# Square (slim) > Square is Block's commerce and payments platform for sellers. Its REST API covers catalogue, orders, payment links, payments, inventory and customers, with seven SDKs and a beta MCP server hosted at mcp.squareup.com. - Full: https://www.anchorterminal.com/tools/square.md (~7,900 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/square.json · canonical https://www.anchorterminal.com/tools/square - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 69.2/100 · rank #166 of 722 · #6 in Commerce & checkout · not agent-ready · confidence medium** Assessment: The REST API has a public OpenAPI 3.0 spec, OAuth scopes split by read and write for each resource, idempotency keys on writes and a free sandbox. The MCP server is in beta and its remote instance reaches production only. No numeric REST rate limits or SLA were found, and the status page recorded widespread errors on 27 September 2026. ## Facts - Kind: HTTP API · vendor: Block, Inc. · category: Commerce & checkout · legal entity: Block, Inc. · provenance 84/100 - Endpoint: `https://mcp.squareup.com/mcp` (HTTP, Streamable HTTP, stdio) - Auth: OAuth or key · pricing: Pay per use · x402: no · licence: Proprietary service under the Square Developer Terms of Service. The MCP server and the OpenAPI specification on GitHub are Apache 2.0, and the Node.js SDK is MIT - Probe metrics: not measured yet (probes haven't run) - APIs: REST at https://connect.squareup.com/v2, sandbox at https://connect.squareupsandbox.com/v2. 332 operations in the 2026-09-16 spec, among them catalogue (14), orders (8), checkout and payment links (10), payments (7), inventory (19) and customers (14). GraphQL for reads - MCP server: Beta. Remote at https://mcp.squareup.com/mcp with OAuth, production only. Local over stdio with `npx square-mcp-server start`, an access token, and `SANDBOX` or `PRODUCTION` set. Three tools in the open-source server - Cart and checkout: Orders API with a DRAFT state, CalculateOrder for totals and discounts on orders, PayOrder, and CreatePaymentLink for a Square-hosted checkout page - Credentials: Personal access token (unrestricted, own account) or OAuth access token limited by scopes. OAuth tokens expire after 30 days, with refresh and revoke endpoints - Rate limits: No numbers published for REST. 429 with `RATE_LIMITED`, and the docs ask for exponential backoff with jitter. GraphQL allows 10 queries a second, depth 10 and a complexity score of 250 - Errors: An `errors` array with category, code, detail and field. Retired endpoints return 410 - Idempotency: `idempotency_key` on 78 request schemas, and optimistic concurrency by object version - Versioning: Dated versions (YYYY-MM-DD) pinned per application and overridden with the `Square-Version` header. Releases roughly monthly - SDKs: Java 48.0.0.20260916, .NET 47.0.0, Node.js 46.0.0, PHP 47.0.0.20260916, Python 46.0.0.20260916, Ruby 47.0.0.20260916, Go v5.0.0 - Sandbox: Free, provisioned for each application, with test cards and payment tokens. Hardware, the Point of Sale API, Snippets API and Sites API aren't supported in it - Audit: API Logs in the Developer Console keep each request and response for 28 days, filterable by API, endpoint, status and error code. GraphQL queries aren't logged there - Deprecations: Typically at least 12 months between deprecation and retirement, and at least 6 months in maintenance once a replacement is generally available - Status: issquareup.com, 15 incidents between 10 July and 8 October 2026, all labelled minor by Square - Prices: Card payment through the payments APIs (US) 2.9% percentage fee; ACH bank transfer through the API (US) 1% percentage fee; Square Free free per month (plan); Square Plus $49 per month (plan); Square Premium $149 per month (plan) - Scores: Reliability 58, Performance pending, Schema & documentation 87, Agent ergonomics 83, Security & auth 67, Payments & pricing 40, Task success pending, Maintenance & community 81, Transparency & trust 70 · total over the 7 assessed categories - Why: Reliability, Graded on the hosted REST API. · Schema & documentation, Public OpenAPI 3.0 spec in square/connect-api-specification with 332 operations and 1,476 schemas (25). · Agent ergonomics, List endpoints take `limit` and a cursor, and GraphQL selects fields for reads. · Security & auth, OAuth with code and PKCE flows, read and write scopes for each resource, 30-day access tokens, refresh and revocation. · Payments & pricing, No x402, MPP or L402 found in the docs index or the spec (0). · Maintenance & community, API version 2026-09-16 was released 22 days before the check (30). · Transparency & trust, Closed service under published developer terms. - Sources: 25, open questions: 8, both in the full twin - Capabilities: commerce.products, commerce.orders, commerce.checkout, commerce.cart, commerce.headless, payments.card, payments.checkout - JSON: https://www.anchorterminal.com/api/v1/tools/square.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/square.svg` or a link to https://www.anchorterminal.com/tools/square from a page on squareup.com or one of its subdomains, or the README of github.com/square/square-mcp-server, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Test against the sandbox first with the local MCP server and `SANDBOX=true`. The remote server at mcp.squareup.com reaches production only 2. Set `DISALLOW_WRITES=true` on the local MCP server when the task only reads 3. Call `get_service_info`, then `get_type_info`, before each `make_api_request`. The request body is otherwise untyped 4. Send a fresh `idempotency_key` on every write, and reuse it when retrying the same write 5. Pin `Square-Version` in each request. Use a page cursor within 5 minutes of receiving it ## Connect ```bash npx square-mcp-server start ``` ```bash curl https://connect.squareupsandbox.com/v2/locations \ -H 'Square-Version: 2026-09-16' \ -H 'Authorization: Bearer {SANDBOX_ACCESS_TOKEN}' \ -H 'Content-Type: application/json' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/square ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Shopify API + MCP | BB | 75 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/shopify.min.md | | WooCommerce API + MCP | BB | 72.9 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/woocommerce.min.md | | Shopware | BB | 71.4 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/shopware.min.md | | commercetools | BB | 71.3 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/commercetools.min.md | | Vendure | BB | 70.9 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | https://www.anchorterminal.com/tools/vendure.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)