Imagine your online store sells 10,000 products, and supplier changes prices twice a day. Manual Excel upload takes hours and leads to outdated prices and stock errors. Direct integration via supplier API solves this — data updates automatically without human involvement. Over 10 years, we have implemented more than 50 such integrations, from simple REST links to multi-supplier systems with OAuth 2.0 and SOAP. Our experience confirms that the right architecture ensures stability and data accuracy. For instance, for an auto parts store with 500,000 SKUs, we set up incremental synchronization with 5 suppliers, each with its own API. Result: prices and stock are accurate with a delay of no more than 15 minutes.
The challenge is that supplier APIs vary greatly. Authentication formats, response structures, pagination models — all are unique. Without proper architecture, integration turns into chaos. We use proven patterns that simplify adding new suppliers and ensure stability.
How to choose the API type for a supplier?
| Type | Example | Specifics |
|---|---|---|
| REST JSON | Most modern | Cursor/offset pagination, JWT/API-key |
| REST XML | Legacy systems (1C) | Need XML response parser |
| SOAP | Corporate ERP | WSDL, SOAPClient |
| GraphQL | Rare among suppliers | Flexible field selection |
| oData | SAP, Microsoft | $filter, $top, $skip |
Determining the type is the first step. We always start by analyzing the supplier's documentation: if there is a REST API specification, half the work is done.
Basic client with retry and rate limiting
class SupplierApiClient { private \GuzzleHttp\Client $http; private RateLimiter $rateLimiter; public function __construct( private SupplierApiConfig $config, ) { $this->http = new \GuzzleHttp\Client([ 'base_uri' => $config->baseUrl, 'timeout' => 30, 'handler' => $this->buildHandlerStack(), ]); } private function buildHandlerStack(): \GuzzleHttp\HandlerStack { $stack = \GuzzleHttp\HandlerStack::create(); $stack->push(\GuzzleHttp\Middleware::retry( function (int $retries, $request, $response, $exception) { if ($retries >= 3) return false; if ($exception instanceof \GuzzleHttp\Exception\ConnectException) return true; if ($response && $response->getStatusCode() >= 500) return true; return false; }, fn(int $retries) => 1000 * (2 ** $retries) )); return $stack; } public function get(string $path, array $params = []): array { $this->rateLimiter->throttle($this->config->id, $this->config->rateLimit); $response = $this->http->get($path, [ 'query' => $params, 'headers' => $this->buildHeaders(), ]); return json_decode($response->getBody(), true); } private function buildHeaders(): array { return match ($this->config->authType) { 'bearer' => ['Authorization' => 'Bearer ' . $this->config->token], 'api_key' => ['X-API-Key' => $this->config->apiKey], 'basic' => ['Authorization' => 'Basic ' . base64_encode( $this->config->login . ':' . $this->config->password )], default => [], }; } } Exponential backoff (1s, 2s, 4s) reduces load on the supplier's server and increases success probability during transient failures. Rate limiting prevents blocking due to exceeding request limits.
Why is data normalization important?
Each supplier has its own JSON field for name, price, SKU. Without normalization, the code becomes messy — checks and extractions everywhere. We use a fieldMap with dot-notation, stored in the database as JSON. Adding a new supplier is just an entry in the table, with no code changes.
class SupplierResponseNormalizer { private array $fieldMap; public function normalize(array $raw): array { return [ 'sku' => $this->extract($raw, $this->fieldMap['sku']), 'name' => $this->extract($raw, $this->fieldMap['name']), 'price' => (float) $this->extract($raw, $this->fieldMap['price']), 'qty' => (int) $this->extract($raw, $this->fieldMap['qty']), 'description' => $this->extract($raw, $this->fieldMap['description']), 'images' => $this->extractImages($raw), ]; } private function extract(array $data, string $path): mixed { return data_get($data, $path); } } When is incremental synchronization needed?
Incremental synchronization is indispensable when data volume is large or update frequency is high. It requests only changes since the last update, using the updated_after parameter. The time of the last successful sync is stored in the database. This reduces data transfer volume many times over — in one project with 500,000 SKUs, API load dropped by 90%.
Pagination and method comparison
| Type | Simplicity | Efficiency with shifts | Transfer volume |
|---|---|---|---|
| Offset | High | Low | Full reset |
| Cursor | Medium | High | Only diff |
| Scroll | Low | High | Streaming |
Cursor pagination is up to 10 times more efficient than offset for large datasets under frequent changes because it uses a unique identifier for the last record. Offset is simple but inefficient when data shifts. For large volumes, we recommend cursor or scroll.
OAuth 2.0 authorization
Many suppliers require OAuth 2.0 client credentials. The token is cached until expiration — eliminating extra requests.
class OAuth2TokenProvider { private ?string $accessToken = null; private ?int $expiresAt = null; public function getToken(): string { if ($this->accessToken && time() < ($this->expiresAt - 60)) { return $this->accessToken; } $response = Http::asForm()->post($this->tokenUrl, [ 'grant_type' => 'client_credentials', 'client_id' => $this->clientId, 'client_secret' => $this->clientSecret, 'scope' => 'products:read stocks:read', ]); $data = $response->json(); $this->accessToken = $data['access_token']; $this->expiresAt = time() + $data['expires_in']; return $this->accessToken; } } SOAP client for 1C-compatible suppliers
For integration with 1C-based systems, we use SOAP. WSDL documentation describes methods and data structures.
$client = new \SoapClient($this->wsdlUrl, [ 'login' => $this->login, 'password' => $this->password, 'encoding' => 'UTF-8', 'soap_version' => SOAP_1_2, 'cache_wsdl' => WSDL_CACHE_DISK, ]); $result = $client->GetProductList([ 'DateFrom' => $since->format('Y-m-d\TH:i:s'), 'Categories' => $this->categoryFilter, ]); foreach ($result->Products->Product as $product) { yield (array) $product; } Typical issues and solutions
| Issue | Solution |
|---|---|
| Different field formats | Normalization via fieldMap |
| Network failures | Retry with exponential backoff |
| Exceeding request limits | Rate limiting + queue |
| Outdated stock | Incremental sync (90% data reduction) |
| Slow pagination | Cursor pagination (10x faster than offset) |
What’s included in the work
- Analysis of supplier API documentation (OpenAPI, WSDL, Postman collections).
- Development of client with retry, rate limiting, authentication (OAuth 2.0, API-key, Basic).
- Implementation of pagination (offset, cursor, scroll).
- Normalization of fields to a unified format (sku, name, price, qty).
- Configuration of incremental synchronization by updated_after.
- Stability testing under network failures and timeouts.
- Integration documentation (data schema, configuration, instructions for adding a new supplier).
- Training of your team (1–2 hour workshop).
- One month of support after launch (bug fixes, tuning).
Implementation timelines and cost
We deliver turnkey. Approximate timelines and cost:
- One REST supplier with offset pagination and normalization — from 2 days, cost starting at $2,000.
- Adding OAuth 2.0, cursor pagination, and incremental sync — +1 day, +$1,000.
- Multi-supplier with configurable settings, SOAP, rate limiting — +2 days, +$2,000.
Timelines are approximate — an accurate estimate is given after analyzing the supplier's documentation. With 10+ years of experience, we guarantee a smooth integration. Request a preliminary assessment of your project — we will calculate the timeline and cost individually. Contact us, and we will prepare a detailed proposal. Get a consultation — we will evaluate your project within one business day.







