# Punch-out Catalogue Integration UK: OCI and cXML

Source: https://dijituldevelopments.co.uk/punchout-oci-integration/
Updated: 2026-10-10

> dijitul developments builds punch-out catalogue integrations for UK suppliers, so corporate buyers can shop your website from inside SAP, Ariba, Coupa, Jaggaer or other procurement systems and return the basket for approval. We support SAP OCI and cXML, having built an OCI-compliant VirtueMart for Joomla years ago. Every project is a fixed-price quote after a free chat.

## Problems this solves

- A large customer says you must offer punch-out to stay on their approved supplier list
- Buyers phone or email orders because your website isn't connected to their procurement system
- Your ecommerce platform's punch-out plugin doesn't support the buyer's system
- Each corporate customer needs different prices and product ranges
- Purchase orders arrive as PDFs and are keyed into your system by hand
- You've been sent a cXML or OCI specification and don't know where to start

## Key facts

- We built OCI-compliant VirtueMart for Joomla, a punch-out catalogue for large companies' procurement systems
- SAP OCI (Open Catalog Interface) returns the basket as HTML form fields posted to the buyer's HOOK_URL
- cXML punch-out uses XML messages: PunchOutSetupRequest, then PunchOutOrderMessage back to the buyer
- OCI is common with SAP SRM and S/4HANA buyers; cXML is used by SAP Ariba, Coupa and many other platforms
- Each buying organisation gets its own credentials, price list and catalogue rules
- Purchase orders can come back by cXML OrderRequest, email or EDI and flow into your order system
- Buyers see contract prices and only the products they're allowed to buy

## What punch-out is and why buyers ask for it

Large organisations don't let staff buy with a credit card on any website. Purchases go through a procurement system that enforces approvals, budgets and approved suppliers. Punch-out lets a buyer click your catalogue from inside that system, browse your live site with their own prices, fill a basket, and then send that basket back to the procurement system instead of checking out. Their approval workflow runs, and a purchase order is issued to you.

For suppliers to corporate, public sector or education buyers, punch-out is often a condition of staying on the approved list. We've built this before: our OCI-compliant VirtueMart for Joomla let large companies' procurement systems punch out to a Joomla shop. Today we build it for most ecommerce platforms and bespoke B2B portals.

## OCI and cXML: the two main standards

| | SAP OCI | cXML punch-out |

| Origin | SAP's Open Catalog Interface | Open XML standard from cxml.org |
| Typical buyers | SAP SRM and S/4HANA | SAP Ariba, Coupa, Jaggaer and many others |
| Session start | Browser opens your URL with login parameters and a `HOOK_URL` | Server-to-server `PunchOutSetupRequest` with a shared secret; you return a `StartPage` URL |
| Basket return | HTML form posted to the `HOOK_URL` with fields such as `NEW_ITEM-DESCRIPTION[n]`, `NEW_ITEM-QUANTITY[n]`, `NEW_ITEM-PRICE[n]` | `PunchOutOrderMessage` XML posted back through the browser |
| Purchase order | Usually separate: email, EDI or IDoc | Often a cXML `OrderRequest` |

OCI exists in versions 4.0 and 5.0, and buyers' SAP teams usually send a field list showing exactly what they expect, including unit of measure codes, material groups and vendor part numbers. We build to the buyer's specification rather than guessing.

## How we build it

- **Session handling:** we authenticate the punch-out request, start a dedicated shop session for that buyer, and hide normal checkout so the only exit is "transfer basket".
- **Customer rules:** each buying organisation has its own credentials, shared secret, price list, product range and field mappings, managed from an admin screen.
- **Field mapping:** product codes, units of measure (UN/CEFACT codes are common), classification codes such as UNSPSC where requested, VAT and lead times mapped exactly.
- **Order receipt:** when the PO arrives, by cXML `OrderRequest`, email or EDI file, we parse it, match it to the original basket and create the order in your system, which can link into [your ERP](https://dijituldevelopments.co.uk/ecommerce-erp-integration/).
- **Logging:** every setup request, basket transfer and PO is logged so problems can be traced with the buyer's IT team.

## Testing with the buyer

Punch-out projects involve the customer's procurement team as well as yours, so most of the elapsed time is coordination. We prepare a test environment, supply the URLs, identities and shared secrets the buyer needs, and work through their test scripts with them. Typical issues are mismatched units of measure, prices with too many decimal places, or classification codes the buyer's system rejects, and we fix those quickly because we built the mapping ourselves.

Once the first buyer is live, adding the next is usually configuration rather than code.

## Sessions, iframes and security

Punch-out has some quirks ordinary ecommerce doesn't. Many procurement systems open the supplier site inside an iframe, which means your session cookie is a third-party cookie from the browser's point of view. We set cookies with `SameSite=None; Secure` where the buyer's system needs it, or pass a session token in the URL where browsers block third-party cookies entirely, and test in the browsers the buyer's staff actually use.

Each buying organisation has its own identity and shared secret, stored encrypted and rotatable. Punch-out sessions expire after a sensible period, payment steps are removed, and buyers can never see another organisation's prices. Every incoming request is checked against the expected sender, and we log enough detail to diagnose a failed transfer without storing more personal data than needed.

## Platforms we work with

We add punch-out to WooCommerce, Magento, OpenCart, PrestaShop and bespoke B2B portals, and can build a dedicated punch-out catalogue alongside your main site if your platform makes it awkward. For trade portals in general see [customer portal development](https://dijituldevelopments.co.uk/customer-portal-development/) and [software for wholesalers](https://dijituldevelopments.co.uk/software-for-wholesalers/). Every project is quoted at a fixed price after a free chat, once we've seen the buyer's specification. [Get in touch](https://dijituldevelopments.co.uk/contact/).

## What we deliver

- OCI punch-out endpoint with HOOK_URL return and NEW_ITEM field mapping
- cXML punch-out: PunchOutSetupRequest handling, session login and PunchOutOrderMessage
- Per-customer credentials, shared secrets and catalogue restrictions
- Contract pricing and product visibility per buying organisation
- Purchase order receipt (cXML OrderRequest or other formats) into your order system
- Test support with the buyer's procurement team through to go-live
- Admin screens to onboard new punch-out customers without code changes

Technologies: SAP OCI, cXML, SAP Ariba, Coupa, PHP 8, Laravel, XML

## FAQs

### What is a punch-out catalogue?

A punch-out catalogue lets a buyer open your website from inside their procurement system, shop with their agreed prices, and send the basket back for internal approval instead of paying online. A purchase order then comes to you. dijitul builds these using OCI or cXML.

### What's the difference between OCI and cXML punch-out?

OCI is SAP's interface: the basket returns as HTML form fields posted to the buyer's HOOK_URL. cXML is an XML standard used by Ariba, Coupa and others, with a PunchOutSetupRequest to start and a PunchOutOrderMessage to return the basket.

### Has dijitul built punch-out before?

Yes. dijitul built an OCI-compliant version of VirtueMart for Joomla, letting large companies' procurement systems punch out to a Joomla shop. We now build OCI and cXML punch-out for other platforms and bespoke B2B portals.

### Can each corporate customer have different prices?

Yes. Each buying organisation gets its own credentials, price list, product range and field mappings, managed from an admin screen, so you can onboard new punch-out customers without code changes.

### Can purchase orders go straight into our system?

Yes. dijitul can receive cXML OrderRequest documents, parse emailed or EDI purchase orders, match them to the punch-out basket and create the order in your shop or ERP automatically, with no rekeying.

### What do we need from the buyer to get started?

Their punch-out specification: protocol (OCI or cXML), version, required fields, test credentials and any classification or unit of measure codes. dijitul uses that to scope the work and give a fixed-price quote.

## Pricing and contact

Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data. Book a free chat: https://dijituldevelopments.co.uk/contact/ · 01623 650333 · info@dijitul.uk
