{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/shopify.json",
        "name": "Shopify API + MCP",
        "score": 75,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "shopify"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/woocommerce.json",
        "name": "WooCommerce API + MCP",
        "score": 72.9,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "woocommerce"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/commercetools.json",
        "name": "commercetools",
        "score": 71.3,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "commercetools"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/vendure.json",
        "name": "Vendure",
        "score": 70.9,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "vendure"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/square.json",
        "name": "Square",
        "score": 69.2,
        "shared": [
          "commerce.products",
          "commerce.orders",
          "commerce.checkout",
          "commerce.cart",
          "commerce.headless"
        ],
        "slug": "square"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/saleor.json",
        "name": "Saleor API + MCP",
        "score": 68.6,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "saleor"
      }
    ],
    "tool": {
      "slug": "shopware",
      "name": "Shopware",
      "vendor": "shopware AG",
      "vendorUrl": "https://www.shopware.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Open-source commerce platform from shopware AG in Germany, written in PHP on Symfony. Agents reach a store through its Store API for shopping, its Admin API for back-office work, and a built-in MCP server on both.",
      "url": "https://www.anchorterminal.com/tools/shopware",
      "markdownUrl": "https://www.anchorterminal.com/tools/shopware.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shopware.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shopware.json",
      "repo": "https://github.com/shopware/shopware",
      "license": "MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms",
      "transports": [
        "http",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "packagist",
          "name": "shopware/core"
        },
        {
          "registry": "npm",
          "name": "@shopware/api-client"
        }
      ],
      "auth": "mixed",
      "authNotes": "Access comes from the merchant who runs the store, with no vendor review. The Admin API takes an OAuth 2.0 bearer token from /api/oauth/token, normally by client credentials from an integration created in Settings or with `bin/console integration:create`, and tokens last 10 minutes by default. An integration gets an ACL role, or full access with --admin. The MCP endpoint at /api/_mcp also accepts the integration's `sw-access-key` and `sw-secret-access-key` headers, and each integration and user has an MCP allowlist. The Store API takes the sales channel's `sw-access-key`, which is public in a headless shop, plus an `sw-context-token` for the cart and customer session.",
      "pricing": "freemium",
      "pricingNotes": "The Community Edition is free under MIT with no account, so an agent's owner can start with `shopware-cli project create` and Docker, with no contract (the docs say no Shopware account is needed to install or run a store). Paid plans start at €600 a month for Rise and €2,400 for Evolve, excluding VAT, with Beyond on request, and the pricing page says the price depends on GMV. Shopware SaaS is priced the same as self-hosted. No trial of the paid plans was found on the pricing page (https://www.shopware.com/en/pricing/, checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the repository or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 14,
      "popularity": {
        "githubStars": 3400,
        "npmWeekly": 30917,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.shopware.com/docs/",
      "llmsTxt": "https://developer.shopware.com/llms.txt",
      "openapi": "https://github.com/shopware/shopware/tree/trunk/src/Core/Framework/Api/ApiDefinition/Generator/Schema",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "open-source",
        "self-hosted",
        "local",
        "hosted",
        "mcp",
        "openapi",
        "llms-txt",
        "oauth",
        "php",
        "typescript",
        "webhooks",
        "freemium",
        "eu",
        "bug-bounty",
        "iso27001",
        "beta"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 71.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 112,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 87,
          "payments": 50,
          "reliability": 83,
          "schema": 85,
          "security": 73,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 83,
            "points": 16.6,
            "reason": "Graded with the self-hosted package lines, because each store's APIs run on the merchant's own server or SaaS shop. Composer packages on Packagist with PHP 8.2 to 8.5 stated in composer.json (20). Nightly workflow on trunk, the last 10 scheduled runs all passing (25). 1,169 open issues, with bugs opened on 8 October 2026 already answered the same day and a triage labeller in the workflows (10). Semantic versioning with a written backward compatibility promise and UPGRADE and RELEASE_INFO files, but 6.7.14.0 changed what tools/list returns on the experimental Store API MCP endpoint in a minor release (13). 6.7 is stable, while the MCP server is experimental until 6.8 (15). Shopware SaaS has a status page at status.shopware.com, which lists a 36 minute outage of storefront and administration on 6 August 2026 and 1 hour 49 minutes of raised errors on 17 August. That isn't scored here."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 85,
            "points": 13.81,
            "reason": "OpenAPI 3 for both APIs, as JSON in the repository, on a hosted Stoplight reference and from each instance at /_info/openapi3.json in dev mode. MCP tools have typed inputs (25). llms.txt with every docs page as Markdown (10). 109 of 116 Store API operations and 105 of 108 Admin API operations in the repository schema carry a description, and the MCP tool reference says when to use search, read or aggregate (16). Types and required fields are set, but the MCP tools take criteria, payload, aggregations and ids as JSON-encoded strings, and Admin API entity routes accept open criteria objects (9). Request examples in the guides, a JSON:API error schema and a fixed success and error envelope for MCP tools (12). No API version in the path since 2020, so the contract follows the product version, with release notes on GitHub and RELEASE_INFO files (13)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 78,
            "points": 12.68,
            "reason": "A fresh MCP session advertises three discovery tools and loads the rest by toolset. `includes` selects fields, and MCP results over 100 KB come back as a resource reference (25). page, limit, total-count-mode, filters, sorting and aggregations in one criteria object (20). MCP errors are a message written to say what to do next, and the APIs return JSON:API errors with codes. A 429 on MCP has no Retry-After header (16). No idempotency keys found. Write tools default to dryRun=true, but no MCP tool carries readOnlyHint or destructiveHint in the source (8). Few required parameters and sensible defaults (limit 25, maxResults 3). One official API client, @shopware/api-client for TypeScript, and none found in a second language (9)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 73,
            "points": 12.78,
            "reason": "Admin API by OAuth 2.0 client credentials from a revocable integration with an ACL role and 10 minute tokens, or the integration's key and secret in headers on MCP. No secret in a URL was found in the docs. No OAuth scopes beyond ACL roles, and key rotation wasn't found (25). ACL checks on every MCP call, allowlists per integration and per user, a global allowed_tools switch and dry run by default on write tools. shopware-media-upload has no dry run and the Store API MCP endpoint has no allowlist (17). The MCP best practices page has a section on prompt injection through order notes, names and product text and advises read-only integrations for such data (11). An integration records when it was last used, and no audit log of API or MCP calls was found (4). Bug bounty through the security reporting form per SECURITY.md, ISO/IEC 27001:2022 on the trust centre, and advisories published on GitHub. The security.txt file expired on 31 December 2025 (16)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 50,
            "points": 6.25,
            "reason": "No x402, MPP or L402 (0). The paid plans have public starting prices, Rise from €600 and Evolve from €2,400 a month, with the real price set by GMV and Beyond on request (10). The MIT Community Edition is free with no card (20). An agent's owner can install it with Shopware CLI and Docker, and the install guide says no Shopware account is needed. A paid plan or SaaS shop needs a browser signup or sales (20)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 87,
            "points": 7.61,
            "reason": "6.7.15.1 tagged on 2 October 2026 (30). Seven releases between 19 August and 2 October 2026, from 6.7.13.1 to 6.7.15.1 (20). Issues opened on 8 October 2026 had same-day replies, against 1,169 open issues and 322 open pull requests (17). @shopware/api-client 1.7.0 was published on 6 October 2026. The MCP server is built in and has no entry in the official registry, where the only Shopware server is a third party's (10). Nightly, integration, acceptance, static analysis and npm audit workflows in the repository (10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 76,
            "points": 6.65,
            "note": "editorial 80, provenance 71",
            "reason": "MIT licence for the core (30). A self-hosted store keeps its data on the merchant's server. The privacy page, updated 18 August 2026, names shopware AG and links a data processing agreement, but no retention periods or sub-processors were found on it (18). A backward compatibility promise, `@deprecated` markers that name the major version of removal, and releases.json with an end date for security fixes on every version (18). A telemetry page lists what Shopware CLI, the Deployment Helper and the web installer send, by unencrypted UDP to a server in Frankfurt, with DO_NOT_TRACK as the opt-out. The core has a usage data module with consent that we didn't read (14)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "A fresh MCP session advertises three discovery tools and loads the rest by toolset. `includes` selects fields, and MCP results over 100 KB come back as a resource reference (25). page, limit, total-count-mode, filters, sorting and aggregations in one criteria object (20). MCP errors are a message written to say what to do next, and the APIs return JSON:API errors with codes. A 429 on MCP has no Retry-After header (16). No idempotency keys found. Write tools default to dryRun=true, but no MCP tool carries readOnlyHint or destructiveHint in the source (8). Few required parameters and sensible defaults (limit 25, maxResults 3). One official API client, @shopware/api-client for TypeScript, and none found in a second language (9).",
            "maintenance": "6.7.15.1 tagged on 2 October 2026 (30). Seven releases between 19 August and 2 October 2026, from 6.7.13.1 to 6.7.15.1 (20). Issues opened on 8 October 2026 had same-day replies, against 1,169 open issues and 322 open pull requests (17). @shopware/api-client 1.7.0 was published on 6 October 2026. The MCP server is built in and has no entry in the official registry, where the only Shopware server is a third party's (10). Nightly, integration, acceptance, static analysis and npm audit workflows in the repository (10).",
            "payments": "No x402, MPP or L402 (0). The paid plans have public starting prices, Rise from €600 and Evolve from €2,400 a month, with the real price set by GMV and Beyond on request (10). The MIT Community Edition is free with no card (20). An agent's owner can install it with Shopware CLI and Docker, and the install guide says no Shopware account is needed. A paid plan or SaaS shop needs a browser signup or sales (20).",
            "reliability": "Graded with the self-hosted package lines, because each store's APIs run on the merchant's own server or SaaS shop. Composer packages on Packagist with PHP 8.2 to 8.5 stated in composer.json (20). Nightly workflow on trunk, the last 10 scheduled runs all passing (25). 1,169 open issues, with bugs opened on 8 October 2026 already answered the same day and a triage labeller in the workflows (10). Semantic versioning with a written backward compatibility promise and UPGRADE and RELEASE_INFO files, but 6.7.14.0 changed what tools/list returns on the experimental Store API MCP endpoint in a minor release (13). 6.7 is stable, while the MCP server is experimental until 6.8 (15). Shopware SaaS has a status page at status.shopware.com, which lists a 36 minute outage of storefront and administration on 6 August 2026 and 1 hour 49 minutes of raised errors on 17 August. That isn't scored here.",
            "schema": "OpenAPI 3 for both APIs, as JSON in the repository, on a hosted Stoplight reference and from each instance at /_info/openapi3.json in dev mode. MCP tools have typed inputs (25). llms.txt with every docs page as Markdown (10). 109 of 116 Store API operations and 105 of 108 Admin API operations in the repository schema carry a description, and the MCP tool reference says when to use search, read or aggregate (16). Types and required fields are set, but the MCP tools take criteria, payload, aggregations and ids as JSON-encoded strings, and Admin API entity routes accept open criteria objects (9). Request examples in the guides, a JSON:API error schema and a fixed success and error envelope for MCP tools (12). No API version in the path since 2020, so the contract follows the product version, with release notes on GitHub and RELEASE_INFO files (13).",
            "security": "Admin API by OAuth 2.0 client credentials from a revocable integration with an ACL role and 10 minute tokens, or the integration's key and secret in headers on MCP. No secret in a URL was found in the docs. No OAuth scopes beyond ACL roles, and key rotation wasn't found (25). ACL checks on every MCP call, allowlists per integration and per user, a global allowed_tools switch and dry run by default on write tools. shopware-media-upload has no dry run and the Store API MCP endpoint has no allowlist (17). The MCP best practices page has a section on prompt injection through order notes, names and product text and advises read-only integrations for such data (11). An integration records when it was last used, and no audit log of API or MCP calls was found (4). Bug bounty through the security reporting form per SECURITY.md, ISO/IEC 27001:2022 on the trust centre, and advisories published on GitHub. The security.txt file expired on 31 December 2025 (16).",
            "transparency": "MIT licence for the core (30). A self-hosted store keeps its data on the merchant's server. The privacy page, updated 18 August 2026, names shopware AG and links a data processing agreement, but no retention periods or sub-processors were found on it (18). A backward compatibility promise, `@deprecated` markers that name the major version of removal, and releases.json with an end date for security fixes on every version (18). A telemetry page lists what Shopware CLI, the Deployment Helper and the web installer send, by unencrypted UDP to a server in Frankfurt, with DO_NOT_TRACK as the opt-out. The core has a usage data module with consent that we didn't read (14)."
          },
          "sources": [
            {
              "what": "core repository at commit of 8 October 2026 (LICENSE, composer.json, releases.json, SECURITY.md, workflows, MCP source, OpenAPI schema files, rate limiter config)",
              "url": "https://github.com/shopware/shopware",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index for agents",
              "url": "https://developer.shopware.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP overview and status",
              "url": "https://developer.shopware.com/docs/products/tools/mcp-server.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP getting started (auth, client config, discovery)",
              "url": "https://developer.shopware.com/docs/products/tools/mcp-server/getting-started.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP configuration (allowlists, sessions, rate limits)",
              "url": "https://developer.shopware.com/docs/products/tools/mcp-server/configuration.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP tools reference",
              "url": "https://developer.shopware.com/docs/products/tools/mcp-server/tools-reference.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Store API MCP endpoint",
              "url": "https://developer.shopware.com/docs/products/tools/mcp-server/store-api.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP best practices (prompt injection)",
              "url": "https://developer.shopware.com/docs/products/tools/mcp-server/best-practices.md",
              "seen": "2026-10-08"
            },
            {
              "what": "API authentication and OpenAPI endpoints",
              "url": "https://developer.shopware.com/docs/guides/development/integrations-api/auth-api-requests.md",
              "seen": "2026-10-08"
            },
            {
              "what": "search criteria",
              "url": "https://developer.shopware.com/docs/guides/development/integrations-api/search-criteria.md",
              "seen": "2026-10-08"
            },
            {
              "what": "rate limiter defaults",
              "url": "https://developer.shopware.com/docs/guides/hosting/infrastructure/rate-limiter.md",
              "seen": "2026-10-08"
            },
            {
              "what": "backward compatibility promise",
              "url": "https://developer.shopware.com/docs/resources/guidelines/code/backward-compatibility.md",
              "seen": "2026-10-08"
            },
            {
              "what": "installation guide",
              "url": "https://developer.shopware.com/docs/guides/installation.md",
              "seen": "2026-10-08"
            },
            {
              "what": "tools telemetry",
              "url": "https://developer.shopware.com/docs/resources/references/telemetry.md",
              "seen": "2026-10-08"
            },
            {
              "what": "security advisories, pages 1 and 2",
              "url": "https://github.com/shopware/shopware/security/advisories",
              "seen": "2026-10-08"
            },
            {
              "what": "advisory for the Store API SQL injection",
              "url": "https://github.com/shopware/shopware/security/advisories/GHSA-p37c-pm9p-7vm5",
              "seen": "2026-10-08"
            },
            {
              "what": "open issues",
              "url": "https://github.com/shopware/shopware/issues?q=is%3Aissue+is%3Aopen+sort%3Acreated-desc",
              "seen": "2026-10-08"
            },
            {
              "what": "nightly workflow runs",
              "url": "https://github.com/shopware/shopware/actions/workflows/nightly.yml?query=event%3Aschedule+branch%3Atrunk",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://www.shopware.com/en/pricing/",
              "seen": "2026-10-08"
            },
            {
              "what": "general terms",
              "url": "https://www.shopware.com/en/gtc/",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy page",
              "url": "https://www.shopware.com/en/privacy/",
              "seen": "2026-10-08"
            },
            {
              "what": "legal notice",
              "url": "https://www.shopware.com/en/legal-notice/",
              "seen": "2026-10-08"
            },
            {
              "what": "trust centre",
              "url": "https://www.shopware.com/en/shopware-trust-center/",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.shopware.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "status history",
              "url": "https://status.shopware.com/history",
              "seen": "2026-10-08"
            },
            {
              "what": "npm package",
              "url": "https://registry.npmjs.org/@shopware/api-client/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=shopware",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.verisign.com/com/v1/domain/shopware.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: the security reporting page at www.shopware.com/en/contact/security-reporting/ answered 503, so the bug bounty's scope and rewards weren't read",
            "unchecked: the data processing agreement at www.shopware.com/en/privacy/dpa and any sub-processor list",
            "unchecked: the core's usage data module and what consent it asks for",
            "unchecked: the exact GitHub star count. The repository page showed 3.4k and the API refused us for its rate limit",
            "unchecked: whether an official API client exists in a second language",
            "The pricing page shows the plan prices in euros. US dollar prices for Rise and Evolve weren't in the page as fetched",
            "Whether the Store API MCP endpoint gains cart and checkout tools when it leaves experimental status in 6.8"
          ]
        },
        "negative": -5,
        "negativeNotes": [
          "GitHub lists 20 security advisories for shopware/shopware published between 19 May and 16 September 2026, four of them critical (an app script sandbox escape, stored SQL injection through app manifests, admin account takeover by host-header poisoning and a webhook permission bypass), plus a pre-authentication SQL injection in the Store API (GHSA-p37c-pm9p-7vm5, CVSS 8.6, published 25 August 2026, fixed in 6.7.13.1 and 6.6.10.23). All were disclosed in public with fixed versions, so the deduction is 5 of a possible 15 (https://github.com/shopware/shopware/security/advisories)."
        ],
        "verdict": "MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.",
        "bestFor": "A merchant already on Shopware, or a team that wants an MIT PHP backend with a built-in MCP server for back-office work.",
        "strengths": [
          "MIT core, free to self-host, with security fixes for the 6.7 line promised until 28 February 2028 in releases.json",
          "Built-in MCP server advertises three discovery tools, and other tools load by toolset for the session",
          "MCP write tools default to dryRun=true, which runs the change in a transaction and rolls it back",
          "Per-integration ACL roles and MCP allowlists, with a 300 a minute limit on /api/_mcp",
          "OpenAPI 3 schemas for the Store API and Admin API in the repository, plus llms.txt and Markdown docs"
        ],
        "weaknesses": [
          "The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint",
          "20 advisories published between 19 May and 16 September 2026, four critical, including a pre-authentication SQL injection in the Store API",
          "MCP tools carry no readOnlyHint or destructiveHint annotations, and criteria and payloads travel as JSON-encoded strings",
          "A 429 from the MCP endpoints carries the wait time in the body, with no Retry-After header",
          "The Store API MCP endpoint ships one domain tool, has no allowlist, and the security.txt file expired on 31 December 2025"
        ],
        "agentNotes": [
          "Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp",
          "Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools",
          "Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once",
          "For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core",
          "Send `includes` in search criteria to cut response size, and read the 429 body for the wait time"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 71.4
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 87,
          "payments": 50,
          "reliability": 83,
          "schema": 85,
          "security": 73,
          "transparency": 80
        },
        "provenanceScore": 71
      },
      "connect": {
        "install": "npx @shopware-ag/shopware-cli project create my-shop",
        "http": "curl -X POST \"http://localhost:8000/api/search/product\" \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{}'",
        "claudeCode": "claude mcp add --transport http shopware http://localhost:8000/api/_mcp --header \"sw-access-key: SWIA...\" --header \"sw-secret-access-key: ...\"",
        "config": {
          "mcpServers": {
            "shopware": {
              "headers": {
                "sw-access-key": "SWIA...",
                "sw-secret-access-key": "..."
              },
              "type": "streamable-http",
              "url": "https://your-shop.example.com/api/_mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/shopware"
      },
      "notable": [
        "The MCP server is part of the core since 6.7.11.0 at /api/_mcp and /store-api/_mcp, with the feature flag removed in 6.7.14.0 and the classes marked experimental until 6.8.0 (https://developer.shopware.com/docs/products/tools/mcp-server.md)",
        "A fresh MCP session advertises only shopware-tool-search, shopware-toolsets-list and shopware-toolset-enable. Core toolsets are entity, system-config, media, order, theme and store-api (https://developer.shopware.com/docs/products/tools/mcp-server/tools-reference.md)",
        "MCP rate limits are 300 a minute and 1,000 per 10 minutes on the Admin API endpoint, 120 and 600 on the Store API endpoint, and a 429 has no Retry-After header (https://developer.shopware.com/docs/products/tools/mcp-server/configuration.md)",
        "GitHub lists 20 advisories published between 19 May and 16 September 2026, four critical. GHSA-p37c-pm9p-7vm5, a pre-authentication SQL injection in the Store API, was fixed in 6.7.13.1 and 6.6.10.23 (https://github.com/shopware/shopware/security/advisories)",
        "6.7.15.1 was tagged on 2 October 2026, and minor versions have shipped monthly, 6.7.13.0 on 3 August, 6.7.14.0 on 7 September and 6.7.15.0 on 5 October per releases.json (https://github.com/shopware/shopware/blob/trunk/releases.json)",
        "www.shopware.com/.well-known/security.txt gives alert@shopware.com and an Expires date of 31 December 2025 (https://www.shopware.com/.well-known/security.txt)",
        "The only Shopware entry in the official MCP registry is a third-party server, io.github.bnymnDev/shopware-mcp (https://registry.modelcontextprotocol.io/v0/servers?search=shopware)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Free tier",
          "value": "Community Edition is free under MIT. Hosting is the merchant's cost"
        },
        {
          "label": "Paid plans",
          "value": "Rise from €600 a month, Evolve from €2,400 a month, Beyond on request, all excluding VAT and priced on GMV. SaaS costs the same as self-hosted per the pricing page (https://www.shopware.com/en/pricing/)"
        },
        {
          "label": "APIs",
          "value": "Store API under /store-api (cart, checkout, orders, products, search, account) and Admin API under /api (entity CRUD, search, sync, order states). OpenAPI 3 at /(api|store-api)/_info/openapi3.json when APP_ENV is dev"
        },
        {
          "label": "MCP server",
          "value": "Built into core since 6.7.11.0, streamable HTTP at /api/_mcp and /store-api/_mcp, experimental until 6.8.0. 14 Admin API tools in core and the Storefront bundle, of which 3 are advertised at the start of a session"
        },
        {
          "label": "Auth and scopes",
          "value": "Admin API takes OAuth 2.0 client credentials from an integration, or the integration's key and secret as headers on MCP. ACL roles per integration. Store API takes a sales channel access key and a context token"
        },
        {
          "label": "Rate limits",
          "value": "MCP 300 a minute and 1,000 per 10 minutes (Admin), 120 and 600 (Store). Login, password reset and form routes are limited by default. No general request limit on the other API routes"
        },
        {
          "label": "Write safety",
          "value": "MCP write tools default to dryRun=true and roll the transaction back. shopware-media-upload has no dry run"
        },
        {
          "label": "Response size",
          "value": "`includes` selects fields, page and limit paginate, and an MCP result over 100 KB comes back as a shopware://tool-result/{id} resource"
        },
        {
          "label": "SDKs",
          "value": "@shopware/api-client 1.7.0 on npm (MIT, published 6 October 2026), generated from the OpenAPI schemas"
        },
        {
          "label": "Support window",
          "value": "releases.json gives 28 February 2028 as the end of security fixes for 6.7 and 28 February 2027 for 6.6"
        },
        {
          "label": "Certifications",
          "value": "ISO/IEC 27001:2022 per the trust centre, which says hosted environments align with SOC 2 Type II principles (vendor claims)"
        },
        {
          "label": "Status",
          "value": "status.shopware.com covers Shopware SaaS, PaaS and vendor services. A self-hosted store has no vendor status"
        }
      ],
      "unitPrices": [
        {
          "item": "Community Edition",
          "unit": "month",
          "usd": 0,
          "note": "MIT core, you pay for your own hosting"
        }
      ],
      "provenance": {
        "legalEntity": "shopware AG",
        "domain": "shopware.com",
        "domainRegistered": "1998-08-08",
        "endpointOnVendorDomain": false,
        "terms": "https://www.shopware.com/en/gtc/",
        "privacy": "https://www.shopware.com/en/privacy/",
        "statusPage": "https://status.shopware.com",
        "changelog": "https://github.com/shopware/shopware/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The legal notice names shopware AG, Ebbinghoff 10, 48624 Schoeppingen, Germany, Amtsgericht Coesfeld HRB 11471.",
          "The general terms cover every product. Part 2 covers the free Community Edition and Part 4 covers SaaS, and only the German version is binding.",
          "The Store API, Admin API and MCP endpoints run on each merchant's own domain or SaaS shop, not on shopware.com.",
          "security.txt at www.shopware.com gives Expires 31 December 2025.",
          "www.shopware.com answered several requests with a 503 first byte timeout on 8 October 2026. The terms loaded on a retry and the privacy page loaded once.",
          "status.shopware.com covers Shopware SaaS, PaaS and vendor services, not self-hosted stores.",
          "Verisign RDAP gives a registration date of 1998-08-08 for shopware.com."
        ],
        "score": 71,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "shopware AG",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "shopware.com, registered 1998-08-08 (28 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": " is not on shopware.com",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 4.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "published, but our reader couldn't read it",
            "points": 7,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.shopware.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "published but past its Expires date",
            "points": 5,
            "max": 10,
            "state": "part"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.shopware.com/en/gtc/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-06-10",
            "words": 17397,
            "points": 4.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last update: 2026-06-10 10:06:16",
                "says": "Last updated 2026-06-10"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": false
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…payment and simple negligence (einfache Fahrlässigkeit) occurs in this context, liability shall be limited to cases of non-compliance with obligations the fulfilment of which is indispensable for using the services owed by shopware and on the compliance with which Customer usually relies or is reasonably allowed to re…"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "The agreement can be terminated at any time without giving reasons and without observing a notice period."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Without the express written consent of shopware, Customer shall not make any declarations to third parties regarding the infringement of proprietary rights, in particular, without limitation, Customer shall not acknowledge any rights or facts or otherwise assume any liability."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "Customer and shopware may specify in a Service Level Agreement the times within which and, if applicable, the other quantitative or qualitative parameters with which the support services are to be provided."
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "shopware shall insofar not be subject to any restrictions regarding also the commercial use of such work results for its own purposes and for the purposes of third parties (e. g. benchmarking, quality improvement, training and validation of AI models).",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "Under no circumstances shall Customer use the shopware software to directly or indirectly develop or improve a comparable product itself or through third parties.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "In the case of a contract for the performance of continuing obligations (Dauerschuldverhältnis), shopware is also entitled to terminate the contract by ordinary termination without an objective ground as provided for by these GTC and the contract."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The Rise, Evolve and Beyond plans carry a 24 month minimum term, which renews for up to 24 months unless ended in writing with six months' notice.",
                "quote": "In the case of provision of shopware Rise, shopware Evolve or shopware Beyond, the minimum term of the contract shall be initially 24 months, unless otherwise specified in the contract."
              },
              {
                "date": "2026-10-08",
                "text": "After the minimum term, shopware may raise the price by up to 20 per cent at the start of each new contract term, with four months' notice.",
                "quote": "shopware is entitled, after expiry of the minimum contract term, to increase the remuneration by up to 20% at the beginning of each new contract term, subject to four months’ prior notice."
              },
              {
                "date": "2026-10-08",
                "text": "The customer alone is responsible for its use of shopware's AI assistant functions and for the content they generate.",
                "quote": "Customer shall be solely responsible for the use of AI Systems and for the use of the content generated by AI Systems (output)."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.shopware.com/en/privacy/",
            "state": "unreadable",
            "reason": "the page has 181 words of text without a browser, so the document is drawn by script or sits elsewhere",
            "readAt": "2026-10-08",
            "points": 7,
            "max": 10
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shopware.json",
      "live": {
        "slug": "shopware",
        "vendorStatus": {
          "page": "https://status.shopware.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:10.49832559Z"
        },
        "pages": [
          {
            "url": "https://www.shopware.com/en/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:28.817122652Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a8eeb1d7324d"
          },
          {
            "url": "https://www.shopware.com/en/privacy/",
            "kind": "privacy",
            "status": 503,
            "checkedAt": "2026-10-08T18:30:30.769152247Z",
            "changedAt": "0001-01-01T00:00:00Z"
          },
          {
            "url": "https://www.shopware.com/en/gtc/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:30:26.06911646Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "034d628e8015"
          }
        ],
        "updatedAt": "2026-10-08T19:39:10.49832559Z"
      }
    },
    "verify": {
      "accepts": "a page on shopware.com or one of its subdomains, or the README of github.com/shopware/shopware",
      "badgeUrl": "https://www.anchorterminal.com/badges/shopware.svg",
      "body": {
        "slug": "shopware",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/shopware",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/shopware\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/shopware.svg\" alt=\"Shopware on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Shopware on Anchor Terminal](https://www.anchorterminal.com/badges/shopware.svg)](https://www.anchorterminal.com/tools/shopware)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/shopware\"\u003eShopware on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/shopware",
    "json": "https://www.anchorterminal.com/tools/shopware.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/shopware.md",
    "slim": "https://www.anchorterminal.com/tools/shopware.min.md"
  },
  "markdown": "## Overview\n\n**Grade BB · 71.4/100 · rank #112 of 722 · #3 in Commerce \u0026 checkout · agent-ready · confidence medium**\n\n\n## Assessment\n\nMIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | shopware AG (https://www.shopware.com) |\n| Kind | HTTP API |\n| Category | Commerce \u0026 checkout (https://www.anchorterminal.com/categories/commerce) |\n| Transport | HTTP, Streamable HTTP |\n| Auth | OAuth or key · Access comes from the merchant who runs the store, with no vendor review. The Admin API takes an OAuth 2.0 bearer token from /api/oauth/token, normally by client credentials from an integration created in Settings or with `bin/console integration:create`, and tokens last 10 minutes by default. An integration gets an ACL role, or full access with --admin. The MCP endpoint at /api/_mcp also accepts the integration's `sw-access-key` and `sw-secret-access-key` headers, and each integration and user has an MCP allowlist. The Store API takes the sales channel's `sw-access-key`, which is public in a headless shop, plus an `sw-context-token` for the cart and customer session. |\n| Pricing | Freemium (Freemium) · The Community Edition is free under MIT with no account, so an agent's owner can start with `shopware-cli project create` and Docker, with no contract (the docs say no Shopware account is needed to install or run a store). Paid plans start at €600 a month for Rise and €2,400 for Evolve, excluding VAT, with Beyond on request, and the pricing page says the price depends on GMV. Shopware SaaS is priced the same as self-hosted. No trial of the paid plans was found on the pricing page (https://www.shopware.com/en/pricing/, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the developer docs, the repository or the pricing page (checked 2026-10-08). |\n| Licence | MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms |\n| Tools exposed | 14 |\n| Packages | packagist: `shopware/core`; npm: `@shopware/api-client` |\n| Source | https://github.com/shopware/shopware |\n| Docs | https://developer.shopware.com/docs/ |\n| llms.txt | https://developer.shopware.com/llms.txt |\n| Last release | 2026-10-02 |\n| GitHub stars | 3,400 (as of 2026-10-08) |\n| npm downloads / week | 30,917 |\n| Free tier | Community Edition is free under MIT. Hosting is the merchant's cost |\n| Paid plans | Rise from €600 a month, Evolve from €2,400 a month, Beyond on request, all excluding VAT and priced on GMV. SaaS costs the same as self-hosted per the pricing page (https://www.shopware.com/en/pricing/) |\n| APIs | Store API under /store-api (cart, checkout, orders, products, search, account) and Admin API under /api (entity CRUD, search, sync, order states). OpenAPI 3 at /(api\\|store-api)/_info/openapi3.json when APP_ENV is dev |\n| MCP server | Built into core since 6.7.11.0, streamable HTTP at /api/_mcp and /store-api/_mcp, experimental until 6.8.0. 14 Admin API tools in core and the Storefront bundle, of which 3 are advertised at the start of a session |\n| Auth and scopes | Admin API takes OAuth 2.0 client credentials from an integration, or the integration's key and secret as headers on MCP. ACL roles per integration. Store API takes a sales channel access key and a context token |\n| Rate limits | MCP 300 a minute and 1,000 per 10 minutes (Admin), 120 and 600 (Store). Login, password reset and form routes are limited by default. No general request limit on the other API routes |\n| Write safety | MCP write tools default to dryRun=true and roll the transaction back. shopware-media-upload has no dry run |\n| Response size | `includes` selects fields, page and limit paginate, and an MCP result over 100 KB comes back as a shopware://tool-result/{id} resource |\n| SDKs | @shopware/api-client 1.7.0 on npm (MIT, published 6 October 2026), generated from the OpenAPI schemas |\n| Support window | releases.json gives 28 February 2028 as the end of security fixes for 6.7 and 28 February 2027 for 6.6 |\n| Certifications | ISO/IEC 27001:2022 per the trust centre, which says hosted environments align with SOC 2 Type II principles (vendor claims) |\n| Status | status.shopware.com covers Shopware SaaS, PaaS and vendor services. A self-hosted store has no vendor status |\n| Capabilities | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless |\n| Tags | open-source, self-hosted, local, hosted, mcp, openapi, llms-txt, oauth, php, typescript, webhooks, freemium, eu, bug-bounty, iso27001, beta |\n| JSON | https://www.anchorterminal.com/api/v1/tools/shopware.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 83 | 16.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 85 | 13.8 |\n| Agent ergonomics | 13% | 16.2 | 78 | 12.7 |\n| Security \u0026 auth | 14% | 17.5 | 73 | 12.8 |\n| Payments \u0026 pricing | 10% | 12.5 | 50 | 6.2 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 87 | 7.6 |\n| Transparency \u0026 trust (editorial 80, provenance 71) | 7% | 8.8 | 76 | 6.7 |\n| Negative events | up to −15 | up to −15 | GitHub lists 20 security advisories for shopware/shopware published between 19 May and 16 September 2026, four of them critical (an app script sandbox escape, stored SQL injection through app manifests, admin account takeover by host-header poisoning and a webhook permission bypass), plus a pre-authentication SQL injection in the Store API (GHSA-p37c-pm9p-7vm5, CVSS 8.6, published 25 August 2026, fixed in 6.7.13.1 and 6.6.10.23). All were disclosed in public with fixed versions, so the deduction is 5 of a possible 15 (https://github.com/shopware/shopware/security/advisories).  | -5 |\n| **Total** | | | | **71.4 → BB** |\n\n### Why each score\n\n- Reliability 83: Graded with the self-hosted package lines, because each store's APIs run on the merchant's own server or SaaS shop. Composer packages on Packagist with PHP 8.2 to 8.5 stated in composer.json (20). Nightly workflow on trunk, the last 10 scheduled runs all passing (25). 1,169 open issues, with bugs opened on 8 October 2026 already answered the same day and a triage labeller in the workflows (10). Semantic versioning with a written backward compatibility promise and UPGRADE and RELEASE_INFO files, but 6.7.14.0 changed what tools/list returns on the experimental Store API MCP endpoint in a minor release (13). 6.7 is stable, while the MCP server is experimental until 6.8 (15). Shopware SaaS has a status page at status.shopware.com, which lists a 36 minute outage of storefront and administration on 6 August 2026 and 1 hour 49 minutes of raised errors on 17 August. That isn't scored here.\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 85: OpenAPI 3 for both APIs, as JSON in the repository, on a hosted Stoplight reference and from each instance at /_info/openapi3.json in dev mode. MCP tools have typed inputs (25). llms.txt with every docs page as Markdown (10). 109 of 116 Store API operations and 105 of 108 Admin API operations in the repository schema carry a description, and the MCP tool reference says when to use search, read or aggregate (16). Types and required fields are set, but the MCP tools take criteria, payload, aggregations and ids as JSON-encoded strings, and Admin API entity routes accept open criteria objects (9). Request examples in the guides, a JSON:API error schema and a fixed success and error envelope for MCP tools (12). No API version in the path since 2020, so the contract follows the product version, with release notes on GitHub and RELEASE_INFO files (13).\n- Agent ergonomics 78: A fresh MCP session advertises three discovery tools and loads the rest by toolset. `includes` selects fields, and MCP results over 100 KB come back as a resource reference (25). page, limit, total-count-mode, filters, sorting and aggregations in one criteria object (20). MCP errors are a message written to say what to do next, and the APIs return JSON:API errors with codes. A 429 on MCP has no Retry-After header (16). No idempotency keys found. Write tools default to dryRun=true, but no MCP tool carries readOnlyHint or destructiveHint in the source (8). Few required parameters and sensible defaults (limit 25, maxResults 3). One official API client, @shopware/api-client for TypeScript, and none found in a second language (9).\n- Security \u0026 auth 73: Admin API by OAuth 2.0 client credentials from a revocable integration with an ACL role and 10 minute tokens, or the integration's key and secret in headers on MCP. No secret in a URL was found in the docs. No OAuth scopes beyond ACL roles, and key rotation wasn't found (25). ACL checks on every MCP call, allowlists per integration and per user, a global allowed_tools switch and dry run by default on write tools. shopware-media-upload has no dry run and the Store API MCP endpoint has no allowlist (17). The MCP best practices page has a section on prompt injection through order notes, names and product text and advises read-only integrations for such data (11). An integration records when it was last used, and no audit log of API or MCP calls was found (4). Bug bounty through the security reporting form per SECURITY.md, ISO/IEC 27001:2022 on the trust centre, and advisories published on GitHub. The security.txt file expired on 31 December 2025 (16).\n- Payments \u0026 pricing 50: No x402, MPP or L402 (0). The paid plans have public starting prices, Rise from €600 and Evolve from €2,400 a month, with the real price set by GMV and Beyond on request (10). The MIT Community Edition is free with no card (20). An agent's owner can install it with Shopware CLI and Docker, and the install guide says no Shopware account is needed. A paid plan or SaaS shop needs a browser signup or sales (20).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 87: 6.7.15.1 tagged on 2 October 2026 (30). Seven releases between 19 August and 2 October 2026, from 6.7.13.1 to 6.7.15.1 (20). Issues opened on 8 October 2026 had same-day replies, against 1,169 open issues and 322 open pull requests (17). @shopware/api-client 1.7.0 was published on 6 October 2026. The MCP server is built in and has no entry in the official registry, where the only Shopware server is a third party's (10). Nightly, integration, acceptance, static analysis and npm audit workflows in the repository (10).\n- Transparency \u0026 trust 76: MIT licence for the core (30). A self-hosted store keeps its data on the merchant's server. The privacy page, updated 18 August 2026, names shopware AG and links a data processing agreement, but no retention periods or sub-processors were found on it (18). A backward compatibility promise, `@deprecated` markers that name the major version of removal, and releases.json with an end date for security fixes on every version (18). A telemetry page lists what Shopware CLI, the Deployment Helper and the web installer send, by unencrypted UDP to a server in Frankfurt, with DO_NOT_TRACK as the opt-out. The core has a usage data module with consent that we didn't read (14).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/shopware.md (JSON https://www.anchorterminal.com/fixes/shopware.json)\n\n### What we couldn't check\n\n- unchecked: the security reporting page at www.shopware.com/en/contact/security-reporting/ answered 503, so the bug bounty's scope and rewards weren't read\n- unchecked: the data processing agreement at www.shopware.com/en/privacy/dpa and any sub-processor list\n- unchecked: the core's usage data module and what consent it asks for\n- unchecked: the exact GitHub star count. The repository page showed 3.4k and the API refused us for its rate limit\n- unchecked: whether an official API client exists in a second language\n- The pricing page shows the plan prices in euros. US dollar prices for Rise and Evolve weren't in the page as fetched\n- Whether the Store API MCP endpoint gains cart and checkout tools when it leaves experimental status in 6.8\n\n### Sources\n\n- core repository at commit of 8 October 2026 (LICENSE, composer.json, releases.json, SECURITY.md, workflows, MCP source, OpenAPI schema files, rate limiter config): \u003chttps://github.com/shopware/shopware\u003e (seen 2026-10-08)\n- docs index for agents: \u003chttps://developer.shopware.com/llms.txt\u003e (seen 2026-10-08)\n- MCP overview and status: \u003chttps://developer.shopware.com/docs/products/tools/mcp-server.md\u003e (seen 2026-10-08)\n- MCP getting started (auth, client config, discovery): \u003chttps://developer.shopware.com/docs/products/tools/mcp-server/getting-started.md\u003e (seen 2026-10-08)\n- MCP configuration (allowlists, sessions, rate limits): \u003chttps://developer.shopware.com/docs/products/tools/mcp-server/configuration.md\u003e (seen 2026-10-08)\n- MCP tools reference: \u003chttps://developer.shopware.com/docs/products/tools/mcp-server/tools-reference.md\u003e (seen 2026-10-08)\n- Store API MCP endpoint: \u003chttps://developer.shopware.com/docs/products/tools/mcp-server/store-api.md\u003e (seen 2026-10-08)\n- MCP best practices (prompt injection): \u003chttps://developer.shopware.com/docs/products/tools/mcp-server/best-practices.md\u003e (seen 2026-10-08)\n- API authentication and OpenAPI endpoints: \u003chttps://developer.shopware.com/docs/guides/development/integrations-api/auth-api-requests.md\u003e (seen 2026-10-08)\n- search criteria: \u003chttps://developer.shopware.com/docs/guides/development/integrations-api/search-criteria.md\u003e (seen 2026-10-08)\n- rate limiter defaults: \u003chttps://developer.shopware.com/docs/guides/hosting/infrastructure/rate-limiter.md\u003e (seen 2026-10-08)\n- backward compatibility promise: \u003chttps://developer.shopware.com/docs/resources/guidelines/code/backward-compatibility.md\u003e (seen 2026-10-08)\n- installation guide: \u003chttps://developer.shopware.com/docs/guides/installation.md\u003e (seen 2026-10-08)\n- tools telemetry: \u003chttps://developer.shopware.com/docs/resources/references/telemetry.md\u003e (seen 2026-10-08)\n- security advisories, pages 1 and 2: \u003chttps://github.com/shopware/shopware/security/advisories\u003e (seen 2026-10-08)\n- advisory for the Store API SQL injection: \u003chttps://github.com/shopware/shopware/security/advisories/GHSA-p37c-pm9p-7vm5\u003e (seen 2026-10-08)\n- open issues: \u003chttps://github.com/shopware/shopware/issues?q=is%3Aissue+is%3Aopen+sort%3Acreated-desc\u003e (seen 2026-10-08)\n- nightly workflow runs: \u003chttps://github.com/shopware/shopware/actions/workflows/nightly.yml?query=event%3Aschedule+branch%3Atrunk\u003e (seen 2026-10-08)\n- pricing: \u003chttps://www.shopware.com/en/pricing/\u003e (seen 2026-10-08)\n- general terms: \u003chttps://www.shopware.com/en/gtc/\u003e (seen 2026-10-08)\n- privacy page: \u003chttps://www.shopware.com/en/privacy/\u003e (seen 2026-10-08)\n- legal notice: \u003chttps://www.shopware.com/en/legal-notice/\u003e (seen 2026-10-08)\n- trust centre: \u003chttps://www.shopware.com/en/shopware-trust-center/\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.shopware.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- status history: \u003chttps://status.shopware.com/history\u003e (seen 2026-10-08)\n- npm package: \u003chttps://registry.npmjs.org/@shopware/api-client/latest\u003e (seen 2026-10-08)\n- MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=shopware\u003e (seen 2026-10-08)\n- domain registration: \u003chttps://rdap.verisign.com/com/v1/domain/shopware.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 71/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | shopware AG | 20/20 |\n| Domain age | shopware.com, registered 1998-08-08 (28 years) | 15/15 |\n| Endpoint on the vendor's domain |  is not on shopware.com | 0/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points | 4.3/10 |\n| Privacy policy | published, but our reader couldn't read it | 7/10 |\n| Status page | status.shopware.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | published but past its Expires date | 5/10 |\n\nThe legal notice names shopware AG, Ebbinghoff 10, 48624 Schoeppingen, Germany, Amtsgericht Coesfeld HRB 11471.\n\nThe general terms cover every product. Part 2 covers the free Community Edition and Part 4 covers SaaS, and only the German version is binding.\n\nThe Store API, Admin API and MCP endpoints run on each merchant's own domain or SaaS shop, not on shopware.com.\n\nsecurity.txt at www.shopware.com gives Expires 31 December 2025.\n\nwww.shopware.com answered several requests with a 503 first byte timeout on 8 October 2026. The terms loaded on a retry and the privacy page loaded once.\n\nstatus.shopware.com covers Shopware SaaS, PaaS and vendor services, not self-hosted stores.\n\nVerisign RDAP gives a registration date of 1998-08-08 for shopware.com.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.shopware.com/en/gtc/), read 2026-10-08, dated 2026-06-10, states 5 of the 7 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"shopware shall insofar not be subject to any restrictions regarding also the commercial use of such work results for its own purposes and for the purposes of third parties (e. g. benchmarking, quality improvement, training and validation of AI models).\"\n- To know. Restricts benchmarking or competitive use (costs points). \"Under no circumstances shall Customer use the shopware software to directly or indirectly develop or improve a comparable product itself or through third parties.\"\n- To know. Says access can be ended without notice or for any reason. \"In the case of a contract for the performance of continuing obligations (Dauerschuldverhältnis), shopware is also entitled to terminate the contract by ordinary termination without an objective ground as provided for by these GTC and the contract.\"\n- Gives the date it was last updated. Last updated 2026-06-10.\n- Not found in the text. Names the governing law or courts.\n- Not found in the text. Says how changes to the terms are announced.\n- Also in the text (2026-10-08). The Rise, Evolve and Beyond plans carry a 24 month minimum term, which renews for up to 24 months unless ended in writing with six months' notice. \"In the case of provision of shopware Rise, shopware Evolve or shopware Beyond, the minimum term of the contract shall be initially 24 months, unless otherwise specified in the contract.\"\n- Also in the text (2026-10-08). After the minimum term, shopware may raise the price by up to 20 per cent at the start of each new contract term, with four months' notice. \"shopware is entitled, after expiry of the minimum contract term, to increase the remuneration by up to 20% at the beginning of each new contract term, subject to four months’ prior notice.\"\n- Also in the text (2026-10-08). The customer alone is responsible for its use of shopware's AI assistant functions and for the content they generate. \"Customer shall be solely responsible for the use of AI Systems and for the use of the content generated by AI Systems (output).\"\n\n**Privacy policy** (https://www.shopware.com/en/privacy/), read 2026-10-08. Our reader couldn't read it (the page has 181 words of text without a browser, so the document is drawn by script or sits elsewhere).\n\n\n## Live (updated 2026-10-08 19:39 UTC)\n\n- Vendor status page: unknown, no machine-readable status found\n- Watching pricing \u003chttps://www.shopware.com/en/pricing/\u003e\n- Watching privacy \u003chttps://www.shopware.com/en/privacy/\u003e\n- Watching terms \u003chttps://www.shopware.com/en/gtc/\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/shopware.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Community Edition | free | per month (plan) | MIT core, you pay for your own hosting |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- MIT core, free to self-host, with security fixes for the 6.7 line promised until 28 February 2028 in releases.json\n- Built-in MCP server advertises three discovery tools, and other tools load by toolset for the session\n- MCP write tools default to dryRun=true, which runs the change in a transaction and rolls it back\n- Per-integration ACL roles and MCP allowlists, with a 300 a minute limit on /api/_mcp\n- OpenAPI 3 schemas for the Store API and Admin API in the repository, plus llms.txt and Markdown docs\n\n## Weaknesses\n\n- The MCP server is marked experimental until 6.8, and 6.7.14.0 changed what tools/list returns on the Store API endpoint\n- 20 advisories published between 19 May and 16 September 2026, four critical, including a pre-authentication SQL injection in the Store API\n- MCP tools carry no readOnlyHint or destructiveHint annotations, and criteria and payloads travel as JSON-encoded strings\n- A 429 from the MCP endpoints carries the wait time in the body, with no Retry-After header\n- The Store API MCP endpoint ships one domain tool, has no allowlist, and the security.txt file expired on 31 December 2025\n\n## Before you call it (notes for agents)\n\n1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp\n2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools\n3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once\n4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core\n5. Send `includes` in search criteria to cut response size, and read the 429 body for the wait time\n\n## Connect\n\nInstall:\n\n```bash\nnpx @shopware-ag/shopware-cli project create my-shop\n```\n\nFirst request:\n\n```bash\ncurl -X POST \"http://localhost:8000/api/search/product\" \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{}'\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport http shopware http://localhost:8000/api/_mcp --header \"sw-access-key: SWIA...\" --header \"sw-secret-access-key: ...\"\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"shopware\": {\n      \"headers\": {\n        \"sw-access-key\": \"SWIA...\",\n        \"sw-secret-access-key\": \"...\"\n      },\n      \"type\": \"streamable-http\",\n      \"url\": \"https://your-shop.example.com/api/_mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/shopware. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Shopify API + MCP | BB | 75 | 52 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/shopify.md |\n| WooCommerce API + MCP | BB | 72.9 | 84 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/woocommerce.md |\n| commercetools | BB | 71.3 | 116 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/commercetools.md |\n| Vendure | BB | 70.9 | 123 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/vendure.md |\n| Square | B | 69.2 | 166 | commerce.products, commerce.orders, commerce.checkout, commerce.cart, commerce.headless | no | https://www.anchorterminal.com/tools/square.md |\n| Saleor API + MCP | B | 68.6 | 175 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/saleor.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The MCP server is part of the core since 6.7.11.0 at /api/_mcp and /store-api/_mcp, with the feature flag removed in 6.7.14.0 and the classes marked experimental until 6.8.0 (source: \u003chttps://developer.shopware.com/docs/products/tools/mcp-server.md\u003e)\n- A fresh MCP session advertises only shopware-tool-search, shopware-toolsets-list and shopware-toolset-enable. Core toolsets are entity, system-config, media, order, theme and store-api (source: \u003chttps://developer.shopware.com/docs/products/tools/mcp-server/tools-reference.md\u003e)\n- MCP rate limits are 300 a minute and 1,000 per 10 minutes on the Admin API endpoint, 120 and 600 on the Store API endpoint, and a 429 has no Retry-After header (source: \u003chttps://developer.shopware.com/docs/products/tools/mcp-server/configuration.md\u003e)\n- GitHub lists 20 advisories published between 19 May and 16 September 2026, four critical. GHSA-p37c-pm9p-7vm5, a pre-authentication SQL injection in the Store API, was fixed in 6.7.13.1 and 6.6.10.23 (source: \u003chttps://github.com/shopware/shopware/security/advisories\u003e)\n- 6.7.15.1 was tagged on 2 October 2026, and minor versions have shipped monthly, 6.7.13.0 on 3 August, 6.7.14.0 on 7 September and 6.7.15.0 on 5 October per releases.json (source: \u003chttps://github.com/shopware/shopware/blob/trunk/releases.json\u003e)\n- www.shopware.com/.well-known/security.txt gives alert@shopware.com and an Expires date of 31 December 2025 (source: \u003chttps://www.shopware.com/.well-known/security.txt\u003e)\n- The only Shopware entry in the official MCP registry is a third-party server, io.github.bnymnDev/shopware-mcp (source: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=shopware\u003e)\n\n## Compare\n\n- [Adobe Commerce (Magento) vs Shopware](https://www.anchorterminal.com/compare/adobe-commerce-vs-shopware.md): B 63.9 vs BB 71.4\n- [BigCommerce API + MCP vs Shopware](https://www.anchorterminal.com/compare/bigcommerce-vs-shopware.md): B 64.3 vs BB 71.4\n- [Commerce Layer API + MCP vs Shopware](https://www.anchorterminal.com/compare/commerce-layer-vs-shopware.md): B 63.7 vs BB 71.4\n- [commercetools vs Shopware](https://www.anchorterminal.com/compare/commercetools-vs-shopware.md): BB 71.3 vs BB 71.4\n- [Ecwid by Lightspeed vs Shopware](https://www.anchorterminal.com/compare/ecwid-vs-shopware.md): B 63.2 vs BB 71.4\n- [Elastic Path API + MCP vs Shopware](https://www.anchorterminal.com/compare/elastic-path-vs-shopware.md): D 50.1 vs BB 71.4\n- [Medusa API + MCP vs Shopware](https://www.anchorterminal.com/compare/medusa-vs-shopware.md): B 63.5 vs BB 71.4\n- [Saleor API + MCP vs Shopware](https://www.anchorterminal.com/compare/saleor-vs-shopware.md): B 68.6 vs BB 71.4\n- [Shopify API + MCP vs Shopware](https://www.anchorterminal.com/compare/shopify-vs-shopware.md): BB 75 vs BB 71.4\n- [Shopware vs Snipcart API + MCP](https://www.anchorterminal.com/compare/shopware-vs-snipcart.md): BB 71.4 vs E 40.8\n- [Shopware vs Square](https://www.anchorterminal.com/compare/shopware-vs-square.md): BB 71.4 vs B 69.2\n- [Shopware vs Swell](https://www.anchorterminal.com/compare/shopware-vs-swell.md): BB 71.4 vs C 55\n- [Shopware vs Vendure](https://www.anchorterminal.com/compare/shopware-vs-vendure.md): BB 71.4 vs BB 70.9\n- [Shopware vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/shopware-vs-wix.md): BB 71.4 vs C 61.4\n- [Shopware vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/shopware-vs-woocommerce.md): BB 71.4 vs BB 72.9\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on shopware.com or one of its subdomains, or the README of github.com/shopware/shopware. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"shopware\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/shopware\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/shopware.svg\" alt=\"Shopware on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Shopware on Anchor Terminal](https://www.anchorterminal.com/badges/shopware.svg)](https://www.anchorterminal.com/tools/shopware)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/shopware\"\u003eShopware on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Shopware is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/shopware-dark.png\n- Light: https://www.anchorterminal.com/assets/share/shopware-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Commerce \u0026 checkout",
        "url": "https://www.anchorterminal.com/categories/commerce"
      },
      {
        "name": "Shopware",
        "url": ""
      }
    ],
    "description": "Open-source commerce platform from shopware AG in Germany, written in PHP on Symfony. Agents reach a store through its Store API for shopping, its Admin API for back-office work, and a built-in MCP server on both.",
    "facts": [
      "rank #112 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Shopware",
    "image": "https://www.anchorterminal.com/assets/og/tools-shopware.png",
    "path": "/tools/shopware",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Shopware review for AI agents, grade BB (71.4/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/shopware"
  },
  "tokens": {
    "markdown": 7950,
    "slim": 1830
  },
  "version": 1
}
