Ecommerce
BigCommerce
Send order webhooks to OrcLink. OrcLink reads each order from your store with an API token, so the order is the store's own record.
Live: shipped in OrcLink's production release before this one. Built, not yet tested live: built and tested with sample data, not yet run against a live account of the vendor. Coming soon: listed, not available to connect yet.
How to connect
- Dashboard > Integrations > BigCommerce: paste Store hash, API token and webhook secret (store_hash:api_token:webhook_secret), then Connect. It is stored encrypted and never shown again.
What OrcLink reads
- Order webhooks, then the order and its refunds read from your store with your API token: the order in OrcLink is the store's own record.
What OrcLink writes back
- The optional checkout script (experimental) writes the click id into the order comment, which the shopper can see and BigCommerce prints on invoices.
Never stored
- Raw email addresses and phone numbers: hashed (SHA-256) the moment they arrive.
- The raw payload: only its SHA-256, for provenance.
- Your credentials and webhook secrets in clear: they are stored encrypted (AES-256-GCM).
Known limits
- Not yet run against a real store.
UNTESTED on a real store. The adapter (app/lib/outcomes/sources/bigcommerce.ts) and its order fetch are tested against fixtures and a fake API built from the public BigCommerce v2 / v3 shapes; the fetch has never run against BigCommerce, and the checkout script has never run on a storefront.
How it works
BigCommerce webhooks carry no signature and no order: they say which order changed (store/order/statusUpdated, store/order/created, ...). OrcLink checks a secret header you set on the webhook, then reads the order and its refunds from your store with an API token. So the order in OrcLink is the store's own record, never the webhook's.
1. Make an API account
BigCommerce admin > Settings > API > Store-level API accounts > Create API account. Token scopes: Orders: read-only and Order Transactions: read-only. Keep the store hash (the abc123 in https://api.bigcommerce.com/stores/abc123/v3/) and the access token.
2. Connect in OrcLink
Pick a long webhook secret (openssl rand -hex 32). Dashboard > Integrations > BigCommerce: paste store_hash:api_token:webhook_secret (for example abc123:xxxxxxxxxxxx:0123...) and Connect. Copy the webhook URL. The three values are stored encrypted in one value (the connect form takes one field). A value in another form is refused at connect (400, with the form to use).
The connection is bound to the store hash you paste (one store per connection); a webhook from another store hash is ignored with a note.
3. Create the webhook through the API
curl -X POST https://api.bigcommerce.com/stores/STORE_HASH/v3/hooks \
-H "X-Auth-Token: ACCESS_TOKEN" -H "Content-Type: application/json" -H "Accept: application/json" \
-d '{"scope":"store/order/*","destination":"<OrcLink webhook URL>","is_active":true,
"headers":{"X-Orclink-Secret":"<the webhook secret>"}}'store/order/* covers created, updated, status updated and refund created. OrcLink reads only those four; every other order scope (messages, transactions, archived) is ignored without a fetch. A webhook whose producer is another store hash is ignored with a note.
4. The tag and the click id
Storefront > Script Manager > Create a script (two scripts):
- Name
OrcLink tag, location Header, pages All pages, category Analytics, type Script:<script async src="https://t.YOURDOMAIN.com/t.js?w=WORKSPACE_ID" data-w="WORKSPACE_ID"></script>(as a "Script contents" snippet, without the outer tag if the form asks for JS only). - Experimental. Name
OrcLink order click id, location Footer, pages Checkout, category Functional, type Script: the contents oforclink-checkout.js.
Step 2 is experimental and has never run on a real storefront. It keeps one line orclink_olid=ol_... in the shopper's order comment (customer_message) through the Storefront Checkout API. Each time the checkout page loads it writes or replaces the line from a valid orc_olid cookie, and removes an older line when there is no valid cookie (no consent, consent withdrawn, expired). Limits, plainly:
- The click id is written into the shopper-visible order comment, so the shopper and the merchant can see it, and BigCommerce prints the comment on invoices and packing slips. The Storefront API offers no hidden field for it (order metafields are server-side only).
- A shopper can type the line by hand. OrcLink bounds that: an olid matches an order only when its click happened before the order, and an olid on orders of many different customers stops matching (see the help page).
- The checkout page keeps its own copy of the comment and can rewrite it (when the shopper types in the box or continues), which loses the line.
- Without the line, the order is still recorded, but unattributed (or matched by the buyer's hashed email when an earlier order carried the olid).
A more reliable path would write an order metafield from a small server-side piece after the created webhook; that is not built, and OrcLink does not read metafields yet.
What OrcLink does with an order
BigCommerce status_id | OrcLink |
|---|---|
| 2 Shipped, 3 Partially Shipped, 8 Awaiting Pickup, 9 Awaiting Shipment, 10 Completed, 11 Awaiting Fulfillment, 13 Disputed, 14 Partially Refunded | order won (paid), value = total_inc_tax in default_currency_code (the currency the shopper pays in; currency_code, the display currency, only when the first is absent: check one multi-currency order) |
| 0 Incomplete, 1 Pending, 6 Declined, 7 Awaiting Payment, 12 Manual Verification Required | open |
| 5 Cancelled | cancelled |
| 4 Refunded | won, net value 0 |
a refund (/v3/orders/{id}/payment_actions/refunds, total_amount) | one revision per refund id that lowers net value |
payment_provider_id = testgateway | test order (never revenue) |
| any other status id | ignored; the integration shows a fixed note |