UK software developers since 2006 · fixed-price quotes · you own the code01623 650333 · info@dijitul.uk
Free chat

Punch-out Catalogue Integration UK: OCI and cXML

dijitul developments builds punch-out catalogue integrations for UK suppliers, so corporate buyers can shop your website from inside SAP, Ariba, Coupa, Jaggaer or other procurement systems and return the basket for approval. We support SAP OCI and cXML, having built an OCI-compliant VirtueMart for Joomla years ago. Every project is a fixed-price quote after a free chat.

Updated 2026-10-10 · by the dijitul development team, Mansfield, UK

  • SAP OCI
  • cXML
  • SAP Ariba
  • Coupa
  • PHP 8
  • Laravel
  • XML

Sound familiar?

  • A large customer says you must offer punch-out to stay on their approved supplier list
  • Buyers phone or email orders because your website isn't connected to their procurement system
  • Your ecommerce platform's punch-out plugin doesn't support the buyer's system
  • Each corporate customer needs different prices and product ranges
  • Purchase orders arrive as PDFs and are keyed into your system by hand
  • You've been sent a cXML or OCI specification and don't know where to start

Key facts

  • We built OCI-compliant VirtueMart for Joomla, a punch-out catalogue for large companies' procurement systems
  • SAP OCI (Open Catalog Interface) returns the basket as HTML form fields posted to the buyer's HOOK_URL
  • cXML punch-out uses XML messages: PunchOutSetupRequest, then PunchOutOrderMessage back to the buyer
  • OCI is common with SAP SRM and S/4HANA buyers; cXML is used by SAP Ariba, Coupa and many other platforms
  • Each buying organisation gets its own credentials, price list and catalogue rules
  • Purchase orders can come back by cXML OrderRequest, email or EDI and flow into your order system
  • Buyers see contract prices and only the products they're allowed to buy

What punch-out is and why buyers ask for it

Large organisations don't let staff buy with a credit card on any website. Purchases go through a procurement system that enforces approvals, budgets and approved suppliers. Punch-out lets a buyer click your catalogue from inside that system, browse your live site with their own prices, fill a basket, and then send that basket back to the procurement system instead of checking out. Their approval workflow runs, and a purchase order is issued to you.

For suppliers to corporate, public sector or education buyers, punch-out is often a condition of staying on the approved list. We've built this before: our OCI-compliant VirtueMart for Joomla let large companies' procurement systems punch out to a Joomla shop. Today we build it for most ecommerce platforms and bespoke B2B portals.

OCI and cXML: the two main standards

SAP OCIcXML punch-out
OriginSAP's Open Catalog InterfaceOpen XML standard from cxml.org
Typical buyersSAP SRM and S/4HANASAP Ariba, Coupa, Jaggaer and many others
Session startBrowser opens your URL with login parameters and a HOOK_URLServer-to-server PunchOutSetupRequest with a shared secret; you return a StartPage URL
Basket returnHTML form posted to the HOOK_URL with fields such as NEW_ITEM-DESCRIPTION[n], NEW_ITEM-QUANTITY[n], NEW_ITEM-PRICE[n]PunchOutOrderMessage XML posted back through the browser
Purchase orderUsually separate: email, EDI or IDocOften a cXML OrderRequest

OCI exists in versions 4.0 and 5.0, and buyers' SAP teams usually send a field list showing exactly what they expect, including unit of measure codes, material groups and vendor part numbers. We build to the buyer's specification rather than guessing.

How we build it

  • Session handling: we authenticate the punch-out request, start a dedicated shop session for that buyer, and hide normal checkout so the only exit is "transfer basket".
  • Customer rules: each buying organisation has its own credentials, shared secret, price list, product range and field mappings, managed from an admin screen.
  • Field mapping: product codes, units of measure (UN/CEFACT codes are common), classification codes such as UNSPSC where requested, VAT and lead times mapped exactly.
  • Order receipt: when the PO arrives, by cXML OrderRequest, email or EDI file, we parse it, match it to the original basket and create the order in your system, which can link into your ERP.
  • Logging: every setup request, basket transfer and PO is logged so problems can be traced with the buyer's IT team.

Testing with the buyer

Punch-out projects involve the customer's procurement team as well as yours, so most of the elapsed time is coordination. We prepare a test environment, supply the URLs, identities and shared secrets the buyer needs, and work through their test scripts with them. Typical issues are mismatched units of measure, prices with too many decimal places, or classification codes the buyer's system rejects, and we fix those quickly because we built the mapping ourselves.

Once the first buyer is live, adding the next is usually configuration rather than code.

Sessions, iframes and security

Punch-out has some quirks ordinary ecommerce doesn't. Many procurement systems open the supplier site inside an iframe, which means your session cookie is a third-party cookie from the browser's point of view. We set cookies with SameSite=None; Secure where the buyer's system needs it, or pass a session token in the URL where browsers block third-party cookies entirely, and test in the browsers the buyer's staff actually use.

Each buying organisation has its own identity and shared secret, stored encrypted and rotatable. Punch-out sessions expire after a sensible period, payment steps are removed, and buyers can never see another organisation's prices. Every incoming request is checked against the expected sender, and we log enough detail to diagnose a failed transfer without storing more personal data than needed.

Platforms we work with

We add punch-out to WooCommerce, Magento, OpenCart, PrestaShop and bespoke B2B portals, and can build a dedicated punch-out catalogue alongside your main site if your platform makes it awkward. For trade portals in general see customer portal development and software for wholesalers. Every project is quoted at a fixed price after a free chat, once we've seen the buyer's specification. Get in touch.

What we deliver

  • OCI punch-out endpoint with HOOK_URL return and NEW_ITEM field mapping
  • cXML punch-out: PunchOutSetupRequest handling, session login and PunchOutOrderMessage
  • Per-customer credentials, shared secrets and catalogue restrictions
  • Contract pricing and product visibility per buying organisation
  • Purchase order receipt (cXML OrderRequest or other formats) into your order system
  • Test support with the buyer's procurement team through to go-live
  • Admin screens to onboard new punch-out customers without code changes

How it works and what it costs

Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data.

  1. Free chat

    Tell us the problem in plain English: what you do now, what goes wrong and what "better" looks like. No charge, no obligation.

  2. Scoping

    We map the processes, systems and data involved, agree what is in and out, and write it down so there are no surprises.

  3. Fixed-price quote

    You get a fixed price for the agreed scope, or a phased plan for bigger builds, so you can start small and prove it works.

  4. Build and test

    We build in short stages you can see and try, test against real data, then go live carefully with a rollback plan.

  5. Hand over and look after

    You own the code and the data. We can host it, support it and keep improving it, or hand it to your own team.

Frequently asked questions

What is a punch-out catalogue?

A punch-out catalogue lets a buyer open your website from inside their procurement system, shop with their agreed prices, and send the basket back for internal approval instead of paying online. A purchase order then comes to you. dijitul builds these using OCI or cXML.

What's the difference between OCI and cXML punch-out?

OCI is SAP's interface: the basket returns as HTML form fields posted to the buyer's HOOK_URL. cXML is an XML standard used by Ariba, Coupa and others, with a PunchOutSetupRequest to start and a PunchOutOrderMessage to return the basket.

Has dijitul built punch-out before?

Yes. dijitul built an OCI-compliant version of VirtueMart for Joomla, letting large companies' procurement systems punch out to a Joomla shop. We now build OCI and cXML punch-out for other platforms and bespoke B2B portals.

Can each corporate customer have different prices?

Yes. Each buying organisation gets its own credentials, price list, product range and field mappings, managed from an admin screen, so you can onboard new punch-out customers without code changes.

Can purchase orders go straight into our system?

Yes. dijitul can receive cXML OrderRequest documents, parse emailed or EDI purchase orders, match them to the punch-out basket and create the order in your shop or ERP automatically, with no rekeying.

What do we need from the buyer to get started?

Their punch-out specification: protocol (OCI or cXML), version, required fields, test credentials and any classification or unit of measure codes. dijitul uses that to scope the work and give a fixed-price quote.

Related

Tell us what you need to build

Free chat, clear scope, fixed-price quote. You own everything we build.

Call usFree chat