Build Flows

Integration guide

Procore and CMiC integration

CMiC and Procore both publish REST APIs with webhooks, so changes can be pushed in either direction. The binding limits are on the CMiC side: 5 concurrent requests and 15 per second per IP, a 1,000-record cap per response, and Basic authentication ending March 31, 2027.

System facts last verified October 2026 against the vendors' documentation (sources below). Confirm details with Procore Technologies and CMiC before you build.

Procore and CMiC side by side

API style
ProcoreREST/JSON. Procore states that direct database access and RDBMS, XML or SOAP integrations aren't supported.
CMiCREST/JSON, grouped into API programs by module (for example project management, general ledger, HCM and document management).
Authentication
ProcoreOAuth 2.0, registered as an app in the Procore Developer Portal: authorization code (acts as a specific user) or client credentials through a Developer Managed Service Account (DMSA) with company and project permissions. Traditional service accounts were sunset on March 18, 2025.
CMiCBasic authentication with an API service account, or OAuth 2.0 through an external identity provider such as Microsoft Entra ID, Okta or Google, whose access token CMiC validates. CMiC states Basic authentication is deprecated effective March 31, 2027.
Webhooks / events
ProcoreYes. Company- or project-level create, update and delete triggers; Procore recommends payload v4.0 for new integrations. Delivery is best-effort with retries, and events are discarded after 12 hours of continuous failure, so pair webhooks with a periodic reconciliation sync.
CMiCYes. CMiC Webhooks send event-based messages from CMiC to a recipient platform.
Rate limits
ProcoreAn hourly (60-minute) limit and a 10-second spike limit, reported in X-Rate-Limit-Limit, -Remaining and -Reset headers; exceeding either returns 429, and 503 with Retry-After signals platform load. Procore publishes no fixed default: its rate-limiting page uses sample headers (600 per hour, 25 per spike window), warns not to assume a fixed window such as 3,600/hour, says values can change, and lets apps request an increase. Every request counts, including failed ones.
CMiCUp to 5 concurrent requests and 15 requests per second per IP address; excess requests get HTTP 429 with no Retry-After header. Responses are capped at 1,000 records per request, and asking for more returns HTTP 400.
Sandbox
ProcoreYes. A developer sandbox with seed data is created when you register an app (you can have many). Customers can also enable on-demand and monthly sandboxes; the monthly one is refreshed from production each month. Not available to Federal Zone customers.
CMiCCMiC documents separate test environments and URLs for cloud customers. No public developer sandbox; confirm with vendor.
Exports and files
ProcoreNo bulk export API confirmed; reporting integrations page through list endpoints. Procore Analytics is a separate product.
CMiCNot confirmed. CMiC's best-practice guidance is to poll by audit or update date and page with limit and offset.
Marketplace / partners
ProcoreProcore App Marketplace and the Procore Technology Partner Program (application, technical review, certification, agreement, listing).
CMiCNot confirmed by name; CMiC's developer site lists a partnership contact.

Who owns what

  • Accounting usually owns jobs, vendors and cost codes; they flow into project management.
  • Commitments and change orders are typically created in project management and pushed to accounting on approval.
  • Actual costs flow from accounting back to project management or into a reporting model.

What syncs between Procore and CMiC

The typical shape for this pair. Every row is typical: confirm it against your configuration in discovery.

ProcoreCMiCProjects / jobsVendorsCost codes and cost typesBudgetsSubcontracts and purchase ordersChange ordersSubcontractor invoices / progress paymentsPayments
Arrows point from the system that sends to the system that receives. Dashed means it stays put.
ObjectDirectionSystem of record
Projects / jobsCMiC to ProcoreCMiC (job number)
Typical frequency: Hourly or on CMiC webhook. Notes: Create the job in CMiC, then the Procore project carrying the CMiC job number. Poll by audit or update date as a backstop to webhooks.(Typical: confirm against your configuration.)
VendorsCMiC to ProcoreCMiC (AP vendors)
Typical frequency: Hourly. Notes: Reference the CMiC vendor code from the Procore directory; never match on name alone.(Typical: confirm against your configuration.)
Cost codes and cost typesCMiC to ProcoreCMiC
Typical frequency: On change. Notes: Map CMiC job cost structure to Procore cost codes and cost types in a table accounting reviews. Reject unknown codes instead of defaulting them.(Typical: confirm against your configuration.)
BudgetsCMiC to ProcoreCMiC or estimate at award; Procore after
Typical frequency: Once at setup. Notes: Seed Procore budget lines once; changes after award go through Procore budget changes.(Typical: confirm against your configuration.)
Subcontracts and purchase ordersProcore to CMiCPick one: usually Procore
Typical frequency: Every 15 minutes. Notes: CMiC exposes subcontracts and purchase orders. Send approved or executed commitments only; two-way commitment sync without one owner causes loops.(Typical: confirm against your configuration.)
Change ordersProcore to CMiCProcore for approval; CMiC for posted cost
Typical frequency: Every 15 minutes. Notes: Approved commitment change orders only. Hold one whose commitment hasn't synced yet and retry.(Typical: confirm against your configuration.)
Subcontractor invoices / progress paymentsProcore to CMiCCMiC after posting
Typical frequency: Hourly. Notes: CMiC exposes AP registered invoices and vouchers and subcontract progress payments. Agree with accounting which one Procore invoices land as, and carry the Procore invoice ID.(Typical: confirm against your configuration.)
PaymentsCMiC to ProcoreCMiC (AP cheques)
Typical frequency: Daily. Notes: Paid status read back from CMiC AP cheques so project teams see it in Procore.(Typical: confirm against your configuration.)

Directions, owners and frequencies are the typical pattern from our integration guides and mapping workbook. Confirm each one against your configuration in discovery.

Is a native connector enough?

We haven't confirmed a documented native connector for this pair. Check the Procore App Marketplace and ask CMiC (its developer site lists a partnership contact) for a partner connector first: if one moves the records you need with your cost structure and approvals, configure it. Build when the mapping needs governing, when failures need routing to a person, or when you also need cross-system reporting.

Compare native connectors with a custom build

Common gotchas

  • CMiC's 5-concurrent-requests-per-IP cap binds first and its 429s carry no Retry-After header, while Procore's do. Build your own backoff for the CMiC side and keep every worker behind one queue.
  • CMiC requests over 1,000 records fail with HTTP 400 instead of truncating. Page with limit and offset on every read, including the initial backfill.
  • Basic authentication ends March 31, 2027. Build on OAuth through the customer's identity provider (such as Microsoft Entra ID or Okta), which means provisioning the integration identity there early.
  • Procore delivers webhooks best-effort and discards events after 12 hours of continuous failure. Pair webhooks on both sides with a scheduled reconciliation.

Sources

Frequently asked questions

Can CMiC push changes to Procore?

Yes, through CMiC Webhooks, which send event-based messages to a recipient platform. Your integration receives them and calls the Procore API. Keep a scheduled poll by update date as a backstop.

Which CMiC API limits matter for a Procore sync?

Up to 5 concurrent requests and 15 requests per second per IP address, with no Retry-After header on 429, and a maximum of 1,000 records per request. Size the backfill around them.

Should a new Procore and CMiC integration use Basic authentication?

No. CMiC states Basic authentication is deprecated effective March 31, 2027. Use OAuth through the customer's identity provider.

Next step

Connecting Procore and CMiC?

Bring one real job and the records you want to move. We'll walk through what syncs, who owns each record, and what to check first.