ERP API Integration Explained: REST, Webhooks, Auth and Idempotency
A plain-English explanation of ERP API integration: REST APIs, webhooks, authentication methods, idempotency, pagination, rate limits and error handling.
Integration · Commerce
Overview
We integrate WooCommerce through its REST API and signed webhooks, with explicit mapping for custom fields that plugins add.
01Data
| Entity | Direction | Notes |
|---|---|---|
| Orders | App → ERP | Orders imported on creation or payment, including meta fields added by plugins. |
| Order status | ERP → App | Processing, completed and tracking numbers updated from the ERP. |
| Products | ERP → App | SKUs, prices and stock status; descriptions may remain WooCommerce-managed. |
| Stock quantities | ERP → App | Available stock pushed per product and variation. |
| Customers | App → ERP | Registered customers and guest buyers matched by email. |
02Use cases
Orders arrive in the ERP automatically with correct prices and taxes.
Stock levels kept current from ERP inventory.
B2B orders in ERP, retail via WooCommerce.
03 — Architecture
WooCommerce webhooks notify an integration endpoint of new or updated orders. The endpoint verifies the signature, queues the event and fetches the full order through the REST API before processing — which also protects against partial payloads.
Stock and status updates flow outbound in batches using the REST API's batch endpoints, reducing load on the WordPress server.
04Reliability
REST API consumer key and secret generated for a dedicated integration user with the minimum required permissions, over HTTPS only.
Orders are processed idempotently by WooCommerce order ID. Mapping failures — unknown SKUs, invalid addresses — are held in an exception queue with clear reasons.
Failed API calls retry with backoff, accounting for hosting limits on shared WordPress servers. Persistent failures alert the team and a nightly reconciliation catches gaps.
05 — Data mapping
| WooCommerce | ERP |
|---|---|
| id / number | Sales order reference |
| line_items.sku | Product reference |
| billing.email | Partner |
| meta_data (plugin fields) | Mapped custom fieldsDocumented per plugin |
| shipping_lines.method_id | Delivery method |
06 — Automation
07 — Security
Webhook signatures (HMAC-SHA256) are verified. API keys are scoped to a dedicated user and rotated periodically. WordPress and WooCommerce should be kept patched, because the integration is only as secure as the store.
Related
Other integrations
Insights
A plain-English explanation of ERP API integration: REST APIs, webhooks, authentication methods, idempotency, pagination, rate limits and error handling.
How to integrate an ERP with eCommerce, CRM, payments and other systems: data ownership, integration patterns, middleware, error handling, monitoring and common failure modes.
How to integrate RFID readers with Odoo inventory: middleware design, mapping EPCs to products and serials, receiving and counting flows, performance and what to build vs buy.
FAQ
They can if plugins change data structures. We document dependencies and include integration checks in your update routine.
Batching and scheduling outbound updates keeps load modest. Very large catalogues may need better hosting.
Yes, but many clients keep marketing content in WooCommerce and sync only operational data.
Next step
Tell us your volumes, channels and data rules. We will outline the architecture and the risks before anything is built.