{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/shopify.json",
        "name": "Shopify API + MCP",
        "score": 75,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "shopify"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/woocommerce.json",
        "name": "WooCommerce API + MCP",
        "score": 72.9,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "woocommerce"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/shopware.json",
        "name": "Shopware",
        "score": 71.4,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "shopware"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/commercetools.json",
        "name": "commercetools",
        "score": 71.3,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "commercetools"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/vendure.json",
        "name": "Vendure",
        "score": 70.9,
        "shared": [
          "commerce.products",
          "commerce.cart",
          "commerce.checkout",
          "commerce.orders",
          "commerce.headless"
        ],
        "slug": "vendure"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/square.json",
        "name": "Square",
        "score": 69.2,
        "shared": [
          "commerce.products",
          "commerce.orders",
          "commerce.checkout",
          "commerce.cart",
          "commerce.headless"
        ],
        "slug": "square"
      }
    ],
    "tool": {
      "slug": "wix",
      "name": "Wix Stores and eCommerce API",
      "vendor": "Wix.com Ltd.",
      "vendorUrl": "https://www.wix.com",
      "kind": "http-api",
      "category": "commerce",
      "summary": "Wix is a hosted website and online store platform. Agents reach its Stores and eCommerce data through the REST API at `www.wixapis.com`, a JavaScript SDK, and a hosted MCP server at `mcp.wix.com` that searches the docs and calls site APIs.",
      "url": "https://www.anchorterminal.com/tools/wix",
      "markdownUrl": "https://www.anchorterminal.com/tools/wix.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/wix.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/wix.json",
      "repo": "https://github.com/wix/wix-mcp",
      "license": "Proprietary service under the Wix Terms of Use. `@wix/sdk`, `@wix/stores` and the wix/skills repository are MIT. `@wix/mcp` states no licence",
      "transports": [
        "http",
        "streamable-http",
        "sse"
      ],
      "remoteUrl": "https://www.wixapis.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@wix/sdk"
        },
        {
          "registry": "npm",
          "name": "@wix/stores"
        },
        {
          "registry": "npm",
          "name": "@wix/mcp"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. An account owner or co-owner creates an API key in the API Keys Manager with permission scopes and a list of sites, then sends it in `Authorization` with `wix-site-id` or `wix-account-id`. Apps use OAuth client credentials, with tokens valid for 4 hours. Headless storefronts get visitor tokens from the `anonymous` grant. The MCP server takes an OAuth login with dynamic client registration, or the API key and `wix-account-id` as headers.",
      "pricing": "freemium",
      "pricingNotes": "Plan pricing with no per-call charge. Free plan with no card, then Light, Core, Business and Business Elite, with eCommerce on Core and above. wix.com/plans shows prices in the reader's currency, and our reader was served rupees, so US dollar prices are unconfirmed (checked 2026-10-08). API access needs no contract.",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs corpus or on the plans page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 18,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 87183,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://dev.wix.com/docs/api-reference",
      "llmsTxt": "https://dev.wix.com/docs/llms.txt",
      "registryName": "com.wix/mcp",
      "capabilities": [
        "commerce.products",
        "commerce.cart",
        "commerce.checkout",
        "commerce.orders",
        "commerce.headless"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "api-key",
        "llms-txt",
        "webhooks",
        "javascript",
        "headless",
        "status-page",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61.4,
        "grade": "C",
        "agentReady": false,
        "rank": 364,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 13,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 83,
          "payments": 30,
          "reliability": 48,
          "schema": 76,
          "security": 61,
          "transparency": 77
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 48,
            "points": 9.6,
            "reason": "Atlassian Statuspage at status.wix.com with 119 components, Stores and Payments among them, and an incident feed (20). From 10 July to 8 October 2026 the feed holds 10 incidents. Three are marked critical: 1 August, 3 hours 17 minutes across nearly every component including Store Management, Checkout and APIs, 24 July, 47 minutes on sign-in, site loading and checkout, and 15 September, 42 minutes in Europe, with a postmortem. Three marked major lasted 12 to 26 minutes, the latest on 1 October on Store Management, Storefront and Checkout. One outage over an hour plus two shorter critical ones (7). No numeric limit for REST calls was found. The docs publish per-minute quotas only for site data requests and tell callers to space some writes one second apart (3). The 429 guidance is to wait a minute and retry, updates are guarded by revision numbers that return 409, and idempotency keys exist on a few methods only (8). The trust centre FAQ states a service level objective and a 99.99 per cent figure for 2021, with no SLA found (0). The REST APIs are released, and Cart V2 shipped on 5 August 2026 without a preview label (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 76,
            "points": 12.35,
            "reason": "No public OpenAPI file was found. The contract is the Markdown reference, which the MCP tools `ReadFullDocsMethodSchema` and `SearchWixAPISpec` also serve, and the MCP tools have typed inputs (12). `llms.txt`, `llms-full.txt` and a `.md` twin of every docs page (10). Method pages state purpose and limits, for example that Query Products supports a narrow set of filters and that Search Products is the route for name lookups (15). REST fields carry types, enums and minimum and maximum values, but the MCP's `CallWixSiteAPI` takes a free-form URL, method and body (11). Each method page has a curl example and a list of HTTP and application error codes, and a general errors article documents the error format (13). Versions are per module, and dev.wix.com/changelog is dated (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 68,
            "points": 11.05,
            "reason": "The MCP lists 18 tools, all on by default, with no toolsets or read-only subset documented. Most calls need a docs lookup first, and the Query Products page alone is 327 KB of Markdown (15). Cursor and offset paging, a query language with filters and sorting, and a `fields` parameter for projection. Query Products returns at most 100 a page (18). Errors use one format with application codes and per-field violations, though system errors are empty by design (16). Revision numbers guard updates, idempotency keys cover a few methods, and the `@wix/mcp` package sets annotations, with `destructiveHint` true on `CallWixSiteAPI` (12). Every site call needs a site ID header, and the only official SDK is JavaScript (7)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 61,
            "points": 10.68,
            "reason": "API keys carry permission scopes and a list of sites they may target, and stay valid until revoked or rotated in the dashboard. App tokens come from OAuth client credentials and last 4 hours. The MCP uses OAuth with dynamic client registration, advertises only `offline_access` as a scope and still accepts the `plain` PKCE method (26). Read and admin scopes are separate (`SCOPE.STORES.PRODUCT_READ` and `SCOPE.STORES.PRODUCT_READ_ADMIN`), but no read-only mode or confirmation step for the MCP was found (11). The API returns merchant and customer content, and no prompt-injection guidance was found. The `@wix/mcp` package limits call URLs to five Wix hostnames (4). No audit log or per-call log for API keys was found in the developer docs. Responses carry `x-wix-request-id` (2). The security page lists SOC 2 Type 2, PCI DSS Level 1 and several ISO certificates and a bug bounty at bugbounty@wix.com. `/security.txt` has a contact but no Expires field, and `/.well-known/security.txt` returns 404 (18)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "No x402, MPP or L402 found (0). Plan prices are public on wix.com/plans but shown in the reader's currency, with nothing per call (10). A free plan, marked no credit card required, with eCommerce on Core and above (20). A person signs up in a browser and creates the API key in the API Keys Manager (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 83,
            "points": 7.26,
            "reason": "Changelog entries on 8 October 2026, and `@wix/mcp` 1.0.92 published the same day (30). 101 dated changelog entries between 6 July and 8 October 2026 (20). Public changelog, a support site, and the public wix/skills repository with commits on 8 October 2026 (12). The MCP server is in the official registry as `com.wix/mcp`, version 1.0.2 of 22 December 2025, and `@wix/sdk` 1.21.17 is current (15). `@wix/mcp` had 30 releases in 90 days. The server's source and CI are not public, and the package states no licence (6)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 77,
            "points": 6.74,
            "note": "editorial 69, provenance 84",
            "reason": "Closed platform under the Wix Terms of Use. `@wix/sdk` and `@wix/stores` are MIT and wix/skills is MIT (15). Privacy policy effective 18 June 2026 and a data processing addendum effective 1 December 2025. Retention is stated as the time reasonably necessary, with no fixed periods found (20). The versioning article says deprecated APIs are marked, logged in the changelog and not removed, and Developer Preview lasts at most 6 months (16). A sub-processor list names Wix entities and third parties with locations, and the security page names AWS, Google Cloud and Equinix as hosts (18)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The MCP lists 18 tools, all on by default, with no toolsets or read-only subset documented. Most calls need a docs lookup first, and the Query Products page alone is 327 KB of Markdown (15). Cursor and offset paging, a query language with filters and sorting, and a `fields` parameter for projection. Query Products returns at most 100 a page (18). Errors use one format with application codes and per-field violations, though system errors are empty by design (16). Revision numbers guard updates, idempotency keys cover a few methods, and the `@wix/mcp` package sets annotations, with `destructiveHint` true on `CallWixSiteAPI` (12). Every site call needs a site ID header, and the only official SDK is JavaScript (7).",
            "maintenance": "Changelog entries on 8 October 2026, and `@wix/mcp` 1.0.92 published the same day (30). 101 dated changelog entries between 6 July and 8 October 2026 (20). Public changelog, a support site, and the public wix/skills repository with commits on 8 October 2026 (12). The MCP server is in the official registry as `com.wix/mcp`, version 1.0.2 of 22 December 2025, and `@wix/sdk` 1.21.17 is current (15). `@wix/mcp` had 30 releases in 90 days. The server's source and CI are not public, and the package states no licence (6).",
            "payments": "No x402, MPP or L402 found (0). Plan prices are public on wix.com/plans but shown in the reader's currency, with nothing per call (10). A free plan, marked no credit card required, with eCommerce on Core and above (20). A person signs up in a browser and creates the API key in the API Keys Manager (0).",
            "reliability": "Atlassian Statuspage at status.wix.com with 119 components, Stores and Payments among them, and an incident feed (20). From 10 July to 8 October 2026 the feed holds 10 incidents. Three are marked critical: 1 August, 3 hours 17 minutes across nearly every component including Store Management, Checkout and APIs, 24 July, 47 minutes on sign-in, site loading and checkout, and 15 September, 42 minutes in Europe, with a postmortem. Three marked major lasted 12 to 26 minutes, the latest on 1 October on Store Management, Storefront and Checkout. One outage over an hour plus two shorter critical ones (7). No numeric limit for REST calls was found. The docs publish per-minute quotas only for site data requests and tell callers to space some writes one second apart (3). The 429 guidance is to wait a minute and retry, updates are guarded by revision numbers that return 409, and idempotency keys exist on a few methods only (8). The trust centre FAQ states a service level objective and a 99.99 per cent figure for 2021, with no SLA found (0). The REST APIs are released, and Cart V2 shipped on 5 August 2026 without a preview label (10).",
            "schema": "No public OpenAPI file was found. The contract is the Markdown reference, which the MCP tools `ReadFullDocsMethodSchema` and `SearchWixAPISpec` also serve, and the MCP tools have typed inputs (12). `llms.txt`, `llms-full.txt` and a `.md` twin of every docs page (10). Method pages state purpose and limits, for example that Query Products supports a narrow set of filters and that Search Products is the route for name lookups (15). REST fields carry types, enums and minimum and maximum values, but the MCP's `CallWixSiteAPI` takes a free-form URL, method and body (11). Each method page has a curl example and a list of HTTP and application error codes, and a general errors article documents the error format (13). Versions are per module, and dev.wix.com/changelog is dated (15).",
            "security": "API keys carry permission scopes and a list of sites they may target, and stay valid until revoked or rotated in the dashboard. App tokens come from OAuth client credentials and last 4 hours. The MCP uses OAuth with dynamic client registration, advertises only `offline_access` as a scope and still accepts the `plain` PKCE method (26). Read and admin scopes are separate (`SCOPE.STORES.PRODUCT_READ` and `SCOPE.STORES.PRODUCT_READ_ADMIN`), but no read-only mode or confirmation step for the MCP was found (11). The API returns merchant and customer content, and no prompt-injection guidance was found. The `@wix/mcp` package limits call URLs to five Wix hostnames (4). No audit log or per-call log for API keys was found in the developer docs. Responses carry `x-wix-request-id` (2). The security page lists SOC 2 Type 2, PCI DSS Level 1 and several ISO certificates and a bug bounty at bugbounty@wix.com. `/security.txt` has a contact but no Expires field, and `/.well-known/security.txt` returns 404 (18).",
            "transparency": "Closed platform under the Wix Terms of Use. `@wix/sdk` and `@wix/stores` are MIT and wix/skills is MIT (15). Privacy policy effective 18 June 2026 and a data processing addendum effective 1 December 2025. Retention is stated as the time reasonably necessary, with no fixed periods found (20). The versioning article says deprecated APIs are marked, logged in the changelog and not removed, and Developer Preview lasts at most 6 months (16). A sub-processor list names Wix entities and third parties with locations, and the security page names AWS, Google Cloud and Equinix as hosts (18)."
          },
          "sources": [
            {
              "what": "Wix MCP article, tools and configuration",
              "url": "https://dev.wix.com/docs/sdk/articles/use-the-wix-mcp/about-the-wix-mcp.md",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index for agents",
              "url": "https://dev.wix.com/docs/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "full docs corpus, searched for rate limits, idempotency, OpenAPI and audit logs",
              "url": "https://dev.wix.com/docs/llms-full.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "REST API authentication",
              "url": "https://dev.wix.com/docs/api-reference/articles/rest-authentication/rest-api-authentication.md",
              "seen": "2026-10-08"
            },
            {
              "what": "authentication methods, API keys and token lifetime",
              "url": "https://dev.wix.com/docs/rest/articles/get-started/api-keys.md",
              "seen": "2026-10-08"
            },
            {
              "what": "making calls with an API key",
              "url": "https://dev.wix.com/docs/api-reference/articles/authentication/api-keys/make-api-calls-with-an-api-key.md",
              "seen": "2026-10-08"
            },
            {
              "what": "error format",
              "url": "https://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/troubleshooting/about-errors.md",
              "seen": "2026-10-08"
            },
            {
              "what": "troubleshooting, 409 and 429",
              "url": "https://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/troubleshooting/troubleshooting.md",
              "seen": "2026-10-08"
            },
            {
              "what": "sorting and paging",
              "url": "https://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/data-retrieval/about-sorting-and-paging.md",
              "seen": "2026-10-08"
            },
            {
              "what": "versions and deprecation",
              "url": "https://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/platform/about-api-versions-and-deprecation.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Developer Preview",
              "url": "https://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/platform/about-developer-preview.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Query Products reference",
              "url": "https://dev.wix.com/docs/api-reference/business-solutions/stores/catalog-v3/products-v3/query-products.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Stores API menu",
              "url": "https://dev.wix.com/docs/api-reference/business-solutions/stores.md",
              "seen": "2026-10-08"
            },
            {
              "what": "eCommerce API menu",
              "url": "https://dev.wix.com/docs/api-reference/business-solutions/e-commerce.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Wix plugin and skills",
              "url": "https://dev.wix.com/docs/api-reference/articles/ai-tools/about-the-wix-plugin.md",
              "seen": "2026-10-08"
            },
            {
              "what": "developer changelog",
              "url": "https://dev.wix.com/changelog",
              "seen": "2026-10-08"
            },
            {
              "what": "status incident feed",
              "url": "https://status.wix.com/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP OAuth metadata",
              "url": "https://mcp.wix.com/.well-known/oauth-authorization-server",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry entry",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=wix",
              "seen": "2026-10-08"
            },
            {
              "what": "@wix/mcp package 1.0.92, tool code and annotations",
              "url": "https://registry.npmjs.org/@wix/mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "@wix/sdk package",
              "url": "https://registry.npmjs.org/@wix/sdk/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "wix-mcp repository",
              "url": "https://github.com/wix/wix-mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "wix/skills repository",
              "url": "https://github.com/wix/skills",
              "seen": "2026-10-08"
            },
            {
              "what": "plans and prices",
              "url": "https://www.wix.com/plans",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of use",
              "url": "https://www.wix.com/about/terms-of-use",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.wix.com/about/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "data processing addendum",
              "url": "https://www.wix.com/about/privacy-dpa-users",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processor list",
              "url": "https://support.wix.com/en/article/list-of-wixs-sub-processors",
              "seen": "2026-10-08"
            },
            {
              "what": "security page",
              "url": "https://www.wix.com/trust-center/security",
              "seen": "2026-10-08"
            },
            {
              "what": "trust centre FAQ",
              "url": "https://www.wix.com/trust-center/faq",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.wix.com/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "reporting a security issue",
              "url": "https://support.wix.com/en/article/reporting-a-security-issue",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration (RDAP)",
              "url": "https://rdap.verisign.com/com/v1/domain/wix.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: US dollar plan prices. wix.com/plans served rupee prices to our reader (Light 250, Core 500, Business 900 and Business Elite 1,800 rupees a month before a 50 per cent offer). A request with `currency=USD` returned unfilled markup showing 17, 29, 39 and 159, which we did not treat as confirmed.",
            "unchecked: the live MCP tool list and schemas. `mcp.wix.com/mcp` answers 401 without a token, so the 18 tools are from the docs and the annotations from the `@wix/mcp` 1.0.92 package.",
            "unchecked: GitHub stars, and the full text of the terms of use and privacy policy, whose collapsed sections were not in the HTML we received.",
            "No numeric REST rate limit, no OpenAPI file, no SLA and no API audit log were found in the reviewed documentation.",
            "Whether a free site can call the Stores APIs before a paid plan is bought was not established.",
            "The `@wix/mcp` package builds tool text with a block of instructions addressed to the model, telling it to call `WixREADME` first. Recorded as a fact, with no deduction.",
            "The lead's docs URL still resolves, but the MCP article now lives under dev.wix.com/docs/api-reference/articles/ai-tools/wix-mcp. The MCP has no Stores tools of its own. It reaches Stores through the general `CallWixSiteAPI` and `ExecuteWixAPI` tools.",
            "Wix WebMCP, for agents in a visitor's browser, was announced in the changelog on 8 October 2026 and is not graded here."
          ]
        },
        "negative": 0,
        "verdict": "The developer docs are served as Markdown with an llms.txt index, and API keys carry permission scopes and a site restriction. No numeric REST rate limit or OpenAPI file was found, and status.wix.com records a platform-wide incident of 3 hours 17 minutes on 1 August 2026. A person must create the account and the key.",
        "bestFor": "An agent managing a merchant's existing Wix store or building a headless storefront on Wix.",
        "strengths": [
          "Every docs page has a Markdown twin (append `.md`), with `llms.txt` and `llms-full.txt` indexes at dev.wix.com/docs",
          "API keys combine permission scopes with a per-site access list, and can be revoked or rotated in the dashboard",
          "Method pages list permission scopes, field constraints, enums, a curl example and per-method error codes",
          "Hosted MCP server at `https://mcp.wix.com/mcp` with OAuth dynamic client registration, listed as `com.wix/mcp` in the official registry",
          "Dated developer changelog with 101 entries between 6 July and 8 October 2026, and a policy that deprecated APIs keep working"
        ],
        "weaknesses": [
          "No numeric rate limit for the REST API was found in the reviewed documentation. The 429 guidance is to wait a minute and retry",
          "No public OpenAPI file was found. Schemas are read from the Markdown reference or through the MCP schema tools",
          "status.wix.com shows 10 incidents from 10 July to 8 October 2026, three marked critical, the longest 3 hours 17 minutes on 1 August",
          "The MCP's `CallWixSiteAPI` takes a free-form URL, method and body, and no read-only mode or confirmation step is documented",
          "The only official SDK is JavaScript, and plan prices on wix.com/plans are shown in the reader's local currency"
        ],
        "agentNotes": [
          "Send the API key in `Authorization` with `wix-site-id` for site calls or `wix-account-id` for account calls, never both",
          "Fetch the product first and pass `product.revision` on every Catalogue V3 update, or the call fails with 409",
          "Use Cart V2 for new work. The older eCommerce Cart and Checkout APIs were deprecated on 5 August 2026",
          "Request `cursorPaging.limit` of at most 100 on Query Products and use Search Products for lookups by name",
          "Over MCP, read the method page with `ReadFullDocsArticle` before `CallWixSiteAPI`. Responses are cut at 50,000 characters by default"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61.4
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 83,
          "payments": 30,
          "reliability": 48,
          "schema": 76,
          "security": 61,
          "transparency": 69
        },
        "provenanceScore": 84
      },
      "connect": {
        "install": "npm install @wix/sdk @wix/stores",
        "http": "curl -X POST 'https://www.wixapis.com/stores/v3/products/query' \\\n  -H 'Content-Type: application/json' \\\n  -H 'Authorization: \u003cAPI_KEY\u003e' \\\n  -H 'wix-site-id: \u003cSITE_ID\u003e' \\\n  -d '{\"query\": {\"cursorPaging\": {\"limit\": 10}}}'",
        "claudeCode": "/plugin marketplace add wix/skills\n/plugin install wix@wix",
        "config": {
          "mcpServers": {
            "wix-mcp-remote": {
              "type": "http",
              "url": "https://mcp.wix.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/commerce.products",
        "tool": "https://letme.dev/wix"
      },
      "notable": [
        "The MCP server reaches Stores through two general tools, `CallWixSiteAPI` for one REST call and `ExecuteWixAPI` for a script that chains or pages calls (https://dev.wix.com/docs/sdk/articles/use-the-wix-mcp/about-the-wix-mcp.md)",
        "Every docs page has a Markdown version at the same URL plus `.md`, indexed by https://dev.wix.com/docs/llms.txt",
        "Cart V2 replaced the eCommerce Cart and Checkout APIs on 5 August 2026 (https://dev.wix.com/changelog)",
        "Wix says it doesn't remove deprecated APIs (https://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/platform/about-api-versions-and-deprecation.md)",
        "status.wix.com records a critical incident of 3 hours 17 minutes on 1 August 2026 across nearly every component (https://stspg.io/6t722nl4gdcp)",
        "The `@wix/mcp` 1.0.92 package builds tool text with a block of instructions addressed to the model, telling it to call `WixREADME` first (https://registry.npmjs.org/@wix/mcp)",
        "Wix WebMCP, which gives agents in a visitor's browser tools to search, add to the cart and open checkout, was announced on 8 October 2026 (https://dev.wix.com/changelog)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Free tier",
          "value": "Free plan with no card. eCommerce is on Core, Business and Business Elite, each with 50,000 products"
        },
        {
          "label": "Access",
          "value": "Self-serve API key from the API Keys Manager, created by an account owner or co-owner. No partner or sales approval"
        },
        {
          "label": "Auth and scopes",
          "value": "API key with permission scopes and a site access list, long-lived until revoked or rotated. OAuth client credentials for apps, tokens valid 4 hours. Visitor and member tokens for headless storefronts"
        },
        {
          "label": "Rate limits",
          "value": "No numeric REST limit found in the reviewed documentation. A 429 means wait a minute and retry"
        },
        {
          "label": "Catalogue",
          "value": "Stores Catalogue V3 (products, variants, inventory, brands, ribbons, promotions) and the older Catalogue V1. Query Products returns up to 100 a page with cursor paging"
        },
        {
          "label": "Cart and checkout",
          "value": "eCommerce Cart V2 covers cart and checkout in one entity since 5 August 2026. The earlier Cart and Checkout APIs are deprecated and still work"
        },
        {
          "label": "Orders",
          "value": "eCommerce Orders, draft orders, fulfilments, invoices, payment requests and transactions"
        },
        {
          "label": "Webhooks",
          "value": "Yes, events such as Cart Created and Cart Updated, with a documented webhook structure"
        },
        {
          "label": "MCP server",
          "value": "Official, hosted at `https://mcp.wix.com/mcp` (also `/sse`). 18 tools, 11 for docs and schema lookup, plus `ListWixSites`, `GetSiteContext`, `CallWixSiteAPI`, `ExecuteWixAPI`, `ManageWixSite`, `UploadImageToWixSite` and `SupportAndFeedback`. No Stores tools of its own"
        },
        {
          "label": "SDKs",
          "value": "JavaScript only. `@wix/sdk` 1.21.17 and `@wix/stores` 1.0.938, both MIT"
        },
        {
          "label": "Docs for agents",
          "value": "`llms.txt`, `llms-full.txt`, a `.md` twin of every page, Wix Skills (wix/skills, MIT) and a Wix plugin for Claude Code, Cursor, Codex, VS Code and Gemini CLI"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type 2, PCI DSS Level 1 and several ISO certificates per the Wix security page. Bug bounty at bugbounty@wix.com"
        },
        {
          "label": "Status",
          "value": "status.wix.com on Atlassian Statuspage, 119 components. 10 incidents from 10 July to 8 October 2026, three marked critical"
        },
        {
          "label": "Open source",
          "value": "No. The SDK packages and wix/skills are MIT"
        }
      ],
      "provenance": {
        "legalEntity": "Wix.com Ltd.",
        "domain": "wix.com",
        "domainRegistered": "1995-05-12",
        "endpointOnVendorDomain": true,
        "terms": "https://www.wix.com/about/terms-of-use",
        "privacy": "https://www.wix.com/about/privacy",
        "statusPage": "https://status.wix.com",
        "changelog": "https://dev.wix.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Wix Terms of Use name Wix.com Ltd. and its affiliates as the contracting party and give the address 5 Yunitzman St., Tel Aviv, Israel. They cover all Wix Services, and no separate API terms for site owners were found.",
          "The privacy policy states it is effective from 18 June 2026. A data processing addendum for users, effective 1 December 2025, is at https://www.wix.com/about/privacy-dpa-users.",
          "REST calls go to www.wixapis.com, a Wix domain other than wix.com, and the MCP server is at mcp.wix.com.",
          "https://www.wix.com/.well-known/security.txt returns 404. https://www.wix.com/security.txt has a contact (security-report@wix.com) and no Expires field, so it is recorded as none.",
          "RDAP for wix.com gives a registration date of 1995-05-12, before the company was founded in 2006."
        ],
        "score": 84,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Wix.com Ltd.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "wix.com, registered 1995-05-12 (31 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "www.wixapis.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "published, but our reader couldn't read it",
            "points": 7,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "published, but our reader couldn't read it",
            "points": 7,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.wix.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.wix.com/about/terms-of-use",
            "state": "unreadable",
            "reason": "the page shows only the opening sections of the document without a browser, and the rest opens by script",
            "readAt": "2026-10-08",
            "points": 7,
            "max": 10
          },
          {
            "kind": "privacy",
            "url": "https://www.wix.com/about/privacy",
            "state": "unreadable",
            "reason": "the page shows only the opening sections of the document without a browser, and the rest opens by script",
            "readAt": "2026-10-08",
            "points": 7,
            "max": 10
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/wix.json",
      "live": {
        "slug": "wix",
        "probe": {
          "target": "https://www.wixapis.com",
          "method": "get",
          "lastAt": "2026-10-08T22:40:03.44196939Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 225,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 229,
          "p95ms24h": 290,
          "samples24h": 36,
          "samples30d": 36,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 36,
              "ok": 36
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.wix.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T22:39:45.889798127Z"
        },
        "updatedAt": "2026-10-08T22:40:03.44196939Z"
      }
    },
    "verify": {
      "accepts": "a page on wix.com or one of its subdomains, or the README of github.com/wix/wix-mcp",
      "badgeUrl": "https://www.anchorterminal.com/badges/wix.svg",
      "body": {
        "slug": "wix",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/wix",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/wix\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/wix.svg\" alt=\"Wix Stores and eCommerce API on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Wix Stores and eCommerce API on Anchor Terminal](https://www.anchorterminal.com/badges/wix.svg)](https://www.anchorterminal.com/tools/wix)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/wix\"\u003eWix Stores and eCommerce API on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/wix",
    "json": "https://www.anchorterminal.com/tools/wix.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/wix.md",
    "slim": "https://www.anchorterminal.com/tools/wix.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 61.4/100 · rank #364 of 722 · #13 in Commerce \u0026 checkout · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe developer docs are served as Markdown with an llms.txt index, and API keys carry permission scopes and a site restriction. No numeric REST rate limit or OpenAPI file was found, and status.wix.com records a platform-wide incident of 3 hours 17 minutes on 1 August 2026. A person must create the account and the key.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Wix.com Ltd. (https://www.wix.com) |\n| Kind | HTTP API |\n| Category | Commerce \u0026 checkout (https://www.anchorterminal.com/categories/commerce) |\n| Transport | HTTP, Streamable HTTP, SSE (legacy) |\n| Endpoint | `https://www.wixapis.com` |\n| Auth | OAuth or key · Self-serve. An account owner or co-owner creates an API key in the API Keys Manager with permission scopes and a list of sites, then sends it in `Authorization` with `wix-site-id` or `wix-account-id`. Apps use OAuth client credentials, with tokens valid for 4 hours. Headless storefronts get visitor tokens from the `anonymous` grant. The MCP server takes an OAuth login with dynamic client registration, or the API key and `wix-account-id` as headers. |\n| Pricing | Freemium (Freemium) · Plan pricing with no per-call charge. Free plan with no card, then Light, Core, Business and Business Elite, with eCommerce on Core and above. wix.com/plans shows prices in the reader's currency, and our reader was served rupees, so US dollar prices are unconfirmed (checked 2026-10-08). API access needs no contract. |\n| x402 | No · No x402, MPP or L402 in the developer docs corpus or on the plans page (checked 2026-10-08). |\n| Licence | Proprietary service under the Wix Terms of Use. `@wix/sdk`, `@wix/stores` and the wix/skills repository are MIT. `@wix/mcp` states no licence |\n| Tools exposed | 18 |\n| Packages | npm: `@wix/sdk`; npm: `@wix/stores`; npm: `@wix/mcp` |\n| MCP registry name | `com.wix/mcp` |\n| Source | https://github.com/wix/wix-mcp |\n| Docs | https://dev.wix.com/docs/api-reference |\n| llms.txt | https://dev.wix.com/docs/llms.txt |\n| Last release | 2026-10-08 |\n| npm downloads / week | 87,183 |\n| Free tier | Free plan with no card. eCommerce is on Core, Business and Business Elite, each with 50,000 products |\n| Access | Self-serve API key from the API Keys Manager, created by an account owner or co-owner. No partner or sales approval |\n| Auth and scopes | API key with permission scopes and a site access list, long-lived until revoked or rotated. OAuth client credentials for apps, tokens valid 4 hours. Visitor and member tokens for headless storefronts |\n| Rate limits | No numeric REST limit found in the reviewed documentation. A 429 means wait a minute and retry |\n| Catalogue | Stores Catalogue V3 (products, variants, inventory, brands, ribbons, promotions) and the older Catalogue V1. Query Products returns up to 100 a page with cursor paging |\n| Cart and checkout | eCommerce Cart V2 covers cart and checkout in one entity since 5 August 2026. The earlier Cart and Checkout APIs are deprecated and still work |\n| Orders | eCommerce Orders, draft orders, fulfilments, invoices, payment requests and transactions |\n| Webhooks | Yes, events such as Cart Created and Cart Updated, with a documented webhook structure |\n| MCP server | Official, hosted at `https://mcp.wix.com/mcp` (also `/sse`). 18 tools, 11 for docs and schema lookup, plus `ListWixSites`, `GetSiteContext`, `CallWixSiteAPI`, `ExecuteWixAPI`, `ManageWixSite`, `UploadImageToWixSite` and `SupportAndFeedback`. No Stores tools of its own |\n| SDKs | JavaScript only. `@wix/sdk` 1.21.17 and `@wix/stores` 1.0.938, both MIT |\n| Docs for agents | `llms.txt`, `llms-full.txt`, a `.md` twin of every page, Wix Skills (wix/skills, MIT) and a Wix plugin for Claude Code, Cursor, Codex, VS Code and Gemini CLI |\n| Certifications | SOC 2 Type 2, PCI DSS Level 1 and several ISO certificates per the Wix security page. Bug bounty at bugbounty@wix.com |\n| Status | status.wix.com on Atlassian Statuspage, 119 components. 10 incidents from 10 July to 8 October 2026, three marked critical |\n| Open source | No. The SDK packages and wix/skills are MIT |\n| Capabilities | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless |\n| Tags | hosted, closed-source, mcp, oauth, api-key, llms-txt, webhooks, javascript, headless, status-page, bug-bounty, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/wix.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 48 | 9.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 76 | 12.3 |\n| Agent ergonomics | 13% | 16.2 | 68 | 11.1 |\n| Security \u0026 auth | 14% | 17.5 | 61 | 10.7 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 83 | 7.3 |\n| Transparency \u0026 trust (editorial 69, provenance 84) | 7% | 8.8 | 77 | 6.7 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **61.4 → C** |\n\n### Why each score\n\n- Reliability 48: Atlassian Statuspage at status.wix.com with 119 components, Stores and Payments among them, and an incident feed (20). From 10 July to 8 October 2026 the feed holds 10 incidents. Three are marked critical: 1 August, 3 hours 17 minutes across nearly every component including Store Management, Checkout and APIs, 24 July, 47 minutes on sign-in, site loading and checkout, and 15 September, 42 minutes in Europe, with a postmortem. Three marked major lasted 12 to 26 minutes, the latest on 1 October on Store Management, Storefront and Checkout. One outage over an hour plus two shorter critical ones (7). No numeric limit for REST calls was found. The docs publish per-minute quotas only for site data requests and tell callers to space some writes one second apart (3). The 429 guidance is to wait a minute and retry, updates are guarded by revision numbers that return 409, and idempotency keys exist on a few methods only (8). The trust centre FAQ states a service level objective and a 99.99 per cent figure for 2021, with no SLA found (0). The REST APIs are released, and Cart V2 shipped on 5 August 2026 without a preview label (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 76: No public OpenAPI file was found. The contract is the Markdown reference, which the MCP tools `ReadFullDocsMethodSchema` and `SearchWixAPISpec` also serve, and the MCP tools have typed inputs (12). `llms.txt`, `llms-full.txt` and a `.md` twin of every docs page (10). Method pages state purpose and limits, for example that Query Products supports a narrow set of filters and that Search Products is the route for name lookups (15). REST fields carry types, enums and minimum and maximum values, but the MCP's `CallWixSiteAPI` takes a free-form URL, method and body (11). Each method page has a curl example and a list of HTTP and application error codes, and a general errors article documents the error format (13). Versions are per module, and dev.wix.com/changelog is dated (15).\n- Agent ergonomics 68: The MCP lists 18 tools, all on by default, with no toolsets or read-only subset documented. Most calls need a docs lookup first, and the Query Products page alone is 327 KB of Markdown (15). Cursor and offset paging, a query language with filters and sorting, and a `fields` parameter for projection. Query Products returns at most 100 a page (18). Errors use one format with application codes and per-field violations, though system errors are empty by design (16). Revision numbers guard updates, idempotency keys cover a few methods, and the `@wix/mcp` package sets annotations, with `destructiveHint` true on `CallWixSiteAPI` (12). Every site call needs a site ID header, and the only official SDK is JavaScript (7).\n- Security \u0026 auth 61: API keys carry permission scopes and a list of sites they may target, and stay valid until revoked or rotated in the dashboard. App tokens come from OAuth client credentials and last 4 hours. The MCP uses OAuth with dynamic client registration, advertises only `offline_access` as a scope and still accepts the `plain` PKCE method (26). Read and admin scopes are separate (`SCOPE.STORES.PRODUCT_READ` and `SCOPE.STORES.PRODUCT_READ_ADMIN`), but no read-only mode or confirmation step for the MCP was found (11). The API returns merchant and customer content, and no prompt-injection guidance was found. The `@wix/mcp` package limits call URLs to five Wix hostnames (4). No audit log or per-call log for API keys was found in the developer docs. Responses carry `x-wix-request-id` (2). The security page lists SOC 2 Type 2, PCI DSS Level 1 and several ISO certificates and a bug bounty at bugbounty@wix.com. `/security.txt` has a contact but no Expires field, and `/.well-known/security.txt` returns 404 (18).\n- Payments \u0026 pricing 30: No x402, MPP or L402 found (0). Plan prices are public on wix.com/plans but shown in the reader's currency, with nothing per call (10). A free plan, marked no credit card required, with eCommerce on Core and above (20). A person signs up in a browser and creates the API key in the API Keys Manager (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 83: Changelog entries on 8 October 2026, and `@wix/mcp` 1.0.92 published the same day (30). 101 dated changelog entries between 6 July and 8 October 2026 (20). Public changelog, a support site, and the public wix/skills repository with commits on 8 October 2026 (12). The MCP server is in the official registry as `com.wix/mcp`, version 1.0.2 of 22 December 2025, and `@wix/sdk` 1.21.17 is current (15). `@wix/mcp` had 30 releases in 90 days. The server's source and CI are not public, and the package states no licence (6).\n- Transparency \u0026 trust 77: Closed platform under the Wix Terms of Use. `@wix/sdk` and `@wix/stores` are MIT and wix/skills is MIT (15). Privacy policy effective 18 June 2026 and a data processing addendum effective 1 December 2025. Retention is stated as the time reasonably necessary, with no fixed periods found (20). The versioning article says deprecated APIs are marked, logged in the changelog and not removed, and Developer Preview lasts at most 6 months (16). A sub-processor list names Wix entities and third parties with locations, and the security page names AWS, Google Cloud and Equinix as hosts (18).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/wix.md (JSON https://www.anchorterminal.com/fixes/wix.json)\n\n### What we couldn't check\n\n- unchecked: US dollar plan prices. wix.com/plans served rupee prices to our reader (Light 250, Core 500, Business 900 and Business Elite 1,800 rupees a month before a 50 per cent offer). A request with `currency=USD` returned unfilled markup showing 17, 29, 39 and 159, which we did not treat as confirmed.\n- unchecked: the live MCP tool list and schemas. `mcp.wix.com/mcp` answers 401 without a token, so the 18 tools are from the docs and the annotations from the `@wix/mcp` 1.0.92 package.\n- unchecked: GitHub stars, and the full text of the terms of use and privacy policy, whose collapsed sections were not in the HTML we received.\n- No numeric REST rate limit, no OpenAPI file, no SLA and no API audit log were found in the reviewed documentation.\n- Whether a free site can call the Stores APIs before a paid plan is bought was not established.\n- The `@wix/mcp` package builds tool text with a block of instructions addressed to the model, telling it to call `WixREADME` first. Recorded as a fact, with no deduction.\n- The lead's docs URL still resolves, but the MCP article now lives under dev.wix.com/docs/api-reference/articles/ai-tools/wix-mcp. The MCP has no Stores tools of its own. It reaches Stores through the general `CallWixSiteAPI` and `ExecuteWixAPI` tools.\n- Wix WebMCP, for agents in a visitor's browser, was announced in the changelog on 8 October 2026 and is not graded here.\n\n### Sources\n\n- Wix MCP article, tools and configuration: \u003chttps://dev.wix.com/docs/sdk/articles/use-the-wix-mcp/about-the-wix-mcp.md\u003e (seen 2026-10-08)\n- docs index for agents: \u003chttps://dev.wix.com/docs/llms.txt\u003e (seen 2026-10-08)\n- full docs corpus, searched for rate limits, idempotency, OpenAPI and audit logs: \u003chttps://dev.wix.com/docs/llms-full.txt\u003e (seen 2026-10-08)\n- REST API authentication: \u003chttps://dev.wix.com/docs/api-reference/articles/rest-authentication/rest-api-authentication.md\u003e (seen 2026-10-08)\n- authentication methods, API keys and token lifetime: \u003chttps://dev.wix.com/docs/rest/articles/get-started/api-keys.md\u003e (seen 2026-10-08)\n- making calls with an API key: \u003chttps://dev.wix.com/docs/api-reference/articles/authentication/api-keys/make-api-calls-with-an-api-key.md\u003e (seen 2026-10-08)\n- error format: \u003chttps://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/troubleshooting/about-errors.md\u003e (seen 2026-10-08)\n- troubleshooting, 409 and 429: \u003chttps://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/troubleshooting/troubleshooting.md\u003e (seen 2026-10-08)\n- sorting and paging: \u003chttps://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/data-retrieval/about-sorting-and-paging.md\u003e (seen 2026-10-08)\n- versions and deprecation: \u003chttps://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/platform/about-api-versions-and-deprecation.md\u003e (seen 2026-10-08)\n- Developer Preview: \u003chttps://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/platform/about-developer-preview.md\u003e (seen 2026-10-08)\n- Query Products reference: \u003chttps://dev.wix.com/docs/api-reference/business-solutions/stores/catalog-v3/products-v3/query-products.md\u003e (seen 2026-10-08)\n- Stores API menu: \u003chttps://dev.wix.com/docs/api-reference/business-solutions/stores.md\u003e (seen 2026-10-08)\n- eCommerce API menu: \u003chttps://dev.wix.com/docs/api-reference/business-solutions/e-commerce.md\u003e (seen 2026-10-08)\n- Wix plugin and skills: \u003chttps://dev.wix.com/docs/api-reference/articles/ai-tools/about-the-wix-plugin.md\u003e (seen 2026-10-08)\n- developer changelog: \u003chttps://dev.wix.com/changelog\u003e (seen 2026-10-08)\n- status incident feed: \u003chttps://status.wix.com/api/v2/incidents.json\u003e (seen 2026-10-08)\n- MCP OAuth metadata: \u003chttps://mcp.wix.com/.well-known/oauth-authorization-server\u003e (seen 2026-10-08)\n- official MCP registry entry: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=wix\u003e (seen 2026-10-08)\n- @wix/mcp package 1.0.92, tool code and annotations: \u003chttps://registry.npmjs.org/@wix/mcp\u003e (seen 2026-10-08)\n- @wix/sdk package: \u003chttps://registry.npmjs.org/@wix/sdk/latest\u003e (seen 2026-10-08)\n- wix-mcp repository: \u003chttps://github.com/wix/wix-mcp\u003e (seen 2026-10-08)\n- wix/skills repository: \u003chttps://github.com/wix/skills\u003e (seen 2026-10-08)\n- plans and prices: \u003chttps://www.wix.com/plans\u003e (seen 2026-10-08)\n- terms of use: \u003chttps://www.wix.com/about/terms-of-use\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.wix.com/about/privacy\u003e (seen 2026-10-08)\n- data processing addendum: \u003chttps://www.wix.com/about/privacy-dpa-users\u003e (seen 2026-10-08)\n- sub-processor list: \u003chttps://support.wix.com/en/article/list-of-wixs-sub-processors\u003e (seen 2026-10-08)\n- security page: \u003chttps://www.wix.com/trust-center/security\u003e (seen 2026-10-08)\n- trust centre FAQ: \u003chttps://www.wix.com/trust-center/faq\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.wix.com/security.txt\u003e (seen 2026-10-08)\n- reporting a security issue: \u003chttps://support.wix.com/en/article/reporting-a-security-issue\u003e (seen 2026-10-08)\n- domain registration (RDAP): \u003chttps://rdap.verisign.com/com/v1/domain/wix.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 84/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Wix.com Ltd. | 20/20 |\n| Domain age | wix.com, registered 1995-05-12 (31 years) | 15/15 |\n| Endpoint on the vendor's domain | www.wixapis.com | 15/15 |\n| Terms of service | published, but our reader couldn't read it | 7/10 |\n| Privacy policy | published, but our reader couldn't read it | 7/10 |\n| Status page | status.wix.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Wix Terms of Use name Wix.com Ltd. and its affiliates as the contracting party and give the address 5 Yunitzman St., Tel Aviv, Israel. They cover all Wix Services, and no separate API terms for site owners were found.\n\nThe privacy policy states it is effective from 18 June 2026. A data processing addendum for users, effective 1 December 2025, is at https://www.wix.com/about/privacy-dpa-users.\n\nREST calls go to www.wixapis.com, a Wix domain other than wix.com, and the MCP server is at mcp.wix.com.\n\nhttps://www.wix.com/.well-known/security.txt returns 404. https://www.wix.com/security.txt has a contact (security-report@wix.com) and no Expires field, so it is recorded as none.\n\nRDAP for wix.com gives a registration date of 1995-05-12, before the company was founded in 2006.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.wix.com/about/terms-of-use), read 2026-10-08. Our reader couldn't read it (the page shows only the opening sections of the document without a browser, and the rest opens by script).\n\n\n**Privacy policy** (https://www.wix.com/about/privacy), read 2026-10-08. Our reader couldn't read it (the page shows only the opening sections of the document without a browser, and the rest opens by script).\n\n\n## Live (updated 2026-10-08 22:40 UTC)\n\n- Right now: up, HTTP 404, 225 ms, checked 2026-10-08 22:40 UTC (get on `https://www.wixapis.com`)\n- Uptime 24h 100.0% (36 probes) · 30 days 100.0% (36 probes) · p50 229 ms · p95 290 ms\n- Vendor status page: none, All Systems Operational\n- Always current: https://www.anchorterminal.com/api/v1/live/wix.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Every docs page has a Markdown twin (append `.md`), with `llms.txt` and `llms-full.txt` indexes at dev.wix.com/docs\n- API keys combine permission scopes with a per-site access list, and can be revoked or rotated in the dashboard\n- Method pages list permission scopes, field constraints, enums, a curl example and per-method error codes\n- Hosted MCP server at `https://mcp.wix.com/mcp` with OAuth dynamic client registration, listed as `com.wix/mcp` in the official registry\n- Dated developer changelog with 101 entries between 6 July and 8 October 2026, and a policy that deprecated APIs keep working\n\n## Weaknesses\n\n- No numeric rate limit for the REST API was found in the reviewed documentation. The 429 guidance is to wait a minute and retry\n- No public OpenAPI file was found. Schemas are read from the Markdown reference or through the MCP schema tools\n- status.wix.com shows 10 incidents from 10 July to 8 October 2026, three marked critical, the longest 3 hours 17 minutes on 1 August\n- The MCP's `CallWixSiteAPI` takes a free-form URL, method and body, and no read-only mode or confirmation step is documented\n- The only official SDK is JavaScript, and plan prices on wix.com/plans are shown in the reader's local currency\n\n## Before you call it (notes for agents)\n\n1. Send the API key in `Authorization` with `wix-site-id` for site calls or `wix-account-id` for account calls, never both\n2. Fetch the product first and pass `product.revision` on every Catalogue V3 update, or the call fails with 409\n3. Use Cart V2 for new work. The older eCommerce Cart and Checkout APIs were deprecated on 5 August 2026\n4. Request `cursorPaging.limit` of at most 100 on Query Products and use Search Products for lookups by name\n5. Over MCP, read the method page with `ReadFullDocsArticle` before `CallWixSiteAPI`. Responses are cut at 50,000 characters by default\n\n## Connect\n\nInstall:\n\n```bash\nnpm install @wix/sdk @wix/stores\n```\n\nFirst request:\n\n```bash\ncurl -X POST 'https://www.wixapis.com/stores/v3/products/query' \\\n  -H 'Content-Type: application/json' \\\n  -H 'Authorization: \u003cAPI_KEY\u003e' \\\n  -H 'wix-site-id: \u003cSITE_ID\u003e' \\\n  -d '{\"query\": {\"cursorPaging\": {\"limit\": 10}}}'\n```\n\nClaude Code:\n\n```bash\n/plugin marketplace add wix/skills\n/plugin install wix@wix\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"wix-mcp-remote\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.wix.com/mcp\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/wix. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Shopify API + MCP | BB | 75 | 52 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/shopify.md |\n| WooCommerce API + MCP | BB | 72.9 | 84 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/woocommerce.md |\n| Shopware | BB | 71.4 | 112 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/shopware.md |\n| commercetools | BB | 71.3 | 116 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/commercetools.md |\n| Vendure | BB | 70.9 | 123 | commerce.products, commerce.cart, commerce.checkout, commerce.orders, commerce.headless | no | https://www.anchorterminal.com/tools/vendure.md |\n| Square | B | 69.2 | 166 | commerce.products, commerce.orders, commerce.checkout, commerce.cart, commerce.headless | no | https://www.anchorterminal.com/tools/square.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The MCP server reaches Stores through two general tools, `CallWixSiteAPI` for one REST call and `ExecuteWixAPI` for a script that chains or pages calls (source: \u003chttps://dev.wix.com/docs/sdk/articles/use-the-wix-mcp/about-the-wix-mcp.md\u003e)\n- Every docs page has a Markdown version at the same URL plus `.md`, indexed by https://dev.wix.com/docs/llms.txt\n- Cart V2 replaced the eCommerce Cart and Checkout APIs on 5 August 2026 (source: \u003chttps://dev.wix.com/changelog\u003e)\n- Wix says it doesn't remove deprecated APIs (source: \u003chttps://dev.wix.com/docs/api-reference/articles/work-with-wix-apis/platform/about-api-versions-and-deprecation.md\u003e)\n- status.wix.com records a critical incident of 3 hours 17 minutes on 1 August 2026 across nearly every component (source: \u003chttps://stspg.io/6t722nl4gdcp\u003e)\n- The `@wix/mcp` 1.0.92 package builds tool text with a block of instructions addressed to the model, telling it to call `WixREADME` first (source: \u003chttps://registry.npmjs.org/@wix/mcp\u003e)\n- Wix WebMCP, which gives agents in a visitor's browser tools to search, add to the cart and open checkout, was announced on 8 October 2026 (source: \u003chttps://dev.wix.com/changelog\u003e)\n\n## Compare\n\n- [Adobe Commerce (Magento) vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/adobe-commerce-vs-wix.md): B 63.9 vs C 61.4\n- [BigCommerce API + MCP vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/bigcommerce-vs-wix.md): B 64.3 vs C 61.4\n- [Commerce Layer API + MCP vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/commerce-layer-vs-wix.md): B 63.7 vs C 61.4\n- [commercetools vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/commercetools-vs-wix.md): BB 71.3 vs C 61.4\n- [Ecwid by Lightspeed vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/ecwid-vs-wix.md): B 63.2 vs C 61.4\n- [Elastic Path API + MCP vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/elastic-path-vs-wix.md): D 50.1 vs C 61.4\n- [Medusa API + MCP vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/medusa-vs-wix.md): B 63.5 vs C 61.4\n- [Saleor API + MCP vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/saleor-vs-wix.md): B 68.6 vs C 61.4\n- [Shopify API + MCP vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/shopify-vs-wix.md): BB 75 vs C 61.4\n- [Shopware vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/shopware-vs-wix.md): BB 71.4 vs C 61.4\n- [Snipcart API + MCP vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/snipcart-vs-wix.md): E 40.8 vs C 61.4\n- [Square vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/square-vs-wix.md): B 69.2 vs C 61.4\n- [Swell vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/swell-vs-wix.md): C 55 vs C 61.4\n- [Vendure vs Wix Stores and eCommerce API](https://www.anchorterminal.com/compare/vendure-vs-wix.md): BB 70.9 vs C 61.4\n- [Wix Stores and eCommerce API vs WooCommerce API + MCP](https://www.anchorterminal.com/compare/wix-vs-woocommerce.md): C 61.4 vs BB 72.9\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on wix.com or one of its subdomains, or the README of github.com/wix/wix-mcp. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"wix\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/wix\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/wix.svg\" alt=\"Wix Stores and eCommerce API on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Wix Stores and eCommerce API on Anchor Terminal](https://www.anchorterminal.com/badges/wix.svg)](https://www.anchorterminal.com/tools/wix)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/wix\"\u003eWix Stores and eCommerce API on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Wix Stores and eCommerce API is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/wix-dark.png\n- Light: https://www.anchorterminal.com/assets/share/wix-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Commerce \u0026 checkout",
        "url": "https://www.anchorterminal.com/categories/commerce"
      },
      {
        "name": "Wix Stores and eCommerce API",
        "url": ""
      }
    ],
    "description": "Wix is a hosted website and online store platform. Agents reach its Stores and eCommerce data through the REST API at www.wixapis.com, a JavaScript SDK, and a hosted MCP server at mcp.wix.com that searches the docs and calls site APIs.",
    "facts": [
      "rank #364 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Wix Stores and eCommerce API",
    "image": "https://www.anchorterminal.com/assets/og/tools-wix.png",
    "path": "/tools/wix",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Wix Stores and eCommerce API review for AI agents, grade C (61.4/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/wix"
  },
  "tokens": {
    "markdown": 7250,
    "slim": 1780
  },
  "version": 1
}
