SFCC Integration Guide
Complete guide for integrating SFCC with Forter Agentic Orchestration.
This guide is specifically for merchants using Salesforce Commerce Cloud (SFCC). For other platforms, see Shopify IntegrationShopify Integration or Custom IntegrationCustom Integration.
How It Works
With SFCC integration, Forter:
- Pulls your product catalog via SFCC OCAPI (Shop API)
- Generates and maintains the AI-optimized feed automatically
- Creates orders directly in your SFCC instance via OCAPI Basket/Order APIs
You provide: OCAPI credentials You implement: Nothing - Forter handles everything
Prerequisites
Before starting, ensure you have:
SFCC Instance — Sandbox or production Business Manager access
OCAPI Permissions — Ability to configure OCAPI settings and create API clients
Forter Account — Contact your Forter representative to enable Agentic Orchestration
Tax Nexus List — US states where you collect sales tax
Step 1: Configure SFCC OCAPI Credentials
A. Configure Shop API Settings
- Log in to SFCC Business Manager
- Navigate to: Administration > Site Development > Open Commerce API Settings
- Click on Shop API tab
- Add this JSON configuration:
{
"_v": "23.1",
"clients": [
{
"client_id": "forter-agentic-commerce",
"allowed_origins": [],
"resources": [
{
"resource_id": "/products/**",
"methods": ["get"],
"read_attributes": "(**)",
"write_attributes": "()"
},
{
"resource_id": "/product_search",
"methods": ["get", "post"],
"read_attributes": "(**)",
"write_attributes": "()"
},
{
"resource_id": "/categories/**",
"methods": ["get"],
"read_attributes": "(**)",
"write_attributes": "()"
},
{
"resource_id": "/baskets/**",
"methods": ["get", "post", "put", "patch"],
"read_attributes": "(**)",
"write_attributes": "(**)"
},
{
"resource_id": "/orders/**",
"methods": ["get", "post"],
"read_attributes": "(**)",
"write_attributes": "(**)"
}
]
}
]
}- Click Save
Key Points:
- client_id: Must be forter-agentic-commerce (or your chosen name)
- Read-only for products/categories
- Read/write for baskets/orders (required for checkout)
B. Enable Account Manager
- Navigate to: Administration > Organization > Account Manager
- If not enabled, click Enable Account Manager
- Follow the prompts to complete setup
C. Create API Client
- Navigate to: Administration > Site Development > Open Commerce API Settings > API Client
- Click Add API Client
- Fill in the details:
Client Name: Forter Agentic Commerce
Client ID: forter-agentic-commerce
(must match the client_id in OCAPI settings)
Token Endpoint Auth Method: Client Secret Post
Access Token Format: JWT
Scopes (select all that apply):
☑ SALESFORCE_COMMERCE_API:{tenant_id}.shopper-products-read
☑ SALESFORCE_COMMERCE_API:{tenant_id}.shopper-categories-read
☑ SALESFORCE_COMMERCE_API:{tenant_id}.shopper-search-read
☑ SALESFORCE_COMMERCE_API:{tenant_id}.shopper-baskets-orders
Allowed Grant Types:
☑ Client Credentials
Redirect URIs: (leave empty)- Click Save
- IMPORTANT: Copy the Client Secret immediately - it's only shown once!
D. Test Your Credentials
Test with curl to ensure everything works:
# Get access token
curl -X POST https://account.demandware.com/dwsso/oauth2/access_token \
-H "Content-Type: application/x-www-form-urlencoded" \
-u "forter-agentic-commerce:YOUR_CLIENT_SECRET" \
-d "grant_type=client_credentials"
# Test product access
curl -X GET "https://YOUR_INSTANCE.demandware.net/s/YOUR_SITE_ID/dw/shop/v23_1/product_search?count=10" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"If successful, you'll receive product data.
Step 2: Configure in Forter Portal
Log in to the Forter Portal and navigate to Integrations > SFCC.
A. Basic Store Information
Field | Description | Example |
|---|---|---|
Store Title | Your store name | "My Custom SFCC Store" |
Store URL | Your storefront URL | "https://www.mycustomstore.com" |
Logo URL | URL to your logo | "https://www.mycustomstore.com/logo.png" |
Currency | Primary currency | "USD" |
Origin Country | Shipping origin | "US" |
Origin Region | State/region | "CA" |
B. SFCC Platform Configuration
Field | Description | Example |
|---|---|---|
Platform | Select platform type | "sfcc" |
SFCC Instance URL | Your SFCC instance | "https://dev01-mycustomstore.demandware.net" |
Site ID | Your site identifier | "SiteGenesis" or "RefArch" |
OCAPI Client ID | From Step 1C | "forter-agentic-commerce" |
OCAPI Client Secret | From Step 1C | •••••••• (encrypted) |
OCAPI Version | API version | "v23_1" or your instance version |
C. Store Policies
Field | Description |
|---|---|
Terms of Service URL | Link to your terms |
Privacy Policy URL | Link to your privacy policy |
Return Policy URL | Link to your return policy |
Return Window (Days) | Days allowed for returns (e.g., 30) |
D. Tax Configuration
Field | Description | Example |
|---|---|---|
Tax Nexus Regions | US states where you collect sales tax | ["CA", "NY", "TX"] |
E. Order Management
Field | Description | Example |
|---|---|---|
Order Status URL Template | URL for order tracking | "https://mycustomstore.com/orders/{order_id}" |
The {order_id} placeholder will be replaced with the SFCC order number.
Step 3: Payment & Fraud Settings (Optional)
By default, you handle payment validation and authorization on your SFCC instance. This section is only needed if you want Forter to handle fraud detection and payments.
Option A: Merchant-Side Validation/Authorization (Default)
What happens:
- Forter creates orders in SFCC with payment references
- SFCC processes payments through your existing payment provider
- SFCC handles fraud checks through your existing rules
Configuration: No additional setup needed - this is the default behavior.
Settings in Portal:
Enable Forter Validation: false (default)
Enable Forter Authorization: false (default)
Enable Forter Capture: false (default)Option B: Forter-Side Validation/Authorization (Optional)
What happens:
- Forter validates orders for fraud before creating them in SFCC
- Forter authorizes/captures payments via Forter Payment Orchestration
- Orders are created in SFCC with completed payment status
Configuration Required:
Contact your Forter representative to obtain:
Field | Description |
|---|---|
Validation API Key | Forter fraud detection credentials |
Payment API Key | Forter payment orchestration credentials |
Settings in Portal:
Enable Forter Validation: true
Enable Forter Authorization: true
Enable Forter Capture: true (or false for manual capture)Step 4: Catalog Sync & Testing
A. Initiate First Sync
After configuring SFCC credentials in the portal:
- Forter automatically tests the OCAPI connection
- Initial catalog sync begins (pulls all products via OCAPI)
- Products are normalized to AI-optimized format
- Feed is distributed to AI platforms
Processing Time:
- < 10,000 products: Minutes
- 10,000 - 100,000 products: Under an hour
- > 100,000 products: A few hours
B. Verify Catalog
Check that products were synced by updating inventory for a test product:
curl -X POST \
https://{site_id}.agentic.checkouttools.com/v1/inventory \
-H "Authorization: Bearer YOUR_FORTER_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"id": "TEST-SKU-001",
"quantity": 100
}'If the product exists, you'll receive:
{
"success": true,
"updated": 1,
"results": [{ "success": true, "id": "TEST-SKU-001" }]
}C. Test Checkout Flow
Test end-to-end checkout in the test environment:
1. Create a checkout session:
curl -X POST \
https://{site_id}.agentic.checkouttools.com/checkout_sessions \
-H "Authorization: Bearer sk_test_YOUR_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: test-001" \
-d '{
"items": [{ "id": "TEST-SKU-001", "quantity": 1 }],
"buyer": {
"first_name": "Test",
"email": "[email protected]"
}
}'2. Add shipping and complete order:
curl -X POST \
https://{site_id}.agentic.checkouttools.com/checkout_sessions/{session_id}/complete \
-H "Authorization: Bearer sk_test_YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"fulfillment_address": {
"name": "Test User",
"line_one": "123 Test St",
"city": "San Francisco",
"state": "CA",
"postal_code": "94102",
"country": "US"
},
"payment_data": {
"token": "tok_test_visa_4242",
"provider": "test"
}
}'3. Verify order in SFCC Business Manager
The order should appear in: Merchant Tools > Ordering > Orders
Step 5: Go Live
Production Checklist
Replace test OCAPI credentials with production credentials
Update Forter Portal with production SFCC instance URL
Verify production catalog sync completes successfully
Test at least one production order end-to-end
Configure monitoring and alerting
Enable AI platform distribution (OpenAI, Google, etc.)
Monitoring
Use the Forter Portal to monitor:
- Catalog Health — Product count, sync status, errors
- Order Volume — Checkout sessions, completions, failures
- OCAPI Usage — API call volume, rate limits
- Error Rates — Failed checkouts, SFCC API errors
Troubleshooting
"Invalid OCAPI credentials"
Solution:
- Verify Client ID matches OCAPI Shop API settings
- Check Client Secret (no extra spaces)
- Ensure scopes include required tenant ID
- Wait 5-10 minutes for settings to propagate
"Insufficient permissions"
Solution:
- Check OCAPI Shop API resources include /baskets/** and /orders/**
- Verify API Client scopes include shopper-baskets-orders
- Confirm OCAPI version matches your instance
Products not syncing
Solution:
- Test OCAPI product_search endpoint with curl
- Check SFCC rate limits (100 req/10s)
- Review Forter Portal logs for sync errors
- Verify products are online and searchable in SFCC
Orders not appearing in SFCC
Solution:
- Verify basket creation permissions in OCAPI settings
- Check SFCC Business Manager for failed orders
- Review Forter Portal logs for OCAPI errors
- Confirm site ID is correct
SFCC-Specific Considerations
Rate Limits
SFCC OCAPI has rate limits:
- ~100 requests per 10 seconds
- ~1000 requests per minute
Forter automatically handles rate limiting with exponential backoff.
Catalog Size
For large catalogs (>100k products), consider:
- Enabling SFCC search result pagination
- Monitoring initial sync duration
- Using inventory updates for real-time changes
Multiple Sites
If you have multiple SFCC sites:
- Configure each site as a separate integration in Forter Portal
- Each site gets its own API credentials and configuration
- Orders are routed to the correct site based on Site ID
Quick Reference
Required OCAPI Resources
{
"products": ["get"],
"product_search": ["get", "post"],
"categories": ["get"],
"baskets": ["get", "post", "put", "patch"],
"orders": ["get", "post"]
}Required OCAPI Scopes
shopper-products-read
shopper-categories-read
shopper-search-read
shopper-baskets-ordersNext Steps
- Catalog & InventoryCatalog & Inventory — Product data synchronization details
- Checkout & PaymentsCheckout & Payments — Payment processing and order management
- FAQFAQ — Common questions
Support
For SFCC-specific integration questions, contact your Forter representative or email [email protected].