# Shopware (slim) > Open-source commerce platform from shopware AG in Germany, written in PHP on Symfony. Agents reach a store through its Store API for shopping, its Admin API for back-office work, and a built-in MCP server on both. - Full: https://www.anchorterminal.com/tools/shopware.md (~7,950 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/shopware.json · canonical https://www.anchorterminal.com/tools/shopware - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 71.4/100 · rank #112 of 722 · #3 in Commerce & checkout · agent-ready · confidence medium** Assessment: MIT-licensed core with OpenAPI specs for both APIs and a built-in MCP server that advertises three discovery tools, previews writes by default and limits each integration to an allowlist. The MCP server is experimental until 6.8, and 20 security advisories were published between May and September 2026, four of them critical. ## Facts - Kind: HTTP API · vendor: shopware AG · category: Commerce & checkout · legal entity: shopware AG · provenance 71/100 - Local only (HTTP, Streamable HTTP): packagist `shopware/core`, npm `@shopware/api-client` - Auth: OAuth or key · pricing: Freemium · x402: no · licence: MIT for the Community Edition core. Paid plans add proprietary extensions under shopware AG's general terms - Probe metrics: not measured yet (probes haven't run) - Free tier: Community Edition is free under MIT. Hosting is the merchant's cost - Paid plans: Rise from €600 a month, Evolve from €2,400 a month, Beyond on request, all excluding VAT and priced on GMV. SaaS costs the same as self-hosted per the pricing page (https://www.shopware.com/en/pricing/) - APIs: Store API under /store-api (cart, checkout, orders, products, search, account) and Admin API under /api (entity CRUD, search, sync, order states). OpenAPI 3 at /(api|store-api)/_info/openapi3.json when APP_ENV is dev - MCP server: Built into core since 6.7.11.0, streamable HTTP at /api/_mcp and /store-api/_mcp, experimental until 6.8.0. 14 Admin API tools in core and the Storefront bundle, of which 3 are advertised at the start of a session - Auth and scopes: Admin API takes OAuth 2.0 client credentials from an integration, or the integration's key and secret as headers on MCP. ACL roles per integration. Store API takes a sales channel access key and a context token - Rate limits: MCP 300 a minute and 1,000 per 10 minutes (Admin), 120 and 600 (Store). Login, password reset and form routes are limited by default. No general request limit on the other API routes - Write safety: MCP write tools default to dryRun=true and roll the transaction back. shopware-media-upload has no dry run - Response size: `includes` selects fields, page and limit paginate, and an MCP result over 100 KB comes back as a shopware://tool-result/{id} resource - SDKs: @shopware/api-client 1.7.0 on npm (MIT, published 6 October 2026), generated from the OpenAPI schemas - Support window: releases.json gives 28 February 2028 as the end of security fixes for 6.7 and 28 February 2027 for 6.6 - Certifications: ISO/IEC 27001:2022 per the trust centre, which says hosted environments align with SOC 2 Type II principles (vendor claims) - Status: status.shopware.com covers Shopware SaaS, PaaS and vendor services. A self-hosted store has no vendor status - Prices: Community Edition free per month (plan) - Scores: Reliability 83, Performance pending, Schema & documentation 85, Agent ergonomics 78, Security & auth 73, Payments & pricing 50, Task success pending, Maintenance & community 87, Transparency & trust 76 · negative events -5 · total over the 7 assessed categories - Why: Reliability, Graded with the self-hosted package lines, because each store's APIs run on the merchant's own server or SaaS shop. · Schema & documentation, OpenAPI 3 for both APIs, as JSON in the repository, on a hosted Stoplight reference and from each instance at /_info/openapi3.json in dev mo… · Agent ergonomics, A fresh MCP session advertises three discovery tools and loads the rest by toolset. · Security & auth, Admin API by OAuth 2.0 client credentials from a revocable integration with an ACL role and 10 minute tokens, or the integration's key and s… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, 6.7.15.1 tagged on 2 October 2026 (30). · Transparency & trust, MIT licence for the core (30). - Sources: 28, open questions: 7, both in the full twin - Capabilities: commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless - JSON: https://www.anchorterminal.com/api/v1/tools/shopware.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/shopware.svg` or a link to https://www.anchorterminal.com/tools/shopware from a page on shopware.com or one of its subdomains, or the README of github.com/shopware/shopware, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Ask the merchant for an integration without --admin, tied to an ACL role and an MCP allowlist. Send sw-access-key and sw-secret-access-key headers to /api/_mcp 2. Call shopware-tool-search first, then shopware-toolset-enable, and keep the Mcp-Session-Id header. A fresh session lists only three tools 3. Pass dryRun=false to commit a write. shopware-media-upload has no dry run and uploads at once 4. For shopping, call the Store API over HTTP with the sales channel's sw-access-key and keep the sw-context-token. The Store API MCP endpoint has no cart tools in core 5. Send `includes` in search criteria to cut response size, and read the 429 body for the wait time ## Connect ```bash npx @shopware-ag/shopware-cli project create my-shop ``` ```bash curl -X POST "http://localhost:8000/api/search/product" \ -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \ -H "Content-Type: application/json" \ -d '{}' ``` ```bash claude mcp add --transport http shopware http://localhost:8000/api/_mcp --header "sw-access-key: SWIA..." --header "sw-secret-access-key: ..." ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/shopware ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Shopify API + MCP | BB | 75 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/shopify.min.md | | WooCommerce API + MCP | BB | 72.9 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/woocommerce.min.md | | commercetools | BB | 71.3 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/commercetools.min.md | | Vendure | BB | 70.9 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/vendure.min.md | | Square | B | 69.2 | commerce.products, commerce.orders, commerce.checkout, commerce.cart, commerce.headless | https://www.anchorterminal.com/tools/square.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)