What They Are, Who Creates Them, and Why They Matter.
If you’ve ever worked with PunchOut integrations, you’ve probably encountered this moment:
“Can you just send us your Identity details?”
Or sometimes even more confusing:
“Can you send us our Identity details?”
For something that appears in almost every PunchOut integration, cXML identities are surprisingly misunderstood.
Part of the confusion comes from the fact that different procurement platforms use different terminology, identity values are often manually configured, and there is no central authority that creates or manages them.
To make matters worse, many people assume identities are login credentials.
They aren’t.
cXML identities are not usernames or passwords used by people to access systems. Instead, they are system-level identifiers used to route, identify, and authenticate communication between Buyer and Supplier platforms.
Think of them as digital name tags that allow systems to recognize who they are communicating with.
What Is an “Identity” in PunchOut?
In cXML, an identity is a unique identifier used to represent a system or organization.
Every identity is paired with a domain that defines the type of identifier being used.
Example:
| Field | Value |
|---|---|
| Domain | DUNS |
| Identity | 1009876 |
Together, the Domain and Identity form part of a cXML credential.
These credentials are included in the header of cXML messages and help systems determine:
- Who sent the message
- Who should receive the message
- Whether the message should be trusted
Without identities, Buyer and Supplier systems would have no reliable way to recognize each other.
Where Identities Are Used
Identities appear throughout the entire PunchOut lifecycle.
Some common examples include:
PunchOut Setup Requests (POSR)
When a Buyer launches a PunchOut catalog, the procurement system sends a PunchOut Setup Request to the Supplier.
The identities in the request are used to:
- Authenticate the trading partners
- Validate access permissions
- Route the request to the correct Supplier environment
Shopping Cart Returns (POOM)
When the shopper finishes building their cart, the Supplier returns the cart to the Buyer’s procurement system.
The identities help ensure:
- The cart is returned to the correct Buyer
- The session remains linked to the original PunchOut request
- The message can be authenticated
Purchase Orders
After approval, the Buyer’s procurement system sends a Purchase Order to the Supplier.
At this stage, identities are used to:
- Confirm who is sending the order
- Route the order to the correct Supplier account
- Authenticate the transaction
Understanding From, To, and Sender
Every cXML message contains three primary credential blocks:
-
From
The organization sending the current message. -
To
The organization receiving the message. -
Sender
The system responsible for transmitting and authenticating the message.
One important point that often causes confusion:
The “From” credential is not always the Buyer.
It depends entirely on who is sending the current cXML message.
For example:
| Transaction | From | To |
|---|---|---|
| PunchOut Setup Request | Buyer | Supplier |
| Cart Return (POOM) | Supplier | Buyer |
| Purchase Order | Buyer | Supplier |
| Invoice | Supplier | Buyer |
The easiest way to understand cXML credentials is to follow the direction of communication. Whoever is sending the message is typically represented in the From credential.
Where Do Identities Come From?
This is one of the most common questions in PunchOut projects.
The answer is simple:
There is no global identity registry for cXML.
Buyer identities are typically configured within procurement systems such as:
- Coupa
- SAP Ariba
- Oracle Procurement
Supplier identities are often based on:
- DUNS numbers
- Vendor identifiers
- Business registration numbers
- Supplier-defined identifiers
In many cases, these values are simply agreed upon during onboarding and configured within both systems.
Can Vurbis Help Define Identities?
Yes.
While many organizations already have identity values defined within their procurement or eCommerce platforms, others do not.
In these situations, Vurbis can help establish a consistent identity structure that both Buyer and Supplier systems can use.
This helps ensure:
- Consistent configuration
- Reliable routing
- Easier troubleshooting
- Simpler onboarding for future trading partners
The most important thing is not where the identity comes from, but that both sides agree on how it will be used.
A Quick Note About PunchOut Level 2
In more advanced PunchOut Level 2 environments, identity structures can become significantly more complex.
Procurement hubs, distributor platforms, marketplaces, and intermediary networks may introduce additional routing information into the transaction.
As a result, a single PunchOut Setup Request may contain multiple identifiers used for internal routing and supplier resolution.
This is often where confusion begins because several identities may appear within the same transaction even though the PunchOut session ultimately targets a single supplier relationship.
We’ll explore PunchOut Level 2 identity structures and multi-hop routing in a future blog post.
Common Credential & Identity Mistakes
Some of the most common issues we see include:
-
Using the Same Identity Everywhere
Using Supplier values for From, To, and Sender credentials can create authentication and routing problems. -
Mixing Buyer and Supplier Credentials
Buyer identities should not be used as Supplier credentials, and vice versa. -
Assuming Identities Are Automatically Generated
Most identity values are configured during implementation and onboarding, not automatically created by ERP systems.
Why Identities Matter
When identities are configured incorrectly, integrations can fail.
Common symptoms include:
- Rejected PunchOut requests
- Failed shopping cart returns
- Purchase Order delivery issues
- Authentication failures
- Routing problems
In many PunchOut troubleshooting scenarios, identity mismatches are ultimately the root cause.
Key Takeaway
cXML identities are not user logins, passwords, or centrally managed credentials.
They are system-level identifiers used to help Buyer and Supplier platforms recognize, authenticate, and communicate with each other.
Once you understand who owns them, where they come from, and how they are used throughout the PunchOut lifecycle, PunchOut integrations become significantly easier to implement and support.
About Vurbis
Vurbis helps Buyers and Suppliers simplify PunchOut and eCommerce integrations by connecting procurement systems, eCommerce platforms, and ERP environments through scalable, standardized integration solutions.
From PunchOut onboarding to Purchase Order automation, Vurbis helps organizations reduce complexity, improve reliability, and streamline B2B commerce connectivity.