Custom commercetools integration development
Appfront builds custom commercetools integrations for headless and composable e-commerce. Through the commercetools HTTP/REST and GraphQL API, we connect your catalogue, carts, orders and customers to your frontend, ERP, PIM or own application. With OAuth2 scopes, API Extensions and Subscriptions you keep control over permissions and synchronise in real time, without vendor lock-in on your storefront.
What is a commercetools integration?
commercetools is a composable commerce platform built on the MACH principles: Microservices, API-first, Cloud-native and Headless. Rather than one rigid webshop, it offers loosely coupled, API-driven building blocks for catalogue, carts, orders, customers, prices and discounts. You decide which frontend, checkout and surrounding systems to connect to it, and you can renew each component independently.
In practice, a custom commercetools integration means: reading and updating products and categories through the HTTP/REST or GraphQL API, setting up OAuth2 clients with fine-grained scopes per project and store, connecting cart and order flows to your checkout, synchronising customer data with your CRM, and building event-driven processes with Subscriptions so that external systems stay in real-time sync.
Appfront builds according to the official commercetools HTTP API documentation and the OWASP ASVS security standard. We align scopes, queries, API Extensions and error handling with your actual commerce processes, so the integration grows with your range and international catalogues and continues to run reliably even at peak volumes.
Headless catalogue
You manage products, variants, attributes and categories through the HTTP/REST or GraphQL API. Your frontend determines the presentation itself; the catalogue remains the single source of truth and can be managed centrally across all sales channels.
Carts & orders
Shopping carts, prices, discounts and orders run through the cart and order API, with optimistic concurrency based on version numbers. This keeps checkout and back office consistent, even with simultaneous updates and high volumes.
Event-driven sync
With Subscriptions, you receive real-time events when orders, products or customers change, via Google Cloud Pub/Sub, AWS SNS/SQS or Azure Event Grid. API Extensions add synchronous validation or enrichment to an API call.
Our development process for commercetools integrations
We work to a proven methodology that removes uncertainty early and delivers a stable integration. From an initial analysis of your commerce processes, projects and scopes through to go-live and ongoing management, every step is aimed at an integration your team can understand and trust.
We map out which resources you want to connect (catalogue, carts, orders, customers), which projects and stores are involved, which OAuth2 scopes are required, and whether event-driven processes via Subscriptions are needed.
We design the integration architecture, choose between HTTP/REST and GraphQL per use case, set up OAuth2 clients with least-privilege scopes, and define an error handling and retry strategy.
Implementation of the queries, API Extensions and Subscriptions, with automated tests, structured logging and monitoring. You see working builds along the way.
Controlled go-live with data validation and a safety net, followed by ongoing management, rotation of client credentials and further development.
What a commercetools integration delivers in practice
Every commercetools integration is tailored to your catalogue, commerce flows and surrounding systems. Below are the features we most often deliver for organisations using commercetools as the core of their composable commerce stack.
HTTP/REST API & OAuth2
Authentication via OAuth2 with access tokens and fine-grained scopes, such as manage_products or view_customers per project, or store-bound scopes. Each integration receives exactly the permissions it needs, and all requests run over HTTPS with optimistic concurrency.
GraphQL API
The GraphQL API lets your frontend request exactly the fields it needs — less over- and under-fetching, and faster storefronts. Access uses the same scopes as the REST endpoints, so permissions remain consistent across both APIs.
Product & catalogue sync
We synchronise product types, variants, attributes, categories and prices between your PIM or ERP and commercetools. With user-defined keys, data stays consistent across staging and production, and international catalogues remain centrally manageable.
Carts & orders
We connect carts, line items, discounts and orders to your checkout and back office. Version-based updates prevent race conditions, and order events can flow straight into your ERP, OMS or fulfilment systems via Subscriptions.
Customers & customer groups
You manage customer accounts, addresses and customer groups through the API, with separate view and manage scopes. You synchronise customer data securely with your CRM, and groups form the basis for B2B pricing and segment-specific discounts.
API Extensions & Subscriptions
API Extensions run your own logic synchronously when a call is made on carts, orders, payments or customers — for validation or enrichment. Subscriptions deliver events asynchronously to message brokers (Pub/Sub, SNS/SQS, Event Grid) in CloudEvents format, for reliable event-driven webhooks.
Typical use cases in practice
A commercetools integration looks very different from one organisation to the next. We see a number of patterns recur, and for each we have a working setup that pays close attention to scopes, catalogue sync and the right cart, order and event logic.
Enterprise retail
Large retailers and brands building a headless storefront on commercetools who want to manage their catalogue, prices and orders centrally across web, app and marketplaces. We connect frontend, PIM and ERP via REST and GraphQL. See also our e-commerce development and API integrations.
B2B commerce
Wholesalers and manufacturers with customer-specific pricing, business units, approval flows and orders on account. Customer groups and store-scoped permissions allow separate catalogues and prices per customer group, with orders flowing through to your ERP. See also middleware.
Headless & composable
Organisations that want to renew their frontend, checkout and backend independently, in line with MACH principles. We build the integration layer between commercetools and your own storefront, payment providers and search or CMS systems. See also our web app development.
International & multichannel
Brands selling in multiple countries, languages and currencies across web, app, marketplaces and physical channels. With multiple projects, stores and local catalogues, we serve every channel from a single platform, while Subscriptions keep external systems synchronised in real time.
Technology we use
We build commercetools integrations with the official HTTP/REST and GraphQL APIs, combined with the backend stack that suits you. The precise choice depends on your frontend, message broker and surrounding systems, following MACH and composable principles so that your own team can manage or renew each component independently.
Why choose Appfront for your commercetools integration?
Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands. We always start with a thorough analysis of your existing systems and processes. An integration should not only work technically, but also add practical value to the way you work.
For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.
You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.
Explore our wider services around API integrations, middleware, e-commerce development, custom software and web app development. Working with a different platform? See our integrations for Shopware and BigCommerce too.
- Experience with the commercetools HTTP/REST and GraphQL APIs
- Familiar with OAuth2 scopes, projects, stores and channels
- Builds event-driven integrations with API Extensions and Subscriptions
- Thinks in terms of MACH and composable architecture, not just code
- Secure by default: client credential rotation, signature validation, least-privilege scopes
- Structured error handling and retry mechanisms
- Comprehensive logging and monitoring from day one
- Clear documentation your team can read and manage
- A fixed point of contact, no account managers passed around
- Ongoing maintenance and proactive further development
Security and privacy in commercetools integrations
Orders and customer accounts always contain personal data, and catalogue and pricing data is commercially sensitive. Appfront builds in line with commercetools security best practices and the OWASP ASVS. This includes: client credentials stored in secure vaults, signature validation on incoming Subscription events, least-privilege OAuth2 scopes per project and store, and regular audits of the order and customer flows.
commercetools operates API-first over HTTPS with TLS and OAuth2, where each API client receives only the scopes strictly required, for example view_customers rather than manage_customers where reading is sufficient. We document the data flows, scopes and customer personal data processed so that your record of processing activities is complete and you can demonstrably comply with the GDPR.
More on our security approach: information security policy and CVD policy.
- GDPR-compliant data processing and data minimisation
- Encryption in transit (TLS 1.2+) and at rest
- Least-privilege OAuth2 scopes per project and store
- Audit logs with traceable data flows
- Automatic retries and dead-letter queues
- Monitoring and alerting for anomalies
- Secrets management in line with best practice
- Documentation for your record of processing activities
Frequently asked questions about commercetools integrations
Answers to the questions we are asked most often about commercetools implementations.
A commercetools integration is a technical integration between the commercetools platform and another system, such as your headless frontend, ERP, PIM, OMS or in-house application. Products, categories, carts, orders and customers are read and updated programmatically via the commercetools HTTP/REST API and the GraphQL API. Authentication runs via OAuth2 with scoped access tokens. With API Extensions you add your own business logic synchronously to an API call, and with Subscriptions you receive events asynchronously whenever something changes in a project.
commercetools is a composable commerce platform built on the MACH principles: Microservices, API-first, Cloud-native and Headless. It suits enterprise and mid-market retailers who want to define their own frontend and customer experience, manage international catalogues and multiple sales channels, or serve both B2C and B2B from a single platform. If you need a simple, standardised webshop, we will work with you to determine whether a more traditional platform is a better fit.
A first integration, such as setting up OAuth2 authentication and reading a product catalogue via the HTTP API or GraphQL, can go live relatively quickly. A full composable setup with catalogue sync from a PIM, cart and order flows, customer integration and event-driven processes via Subscriptions usually takes longer. After an intake conversation in which we map out your projects, scopes and data flows, we give you a realistic estimate.
We work with the official commercetools HTTP/REST API and GraphQL API, with OAuth2 for authentication and fine-grained scopes per resource. On the backend we choose the stack that suits you best, whether Node.js, Java, Python, PHP, .NET or Go. For event-driven integrations we use Subscriptions on a message broker such as Google Cloud Pub/Sub, AWS SNS/SQS or Azure Event Grid, with CloudEvents as the format. We handle synchronous validation and enrichment with API Extensions.
The cost depends on the number of systems to be integrated, the complexity of the catalogue and order data flows, the scopes and stores required, and the amount of custom business logic built with API Extensions and Subscriptions. Ongoing management, monitoring and support also affect the total investment. We always provide a clear quote following a no-obligation analysis of your situation.
Yes. commercetools works API-first over HTTPS with OAuth2 and scoped access tokens, so each integration only receives the permissions it strictly needs. Appfront builds in line with OWASP ASVS: client credentials stored in secure vaults, least-privilege scopes per project and store, signature validation on incoming Subscription events, and separate permissions per integration. We document the data flows, including personal data of customers that is processed, so your record of processing activities remains complete and you can demonstrate GDPR compliance.
Yes. Appfront regularly takes over existing commercetools integrations, even if they were originally set up by another party or system integrator. We review the API clients and scopes, the GraphQL and REST queries, the API Extensions and Subscriptions, and the error handling, document the current setup and propose improvements. From that point on, we can handle changes, extensions and monitoring, including timely rotation of client credentials.
commercetools is aimed at enterprise and mid-market e-commerce businesses that want to work headless or composable: international retailers with multiple catalogues and channels, brands serving both B2C and B2B customers, and organisations that want to renew their frontend, checkout and backend independently. Typical use cases include a headless storefront on the catalogue and cart APIs, syncing product data with a PIM, passing orders on to an ERP or OMS, and event-driven processes via Subscriptions. For small, standardised webshops, we will work with you to determine whether a simpler platform would be a better fit.
Ready to build your commercetools integration?
Tell us which resources you want to connect (catalogue, carts, orders or customers) and which frontend, PIM, ERP or message broker commercetools needs to work with. We're happy to think along with you on scopes, API Extensions, Subscriptions and the composable architecture. A no-obligation first advisory conversation will quickly give you a clear picture of what's possible.