.png)
Procurify Integration Guide
Connect Procurify procurement and spend-management data with enterprise systems through REST APIs, OAuth 2.0 authorization, scheduled workflows, and controlled event-driven patterns.
Procurify integration options at a glance
Procurify’s primary documented integration mechanism is its REST API platform, with access, resource coverage, permissions, and API version determined by the Procurify account and current developer documentation. Martini can authenticate with Procurify using OAuth 2.0-style credentials, retrieve JSON resources, apply validation and business rules, and synchronize approved procurement data through scheduled workflows. Common designs cover Users, Vendors, Purchase Requests, Purchase Orders, Bills, and Budgets. Webhook-style notifications may be available for selected events, but broad webhook coverage is not confirmed. No Procurify bulk API, direct database access, or general attachment API has been verified, so larger transfers should use paginated, incremental REST requests with checkpoints and idempotent upserts.
Common Procurify integration patterns
Common Procurify data objects used in integrations
Authentication and security considerations
OAuth 2.0-style authorization
Procurify API access is associated with OAuth 2.0-style authorization. The current developer documentation should be used to confirm the grant type, token endpoint, scopes, refresh-token behavior, and administrator approval requirements.
Credential protection
Store Procurify client credentials, access tokens, and refresh credentials in Martini Secrets Management rather than embedding them in workflows or mappings. Request only the scopes required for the integration.
Least privilege
- Separate read-only synchronization credentials from credentials that can create or update Procurify objects.
- Confirm whether access is controlled by Procurify roles, organization permissions, API scopes, or a combination of these.
- Protect any Martini API endpoint used for event notifications with appropriate authentication and authorization.
Operational considerations for Procurify integrations
Pagination and rate limits
Confirm Procurify page size, cursor or offset behavior, filtering, sorting, and tenant-specific rate limits. Martini workflows should throttle requests, avoid uncontrolled parallelism, handle 429 responses, and use bounded exponential backoff.
Incremental processing
Persist checkpoints based on documented timestamps or identifiers where available. Use overlap windows when timestamp precision or ordering is uncertain, and reconcile totals or high-water marks after each run.
Lifecycle and idempotency
Do not treat every returned object as ready for ERP or accounting posting. Distinguish draft, pending, approved, rejected, canceled, closed, and amended states, and use stable Procurify IDs plus target IDs to prevent duplicates.
Schema and testing
Monitor the Procurify developer documentation for API-version changes, deprecated fields, new required properties, and enum changes. Test pagination, token expiry, rate limits, partial failures, reference mismatches, and replayed events before production deployment.
Attachments and reconciliation
Confirm attachment resources, permissions, binary or signed-URL behavior, and size limits before implementing document transfer. Route failed objects to operational retry or reconciliation processes instead of silently skipping them.
Why use Martini instead of scripts or point-to-point integrations?
Centralized orchestration
Martini provides a maintainable workflow for authentication, Procurify API calls, pagination, reference resolution, business rules, target writes, and reconciliation rather than scattering logic across scripts or point-to-point jobs.
Reusable transformations
Mappings can separate Procurify-specific JSON handling from canonical and target-system models. This makes it easier to support multiple ERP or accounting destinations while preserving consistent Vendor, Purchase Order, Bill, and accounting rules.
Operational reliability
Martini workflows can implement checkpoints, idempotent upserts, rate-limit handling, retries, validation, logging, and controlled failure routing. These controls are important when procurement objects change lifecycle state or when a synchronization run is interrupted.
API-led integration
Martini can consume Procurify APIs and expose controlled APIs for downstream applications or potential Procurify event callbacks. This provides a governed integration boundary without requiring a dedicated vendor connector.