Systems atlas
Construction systems atlas: how each one connects
API style, authentication, webhooks, sandboxes and the objects that matter for 17 systems contractors run, checked against each vendor's own documentation. Unknowns are marked, not guessed.
Last verified October 2026. Confirm details with each vendor before you build.
Browse systems
17 of 17 systems
Project management · Procore Technologies
Procore
Procore exposes a large REST API (our generated MCP server produced 2,755 tools from its OpenAPI spec) with OAuth 2.0, free developer sandboxes and webhooks. Rate limits are enforced per hour and per 10 seconds, with no fixed default published; read the headers rather than hard-coding a number.
- API
- REST
- Auth
- OAuth 2.0 (auth code, DMSA)
Project management · Autodesk
Autodesk Construction Cloud
Autodesk Construction Cloud (presented as part of the Autodesk Forma industry cloud brand since March 24, 2026) is reached through Autodesk Platform Services: REST APIs for issues, RFIs, submittals, cost, forms and files, with OAuth, webhooks and a Data Connector for bulk CSV extracts.
- API
- REST (APS)
- Auth
- OAuth 2.0 (2- and 3-legged)
Project management · Trimble
Trimble ProjectSight
ProjectSight has a versioned REST API with an OpenAPI definition, a .NET SDK and public samples. Access goes through the ProjectSight team rather than self-service sign-up.
- API
- REST (OpenAPI, .NET SDK)
- Auth
- Trimble Identity OAuth 2.0
Project management · Trimble
Trimble Connect
Trimble Connect's REST APIs cover projects, files, models, ToDos and BCF topics. There are no client credentials and no webhooks, so server-side syncs run on a user's refresh token and poll for changes.
- API
- REST (+ BCF API)
- Auth
- OAuth 2.0 auth code + PKCE
ERP & accounting · Trimble
Viewpoint Vista
The Vista API is a paid REST add-on for cloud-hosted Vista on Trimble Construction One, run on Trimble App Xchange; on-premises Vista needs a different route. Reads come from a cache refreshed about hourly; writes are queued actions you check afterwards.
- API
- REST (App Xchange)
- Auth
- API key
ERP & accounting · Trimble
Trimble Spectrum
Spectrum (formerly Viewpoint Spectrum) integrates through Spectrum Data Exchange: SOAP web services on the customer's server, controlled by an Authorization ID scoped to companies and services, with Basic or OAuth-based Enhanced authentication.
- API
- SOAP web services
- Auth
- Authorization ID + Basic / OAuth
ERP & accounting · Sage
Sage 300 CRE
Sage 300 Construction and Real Estate (formerly Timberline) runs on the contractor's own server. Integrations use an on-premises Web API licensed through Sage's development partner program, or ODBC reads.
- API
- On-prem REST + ODBC
- Auth
- Partner key + Windows login
ERP & accounting · Sage
Sage Intacct Construction
Sage Intacct (including the construction edition) is cloud accounting with a REST API, which Sage recommends for new work, and a legacy XML Web Services API. Concurrency, not requests per minute, is the limit you hit first.
- API
- REST + legacy XML
- Auth
- OAuth 2.0 / sender ID
ERP & accounting · Intuit
QuickBooks Online
The QuickBooks Online Accounting API is a well-documented REST API with free sandbox companies, webhooks and published throttles. The construction catch: there are no first-class jobs, so you map them to customers, sub-customers or projects.
- API
- REST (+ GraphQL)
- Auth
- OAuth 2.0 auth code
ERP & accounting · CMiC
CMiC
CMiC publishes a REST API grouped by module (project management, general ledger, HCM and more) with documented throttles, a 1,000-record cap and webhooks. Basic authentication is being retired in favor of OAuth through the customer's identity provider.
- API
- REST
- Auth
- OAuth via IdP (Basic until 2027)
ERP & accounting · Foundation Software
Foundation Software
FOUNDATION construction accounting offers a REST API through a gated onboarding program: a commercial evaluation first, then a sandbox, then production keys. Rate limits depend on the tier you're assigned.
- API
- REST (OpenAPI)
- Auth
- Subscription key + bearer token
Scheduling · Oracle
Oracle Primavera P6
P6 EPPM exposes a large REST API and SOAP web services; P6 Professional and many schedulers exchange XER files. Oracle documents OAuth only for P6 hosted on Oracle Cloud; on-premises installs use basic authentication.
- API
- REST + SOAP + XER/XML files
- Auth
- Basic / OAuth (OCI only)
Scheduling · Microsoft
Microsoft Project
Microsoft Project Online retired on September 30, 2026, and Project for the web moved into Planner. New integrations go through Planner premium plans on Dataverse, or through MPP and Project XML files from the desktop app.
- API
- Dataverse + schedule APIs; MPP/XML files
- Auth
- Entra ID (licensed user)
Estimating & field · HCSS
HCSS HeavyJob & HeavyBid
HCSS publishes REST APIs for HeavyJob, HeavyBid pre-construction, Equipment360, Safety and more, with OAuth client credentials, scoped access, webhooks, and a company-wide rate limit.
- API
- REST
- Auth
- OAuth 2.0 client credentials
CRM · HubSpot
HubSpot
HubSpot's REST APIs cover contacts, companies, deals and custom objects, with OAuth or static tokens, free developer test accounts, webhooks, and published per-app and per-account limits.
- API
- REST
- Auth
- OAuth 2.0 / static token
CRM · Salesforce
Salesforce
Salesforce offers REST, SOAP, Bulk and Pub/Sub APIs, Change Data Capture and platform events, with free Developer Edition orgs. New integrations authenticate through External Client Apps.
- API
- REST, SOAP, Bulk, Pub/Sub
- Auth
- OAuth 2.0 (External Client App)
Reporting destination · Microsoft
Microsoft Fabric & Power BI
Fabric and Power BI are where construction data usually lands, not where it starts. Pipelines and notebooks write to a OneLake lakehouse; Power BI reads the semantic model. The limits that matter are refresh counts and API throttles.
- API
- REST + OneLake (ADLS)
- Auth
- Entra ID / service principal
Connect any two systems
Pick a pair to see what usually moves between them, who should own each record, and where to start.
Procore ↔ Viewpoint Vista
Objects that usually sync
- Jobs / projects
- Vendors / companies
- Cost codes and cost types
- Budgets
- Commitments
- Change orders
- AP invoices
- Actual costs
Direction and ownership
- Accounting usually owns jobs, vendors and cost codes; they flow into project management.
- Commitments and change orders are typically created in project management and pushed to accounting on approval.
- Actual costs flow from accounting back to project management or into a reporting model.
Comparison matrix
The short version. Each system page has the detail and the sources.
Procore
- API style
- REST
- Auth
- OAuth 2.0 (auth code, DMSA)
- Webhooks / events
- Yes (v4.0)
- Sandbox
- Yes, free
Autodesk Construction Cloud
- API style
- REST (APS)
- Auth
- OAuth 2.0 (2- and 3-legged)
- Webhooks / events
- Yes
- Sandbox
- APS free tier
Trimble ProjectSight
- API style
- REST (OpenAPI, .NET SDK)
- Auth
- Trimble Identity OAuth 2.0
- Webhooks / events
- Not documented
- Sandbox
- Not confirmed
Trimble Connect
- API style
- REST (+ BCF API)
- Auth
- OAuth 2.0 auth code + PKCE
- Webhooks / events
- None (poll)
- Sandbox
- Not confirmed
Viewpoint Vista
- API style
- REST (App Xchange)
- Auth
- API key
- Webhooks / events
- Via App Xchange flows
- Sandbox
- Paid test environment
Trimble Spectrum
- API style
- SOAP web services
- Auth
- Authorization ID + Basic / OAuth
- Webhooks / events
- Not documented
- Sandbox
- Not confirmed
Sage 300 CRE
- API style
- On-prem REST + ODBC
- Auth
- Partner key + Windows login
- Webhooks / events
- None documented
- Sandbox
- Partner program only
Sage Intacct Construction
- API style
- REST + legacy XML
- Auth
- OAuth 2.0 / sender ID
- Webhooks / events
- Partial (Smart Events)
- Sandbox
- Add-on module
QuickBooks Online
- API style
- REST (+ GraphQL)
- Auth
- OAuth 2.0 auth code
- Webhooks / events
- Yes
- Sandbox
- Yes, 10 companies
CMiC
- API style
- REST
- Auth
- OAuth via IdP (Basic until 2027)
- Webhooks / events
- Yes
- Sandbox
- Customer test environments
Foundation Software
- API style
- REST (OpenAPI)
- Auth
- Subscription key + bearer token
- Webhooks / events
- Not yet confirmed
- Sandbox
- Yes, after approval
Oracle Primavera P6
- API style
- REST + SOAP + XER/XML files
- Auth
- Basic / OAuth (OCI only)
- Webhooks / events
- JMS eventing (on-prem)
- Sandbox
- None public
Microsoft Project
- API style
- Dataverse + schedule APIs; MPP/XML files
- Auth
- Entra ID (licensed user)
- Webhooks / events
- Via Power Automate
- Sandbox
- Power Platform sandbox env
HCSS HeavyJob & HeavyBid
- API style
- REST
- Auth
- OAuth 2.0 client credentials
- Webhooks / events
- Yes
- Sandbox
- Partners only
HubSpot
- API style
- REST
- Auth
- OAuth 2.0 / static token
- Webhooks / events
- Yes
- Sandbox
- Free test accounts
Salesforce
- API style
- REST, SOAP, Bulk, Pub/Sub
- Auth
- OAuth 2.0 (External Client App)
- Webhooks / events
- CDC + platform events
- Sandbox
- Free Developer Edition
Microsoft Fabric & Power BI
- API style
- REST + OneLake (ADLS)
- Auth
- Entra ID / service principal
- Webhooks / events
- n/a (destination)
- Sandbox
- 60-day trial
Choosing how to connect them is a separate question: compare connectors, iPaaS, in-house and specialist builds, or map your whole stack.
Frequently asked questions
Where does this information come from?
Each system page lists the official developer documentation it was checked against, plus our own build notes where we have integrated the system. Where a vendor doesn't publish something, such as rate limits, the page says so instead of guessing.
Why do some entries say “Confirm with vendor”?
Some construction vendors document their APIs only to customers or partners, or behind a login. We only state what a public official source or our own build work supports, and mark the rest so you know what to ask.
How current is it?
Every entry was last verified in October 2026. Vendors change APIs, limits and partner programs regularly, so check the linked documentation before you design around a detail.
Next step
Connecting two of these?
Tell us which systems and what should move between them. We'll say what we'd build, what we'd buy, and what to check first.
Prefer email? charley@buildflows.ai