How it works
From buyer click to the cart, then to the order in Magento, in 7 steps.
A complete PunchOut flow with Gatebold: the procurement system, the platform, the Magento connector, the cart return and the OrderRequest order. Here is what happens at each step.
How it works
From buyer click to normalized cart - then to the order in Magento .
Procurement system → Gatebold
The buyer clicks PunchOut
Procurement system (Ariba, Coupa, Jaggaer, etc.)
The procurement system sends a PunchOutSetupRequest cXML or OCI to the Gatebold platform. This message contains the buyer identity, the user, and the return URL.
Gatebold → Magento connector
Gatebold validates and opens the session
Gatebold platform
Gatebold verifies credentials (HMAC-SHA256), identifies the connection, creates a signed JWT session and generates the Magento entry URL.
Buyer ↔ Magento storefront
The buyer browses the store
Magento / Adobe Commerce
The buyer is redirected to the Magento storefront with their buyer context. They browse, see their contract prices, and build their cart.
Connector → Gatebold
The cart is sent back
Magento connector → Gatebold
The buyer submits their cart. The connector sends a callback to Gatebold with the cart contents.
Gatebold → Procurement system
Gatebold builds the PunchOutOrderMessage
Gatebold platform
Gatebold applies the cXML or OCI mapping configured for this buyer: product codes, UNSPSC, units of measure, taxes. The cXML message is validated against the official DTD.
Internal approval workflow
The cart lands in the procurement system
Procurement system
The PunchOutOrderMessage is posted to the return URL. The cart appears in the procurement system for internal validation, approval, and purchase order generation.
Procurement system → Gatebold → Magento
The approved order lands in Magento
Procurement system, Gatebold platform, Magento
Once the cart is validated in the procurement system, it sends the cXML OrderRequest to Gatebold, which validates it, maps it and creates the order in your Magento. Every exchange stays traced.
What Gatebold changes
At every step, visibility and control.
Steps 1-2: automatic validation
Credentials verified, JWT session created, connection identified. No invalid Setup Request passes silently.
Steps 3-4: context preserved
The Magento connector maintains buyer context throughout browsing. No lost session, no expired cookie.
Steps 5-7: controlled mapping
The PunchOutOrderMessage is built with the mapping configured for this buyer, DTD-validated before sending. The received OrderRequest is validated and mapped the same way.
Want to see this flow in action?
We can walk you through the full flow in a sandbox environment with your buyer context.



