Skip to content
Web Development

B2B Punchout Catalogs: How Punchout Works With Procurement Systems

How B2B punchout catalogs work: procurement systems, cXML and OCI, authentication, the shopping session, cart transfer, purchase orders and integration architecture.

Quick answer

Punchout lets a buyer inside a procurement system shop on a supplier's site and return the cart to procurement for approval. With cXML, the procurement system sends a PunchOutSetupRequest; the supplier returns a start URL; the buyer shops with their account's catalog and prices; the supplier posts a PunchOutOrderMessage back to the return URL; and the approved order later arrives as an OrderRequest. SAP OCI follows a similar roundtrip using a HOOK_URL. The purchase order, not the returned cart, creates the sales order.

Where This Fits

Punchout is one channel in a B2B platform; see B2B platform architecture. Catalog entitlements are covered in customer-specific catalogs and general integration patterns in API integration and B2B ERP integration.

Why Buyers Use Punchout

Large organizations control purchasing through procurement systems: approved suppliers, budgets, approvals, purchase orders and invoice matching. Punchout gives their buyers the supplier's live catalog, search and configuration while keeping purchasing inside those controls. For suppliers, it is often a requirement to sell to such customers.

cXML Punchout Flow

StepDocument or actionNotes
1. SetupPunchOutSetupRequest from procurementCredentials, buyer identity, BrowserFormPost URL, optional user details
2. ResponsePunchOutSetupResponse with StartPage URLSupplier authenticates and creates a session
3. ShopBuyer browses supplier siteCustomer catalog, prices and rules apply
4. Return cartPunchOutOrderMessage posted to BrowserFormPost URLSent as a hidden form field via the buyer's browser
5. ApproveInside procurement systemBudgets, approvals, PO creation
6. OrderOrderRequest to supplierCreates the sales order; supplier acknowledges

Worth noting

Field names and versions follow the cXML specification published at cxml.org; each procurement platform also documents its own requirements. Test against each buyer's configuration.

SAP OCI Roundtrip

With SAP's Open Catalog Interface, the procurement system opens the supplier catalog URL with parameters including a HOOK_URL (the return address) and agreed login parameters. When the buyer transfers the cart, the supplier's site posts line item fields (such as description, quantity, unit, price, currency and supplier part number) to the HOOK_URL. OCI covers the catalog and cart roundtrip only; the purchase order is transmitted separately.

Authentication and Session

The setup request carries credentials (in cXML, identities and a shared secret) that the supplier validates and maps to a customer account and, where provided, a user. The buyer usually does not log in separately. Sessions should apply the account's catalog, prices and rules, restrict actions that do not belong in punchout (such as direct checkout or account changes), and handle timeouts gracefully.

A key customer asking for punchout?

ZSpace can build cXML or OCI punchout on your B2B platform, map it to customer catalogs and prices and support testing with each buyer.

Start a Project

The Shopping Experience

  • Customer-specific catalog and prices from the start
  • Search, filters and configuration as on the normal site
  • Cart shows 'Return to procurement' instead of checkout
  • Clear indication of the session and buyer organization
  • Support for edit and inspect operations where the buyer's system uses them

Cart Transfer Data

FieldWhy it matters
Supplier part numberIdentifies the item on the PO
DescriptionShown to approvers
Quantity and unit of measureMust match buyer's units (UOM mapping)
Unit price and currencyBecomes the PO price
Classification (e.g. UNSPSC)Required by many buyers for spend analysis
Lead time or delivery dateOptional, for planning
Custom fieldsAgreed per buyer

Order Processing

The approved purchase order arrives as a cXML OrderRequest, EDI message or another agreed format. Validate it against the original cart and current prices, create the sales order in the commerce platform or ERP, send an acknowledgement and handle mismatches (price changes, quantity changes) according to agreed rules. Later documents such as ship notices and invoices may also be exchanged electronically.

Integration Architecture

A punchout layer sits between procurement systems and the commerce platform: an endpoint for setup requests, credential and account mapping, session creation in the storefront, cart serialization to cXML or OCI fields, and an order intake endpoint that turns OrderRequests into sales orders. Some suppliers build it themselves; others use specialist punchout connectors. Log every message for troubleshooting.

Testing and Onboarding

  • Test each buyer's configuration end to end
  • Validate UOM, classification and custom field mapping
  • Test edit and inspect sessions where used
  • Compare PO prices with cart prices
  • Agree support contacts and escalation
  • Document each buyer's setup

Worked Example

An illustrative scenario, not a client case: a laboratory supplier wins a contract that requires cXML punchout. The first integration works, but the buyer rejects carts because units of measure and UNSPSC codes are missing. The team adds UOM mapping and classification codes to product data, tests the full cycle including OrderRequest intake with the buyer's procurement team, and documents the configuration so the next customer can be onboarded faster.

Implementation Steps

  • Confirm the buyer's protocol (cXML or OCI) and requirements
  • Map credentials to customer accounts and catalogs
  • Build setup, session and cart return
  • Add UOM, classification and custom fields
  • Build order intake and acknowledgement
  • Test end to end with the buyer and document

Common Mistakes

  • Creating orders from the punchout cart instead of the PO
  • Missing UOM or classification mappings
  • Showing list prices instead of contract prices
  • Allowing normal checkout during a punchout session
  • No message logging
  • Assuming every buyer's cXML setup is identical

Ready to support procurement-led customers?

Talk to ZSpace about punchout and B2B integration, order intake automation and B2B commerce builds.

Start a Project

Conclusion

Punchout connects a supplier's catalog to buyers' procurement controls: authenticate the session, apply the customer's catalog, return a well-formed cart and create orders from the purchase order. Related: B2B platform architecture and API integration.

FAQ

Common questions

A way for a buyer working inside their organization's procurement system to open a supplier's online store, shop with their negotiated catalog and prices, and send the cart back into the procurement system for approval and purchase order creation.

Get in touch

Have a project in mind?

Whether you're building a new digital product, improving an existing website, or looking to automate part of your business — let's talk.