SAP Ariba

SAP Ariba PunchOut integration, from the supplier’s side

Your buyer runs SAP Ariba and has told you a PunchOut catalogue is required. Here is exactly what that means technically, what Ariba will ask you for, and where suppliers most often lose weeks.

How SAP Ariba PunchOut works

  1. A buyer in Ariba clicks your catalogue. Ariba sends a cXML PunchOutSetupRequest to your endpoint, carrying credentials that identify the buyer organisation and, usually, the individual shopper.
  2. Your endpoint authenticates that request and replies with a PunchOutSetupResponse containing a one-time URL for a shopping session. Ariba redirects the buyer into it.
  3. The buyer shops on your site, seeing their contract pricing rather than list pricing, and clicks a button that ends the session.
  4. Your site posts a cXML PunchOutOrderMessage back to the BrowserFormPost URL Ariba supplied in step one. That message becomes a requisition line in Ariba — it is not an order yet.
  5. The requisition goes through the buyer’s internal approval chain and comes back to you as a purchase order, over cXML if you are set up for it, or as a PDF by email if you are not.

The onboarding sequence

In order. Most of the delay suppliers hit on SAP Ariba comes from discovering one of these steps late, not from the step itself being hard.

  1. Register and get your ANID Your buyer normally sends an onboarding invitation; you can also register directly on SAP Business Network. You are issued an Ariba Network ID formatted like AN01234567890, which appears in every cXML transaction from then on.
  2. Choose the right account type A Standard Account is free but limited on automation. An Enterprise Account supports full cXML integration for orders, ship notices and invoices. If your buyer wants electronic documents rather than just a catalogue, Standard will not carry it — establish this early, because it has a cost attached and it is your decision, not ours.
  3. Accept the relationship request An ANID lets you exist on the network; it does not let you trade with anyone. Your buyer sends a relationship request that you accept in your Ariba portal before any testing can happen. Suppliers routinely lose a week here without realising the request is sitting unread.
  4. Configure the gateway Set a Network Shared Secret in your account settings, and register your PunchOut setup URL — the endpoint that receives cXML requests. Sender credentials, receiver credentials and the shared secret must match on both sides exactly.
  5. Map catalogue data and contract pricing Your storefront must identify the incoming shopper from the Ariba credentials and show that buyer their contracted items and prices. Ariba validates UNSPSC codes and units of measure before it will accept a returned cart.
  6. Test against the sandbox Ariba requires a testing phase using a separate test ANID. The buyer runs a mock PunchOut into your store, returns a cart, and approves a requisition so a test purchase order reaches you — plus a test ASN and invoice if those are in scope.
  7. Switch to production Once the buyer signs off, move credentials and endpoints from test to the production network, and watch the first live transactions closely. Formatting errors that passed in test surface here more often than anyone expects.

What SAP Ariba requires from you

An Ariba Network accountSuppliers transact on the network under an ANID. Your buyer will ask for yours, and it is the identifier the whole relationship hangs off.
A shared secretAriba authenticates to your endpoint using credentials in the cXML Credential block. This is exchanged out of band and configured on both sides.
Separate test and production endpointsAriba treats test and production as different environments with different ANIDs. You will need both, and the buyer will test against the first before touching the second.
Product classificationMost Ariba buyers mandate UNSPSC codes on catalogue lines, and some require a specific revision of the code set. Unit-of-measure values must be valid UN/CEFACT codes.
The right account tierA free Standard Account cannot carry full cXML document automation. If your buyer wants orders and invoices exchanged electronically, an Enterprise Account is required, and SAP charges for it.

Where suppliers lose time on SAP Ariba

Ariba Network fees are not integration feesDepending on transaction volume and the buyer’s programme, SAP may charge you subscription or transaction fees to transact on the network. That is a separate commercial matter between you and SAP — no integration provider can waive it, and anyone who implies otherwise is misleading you.
The naming has changed, the protocol has notAriba Network was folded into SAP Business Network. Documentation, buyer emails, and portal screens use both names, sometimes in the same thread. The cXML underneath is unchanged.
PunchOut is not the same as a hosted CIF catalogueBuyers sometimes say "catalogue" meaning a static CIF file upload, and sometimes meaning PunchOut. These are entirely different pieces of work. Confirm which before anyone estimates anything.
The test queue is the real timelineAriba enablement runs through the buyer’s own programme, often with a dedicated enablement team and a queue. Your technical work can be finished in weeks while approval sits behind other suppliers.

Timeline and price

The supplier-side build for a straightforward Ariba PunchOut is typically two to four weeks. What follows is the buyer’s enablement and test cycle, which you do not control and which is usually the longer half.

A SAP Ariba PunchOut catalogue is our Connect tier at $199/month for year one, stepping down to $129 from year two. If the buyer also wants purchase orders and invoices exchanged electronically, that is Order Loop at $349. You do not start paying until the connection is live in production.

The buyer's test queue, not the integration work, is what usually sets the date — see what actually controls the clock.

SAP Ariba questions

Do we need an Ariba Network account before starting?

Yes, and it is worth starting that early because account setup and ANID issuance is a separate process from the technical integration. Your buyer’s enablement team will normally point you at the right registration path for their programme.

Can we punch out from our existing Shopify or WooCommerce store?

Usually yes. PunchOut is a layer in front of your existing catalogue rather than a replacement for it — the session handling, buyer-specific pricing and cXML cart return are what get added. Whether your platform can show contract pricing per buyer is the question that decides how much work it is.

What is the difference between cXML and OCI here?

Ariba speaks cXML. OCI is SAP’s older HTML-form-based punchout used by SAP SRM and classic ERP setups. If your buyer is on Ariba you need cXML; if they are on SAP SRM you may need OCI instead. We wrote a full comparison of the two protocols.

Working out what your SAP Ariba buyer needs?

Send us the requirement they gave you. We will tell you what it means in SAP Ariba terms, which tier covers it, and roughly how long it takes.

Start a conversation See pricing