ERP & accounting
CMiC API and integration guide
CMiC publishes a REST API grouped by module (project management, general ledger, HCM and more) with documented throttles, a 1,000-record cap and webhooks. Basic authentication is being retired in favor of OAuth through the customer's identity provider.
Last verified October 2026 against the sources below. Confirm details with CMiC before you build.
At a glance
- Category
- ERP & accounting · CMiC
- API style
- REST/JSON, grouped into API programs by module (for example project management, general ledger, HCM and document management).
- Authentication
- Basic authentication with an API service account, or OAuth 2.0 through an external identity provider such as Microsoft Entra ID, Okta or Google, whose access token CMiC validates. CMiC states Basic authentication is deprecated effective March 31, 2027.
- Sandbox / developer program
- CMiC documents separate test environments and URLs for cloud customers. No public developer sandbox; confirm with vendor.
- Webhooks / events
- Yes. CMiC Webhooks send event-based messages from CMiC to a recipient platform.
- Rate limits
- Up to 5 concurrent requests and 15 requests per second per IP address; excess requests get HTTP 429 with no Retry-After header. Responses are capped at 1,000 records per request, and asking for more returns HTTP 400.
- Exports and files
- Not confirmed. CMiC's best-practice guidance is to poll by audit or update date and page with limit and offset.
- Marketplace / partner program
- Not confirmed by name; CMiC's developer site lists a partnership contact.
Key objects for construction workflows
- Jobs
- Job cost transactions
- AP vendors
- AP registered invoices and vouchers
- AP cheques
- Subcontracts and progress payments
- Purchase orders
- PM projects
Notes and gotchas
- The 5-concurrent-requests-per-IP cap binds first, and there is no Retry-After header, so build your own backoff.
- Requests over 1,000 records fail with HTTP 400 instead of truncating; always page.
- Basic authentication ends March 31, 2027; build new work on OAuth through the customer's identity provider.
Sources
Frequently asked questions
Does CMiC have a public API?
Yes. CMiC publishes REST API documentation at developers.cmicglobal.com, with endpoints grouped by module and guides for vouchers, subcontract progress payments and more.
What are CMiC's API rate limits?
CMiC documents up to 5 concurrent requests and 15 requests per second per IP address, and a maximum of 1,000 records per request.
Is CMiC Basic authentication going away?
CMiC states Basic authentication is deprecated effective March 31, 2027. New integrations should use OAuth through the customer's identity provider.
Next step
Connecting CMiC to your other systems?
Bring the systems and the report or workflow you want to fix. We'll walk through what moves, who owns each record, and what to check first.