Integration guide
Procore and CMiC integration
CMiC and Procore both publish REST APIs with webhooks, so changes can be pushed in either direction. The binding limits are on the CMiC side: 5 concurrent requests and 15 per second per IP, a 1,000-record cap per response, and Basic authentication ending March 31, 2027.
System facts last verified October 2026 against the vendors' documentation (sources below). Confirm details with Procore Technologies and CMiC before you build.
Procore and CMiC side by side
- API style
- ProcoreREST/JSON. Procore states that direct database access and RDBMS, XML or SOAP integrations aren't supported.
- CMiCREST/JSON, grouped into API programs by module (for example project management, general ledger, HCM and document management).
- Authentication
- ProcoreOAuth 2.0, registered as an app in the Procore Developer Portal: authorization code (acts as a specific user) or client credentials through a Developer Managed Service Account (DMSA) with company and project permissions. Traditional service accounts were sunset on March 18, 2025.
- CMiCBasic authentication with an API service account, or OAuth 2.0 through an external identity provider such as Microsoft Entra ID, Okta or Google, whose access token CMiC validates. CMiC states Basic authentication is deprecated effective March 31, 2027.
- Webhooks / events
- ProcoreYes. Company- or project-level create, update and delete triggers; Procore recommends payload v4.0 for new integrations. Delivery is best-effort with retries, and events are discarded after 12 hours of continuous failure, so pair webhooks with a periodic reconciliation sync.
- CMiCYes. CMiC Webhooks send event-based messages from CMiC to a recipient platform.
- Rate limits
- ProcoreAn hourly (60-minute) limit and a 10-second spike limit, reported in X-Rate-Limit-Limit, -Remaining and -Reset headers; exceeding either returns 429, and 503 with Retry-After signals platform load. Procore publishes no fixed default: its rate-limiting page uses sample headers (600 per hour, 25 per spike window), warns not to assume a fixed window such as 3,600/hour, says values can change, and lets apps request an increase. Every request counts, including failed ones.
- CMiCUp to 5 concurrent requests and 15 requests per second per IP address; excess requests get HTTP 429 with no Retry-After header. Responses are capped at 1,000 records per request, and asking for more returns HTTP 400.
- Sandbox
- ProcoreYes. A developer sandbox with seed data is created when you register an app (you can have many). Customers can also enable on-demand and monthly sandboxes; the monthly one is refreshed from production each month. Not available to Federal Zone customers.
- CMiCCMiC documents separate test environments and URLs for cloud customers. No public developer sandbox; confirm with vendor.
- Exports and files
- ProcoreNo bulk export API confirmed; reporting integrations page through list endpoints. Procore Analytics is a separate product.
- CMiCNot confirmed. CMiC's best-practice guidance is to poll by audit or update date and page with limit and offset.
- Marketplace / partners
- ProcoreProcore App Marketplace and the Procore Technology Partner Program (application, technical review, certification, agreement, listing).
- CMiCNot confirmed by name; CMiC's developer site lists a partnership contact.
Who owns what
- Accounting usually owns jobs, vendors and cost codes; they flow into project management.
- Commitments and change orders are typically created in project management and pushed to accounting on approval.
- Actual costs flow from accounting back to project management or into a reporting model.
What syncs between Procore and CMiC
The typical shape for this pair. Every row is typical: confirm it against your configuration in discovery.
| Object | Direction | System of record | |
|---|---|---|---|
| Projects / jobs | CMiC to Procore | CMiC (job number) | Hourly or on CMiC webhook |
| Typical frequency: Hourly or on CMiC webhook. Notes: Create the job in CMiC, then the Procore project carrying the CMiC job number. Poll by audit or update date as a backstop to webhooks.(Typical: confirm against your configuration.) | |||
| Vendors | CMiC to Procore | CMiC (AP vendors) | Hourly |
| Typical frequency: Hourly. Notes: Reference the CMiC vendor code from the Procore directory; never match on name alone.(Typical: confirm against your configuration.) | |||
| Cost codes and cost types | CMiC to Procore | CMiC | On change |
| Typical frequency: On change. Notes: Map CMiC job cost structure to Procore cost codes and cost types in a table accounting reviews. Reject unknown codes instead of defaulting them.(Typical: confirm against your configuration.) | |||
| Budgets | CMiC to Procore | CMiC or estimate at award; Procore after | Once at setup |
| Typical frequency: Once at setup. Notes: Seed Procore budget lines once; changes after award go through Procore budget changes.(Typical: confirm against your configuration.) | |||
| Subcontracts and purchase orders | Procore to CMiC | Pick one: usually Procore | Every 15 minutes |
| Typical frequency: Every 15 minutes. Notes: CMiC exposes subcontracts and purchase orders. Send approved or executed commitments only; two-way commitment sync without one owner causes loops.(Typical: confirm against your configuration.) | |||
| Change orders | Procore to CMiC | Procore for approval; CMiC for posted cost | Every 15 minutes |
| Typical frequency: Every 15 minutes. Notes: Approved commitment change orders only. Hold one whose commitment hasn't synced yet and retry.(Typical: confirm against your configuration.) | |||
| Subcontractor invoices / progress payments | Procore to CMiC | CMiC after posting | Hourly |
| Typical frequency: Hourly. Notes: CMiC exposes AP registered invoices and vouchers and subcontract progress payments. Agree with accounting which one Procore invoices land as, and carry the Procore invoice ID.(Typical: confirm against your configuration.) | |||
| Payments | CMiC to Procore | CMiC (AP cheques) | Daily |
| Typical frequency: Daily. Notes: Paid status read back from CMiC AP cheques so project teams see it in Procore.(Typical: confirm against your configuration.) | |||
Directions, owners and frequencies are the typical pattern from our integration guides and mapping workbook. Confirm each one against your configuration in discovery.
Is a native connector enough?
We haven't confirmed a documented native connector for this pair. Check the Procore App Marketplace and ask CMiC (its developer site lists a partnership contact) for a partner connector first: if one moves the records you need with your cost structure and approvals, configure it. Build when the mapping needs governing, when failures need routing to a person, or when you also need cross-system reporting.
Compare native connectors with a custom buildCommon gotchas
- CMiC's 5-concurrent-requests-per-IP cap binds first and its 429s carry no Retry-After header, while Procore's do. Build your own backoff for the CMiC side and keep every worker behind one queue.
- CMiC requests over 1,000 records fail with HTTP 400 instead of truncating. Page with limit and offset on every read, including the initial backfill.
- Basic authentication ends March 31, 2027. Build on OAuth through the customer's identity provider (such as Microsoft Entra ID or Okta), which means provisioning the integration identity there early.
- Procore delivers webhooks best-effort and discards events after 12 hours of continuous failure. Pair webhooks on both sides with a scheduled reconciliation.
Sources
- Procore developer documentation
- Procore: choosing an OAuth grant type
- Procore: rate limiting
- Procore: webhooks
- Procore: development environments
- Procore: financial tools tutorial
- Procore: partner program overview
- CMiC developer documentation
- CMiC: authentication (Basic deprecation, OAuth via IdP)
- CMiC: API request throttling
- CMiC: 1,000-record limit
- CMiC: webhooks
Frequently asked questions
Can CMiC push changes to Procore?
Yes, through CMiC Webhooks, which send event-based messages to a recipient platform. Your integration receives them and calls the Procore API. Keep a scheduled poll by update date as a backstop.
Which CMiC API limits matter for a Procore sync?
Up to 5 concurrent requests and 15 requests per second per IP address, with no Retry-After header on 429, and a maximum of 1,000 records per request. Size the backfill around them.
Should a new Procore and CMiC integration use Basic authentication?
No. CMiC states Basic authentication is deprecated effective March 31, 2027. Use OAuth through the customer's identity provider.
Next step
Connecting Procore and CMiC?
Bring one real job and the records you want to move. We'll walk through what syncs, who owns each record, and what to check first.