Build Flows

Project management

Procore API and integration guide

Procore exposes a large REST API (our generated MCP server produced 2,755 tools from its OpenAPI spec) with OAuth 2.0, free developer sandboxes and webhooks. Rate limits are enforced per hour and per 10 seconds, with no fixed default published; read the headers rather than hard-coding a number.

Last verified October 2026 against the sources below. Confirm details with Procore Technologies before you build.

At a glance

Category
Project management · Procore Technologies
API style
REST/JSON. Procore states that direct database access and RDBMS, XML or SOAP integrations aren't supported.
Authentication
OAuth 2.0, registered as an app in the Procore Developer Portal: authorization code (acts as a specific user) or client credentials through a Developer Managed Service Account (DMSA) with company and project permissions. Traditional service accounts were sunset on March 18, 2025.
Sandbox / developer program
Yes. A developer sandbox with seed data is created when you register an app (you can have many). Customers can also enable on-demand and monthly sandboxes; the monthly one is refreshed from production each month. Not available to Federal Zone customers.
Webhooks / events
Yes. Company- or project-level create, update and delete triggers; Procore recommends payload v4.0 for new integrations. Delivery is best-effort with retries, and events are discarded after 12 hours of continuous failure, so pair webhooks with a periodic reconciliation sync.
Rate limits
An hourly (60-minute) limit and a 10-second spike limit, reported in X-Rate-Limit-Limit, -Remaining and -Reset headers; exceeding either returns 429, and 503 with Retry-After signals platform load. Procore publishes no fixed default: its rate-limiting page uses sample headers (600 per hour, 25 per spike window), warns not to assume a fixed window such as 3,600/hour, says values can change, and lets apps request an increase. Every request counts, including failed ones.
Exports and files
No bulk export API confirmed; reporting integrations page through list endpoints. Procore Analytics is a separate product.
Marketplace / partner program
Procore App Marketplace and the Procore Technology Partner Program (application, technical review, certification, agreement, listing).

Key objects for construction workflows

  • Projects
  • Companies and directory
  • Vendors
  • Cost codes
  • Budgets
  • Commitments
  • Change events and change orders
  • Direct costs
  • Prime contracts
  • Subcontractor invoices and payments
  • RFIs
  • Submittals
  • Drawings and documents

Notes and gotchas

  • Setting origin_id on a direct cost makes it immutable, and subcontractor invoices, payment applications and payments lock once it's set; only one integration can own it.
  • Approved or complete commitments and change orders can't have their schedule of values changed or be deleted.
  • Webhook coverage varies by tool: when we checked for our Procore + P6 analytics build, the event list covered financials and core modules but not the RFIs and submittals we needed, so we polled.

Sources

Frequently asked questions

What is the Procore API rate limit?

Procore enforces an hourly limit and a 10-second spike limit and reports your current values in X-Rate-Limit headers. Its documentation publishes no fixed default and warns against assuming 3,600 per hour, so read the headers, back off on 429, and request an increase if you consistently hit the limit.

Should I use authorization code or a service account?

Use authorization code when the integration should act as a specific user, and client credentials through a Developer Managed Service Account for company-level data connections. Traditional service accounts were sunset in March 2025.

Does Procore have webhooks for RFIs and submittals?

Check the event list for your account before designing around them. In our Procore and P6 build the available events didn't cover RFIs and submittals, so we polled; Procore also advises pairing webhooks with a reconciliation sync.

Next step

Connecting Procore to your other systems?

Bring the systems and the report or workflow you want to fix. We'll walk through what moves, who owns each record, and what to check first.