# Spree Commerce (slim) > Spree Commerce is an open-source commerce platform on Ruby on Rails, maintained by Vendo Connect Inc. A self-hosted store runs a Store API for catalogue, cart and checkout, and an Admin API for back-office work. - Full: https://www.anchorterminal.com/tools/spree-commerce.md (~7,100 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/spree-commerce.json · canonical https://www.anchorterminal.com/tools/spree-commerce - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **BB · 70.4/100 · rank #155 of 950 · #6 in Commerce & checkout · agent-ready · confidence medium** Assessment: A self-hosted BSD 3-Clause platform with public OpenAPI files for the Store and Admin APIs, scoped secret keys, documented rate limits and idempotency keys on cart and checkout calls. GitHub lists six security advisories between January and July 2026, four rated High, and the default docs describe the 6.0 release candidate while 5.6.1 is the stable release. ## Facts - Kind: HTTP API · vendor: Vendo Connect Inc · category: Commerce & checkout · legal entity: Vendo Connect Inc · provenance 45/100 - Local only (HTTP): npm `@spree/sdk`, npm `@spree/cli`, npm `@spree/admin-sdk`, rubygems `spree` - Auth: OAuth or key · pricing: Freemium · x402: no · licence: BSD-3-Clause for the backend, MIT for the npm packages. Enterprise Edition code is under a separate commercial licence - Probe metrics: not measured yet (probes haven't run) - Free tier: The Community Edition is free to self-host. The hosted Sandbox is free and for evaluation with test data only - APIs: Store API at `/api/v3/store` (81 paths, 99 operations on main, 63 paths and 77 operations at 5.6.1), Admin API at `/api/v3/admin` (259 paths, 417 operations, since 5.5) and a Seller API in 6.0, all OpenAPI 3.0.3 - Auth and scopes: Publishable keys (`pk_`) for the Store API, optionally bound to a sales channel. Secret keys (`sk_`) with `read_*` and `write_*` scopes per resource, or admin JWTs, for the Admin API - Rate limits: Defaults of 300 requests a minute per API key, 5 logins, 3 registrations and 10 token refreshes a minute per IP. `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `Retry-After` headers. Configurable by the operator - Cart and checkout: Carts, items, discount codes, gift cards, store credits, payment sessions and `POST /carts/{id}/complete`, which returns an order. Guest carts use a cart token - Idempotency: `Idempotency-Key` on eight cart, checkout and payment calls, cached 24 hours and replayed with `Idempotent-Replayed: true`. Not cached for callers with only a publishable key - Errors: One `error` object with `code`, `message` and per-field `details`. 34 codes, among them `insufficient_stock`, `cart_cannot_complete` and `rate_limit_exceeded` - Webhooks: Signed with HMAC-SHA256 in `X-Spree-Webhook-Signature` with a timestamp, retried with growing delays, and re-sendable from a delivery log - SDKs and CLI: `@spree/sdk` 1.2.1 (Store), `@spree/admin-sdk` 0.1.0 on npm with 1.0.0-rc.1 in the repository, `@spree/seller-sdk`, and `@spree/cli` 3.2.2 with `spree api get/post/patch/delete`. TypeScript only - MCP server: Official and hosted at https://spreecommerce.org/docs/mcp with no authentication. Two tools, docs search and page read. No store data - Open source: BSD 3-Clause backend on Ruby on Rails 8.1, MIT npm packages. Postgres, MySQL or SQLite. Official Docker images - Enterprise Edition: Custom pricing. Adds multi-tenancy, approval workflows, Shopify and WooCommerce seller sync, audit trail, encryption at rest, long-term support releases and SLA support - Prices: Community Edition, self-hosted free per month (plan) - Scores: Reliability 82, Performance pending, Schema & documentation 85, Agent ergonomics 90, Security & auth 65, Payments & pricing 55, Task success pending, Maintenance & community 81, Transparency & trust 60 · negative events -5 · total over the 7 assessed categories - Why: Reliability, Graded as software the owner runs. · Schema & documentation, OpenAPI 3.0.3 files for the Store API (81 paths, 99 operations) and Admin API (259 paths, 417 operations) are public (25). · Agent ergonomics, `fields` trims a response, `expand` adds relations that are left out by default, and `limit` caps a page (23). · Security & auth, Publishable keys for the Store API and secret keys with `read_*` and `write_*` scopes per resource for the Admin API, shown once, revocable… · Payments & pricing, Read with the self-hosted rule. · Maintenance & community, The stable server release is 5.6.1 of 28 July 2026, 73 days before the check (20). · Transparency & trust, BSD 3-Clause for the backend, MIT for the npm packages and CC BY 4.0 for the docs. - Sources: 21, open questions: 8, both in the full twin - Capabilities: commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless - JSON: https://www.anchorterminal.com/api/v1/tools/spree-commerce.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/spree-commerce.svg` or a link to https://www.anchorterminal.com/tools/spree-commerce from a page on spreecommerce.org or one of its subdomains, or the README of github.com/spree/spree, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send a publishable key in `X-Spree-Api-Key` on every Store API call. Add `X-Spree-Token` with the cart token for guest carts, or a customer JWT as a Bearer token 2. Send `Idempotency-Key` with the cart token or a customer JWT on cart, payment and completion calls. A request carrying only the publishable key is never cached 3. Ask for `fields` and `expand` explicitly. Relations are left out by default and `limit` stops at 100 4. Use a secret key with the narrowest scopes for the Admin API. `read_all` gives a read-only key, and the CLI's auto-minted local key is read-only 5. Read the docs under `/docs/v5` for a 5.6 store. The default docs describe 6.0, which renames shipments to fulfilments and splits carts from orders ## Connect ```bash npx create-spree-app@latest my-store ``` ```bash curl -X GET 'http://localhost:3000/api/v3/store/products' -H 'X-Spree-Api-Key: pk_xxx' ``` ```bash claude mcp add --transport http spree-docs https://spreecommerce.org/docs/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/spree-commerce ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Shopify API + MCP | BB | 75 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/shopify.min.md | | WooCommerce API + MCP | BB | 72.9 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/woocommerce.min.md | | Shopware | BB | 71.4 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/shopware.min.md | | commercetools | BB | 71.3 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/commercetools.min.md | | Vendure | BB | 70.9 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/vendure.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)