SHOPIFY × SAP ARIBA
Ariba punchout for your Shopify store
Your biggest customer wants to order through SAP Ariba. Keep them ordering from your Shopify catalog at contract prices, without rebuilding anything.
<cXML payloadID="20260806.1@buyer.example.com">
<Request deploymentMode="production">
<PunchOutSetupRequest operation="create">
<BuyerCookie>7f2c-buyer-session</BuyerCookie>
<Extrinsic name="UserEmail">jane@buyer.example.com</Extrinsic>
<BrowserFormPost>
<URL>https://buyer.example.com/punchout/return</URL>
</BrowserFormPost>
</PunchOutSetupRequest>
</Request>
</cXML><PunchOutOrderMessage>
<BuyerCookie>7f2c-buyer-session</BuyerCookie>
<PunchOutOrderMessageHeader operationAllowed="edit">
<Total><Money currency="USD">1250.00</Money></Total>
</PunchOutOrderMessageHeader>
<ItemIn quantity="50">
<ItemID><SupplierPartID>SKU-4711</SupplierPartID></ItemID>
<ItemDetail>
<UnitPrice><Money currency="USD">25.00</Money></UnitPrice>
<Description xml:lang="en">Nitrile gloves, box of 100</Description>
</ItemDetail>
</ItemIn>
</PunchOutOrderMessage><Request>
<OrderRequest>
<OrderRequestHeader orderID="PO-10023" orderDate="2026-08-06" type="new">
<Total><Money currency="USD">1250.00</Money></Total>
<ShipTo><Address addressID="BER-01"/></ShipTo>
</OrderRequestHeader>
<ItemOut quantity="50" lineNumber="1">
<ItemID><SupplierPartID>SKU-4711</SupplierPartID></ItemID>
</ItemOut>
</OrderRequest>
</Request>Ariba enablement has a reputation, and it is earned. Real buyer documentation quotes 8 to 12 weeks for a punchout catalog to go live. Almost none of that is engineering. It is waiting: trading relationships, test realm credentials, catalog approvals crawling through your buyer's process.
PunchRelay covers the technical half in days. Your store gets a cXML endpoint, shared-secret validation, contract pricing mapped to Shopify B2B company locations, and the full document round trip from PunchOutSetupRequest to OrderRequest. For the waiting half, you get raw XML session logs you can hand to your buyer's IT team, which is the difference between one email loop and five.
One thing to price in before you commit: Ariba is the only major network that charges suppliers. The numbers are in the FAQ below, because finding out about the Silver subscription after go-live is the wrong way to learn about it.
Works with
- SAP Ariba
- Coupa
- Jaggaer
- Oracle Procurement
- Workday
- SAP SRM
- Unimarket
- PO acknowledgment
- <150ms
- protocols, cXML + OCI
- 2
- cXML documents, full round trip
- 4
- contract pricing from Shopify B2B catalogs
- 100%
How it works with Ariba
- 01
PunchOutSetupRequest hits your endpoint
Your buyer clicks your catalog in Ariba. Ariba sends a cXML PunchOutSetupRequest to the endpoint PunchRelay provisions for your store. We validate the shared secret against the buyer's network identity and map it to a Shopify B2B company location.
- 02
The buyer shops at contract prices
PunchRelay answers with a PunchOutSetupResponse carrying a one-time StartPage URL. The buyer lands in your Shopify storefront with their company location's catalog and price list already applied.
- 03
The cart returns as PunchOutOrderMessage
On transfer, the cart posts back to Ariba as a cXML PunchOutOrderMessage: SKUs, quantities, unit prices, UNSPSC classifications. Quantity rules run before transfer, so the requisition matches what you will actually fulfill.
- 04
Requisition and approval inside Ariba
The cart becomes a requisition and works through the buyer's approval chain. The punchout session is complete and fully logged. Nothing on your side blocks while approvers do approver things.
- 05
OrderRequest becomes a Shopify order
The approved purchase order arrives as a cXML OrderRequest. PunchRelay acknowledges it in under 150ms, then creates the Shopify order with the punchout line items and prices. Your team never retypes a PO again.
Built for the buyer's IT checklist
Contract pricing per company location
Prices come straight from Shopify B2B catalogs. Each Ariba buyer sees the prices you negotiated, per company location, in the punchout session and again on the purchase order.
Quantity rules enforced before transfer
Minimums, maximums and case increments from your B2B settings are enforced in the cart, before the PunchOutOrderMessage is sent. Fewer rejected requisitions in Ariba, fewer support emails.
Full XML session logs, both directions
Every cXML document is logged raw, in and out. When your buyer's Ariba admin asks why a cart did not arrive, you answer with the actual PunchOutOrderMessage, not a guess.
Ariba punchout, asked and answered
- What does my customer's Ariba admin need from us?
- A trading relationship on SAP Business Network, your ANID, a shared secret, and your punchout URL, which is the endpoint PunchRelay provisions for your store. Most buyers also want a catalog index file (CIF or cXML) uploaded per buyer, which Ariba validates before testing starts in their test realm.
- PunchRelay generates the credential sheet their enablement team asks for, and the XML logs that keep the test phase short.
- Does this work with Shopify B2B customer accounts?
- Yes, that is the design. PunchRelay maps each Ariba identity to a company location in Shopify B2B. The catalogs and price lists you assign to that location are exactly what the punchout session shows, so contract pricing lives where you already manage it.
- What are the Ariba network fees for suppliers?
- Punchout on Ariba realistically requires an Enterprise account. Fees trigger per buyer relationship once you pass 5 documents and 50,000 USD in a rolling 12 months: a transaction fee of 0.155% of transacted value, capped at 20,000 USD per relationship per year, plus an annual subscription tier.
- Using cXML automation moves you to the Silver tier at 750 USD per year, even at low document counts. Budget for it up front. It is Ariba's fee, not ours, and it surprises suppliers in almost every enablement.
- How long does Ariba enablement take?
- The technical setup on the PunchRelay side is measured in days. Calendar time is dominated by the buyer's process: real supplier documentation quotes 8 to 12 weeks for punchout. The lever you control is how fast each test loop closes, and self-explanatory XML logs are that lever.
- Do you support Level 2 punchout?
- Level 1, store-level punchout, is what ships first. Level 2, where individual items surface in Ariba search and punch into your store, is on the roadmap. Most Shopify suppliers go live with Level 1; it is what buyer enablement teams ask for first.
- What is cXML?
- Commerce XML, the protocol the Ariba world runs on. Four documents make a complete punchout cycle: PunchOutSetupRequest (the buyer knocks), PunchOutSetupResponse (you open the catalog), PunchOutOrderMessage (the cart goes back), OrderRequest (the purchase order comes in). PunchRelay speaks all four.
Want the full fee math, with thresholds, tiers and the calendar cost? Ariba network fees for suppliers, explained.
Get early access
We are onboarding a small group of Shopify B2B merchants and building their first buyer connections with them. Tell us where to reach you.