Build Flows

Estimating & field

HCSS HeavyJob & HeavyBid API and integration guide

HCSS publishes REST APIs for HeavyJob, HeavyBid pre-construction, Equipment360, Safety and more, with OAuth client credentials, scoped access, webhooks, and a company-wide rate limit.

Last verified October 2026 against the sources below. Confirm details with HCSS before you build.

At a glance

Category
Estimating & field · HCSS
API style
REST/JSON, one API per product: HeavyJob, HeavyBid Pre-Construction and Estimate Insights, Equipment360, Safety, Setups, Contacts, Attachments and others.
Authentication
OAuth 2.0 through HCSS Identity. Most integrations use client credentials with space-separated product scopes such as heavyjob:read; an authorization code flow exists for partner apps. Tokens last an hour, and a missing scope returns 403.
Sandbox / developer program
Partners only: HCSS says you must be logged in to an approved partner account to generate a sandbox, which comes with sample data in several products.
Webhooks / events
Yes, for Pre-Construction, HeavyJob and Setups. Subscriptions confirm with a challenge handshake, can be signed (X-HCSS-Signature), and retry up to five times before the subscription stops and must be recreated.
Rate limits
100 requests per minute and 20 concurrent requests, applied at the company level and shared by every client. Throttled calls return 429 with Retry-After.
Exports and files
Not researched. Confirm with vendor.
Marketplace / partner program
HCSS Marketplace partner program (registration through the HCSS Partner Portal).

Key objects for construction workflows

  • Jobs
  • Cost codes
  • Employees
  • Time cards
  • Quantities
  • Materials
  • Vendors
  • Pre-construction estimates
  • Equipment, fuel and work orders

Notes and gotchas

  • The rate limit is company-wide and shared with every other integration the contractor runs; 100 per minute is tight for a time card backfill.
  • A stopped webhook subscription doesn't resume on its own; check subscriptions and recreate them.
  • Setups v1 endpoints are marked deprecated or moving; use the product-specific APIs.

Sources

Frequently asked questions

How do I authenticate to the HCSS API?

Request a token from HCSS Identity with OAuth 2.0 client credentials and the product scopes your client was granted, such as heavyjob:read. Tokens last an hour.

What is the HCSS API rate limit?

HCSS documents 100 requests per minute and 20 concurrent requests per company, shared across every client that company uses.

Does HeavyJob support webhooks?

Yes. HCSS supports webhook subscriptions for HeavyJob, Pre-Construction and Setups, with a challenge handshake, optional signatures and up to five retries.

Next step

Connecting HCSS HeavyJob & HeavyBid to your other systems?

Bring the systems and the report or workflow you want to fix. We'll walk through what moves, who owns each record, and what to check first.