# SFCC Integration Guide

**Complete guide for integrating SFCC with Forter Agentic Orchestration.**

This guide is specifically for merchants using Salesforce Commerce Cloud (SFCC). For other platforms, see [Shopify Integration](https://docs.forter.com/quickstart-shopify) or [Custom Integration](https://docs.forter.com/quickstart-custom).

## [How It Works](https://docs.forter.com/quickstart-sfcc#how-it-works) How It Works

With SFCC integration, Forter:

1. **Pulls your product catalog** via SFCC OCAPI (Shop API)
2. **Generates and maintains** the AI-optimized feed automatically
3. **Creates orders** directly in your SFCC instance via OCAPI Basket/Order APIs

**You provide:** OCAPI credentials  
**You implement:** Nothing - Forter handles everything

## [Prerequisites](https://docs.forter.com/quickstart-sfcc#prerequisites) Prerequisites

Before starting, ensure you have:

- **SFCC Instance** — Sandbox or production Business Manager access
- **OCAPI Permissions** — Ability to configure OCAPI settings and create API clients
- **Forter Account** — Contact your Forter representative to enable Agentic Orchestration
- **Tax Nexus List** — US states where you collect sales tax

## [Step 1: Configure SFCC OCAPI Credentials](https://docs.forter.com/quickstart-sfcc#step-1-configure-sfcc-ocapi-credentials) Step 1: Configure SFCC OCAPI Credentials

### [A. Configure Shop API Settings](https://docs.forter.com/quickstart-sfcc#a-configure-shop-api-settings) A. Configure Shop API Settings

1. Log in to SFCC Business Manager
2. Navigate to: **Administration > Site Development > Open Commerce API Settings**
3. Click on **Shop API** tab
4. Add this JSON configuration:
   
   ```json
   {
       "_v": "23.1",
       "clients":[
           {
               "client_id":"forter-agentic-commerce",
               "allowed_origins":[],
               "resources":[
                   {
                       "resource_id":"/products/**/*",
                       "methods":["get"],
                       "read_attributes":"(***)",
                       "write_attributes":"()"
                   },
                   {
                       "resource_id":"/product_search",
                       "methods":["get","post"],
                       "read_attributes":"(***)",
                       "write_attributes":"()"
                   },
                   {
                       "resource_id":"/categories/**/*",
                       "methods":["get"],
                       "read_attributes":"(***)",
                       "write_attributes":"()"
                   },
                   {
                       "resource_id":"/baskets/**/*",
                       "methods":["get","post","put","patch"],
                       "read_attributes":"(***)",
                       "write_attributes":"(***)"
                   },
                   {
                       "resource_id":"/orders/**/*",
                       "methods":["get","post"],
                       "read_attributes":"(***)",
                       "write_attributes":"(***)"
                   }
               ]
           }
       ]
   }
   ```

5. Click **Save**

**Key Points:**

- client_id: Must be forter-agentic-commerce (or your chosen name)
- Read-only for products/categories
- Read/write for baskets/orders (required for checkout)

### [B. Enable Account Manager](https://docs.forter.com/quickstart-sfcc#b-enable-account-manager) B. Enable Account Manager

1. Navigate to: **Administration > Organization > Account Manager**
2. If not enabled, click **Enable Account Manager**
3. Follow the prompts to complete setup

### [C. Create API Client](https://docs.forter.com/quickstart-sfcc#c-create-api-client) C. Create API Client

1. Navigate to: **Administration > Site Development > Open Commerce API Settings > API Client**
2. Click **Add API Client**
3. Fill in the details:
   
   ```javascript
   Client Name: Forter Agentic Commerce
   Client ID: forter-agentic-commerce (must match the client_id in OCAPI settings)
   Token Endpoint Auth Method: Client Secret Post
   Access Token Format: JWT
   Scopes (select all that apply):
   ✔️ SALESFORCE_COMMERCE_API:{tenant_id}.shopper-products-read
   ✔️ SALESFORCE_COMMERCE_API:{tenant_id}.shopper-categories-read
   ✔️ SALESFORCE_COMMERCE_API:{tenant_id}.shopper-search-read
   ✔️ SALESFORCE_COMMERCE_API:{tenant_id}.shopper-baskets-orders
   Allowed Grant Types:
   ✔️ Client Credentials
   Redirect URIs: (leave empty)
   ```

4. Click **Save**
5. **IMPORTANT:** Copy the **Client Secret** immediately - it's only shown once!

### [D. Test Your Credentials](https://docs.forter.com/quickstart-sfcc#d-test-your-credentials) D. Test Your Credentials

Test with curl to ensure everything works:

```bash
# Get access token
curl -X POST https://account.demandware.com/dwsso/oauth2/access_token \
-H "Content-Type: application/x-www-form-urlencoded" \
-u "forter-agentic-commerce:YOUR_CLIENT_SECRET" \
-d "grant_type=client_credentials"

# Test product access
curl -X GET "https://YOUR_INSTANCE.demandware.net/s/YOUR_SITE_ID/dw/shop/v23_1/product_search?count=10" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"
```

If successful, you'll receive product data.

## [Step 2: Configure in Forter Portal](https://docs.forter.com/quickstart-sfcc#step-2-configure-in-forter-portal) Step 2: Configure in Forter Portal

Log in to the Forter Portal and navigate to **Integrations > SFCC**.

### [A. Basic Store Information](https://docs.forter.com/quickstart-sfcc#a-basic-store-information) A. Basic Store Information

| Field                  | Description                 | Example                            |
|------------------------|-----------------------------|------------------------------------|
| **Store Title**        | Your store name             | "My Custom SFCC Store"            |
| **Store URL**          | Your storefront URL         | "https://www.mycustomstore.com"  |
| **Logo URL**           | URL to your logo            | "https://www.mycustomstore.com/logo.png" |
| **Currency**           | Primary currency            | "USD"                             |
| **Origin Country**     | Shipping origin             | "US"                              |
| **Origin Region**      | State/region                | "CA"                              |

### [B. SFCC Platform Configuration](https://docs.forter.com/quickstart-sfcc#b-sfcc-platform-configuration) B. SFCC Platform Configuration

| Field                       | Description                | Example                                     |
|-----------------------------|----------------------------|---------------------------------------------|
| **Platform**                | Select platform type       | "sfcc"                                     |
| **SFCC Instance URL**       | Your SFCC instance        | "https://dev01-mycustomstore.demandware.net" |
| **Site ID**                 | Your site identifier       | "SiteGenesis" or "RefArch"               |
| **OCAPI Client ID**         | From Step 1C              | "forter-agentic-commerce"                   |
| **OCAPI Client Secret**     | From Step 1C              | •••••••• (encrypted)                         |
| **OCAPI Version**           | API version                | "v23_1" or your instance version           |

### [C. Store Policies](https://docs.forter.com/quickstart-sfcc#c-store-policies) C. Store Policies

| Field                          | Description                              |
|--------------------------------|------------------------------------------|
| **Terms of Service URL**       | Link to your terms                      |
| **Privacy Policy URL**         | Link to your privacy policy             |
| **Return Policy URL**          | Link to your return policy              |
| **Return Window (Days)**       | Days allowed for returns (e.g., 30)    |

### [D. Tax Configuration](https://docs.forter.com/quickstart-sfcc#d-tax-configuration) D. Tax Configuration

| Field                          | Description                              | Example                |
|--------------------------------|------------------------------------------|------------------------|
| **Tax Nexus Regions**          | US states where you collect sales tax   | ["CA", "NY", "TX"]|

### [E. Order Management](https://docs.forter.com/quickstart-sfcc#e-order-management) E. Order Management

| Field                           | Description                                | Example                            |
|---------------------------------|--------------------------------------------|------------------------------------|
| **Order Status URL Template**   | URL for order tracking                     | "https://mycustomstore.com/orders/{order_id}" |
| **The {order_id} placeholder will be replaced with the SFCC order number.** |

## [Step 3: Payment & Fraud Settings (Optional)](https://docs.forter.com/quickstart-sfcc#step-3-payment-fraud-settings-optional) Step 3: Payment & Fraud Settings (Optional)

By default, **you handle payment validation and authorization** on your SFCC instance. This section is only needed if you want **Forter to handle fraud detection and payments**.

### [Option A: Merchant-Side Validation/Authorization (Default)](https://docs.forter.com/quickstart-sfcc#option-a-merchant-side-validationauthorization-def) Option A: Merchant-Side Validation/Authorization (Default)

**What happens:**

- Forter creates orders in SFCC with payment references
- SFCC processes payments through your existing payment provider
- SFCC handles fraud checks through your existing rules

**Configuration:** No additional setup needed - this is the default behavior.

**Settings in Portal:**

```javascript
Enable Forter Validation: false (default)
Enable Forter Authorization: false (default)
Enable Forter Capture: false (default)
```

### [Option B: Forter-Side Validation/Authorization (Optional)](https://docs.forter.com/quickstart-sfcc#option-b-forter-side-validationauthorization-optio) Option B: Forter-Side Validation/Authorization (Optional)

**What happens:**

- Forter validates orders for fraud before creating them in SFCC
- Forter authorizes/captures payments via Forter Payment Orchestration
- Orders are created in SFCC with completed payment status

**Configuration Required:**

Contact your Forter representative to obtain:

| Field                           | Description                                |
|---------------------------------|--------------------------------------------|
| **Validation API Key**          | Forter fraud detection credentials         |
| **Payment API Key**             | Forter payment orchestration credentials   |

**Settings in Portal:**

```javascript
Enable Forter Validation: true
Enable Forter Authorization: true
Enable Forter Capture: true (or false for manual capture)
```

## [Step 4: Catalog Sync & Testing](https://docs.forter.com/quickstart-sfcc#step-4-catalog-sync-testing) Step 4: Catalog Sync & Testing

### [A. Initiate First Sync](https://docs.forter.com/quickstart-sfcc#a-initiate-first-sync) A. Initiate First Sync

After configuring SFCC credentials in the portal:

1. Forter automatically tests the OCAPI connection
2. Initial catalog sync begins (pulls all products via OCAPI)
3. Products are normalized to AI-optimized format
4. Feed is distributed to AI platforms

**Processing Time:**
- < 10,000 products: Minutes
- 10,000 - 100,000 products: Under an hour
- > 100,000 products: A few hours

### [B. Verify Catalog](https://docs.forter.com/quickstart-sfcc#b-verify-catalog) B. Verify Catalog

Check that products were synced by updating inventory for a test product:

```bash
curl -X POST \
 https://{site_id}.agentic.checkouttools.com/v1/inventory \
-H "Authorization: Bearer YOUR_FORTER_API_KEY" \
-H "Content-Type: application/json" \
-d '{
 "id": "TEST-SKU-001",
 "quantity": 100
 }'
```

If the product exists, you'll receive:

```json
{
   "success": true,
   "updated": 1,
   "results":[{"success":true,"id":"TEST-SKU-001"}]
}
```

### [C. Test Checkout Flow](https://docs.forter.com/quickstart-sfcc#c-test-checkout-flow) C. Test Checkout Flow

Test end-to-end checkout in the test environment:

**1. Create a checkout session:**

```bash
curl -X POST \
 https://{site_id}.agentic.checkouttools.com/checkout_sessions \
-H "Authorization: Bearer sk_test_YOUR_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: test-001" \
-d '{
 "items": [{ "id": "TEST-SKU-001", "quantity": 1 }],
 "buyer": {
   "first_name": "Test",
   "email": "test@example.com"
 }
}'
```

**2. Add shipping and complete order:**

```bash
curl -X POST \
 https://{site_id}.agentic.checkouttools.com/checkout_sessions/{session_id}/complete \
-H "Authorization: Bearer sk_test_YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
 "fulfillment_address": {
   "name": "Test User",
   "line_one": "123 Test St",
   "city": "San Francisco",
   "state": "CA",
   "postal_code": "94102",
   "country": "US"
 },
 "payment_data": {
   "token": "tok_test_visa_4242",
   "provider": "test"
 }
}'
```

**3. Verify order in SFCC Business Manager**

The order should appear in: **Merchant Tools > Ordering > Orders**

## [Step 5: Go Live](https://docs.forter.com/quickstart-sfcc#step-5-go-live) Step 5: Go Live

### [Production Checklist](https://docs.forter.com/quickstart-sfcc#production-checklist) Production Checklist

- Replace test OCAPI credentials with production credentials
- Update Forter Portal with production SFCC instance URL
- Verify production catalog sync completes successfully
- Test at least one production order end-to-end
- Configure monitoring and alerting
- Enable AI platform distribution (OpenAI, Google, etc.)

### [Monitoring](https://docs.forter.com/quickstart-sfcc#monitoring) Monitoring

Use the Forter Portal to monitor:

- **Catalog Health** — Product count, sync status, errors
- **Order Volume** — Checkout sessions, completions, failures
- **OCAPI Usage** — API call volume, rate limits
- **Error Rates** — Failed checkouts, SFCC API errors

## [Troubleshooting](https://docs.forter.com/quickstart-sfcc#troubleshooting) Troubleshooting

### ["Invalid OCAPI credentials"](https://docs.forter.com/quickstart-sfcc#invalid-ocapi-credentials)"Invalid OCAPI credentials"
**Solution:**
- Verify Client ID matches OCAPI Shop API settings
- Check Client Secret (no extra spaces)
- Ensure scopes include required tenant ID
- Wait 5-10 minutes for settings to propagate

### ["Insufficient permissions"](https://docs.forter.com/quickstart-sfcc#insufficient-permissions)"Insufficient permissions"
**Solution:**
- Check OCAPI Shop API resources include /baskets/** and /orders/**
- Verify API Client scopes include shopper-baskets-orders
- Confirm OCAPI version matches your instance

### [Products not syncing](https://docs.forter.com/quickstart-sfcc#products-not-syncing) Products not syncing
**Solution:**
- Test OCAPI product_search endpoint with curl
- Check SFCC rate limits (100 req/10s)
- Review Forter Portal logs for sync errors
- Verify products are online and searchable in SFCC

### [Orders not appearing in SFCC](https://docs.forter.com/quickstart-sfcc#orders-not-appearing-in-sfcc) Orders not appearing in SFCC
**Solution:**
- Verify basket creation permissions in OCAPI settings
- Check SFCC Business Manager for failed orders
- Review Forter Portal logs for OCAPI errors
- Confirm site ID is correct

### [SFCC-Specific Considerations](https://docs.forter.com/quickstart-sfcc#sfcc-specific-considerations) SFCC-Specific Considerations

### [Rate Limits](https://docs.forter.com/quickstart-sfcc#rate-limits) Rate Limits

SFCC OCAPI has rate limits:
- **~100 requests per 10 seconds**
- **~1000 requests per minute**

Forter automatically handles rate limiting with exponential backoff.

### [Catalog Size](https://docs.forter.com/quickstart-sfcc#catalog-size) Catalog Size

For large catalogs (>100k products), consider:
- Enabling SFCC search result pagination
- Monitoring initial sync duration
- Using inventory updates for real-time changes

### [Multiple Sites](https://docs.forter.com/quickstart-sfcc#multiple-sites) Multiple Sites

If you have multiple SFCC sites:
- Configure each site as a separate integration in Forter Portal
- Each site gets its own API credentials and configuration
- Orders are routed to the correct site based on Site ID

### [Quick Reference](https://docs.forter.com/quickstart-sfcc#quick-reference) Quick Reference

### [Required OCAPI Resources](https://docs.forter.com/quickstart-sfcc#required-ocapi-resources) Required OCAPI Resources

```json
{
   "products":["get"],
   "product_search":["get","post"],
   "categories":["get"],
   "baskets":["get","post","put","patch"],
   "orders":["get","post"]
}
```

### [Required OCAPI Scopes](https://docs.forter.com/quickstart-sfcc#required-ocapi-scopes) Required OCAPI Scopes

```javascript
shopper-products-read
shopper-categories-read
shopper-search-read
shopper-baskets-orders
```

## [Next Steps](https://docs.forter.com/quickstart-sfcc#next-steps) Next Steps

- [Catalog & Inventory](https://docs.forter.com/catalog-and-inventory-orchestration) — Product data synchronization details
- [Checkout & Payments](https://docs.forter.com/checkout-and-payments) — Payment processing and order management
- [FAQ](https://docs.forter.com/faq) — Common questions

## [Support](https://docs.forter.com/quickstart-sfcc#support) Support

For SFCC-specific integration questions, contact your Forter representative or email [support@forter.com](mailto:support@forter.com).
