ERP API Integration Explained: REST, Webhooks, Auth and Idempotency
A plain-English explanation of ERP API integration: REST APIs, webhooks, authentication methods, idempotency, pagination, rate limits and error handling.
Integration · Commerce
Overview
We build Shopify integrations on the Admin API and webhooks, with clear rules about which system owns each piece of data and what happens when either side is unavailable.
01Data
| Entity | Direction | Notes |
|---|---|---|
| Orders | App → ERP | New and paid orders imported as sales orders with lines, discounts, shipping, taxes and payment status. |
| Customers | App → ERP | Matched by email with rules for guest checkouts; B2B companies mapped to ERP accounts. |
| Products & variants | ERP → App | ERP as master for SKUs, prices and core attributes; merchandising content can stay in Shopify. |
| Inventory levels | ERP → App | Available quantity per location pushed with optional safety buffers. |
| Fulfilments & tracking | ERP → App | Shipments and tracking numbers posted back so customers are notified. |
| Refunds & returns | App → ERP | Refunds create credit notes; returns create return receipts. |
| Payouts | App → ERP | Shopify Payments payouts reconciled against orders, fees and refunds. |
02Use cases
One stock figure feeding Shopify, wholesale and marketplaces.
Orders flow to warehouse picking and tracking returns to Shopify automatically.
Sales, taxes, fees and payouts posted correctly without manual journals.
Shopify for consumers, ERP portal or Shopify B2B for trade, with one ledger.
03 — Architecture
Shopify pushes order and refund events through webhooks to a receiving endpoint that verifies the HMAC signature, stores the payload and acknowledges quickly. Processing happens asynchronously from a queue, so a slow ERP never causes Shopify to time out and retry.
Outbound updates — stock, prices, fulfilments — are batched and sent through the Admin API, respecting Shopify's rate limits. A scheduled reconciliation job compares recent orders on both sides to catch anything a webhook missed.
04Reliability
A custom or private app installed on the store with scoped Admin API access tokens limited to the resources the integration needs. Tokens are stored in a secrets manager, never in code.
Each order is processed with its Shopify ID as an idempotency key. Validation errors (unknown SKU, tax mismatch) go to an exception queue with the reason, visible to the operations team.
Transient failures and rate-limit responses retry with exponential backoff. After the final attempt, messages move to a dead-letter queue and an alert is sent; they can be replayed once fixed.
05 — Data mapping
| Shopify | ERP |
|---|---|
| order.id / name | Sales order referenceBoth stored for traceability |
| line_items.sku | Product (internal reference)Unknown SKUs go to exceptions |
| customer.email | PartnerMatched, not duplicated |
| tax_lines | Tax / fiscal positionMapped per jurisdiction |
| shipping_lines | Delivery method & charge |
| inventory_level.available | Free quantity per locationLess safety buffer |
06 — Automation
07 — Security
Webhook payloads are verified with Shopify's HMAC signature before processing. Access tokens have minimum scopes and are rotated when staff with access leave. Customer personal data is only stored where operationally necessary.
Related
Other integrations
Insights
A plain-English explanation of ERP API integration: REST APIs, webhooks, authentication methods, idempotency, pagination, rate limits and error handling.
How to integrate an ERP with eCommerce, CRM, payments and other systems: data ownership, integration patterns, middleware, error handling, monitoring and common failure modes.
How to integrate RFID readers with Odoo inventory: middleware design, mapping EPCs to products and serials, receiving and counting flows, performance and what to build vs buy.
FAQ
Evaluate it first against your rules for customers, taxes, variants, bundles and multi-location stock. If it fits, it is usually the cheapest option. If it needs heavy modification, a purpose-built integration is easier to own.
Typically within a few minutes. We batch updates and apply buffers rather than pushing every single stock movement.
Yes. Bundles sold in Shopify can explode into component lines in the ERP so stock is deducted correctly.
Next step
Tell us your volumes, channels and data rules. We will outline the architecture and the risks before anything is built.