Magento 2 Extension Punchout

Magento 2 PunchOut extension for OCI and cXML procurement workflows with buyer login, customer-specific shop access, cart return, and templates for SAP Ariba, Coupa, and Oracle Procurement.

SoftwareSilo PunchOut connects Magento 2 with corporate procurement systems through OCI and cXML. A buyer starts in the purchasing platform, enters your Magento store without a separate manual login, shops in the assigned customer context, and sends the completed cart back for approval and ordering.

A familiar shop for the buyer: The buyer still uses your normal Magento catalog, product pages, search, and cart. PunchOut changes how the session starts and where the cart goes afterward. It does not force buyers to work in a separate catalog interface.

OCI and cXML in one extension: The core module handles OCI login and transfer flows as well as cXML PunchOut setup and cart return. This covers SAP-oriented OCI projects and cXML procurement environments without installing two separate protocol modules.

Prepared profiles for common procurement platforms: The package includes mapping templates for SAP OCI 4 and 5, SAP Ariba, Coupa, Oracle Procurement, and general cXML scenarios. Templates give an implementation team a documented starting point while keeping every field adjustable for the buyer's actual requirements.

Buyer-specific catalog and pricing context: Each buyer profile can be linked to a Magento customer, company, price group, store view, and mapping profile. Once the PunchOut session starts, Magento can apply the catalog visibility and pricing that belong to that customer context. The extension does not maintain a second set of product prices.

Cart return instead of Magento checkout: During an active PunchOut session, the regular checkout action can become a return action. Magento converts the cart into the required OCI form data or cXML PunchOutOrderMessage and sends it back to the buyer system. Approval and purchase-order steps remain in the procurement platform.

Mappings without a separate code branch for every buyer: Admin users can map Magento product, customer, address, and cart values to the fields expected by the procurement system. Required fields, value conversions, formatting rules, and custom target keys are managed in reusable mapping profiles.

Control over product and price data: Magento prices are authoritative by default for cart operations. If a controlled integration requires incoming item prices, that behavior can be enabled explicitly per store configuration. Currency and transfer validation help prevent incomplete or inconsistent carts from being returned.

More than the initial cart handoff: The module provides endpoints for inbound purchase orders and outbound shipment notices and invoices. A document queue can process outbound messages with retry rules, so temporary connection failures do not require every message to be rebuilt manually.

Security tied to each connection: Buyer credentials are stored encrypted. Requests can be checked against allowed IP ranges, signatures, protocol credentials, and transport authentication. Return URLs are validated before Magento sends cart or document data to an external destination.

Tools for testing and support: The admin simulator creates repeatable OCI and cXML requests for integration testing. Trace records connect each step through a correlation identifier and store sanitized payload information, which gives both sides useful evidence when a setup or transfer fails.

Suitable for Magento Open Source and Adobe Commerce projects: SoftwareSilo PunchOut is intended for B2B stores that must connect an existing Magento catalog to customer procurement systems. It is especially useful when several buyers need different credentials, customer contexts, mappings, or return formats and the merchant wants to manage those differences in Magento.

OCI and cXML endpoints

Process Punchout setup and transfer through dedicated OCI and cXML routes for standardized procurement integration.

Buyer profiles in admin

Manage buyer profiles with protocol assignment, active status, and encrypted credentials in one backend workflow.

Context token lifecycle

Control Punchout sessions via token, correlation, and lifecycle states for reproducible runtime behavior.

Tokenized cart API

Use add, update, remove, and get endpoints for external cart operations per Punchout context.

Mapping profiles with transformers

Configure field mapping, required rules, and transformer logic per protocol without partner-specific code forks.

Template-based rollout

Start mapping profiles from templates to accelerate onboarding and reduce setup risk.

Multi-layer security validation

Combine IP checks, signature validation, buyer auth, and hook URL controls for secure endpoint operation.

Idempotency and retry control

Handle repeated requests deterministically to avoid duplicate processing and unstable transfer behavior.

Trace viewer with export

Analyze Punchout traffic using trace listing, detail view, and JSON export with correlation data.

Simulator for integration acceptance

Generate reproducible test requests with signature and cURL output to speed up technical validation.

Standards and integration keywords

Fits SAP OCI scenarios and cXML flows with SAP Ariba, Coupa, and Oracle Procurement, plus buyer-profile governance and mapping control.

  • Current Version1.2.0
  • Compatible with Magento 2.4.6 - 2.4.9
  • Compatible with PHP 8.1 - 8.5

If your environment differs from the listed requirements, we can check compatibility in advance. Please contact us via our contact form.

punchout

Version 1.2.0 - 2026-08-28

Added
  • cXML 1.1 and 1.2 profile discovery with Buyer-specific capabilities and Store View URLs
  • Buyer-specific storefront destinations, including the cart, Store homepage, CMS pages, categories and internal Store paths
  • Line-level cXML order confirmations with accept, reject and backorder decisions, expected delivery dates and targeted CLI commands
  • Filterable and exportable analytics for sessions, cart returns, Magento orders, revenue, Buyer performance and transferred products
Changed
  • Cart transfer, authentication, request decoding and outbound documents use extensible handlers with consistent cXML and OCI behavior
  • Confirmations, ship notices and invoices use a durable queue with endpoint validation, automatic recovery and safe retry and archive actions
  • Inbound orders use Magento's native customer, address, payment, price and tax processing, including recoverable order updates
  • PunchOut administration now has its own top-level menu, with standard grids, actions and operational diagnostics
Fixed
  • cXML Buyer credentials, returned-cart snapshots and outbound documents retain the correct Buyer, Store View and transport identity throughout the order lifecycle
  • cXML and OCI requests and cart returns preserve protocol versions, operations, product identifiers, numeric precision and custom fields
  • Cart and inbound-order processing prevents completed-session changes, cross-customer quote access, duplicate lines and incorrect NET or GROSS tax conversion
  • OCI product-detail and direct-add sessions complete without redirect loops or failed AJAX cart returns
  • Admin line-confirmation delivery dates follow the active locale while outbound protocol dates remain ISO formatted

Version 1.1.0 - 2026-08-18

Added
  • Complete cXML OrderRequest processing with configurable acknowledgement, validation and Magento order creation modes, including customer, product, address, shipping, payment and email policies
  • Returned-cart validation with configurable line matching, price and quantity policies, retained cart snapshots and duplicate-order protection
  • Buyer identity mapping and just-in-time Magento customer creation with Magento's native account confirmation rules
  • OCI 4.0 and 5.0 product detail flows, including direct product pages and OCI 5.0 direct item selection
  • An Admin workspace for inbound orders with filtering, manual review, processing, retry and protected deletion actions
  • Store-view debug logging for PunchOut setup, cart return, inbound orders and document delivery
Changed
  • cXML setup now returns a standard PunchOutSetupResponse and creates an isolated PunchOut cart while preserving and restoring the customer's normal Magento session
  • cXML edit and inspect sessions now rebuild the supplied cart, with inspect remaining read-only and Magento remaining authoritative for prices
  • Customer activation now follows Magento's account lockout, confirmation and global or per-website account-sharing rules
  • Outbound confirmation, shipment and invoice documents now use persistent buyer routing instead of the short-lived browser session and support safe queued delivery and manual handling of uncertain outcomes
  • The Admin simulator now uses a Magento UI form with live request preview and opens the storefront in a separate tab
  • Product and protocol mappings now support Store-view product attributes, OCI-specific identifiers and standard OCI delivery and manufacturer fields
Fixed
  • cXML cart returns now preserve the original BuyerCookie, Store View, customer context and standards-compliant cXML envelope throughout the complete return flow
  • NET and GROSS cart prices now use Magento's completed quote and tax calculation for the active Store View, customer and address
  • Product mapping rules now provide the actual Store-view product attributes and readable option labels
  • Request replay is isolated by PunchOut context and retains the original response status and body for failed requests
  • Invoice and shipment documents now contain consistent cXML totals, order-line references, units of measure and carrier tracking information
  • Sensitive OCI and cXML credentials, BuyerCookie values and Magento form keys are consistently masked in traces and exports

Version 1.0.11 - 2026-08-04

Changed
  • Replaced the module information block with the shared Extension Manager extension
Fixed
  • Fixed Punchout session context creation to reject missing buyer IDs and invalid token expiration configuration instead of persisting fallback values
  • Fixed Punchout session currency and simulator defaults to resolve store/configuration values instead of hardcoded EUR/NET defaults
  • Fixed outbound invoice and queue processing to avoid generating documents with fallback buyer or currency values

Version 1.0.10 - 2026-06-18

Added
  • Added explicit store-scoped options for allowing inbound cart item prices and sandbox-only insecure outbound TLS endpoints
Changed
  • Kept outbound document TLS certificate verification enabled by default
  • Made Magento pricing authoritative for Punchout cart API operations by default
Fixed
  • Fixed admin buyer profile saving so explicitly selected `All Store Views` scope is preserved for global buyer profiles
  • Fixed the admin simulator shop-session launch to avoid false popup-blocked errors when the browser successfully opens the storefront tab
  • Made Punchout return auto-submit pages CSP-compatible for OCI and cXML storefront return flows
  • Improved cXML and hook URL validation for IPv6 endpoints, PunchOutOrderMessage buyer cookies, non-negative transfer prices, and mixed-currency cart returns
  • Improved trace sanitization for sensitive key-value payloads at the end of a trace body

Version 1.0.9 - 2026-06-08

Fixed
  • Fixed OCI buyer authentication to accept uppercase `PASSWORD` and `pwd` request password fields
  • Fixed mapping rule application for customers without custom attributes or addresses
  • Fixed Punchout custom quote item prices to remain locked during Magento total recollection

Version 1.0.8 - 2026-05-19

Fixed
  • Fixed simulator endpoint probing to validate hook URLs with the Punchout hook URL validator and to keep TLS certificate verification enabled
  • Fixed mutating admin Punchout actions to require POST-only routing
  • Fixed Punchout persistence and cleanup table resolution to respect Magento database table prefixes

Version 1.0.7 - 2026-05-08

Fixed
  • Restrict Punchout simulator admin access to the dedicated simulator ACL resource
  • Require POST-only routing for mutating external Punchout cart, session, and document endpoints
  • Resolve global buyer profiles for store-scoped Punchout requests while preferring store-specific buyer profiles

Version 1.0.6 - 2026-04-18

Added
  • Added real outbound ASN and invoice delivery to buyer `hook_url` targets, including generated fallback cXML payloads when no valid raw payload is provided
  • Added queue payload hydration for persisted ASN and invoice jobs so existing queue rows can still be delivered with reconstructed business data
Changed
  • Queue processing now applies batch size configuration per store instead of using one shared global batch window
Fixed
  • cXML return payloads now preserve `edit` and `inspect` operations instead of always returning `operationAllowed="create"`
  • Store-scoped Punchout configuration is now resolved consistently from the active Punchout context for storefront operation policy, trace logging, and checkout return labels
  • OCI buyer authentication now cleanly separates protocol credentials from transport authentication, so request `USER` and `password` are no longer overridden by transport `Authorization: Basic` headers
  • Trace sanitization now masks sensitive JSON and XML payload values such as shared secrets, passwords, and buyer cookies before they are persisted
  • ASN and invoice outbound processing now fails and retries correctly when downstream delivery returns transport-level HTTP errors
  • Invoice and ASN delivery now return explicit delivery failure metadata instead of being marked successful without a real outbound request

Version 1.0.5 - 2026-03-07

Changed
  • Improved admin buyer credential UX for stored OCI and cXML secrets
  • Added explicit change toggles for secret replacement in buyer edit forms

Version 1.0.4 - 2026-03-06

Added
  • Improve admin mapping template loading feedback when template data is invalid
Fixed
  • Resolve Punchout request security against the active context store for cart, transfer, and logout endpoints
  • Compare Punchout context expiration timestamps in UTC to avoid timezone-dependent session handling

Version 1.0.3 - 2026-03-05

Fixed
  • Skip queue processing if Punchout is not enabled on specific store

Version 1.0.2 - 2026-03-02

Fixed
  • Fixed admin mapping profile editing so existing Punchout target keys stay populated after reload instead of appearing empty

Version 1.0.1 - 2026-02-27

Added
  • Admin document queue management with dedicated queue grid/actions and cron processing support
  • Operation policy enforcement for storefront punchout operations and simulator endpoint probing tools
  • Extended mapping/profile administration with reusable template copy flow and richer simulator controls
Fixed
  • Buyer save handling now normalizes nested admin form payloads consistently
  • OCI and cXML transfer endpoints now return explicit HTTP `200` for successful and idempotent replay responses
  • cXML PO cancel processing and integration flow coverage were stabilized

Version 1.0.0 - 2026-02-26

Added
  • Initial release
punchout-iframe

Version 1.0.0 - 2026-08-24

Added
  • Initial release
Module-Specific Questions
What is a Magento 2 PunchOut extension?

A Magento 2 PunchOut extension connects a supplier store with a customer's procurement system. The buyer starts in the procurement platform, enters Magento in an authenticated customer context, fills the cart, and returns that cart for approval instead of completing the regular Magento checkout.

Which PunchOut protocols does SoftwareSilo support?

SoftwareSilo PunchOut supports OCI and cXML in the core extension. Both protocols cover the session entry and cart return process, while their authentication, message structure, and field mappings differ.

Does SoftwareSilo PunchOut work with SAP Ariba?

Yes. SAP Ariba PunchOut is supported through cXML. The extension includes Ariba-oriented templates for setup and cart return, including Level 2 variants. The final mapping should still be checked against the buyer's Ariba configuration.

Can Magento 2 connect to Coupa through PunchOut?

Yes. Coupa connections use cXML setup and PunchOutOrderMessage flows. SoftwareSilo includes Coupa-oriented templates and lets you adjust buyer credentials, field mappings, and return behavior for the actual Coupa account.

Is Oracle Procurement supported?

Yes. The extension includes Oracle-oriented cXML templates for setup and cart return. Because Oracle configurations can differ, the buyer's required identities, fields, and callback behavior should be verified during integration testing.

Is Jaggaer supported out of the box?

The current package does not ship a dedicated Jaggaer template, so we do not describe it as a ready-made integration. A Jaggaer project that uses compatible cXML flows can be assessed and configured through the mapping layer after its exact requirements are known.

What is the difference between OCI and cXML PunchOut?

OCI commonly uses browser form parameters and is widespread in SAP-centered procurement. cXML exchanges structured XML messages and is common with platforms such as SAP Ariba, Coupa, and Oracle Procurement. The buyer's procurement system normally determines which protocol is required.

How does PunchOut cart return work in Magento 2?

During an active PunchOut session, the buyer fills the Magento cart and selects the return action. The extension validates the cart, builds OCI form data or a cXML PunchOutOrderMessage, and sends it to the approved return URL. The procurement system then handles approval and order creation.

How are buyers and credentials managed?

Each connection has a buyer profile with protocol, store scope, identities, credentials, customer context, and mapping assignment. Secrets are stored encrypted. Global profiles and store-specific profiles can be used where several storefronts share the installation.

Can PunchOut buyers see customer-specific catalogs and prices?

Yes, when the buyer profile resolves to the correct Magento customer context. Magento can then apply the catalog visibility and pricing configured for that customer, company, price group, and store. The exact result also depends on the pricing and catalog modules installed in the store.

Can field mappings differ for each procurement customer?

Yes. Mapping profiles can define source fields, target keys, required values, formatting, transformers, and value conversions. Profiles can start from a supplied template and then be adapted without maintaining a separate module fork for every buyer.

Can a procurement system update the Magento cart directly?

The extension provides token-bound endpoints to add, update, remove, and read cart items within a PunchOut session. This supports integrations that need controlled cart synchronization before the buyer returns the final cart.

How are duplicate transfers prevented?

The transfer and document flows support idempotency keys. An exact retry can return the recorded result, while reuse of the same key with different content is treated as a conflict. This reduces duplicate processing after timeouts or network retries.

Which security checks are available?

Connections can use buyer credentials, allowed IP ranges, request signatures, HTTPS return URL validation, and optional transport authentication such as Basic or Bearer credentials. The required combination should be agreed with the procurement partner before go-live.

How can an OCI or cXML connection be tested before go-live?

The Magento admin simulator can create repeatable OCI and cXML requests, show the target endpoint, and provide cURL output. Teams can test login, cart changes, return payloads, authentication failures, and retry behavior before connecting the production buyer account.

How are PunchOut errors investigated?

Trace records show protocol, direction, status, correlation data, and sanitized request information. The shared correlation identifier helps the Magento team and the procurement team follow one transaction across setup, cart, transfer, and document steps.

Does the extension support purchase orders, shipment notices, and invoices?

The module provides an inbound purchase-order endpoint and outbound flows for advance shipping notices and invoices. Outbound documents can run through a queue with configurable batch size, retry limit, and retry delay.

Does PunchOut work with Magento Open Source and Adobe Commerce?

The extension is designed for Magento 2 stores and can be used in Magento Open Source and Adobe Commerce projects. The store's exact Magento version, theme, customer model, pricing modules, and procurement requirements should be reviewed before implementation.

Is an external PunchOut gateway required?

No external gateway is required for the OCI and cXML flows implemented by the extension. It runs in Magento and communicates with the procurement system. A separate gateway can still be used if the project requires services or protocols outside the supported scope.

What information is needed to start a PunchOut project?

Ask the buyer for the required protocol, identities and credentials, login or setup format, return URL, sample requests, required cart fields, currency rules, test account, and acceptance process. For cXML document exchange, also define the required purchase-order, shipment, and invoice messages.

How long does a PunchOut implementation take?

There is no reliable fixed duration. A standard template and responsive test partner can shorten the project, while custom mappings, security reviews, customer-specific pricing, or additional document messages add work. The estimate should follow a review of real sample payloads.

Can guests use a PunchOut connection?

PunchOut is built around an authenticated buyer relationship, not an anonymous guest session. The procurement request identifies the buyer profile and establishes the customer context used in Magento.

Which price is used when the procurement system sends item prices?

Magento pricing is authoritative by default. Incoming item prices are ignored unless the store explicitly enables them for a controlled integration. This avoids allowing an external cart request to replace Magento prices unintentionally.

Can one Magento installation serve several PunchOut buyers?

Yes. Buyer profiles separate credentials, protocol, store scope, customer context, and mapping assignment. This allows several procurement customers to use the same Magento installation without forcing them to share one connection configuration.

General Questions
How many Magento installations is the license valid for?

The license is valid for one Magento installation, including multi-website operation. In addition, the module may be installed on any number of development or staging servers. You can find further details in our license terms.

Is installation included in the price?

Installation and configuration are not included in the price. On request, we can support you with a smooth integration into your system.

How do I install a module?

Composer is PHP's package manager, and Magento 2 uses it to install modules and their dependencies. After purchase, the commands for your module are available under Licenses in your customer account. First add the private SoftwareSilo repository and your license token. Then install the listed package with composer require and run php bin/magento setup:upgrade and php bin/magento cache:clean.

What payment methods are available?

You can pay by credit card (Stripe) or bank transfer (prepayment). For credit card payments, the order is processed immediately and the access credentials are provided directly in a separate follow-up email.

What does the order process look like?

After credit card payment, you immediately receive access credentials to obtain the module via Composer. For bank transfer, access is granted once the invoice is paid.

I need a custom modification of the module. Is that possible?

Custom requests are no problem. We tailor our Magento 2 modules to your project and maintain a dedicated internal version so we always know exactly what runs on your system for support.

Can I install a demo version locally?

On each module detail page, you can request your own demo instance and test the module intensively for 7 days. However, we do not provide a local demo version.

Is the source code encrypted?

No, the source code of our modules is not encrypted. If you need a customization, feel free to send us a request. We will get back to you promptly with a non-binding quote.

What is the update policy and support?

You can add a support package to your order. It includes assistance as well as updates and upgrades related to the module. No continuous subscription is required.

I already have a license. How can I perform an update?

You can complete the license update here. If you have an active support package, you receive updates automatically via Composer. If your support package has expired, you can renew your license here or in your account.

I have another question — how can I contact you?

You can reach us anytime via eMail.

Punchout

×

Ideal for these industries & use cases

ERP and procurement integration

Connect procurement systems via OCI or cXML directly to your Magento 2 catalog and cart.

Buyer-specific Punchout flows

Control access, profile settings, and field mapping per buyer for clean integration ownership.

Retry-safe integrations

Stabilize transfers under network issues with idempotent request processing.

Multiple partners with dedicated mappings

Maintain partner-specific field rules per protocol without parallel code branches.

Support and incident analysis with trace

Resolve integration issues faster using correlation, trace details, and export data.

Technical validation before go-live

Validate endpoints and payload behavior through the admin simulator before production rollout.

Try before you buy

Request a personal demo and test the module with realistic sample data in Magento Admin and the storefront. Take your time to see whether it fits your requirements and workflows.

Technical documentation

Practical Magento 2 guides, developer documentation, and API references for installation, configuration, and troubleshooting.

Go to Knowledge Base

Do you need a custom solution?

Do your requirements go beyond the capabilities of our Magento 2 modules? We develop suitable Magento 2 modules and integrations for your business processes.

Request now