Choose the feed that delivers the necessary fields with traceable updates and safe resumability, not the one whose name sounds the most modern. A complete CSV dropped daily can be preferable to an API with no timestamp or reliable pagination. An API becomes attractive for frequent changes and targeted queries; XML suits nested, documented structures; FTP is a transfer channel, often used to drop files, not a catalog format. Before deciding, test the documentation, the volume, the limits, the identifiers, the price, the stock, the security, and the behavior during an interruption.
Separate format, transport, and access contract
CSV and XML mainly describe a data representation. HTTP and FTP describe exchange mechanisms. A "JSON API" generally combines an application contract, JSON documents, and HTTP transport. An "FTP feed" can contain a CSV, an XML file, an archive, or several files. Mixing these levels leads to false comparisons.
RFC 4180 documents a commonly used CSV format and its MIME type. It notably describes rows, separators, and the escaping of quoted fields, but it does not define the price, stock, or ean columns. The W3C XML recommendation defines the syntax and well-formedness of XML documents; it likewise does not provide the supplier's business schema. In both cases, the producer's documentation remains essential.
FTP, historically standardized by RFC 959 and supplemented by later updates, is used for transferring files between hosts. Its existence does not mean the connection is encrypted or that the content is recent. You need to verify the protocol actually offered, the authentication method, the transport protections, and the access rotation policy without exposing any secret in logs.
A fact-based decision matrix
| Option | Typical strength | Risk to check | Good use case |
|---|---|---|---|
| CSV | Easy to archive, compare, and replay | Encoding, separator, flat columns, large full files | Stable periodic export |
| XML | Hierarchical structure and possible schema | Namespaces, malformed documents, nesting complexity | Structured products, variants, and offers |
| HTTP API | Targeted queries, pagination, frequent updates | Quotas, authentication, pagination, versions, partial errors | Stock or prices checked regularly |
| FTP drop | Automated file delivery | Channel security, incomplete files, naming convention | Large scheduled exports |
This matrix does not rank a technology in the absolute. It surfaces the questions the supplier must document. A feed should be judged on real evidence: a sample response, a data dictionary, an announced cadence, terms of use, a resumption method, and an incident contact.
The criteria that actually decide
Business completeness
List the non-negotiable fields before discussing technology: product and variant identifier, SKU, brand, title, price, currency, excl./incl. VAT nature, stock with its precision level, sales unit, MOQ, order increment, image, and timestamp. Use the wholesale catalog column grid to avoid a technical demo masking the absence of an essential data point.
Freshness and proof of change
Ask whether the feed is full or incremental. For a full file, look for a generation date and a mechanism preventing reads before the drop is complete. For an API, document pagination, stable sorting, cursors, and the semantics of deletions. The HTTP ETag and Last-Modified fields are validators defined by RFC 9110, but their presence and meaning depend on the server. They do not replace a business timestamp for price or stock.
The trust window for prices and stock should be chosen based on commercial risk. A specifications catalog may evolve slowly; availability can change between two orders. The same cycle does not necessarily suit both families of fields.
Resumption and idempotence
Simulate an interruption. Can you resume at the next page without missing or duplicating products? Does a file have a temporary name before being declared complete? Does an API provide a stable identifier and order? Updates must be idempotent: replaying the same document must not multiply the offers.
Archive the checksum of the accepted content, the collection date, the URL or file name, and the parser version. This traceability lets you understand whether a difference comes from the supplier or from your own transformation.
Security and rights
Never place an API key in code, in the produced CSV, or in an error message. Limit access to the necessary scope and follow the supplier's rotation procedure. Also check the license or terms of use: a technically accessible resource is not automatically authorized for commercial reuse. RFC 9309 also notes that robots.txt is not a form of access authorization.
Nine-step selection test
1. Obtain the official documentation and terms of use. 2. List the required fields and their definitions. 3. Check a small sample including variants, stockouts, and empty values. 4. Measure the volume and understand pagination or file splitting. 5. Identify frequency, timestamps, and change signals. 6. Trigger a controlled error and observe the code, message, and recovery. 7. Replay the same extract to check for absence of duplicates. 8. Compare the data against authorized official listings. 9. Run a supplier canary batch before scaling up volume.
At the end, write a decision sheet with three columns: "proven," "not provided," and "to confirm." The word "supported" should only be used if a test or official documentation demonstrates it.
Connection checklist
- Format and transport are identified separately.
- The business schema and units are documented.
- Pagination, quotas, and volume have been tested.
- The generation timestamp is available or marked absent.
- Resumption after an interruption has been verified.
- Deletions and stockouts have clear semantics.
- Secrets stay out of files and logs.
- The terms allow the intended use.
- Raw responses and their checksums are archived.
- The canary passes before the full import.
What ArbitragePro+ can automate / what the seller must verify
The proposed diagnostic-flux specification could check structure, types, pagination, identifier stability, checksums, and errors of a canary batch. It could compare the fields provided against the declared requirements, without claiming to define the supplier's contract.
The seller must choose the authorized source, obtain access, confirm the tax basis and units, assess channel security, and then validate that the frequency suits their order model.
Identify the right connection
View the sources tracked by ArbitragePro+ to review the information available for each connection.
Official sources
- IETF, RFC 4180, «Common Format and MIME Type for CSV Files», https://www.rfc-editor.org/info/rfc4180/ — accessed 2026-08-17.
- W3C, «Extensible Markup Language (XML) 1.0», https://www.w3.org/TR/xml/ — accessed 2026-08-17.
- IETF, RFC 9110, «HTTP Semantics», https://www.rfc-editor.org/rfc/rfc9110.html — accessed 2026-08-17.
- IETF, RFC 959, «File Transfer Protocol», https://www.rfc-editor.org/info/rfc959/ — accessed 2026-08-17.
- IETF, RFC 9309, «Robots Exclusion Protocol», https://www.rfc-editor.org/rfc/rfc9309.html — accessed 2026-08-17.
