Build Flows

ERP & accounting

CMiC API and integration guide

CMiC publishes a REST API grouped by module (project management, general ledger, HCM and more) with documented throttles, a 1,000-record cap and webhooks. Basic authentication is being retired in favor of OAuth through the customer's identity provider.

Last verified October 2026 against the sources below. Confirm details with CMiC before you build.

At a glance

Category
ERP & accounting · CMiC
API style
REST/JSON, grouped into API programs by module (for example project management, general ledger, HCM and document management).
Authentication
Basic authentication with an API service account, or OAuth 2.0 through an external identity provider such as Microsoft Entra ID, Okta or Google, whose access token CMiC validates. CMiC states Basic authentication is deprecated effective March 31, 2027.
Sandbox / developer program
CMiC documents separate test environments and URLs for cloud customers. No public developer sandbox; confirm with vendor.
Webhooks / events
Yes. CMiC Webhooks send event-based messages from CMiC to a recipient platform.
Rate limits
Up to 5 concurrent requests and 15 requests per second per IP address; excess requests get HTTP 429 with no Retry-After header. Responses are capped at 1,000 records per request, and asking for more returns HTTP 400.
Exports and files
Not confirmed. CMiC's best-practice guidance is to poll by audit or update date and page with limit and offset.
Marketplace / partner program
Not confirmed by name; CMiC's developer site lists a partnership contact.

Key objects for construction workflows

  • Jobs
  • Job cost transactions
  • AP vendors
  • AP registered invoices and vouchers
  • AP cheques
  • Subcontracts and progress payments
  • Purchase orders
  • PM projects

Notes and gotchas

  • The 5-concurrent-requests-per-IP cap binds first, and there is no Retry-After header, so build your own backoff.
  • Requests over 1,000 records fail with HTTP 400 instead of truncating; always page.
  • Basic authentication ends March 31, 2027; build new work on OAuth through the customer's identity provider.

Sources

Frequently asked questions

Does CMiC have a public API?

Yes. CMiC publishes REST API documentation at developers.cmicglobal.com, with endpoints grouped by module and guides for vouchers, subcontract progress payments and more.

What are CMiC's API rate limits?

CMiC documents up to 5 concurrent requests and 15 requests per second per IP address, and a maximum of 1,000 records per request.

Is CMiC Basic authentication going away?

CMiC states Basic authentication is deprecated effective March 31, 2027. New integrations should use OAuth through the customer's identity provider.

Next step

Connecting CMiC to your other systems?

Bring the systems and the report or workflow you want to fix. We'll walk through what moves, who owns each record, and what to check first.