RXed AI News

AI to the bone.
SCORE 6/10 10/10 criteria · Capable, with friction Assessed 2026-08-19 · ARI rubric v1.0

Lightspeed — can an agent use it?

Visit lightspeedhq.com
“Cloud POS and commerce platform for retail, restaurant, and golf businesses, serving shops, cafes, and restaurants across North America and Europe.” — the vendor’s own words

Lightspeed has strong, well-documented REST APIs with OAuth 2.0 and published rate limits — solid infrastructure for programmatic access. But the Acceptable Use Policy explicitly prohibits 'bots and unapproved automation,' creating a legal contradiction with the developer-friendly API surface. No official MCP server exists. The cheapest upgrade: clarify in the AUP that API-authorized integrations are approved automation, removing the ambiguity that makes compliance counsel nervous.

Category
Retail POS
Agent protocol
Agent payment rails
None published
Site Scan
C (72/100) · crawl-level, 19/08
Sf7
Machine-readable surface
Iq6.5
Information retrieval quality
Dx7.5
Documentation for machines
Ac7
Action coverage
Pt3
Agent protocol support
Au7
Access & auth friction
Py1.5
Agent payment capability
Cf6
Cost & rate fairness
Ts3.5
Permission & ToS stance
Rl7
Reliability & continuity
Tap or hover any criterion to see why it scored that.
FIND & RETRIEVE7.0/10Can an agent get correct information?

Machine-readable surface7/10

Server-side rendered HTML with 1,611 words visible without JS. Valid sitemap index referencing 8 sub-sitemaps (main, blog, integrations, careers, verticals, customers, resources, news). Schema.org JSON-LD present (WebSite, ContactPoint). robots.txt is permissive — no AI-specific blocks, only /rest/, /wp-admin/, /ecommerce/store/ disallowed. No llms.txt, no RSS/JSON feed, no markdown negotiation. Multiple H1 tags (7) is a minor semantic issue. source

Information retrieval quality6.5/10

Pricing page publishes three retail tiers ($89/$149/$289 per month, annual billing saves up to 18%) with feature comparison matrix visible without JS. Per-vertical landing pages describe capabilities in detail. However, restaurant and golf pricing require 'Contact sales' or 'Request a quote.' API access is listed as a Plus-tier feature but the API pricing itself (if any surcharge) is not stated. Hardware pricing absent. source

Documentation for machines7.5/10

Developer portal at developers.lightspeedhq.com lists 9 separate APIs across 4 product lines. X-Series API has full REST documentation with OAuth 2.0 guide, Postman collection, PHP SDK, and webhooks. Rate limit headers documented (X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset). Scopes reference available (products:read, sales:read, customers:read). R-Series and K-Series each have their own documentation portals. Missing: no unified changelog across APIs, no error taxonomy document. source

ACT & TRANSACT4.9/10Can an agent do the job?

Action coverage7/10

X-Series API covers core retail actions: products, inventory, sales, customers, purchase orders, vendors, employees, registers, outlets, promotions, and reporting. Community MCP server (BusyBee3333) maps 77 tools across these domains, confirming broad endpoint coverage. Restaurant K-Series covers menus, tickets, payments, kitchen routing. A reported third-party assessment (Supergood.ai) grades overall API coverage as 'GOOD.' Some advanced features (AI Showroom, AI Blogs, Workforce & Payroll) appear UI-only. source

Agent protocol support3/10

No official MCP server from Lightspeed. Not in the official MCP registry at github.com/modelcontextprotocol/servers. No .well-known/mcp.json or .well-known/skills. A community-built MCP server exists (BusyBee3333/lightspeed-mcp-2026-complete, 77 tools covering Retail R-Series and Restaurant K-Series via OAuth 2.0) — but it is third-party, unendorsed, and part of a batch project covering 40+ platforms. Zapier and viaSocket offer indirect MCP surfaces wrapping the API. source

Access & auth friction7/10

Self-serve developer account registration. OAuth 2.0 Authorization Code Grant with client_id/client_secret generated in the developer dashboard. Personal tokens available as an alternative for single-store scenarios (Plus plan only). Scoped permissions (mandatory since March 2026). Unapproved apps connect to max 30 stores; production public apps require approval. No enterprise gate for basic API access — a developer can start building within minutes. source

Agent payment capability1.5/10

Lightspeed is a paid SaaS ($89-$289/month for retail alone). No support for any agent payment protocol (ACP, AP2, MPP, x402). Subscription payment is via standard web checkout only. Lightspeed Payments processes merchant transactions but there is no programmatic checkout path for an agent to subscribe to or pay for Lightspeed itself on behalf of a merchant. source

Cost & rate fairness6/10

API access included in paid plans (no separate API tier pricing). Rate limits are documented and reasonable: leaky-bucket model with 60-unit burst capacity and 1 req/sec refill rate, scoped per account. K-Series allows 180 requests/minute. Rate limit headers in every response allow agents to self-throttle. No evidence of agent-vs-human price discrimination on the API. However, the base subscription cost ($89-$289/mo) is not trivial for micro-merchants, and some API features require higher tiers. source

TRUST & DURABILITY5.2/10Will it still work next quarter?

Permission & ToS stance3.5/10

The Acceptable Use Policy explicitly states: 'Customer must not use Products in a way that could damage, disable, overburden, impair, descramble or compromise or circumvent our systems or security... This includes the use of bots to access and use Products as well as other unapproved automation.' The API developer agreement separately permits building apps that 'extend functionality,' but the AUP's blanket bot prohibition creates legal ambiguity — an AI agent operating via the sanctioned API could still be classified as an 'unapproved bot.' robots.txt has no AI-specific blocks. AI Terms additionally prohibit circumventing 'rate limits, filters, or access restrictions.' The contradiction between 'here is our API' and 'bots are banned' is exactly the finding this index exists to surface. source

Reliability & continuity7/10

Public status page (Atlassian StatusPage) at status.lightspeedhq.com with per-product component monitoring, incident history, and subscriber notifications (email, SMS, webhook, RSS/Atom). Active incident management visible (e.g., O-Series printer issue 18/08/2026 with detailed updates). X-Series OAuth timeline published for 2026 (scopes mandatory March 31). Multiple API versions across product lines suggest backward compatibility is maintained. No evidence of sudden endpoint sunsetting, though the API License Agreement reserves the right to 'discontinue the API at any time.' source

Sources

Point-in-time assessment — services change terms, prices and APIs often. That volatility is itself scored under Reliability & continuity. Re-verified at least quarterly.