.png)
Hyland OnBase Integration Guide
Integrate OnBase documents, metadata, and content with enterprise applications through REST APIs, selected SOAP services, scheduled workflows, and controlled Martini APIs.
Hyland OnBase integration options at a glance
OnBase API Server is the primary modern integration route, with REST operations that may support document search, metadata, content retrieval, and document import depending on the release, configuration, and licensed modules. Selected SOAP and web-service interfaces may remain necessary for legacy deployments or operations not available through REST. Document content can be imported and retrieved through OnBase APIs, while batch-oriented processing is available in some configurations without a universal public bulk API. A universal webhook model was not confirmed, so Martini can use scheduled workflows for polling, checkpointing, reconciliation, mapping, validation, and controlled API exposure. Authentication may use OAuth 2.0, service identities, or enterprise authentication.
Common Hyland OnBase integration patterns
Common Hyland OnBase data objects used in integrations
Authentication and security considerations
Authentication depends on the OnBase interface
OnBase deployments may use OAuth 2.0, a configured service identity, Windows-integrated authentication, or another enterprise mechanism. Confirm the API Server version, authorization server, grant type, scopes, token lifetime, certificates, and client registration with the OnBase administrator.
Authorization is separate from authentication
The service identity must have access to the relevant Document Types, Keyword Types, folders, Documents, content operations, and workflow or status functions. Test each required operation with least privilege.
Protect integration configuration
- Store credentials, tokens, certificates, and endpoint settings as protected Martini configuration.
- Use encryption in transit and avoid logging document content or sensitive Keyword Values.
- Apply access controls appropriate for healthcare, personnel, financial, customer, and other regulated documents.
Operational considerations for Hyland OnBase integrations
Version and module dependency
OnBase capabilities vary by release, deployment topology, API Server configuration, and licensed modules. Confirm REST and SOAP coverage, Document Types, Keyword Types, Workflow or WorkView scope, and content operations before implementation.
Pagination and limits
Implement explicit pagination and server-side filters. Confirm search limits, concurrent request limits, token duration, request timeouts, reverse-proxy limits, import queue capacity, and maximum document size.
Content and idempotency
Large documents may require separate metadata and content handling, appropriate timeouts, and MIME-type and size validation. Persist source identifiers, OnBase document identifiers, content markers where appropriate, processing status, and error details to prevent duplicate imports.
Retries and reconciliation
Distinguish validation and authorization failures from transient timeouts or server errors. Use exponential backoff for transient failures, durable checkpoints for scheduled synchronization, and reconciliation workflows for partial or queued processing.
Schema and testing
Treat changes to Document Types, Keyword Types, permissions, API versions, and module configuration as integration-impacting changes. Test search, metadata reads, content reads, imports, status updates, permissions, large files, duplicates, and failure recovery in a representative environment.
Why use Martini instead of scripts or point-to-point integrations?
Orchestrate more than one API call
Martini coordinates OnBase REST or SOAP calls with external applications, scheduled processing, validation, transformation, business rules, and downstream writes in a single maintainable workflow.
Separate provider details from business logic
Reusable mappings and services can isolate OnBase Document Types, Keyword Values, content handling, and authentication from a canonical integration model. This reduces duplication when multiple applications consume or submit documents.
Build controlled APIs
Martini can expose a controlled API façade over OnBase, centralizing authorization, search behavior, content handling, normalized responses, and error contracts instead of reproducing those concerns in every point-to-point client.
Operate reliably
- Use checkpoints, idempotency, retry handling, pagination, and reconciliation for scheduled and batch processing.
- Keep secrets and environment-specific endpoints out of workflow logic.
- Monitor workflow outcomes while avoiding sensitive document content in logs.