: Yes, signed with `X-Ecwid-Webhook-Signature` (SHA-256), retried up to 27 times over 24 hours, blocked after two weeks of failures. Needs the app's `webhookUrl` - Errors: A published list of named codes with HTTP status, such as `WRONG_PARAMETER` (400), `INSUFFICIENT_APP_SCOPE` (403) and `PRODUCT_NOT_FOUND` (404) - SDKs: `@lightspeed/ecom-headless` 1.2.1 on npm (1 October 2026, MIT), a typed TypeScript client whose REST functions are GET only with the public token. Java and Kotlin client `ecwid-java-api-client` on GitHub (Apache-2.0, last commit 15 September 2026). Ruby, PHP and C# libraries are community work - MCP server: None found in the developer docs or the Ecwid GitHub organisation - Certifications: SOC 2 Type II and a PCI attestation of compliance listed for E-Series (Ecwid) on Lightspeed's security page, with a public bug bounty and yearly penetration tests - Status: status.ecwid.com on Atlassian Statuspage, six components (Storefront, Checkout, Admin, API, Third-party services, Billing) - Sub-processors: Lightspeed's list, updated 30 September 2026, names each provider's purpose, product line and country. For E-Series it includes Amazon Web Services and Google as cloud hosts - Prices: Starter $5 per month (plan); Venture $35 per month (plan); Business $65 per month (plan); Unlimited $149 per month (plan) - Scores: Reliability 80, Performance pending, Schema & documentation 66, Agent ergonomics 66, Security & auth 61, Payments & pricing 15, Task success pending, Maintenance & community 79, Transparency & trust 72 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted service, on the REST API. · Schema & documentation, OpenAPI 3.0.3 definitions are embedded in the reference for store profile, store logo, orders and order extra fields only, marked version 0… · Agent ergonomics, `responseFields` cuts any response to named fields, including nested ones, and `limit` caps list size (20). · Security & auth, 40 access scopes fixed per app, with tokens revoked by uninstalling the app. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The API changelog's newest entry is 30 September 2026 (30). · Transparency & trust, Closed service with a published service agreement, updated 26 February 2026, that names Ecwid, Inc. - Sources: 25, open questions: 6, both in the full twin - Capabilities: commerce.products, commerce.cart, commerce.orders, commerce.headless - JSON: https://www.anchorterminal.com/api/v1/tools/ecwid.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/ecwid.svg` or a link to https://www.anchorterminal.com/tools/ecwid from a page on ecwid.com or one of its subdomains, or the README of github.com/Ecwid/ecwid-java-api-client, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send the token as `Authorization: Bearer` to `https://app.ecwid.com/api/v3/{storeId}`. Tokens in the query string stopped working in March 2025 2. Use the secret token server-side only. The public token reads enabled products and places orders that are not marked paid 3. Add `responseFields`, for example `total,items(id,name,price)`, to keep responses small, and page with `offset` and `limit` (maximum 100) 4. Stay under 600 requests a minute per token and wait the `Retry-After` seconds on a 429. Repeated calls with a bad token get the token and IP blocked for longer 5. Work in a separate test store. There is no test mode, and `POST /orders` writes a real order with no idempotency key 6. After changing an app's scopes, uninstall and reinstall it, then replace the stored tokens. The old ones stop working ## Connect ```bash npm install @lightspeed/ecom-headless ``` ```bash curl "https://app.ecwid.com/api/v3/$ECWID_STORE_ID/profile?responseFields=generalInfo(storeId,storeUrl)" \ -H "Authorization: Bearer $ECWID_SECRET_TOKEN" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/ecwid ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Shopify API + MCP | BB | 75 | commerce.products, commerce.cart, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/shopify.min.md | | WooCommerce API + MCP | BB | 72.9 | commerce.products, commerce.cart, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/woocommerce.min.md | | Shopware | BB | 71.4 | commerce.products, commerce.cart, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/shopware.min.md | | commercetools | BB | 71.3 | commerce.products, commerce.cart, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/commercetools.min.md | | Vendure | BB | 70.9 | commerce.products, commerce.cart, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/vendure.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)