# Connecting PrestaShop to an ERP, a CRM or a supplier via API

> Getting PrestaShop to talk to a management system, a CRM or a supplier usually goes through PrestaShop’s native webservice. It covers a good share of common needs, but some resources simply aren’t exposed through it, which changes the nature of the work involved.

- Source canonique : [https://allaux.fr/en/prestashop/problemes/connecter-erp-fournisseur-api](https://allaux.fr/en/prestashop/problemes/connecter-erp-fournisseur-api)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Enable the web service under Advanced Parameters > Webservice, create a key and tick the permissions resource by resource: products, orders, customers. A missing permission returns HTTP 401 or an empty list, never a clear message. Test the call on /api/products?output_format=JSON from a browser before wiring the ERP to it.

## PrestaShop’s native webservice

PrestaShop includes a webservice, enabled under Advanced Parameters > Webservice. It follows a REST logic, with responses in XML or JSON, and relies on an authentication key given precise permissions resource by resource: read, write, or both, for products, orders, customers, and other catalogue entities. This is what lets an ERP, a CRM or an external tool read or write data in PrestaShop without going through the back office.

Correctly configuring the key’s permissions, resource by resource, is the step that handles most straightforward needs: sending orders to an invoicing system, or pulling a supplier catalogue into PrestaShop, for example.

## A real and frequently encountered limit

Not every PrestaShop resource is natively exposed through the webservice. Detailed handling of customer returns or credit notes, for instance, doesn’t always have a direct webservice equivalent. In that case, reaching the goal requires developing a dedicated controller or module that exposes the missing resource, or bridges PrestaShop and the external system for that specific case.

## When the external tool has no API

> If the system on the other side (an older ERP, for instance) offers no API, only file exports, the solution stops being a real-time API: it becomes a scheduled import or export, with its own constraints around frequency and reliability.

## Configuration or development?

Enabling the existing webservice, generating a key and setting its permissions resource by resource is configuration. Building a bespoke gateway becomes necessary as soon as the target resource has no native webservice equivalent, the external system has no standard API, or the sync needs to handle business logic specific to the shop, such as catalogue matching rules.

## Related pages

- **PrestaShop CRON tasks not running** — A scheduled sync with an ERP often depends on a cron job, with its own pitfalls. ([/prestashop/problemes/taches-cron-ne-sexecutent-pas](/prestashop/problemes/taches-cron-ne-sexecutent-pas))
- **Bespoke PrestaShop module development** — For exposing a resource missing from the native webservice or building a gateway to a system without an API. ([/prestashop/module-sur-mesure](/prestashop/module-sur-mesure))
- **Exporting the PrestaShop catalogue or orders as CSV, Excel or PDF** — A relevant alternative when the external system only accepts files, not an API. ([/prestashop/problemes/export-catalogue-commandes-csv](/prestashop/problemes/export-catalogue-commandes-csv))

## FAQ

### Does the PrestaShop webservice work the same way on 1.6 and on 1.7 or 8?

The general principle — key, permissions per resource, REST in XML or JSON — is the same. What can change is which resources are natively available, which evolves from one version to another.

### Can stock be synchronised in real time between PrestaShop and an ERP?

The webservice allows one-off calls, not a native continuous stream. True real time generally needs a trigger on the ERP or PrestaShop side for every change, via dedicated development rather than a simple activation.

### My supplier has no API, how can I pull their catalogue automatically?

If they provide a regular file export (CSV, XML), the solution becomes a scheduled import that reads that file at fixed intervals rather than a standard API connection.

### Can customer returns or credit note handling go through the standard webservice?

Not always directly: it’s one of the resources frequently missing from the native webservice. Depending on the exact need, this requires a dedicated controller or module to bridge the gap.

### Is it risky to give an external system API access?

The risk stays limited if the authentication key only holds the permissions strictly needed, resource by resource. That’s a setting to check before going live, not after.
