.png)
SafetyCulture Integration Guide
Connect SafetyCulture inspections, actions, users, locations, and evidence with enterprise applications through REST APIs, selected event notifications, and Martini workflows.
SafetyCulture integration options at a glance
SafetyCulture’s primary integration mechanism is its REST API, which exposes inspections, inspection templates, actions, users, locations, and related resources. Selected events and resources can also support webhook-style notifications, although coverage and delivery behavior should be confirmed for each use case. Where APIs expose media metadata and download operations, Martini can retrieve inspection photographs and attachments. For larger synchronizations, Martini can combine pagination, scheduled workflows, incremental filters, and durable checkpoints; bulk or asynchronous access is resource-specific. API tokens and OAuth 2.0 support server-to-server and delegated access models, while Martini stores credentials in secure environment configuration.
Common SafetyCulture integration patterns
Common SafetyCulture data objects used in integrations
Authentication and security considerations
API tokens and OAuth 2.0
SafetyCulture supports API-token access for suitable server-to-server scenarios and OAuth 2.0 for applications requiring delegated access. Available scopes and authorization flows depend on the API product and application model.
Permissions and secrets
Access is constrained by the SafetyCulture organization, user, role, and permissions associated with the credential. Store API tokens, client credentials, and refresh tokens in Martini environment configuration or secrets management rather than workflow definitions.
Data protection
- Use least-privilege credentials and separate environments where practical.
- Protect inspection photographs, employee information, and safety-related records according to retention and privacy requirements.
- Do not log credentials, refresh tokens, or sensitive media.
Operational considerations for SafetyCulture integrations
Pagination and rate limits
Implement the documented pagination or cursor model for collection endpoints. Confirm applicable SafetyCulture limits and use exponential backoff with jitter for 429 responses and transient failures.
Idempotency and webhooks
Use stable Inspection, Action, template, User, Location, attachment, and event identifiers. Treat notifications as potentially duplicated unless delivery guarantees are explicitly confirmed, and retrieve the current object when the notification is incomplete.
Schema and template changes
Inspection templates can change questions, sections, response types, and scoring rules. Prefer stable identifiers, version mappings, and preserve unknown fields where appropriate.
Attachments and observability
Handle media separately from metadata, account for expiring URLs and large files, and record correlation IDs, source IDs, request types, and retry counts. Route permanent failures to an exception store or review queue.
Why use Martini instead of scripts or point-to-point integrations?
Orchestrate more than API calls
Martini coordinates SafetyCulture retrieval, event intake, enrichment, transformation, business rules, downstream delivery, and exception handling in maintainable workflows rather than scattering logic across scripts.
Reuse integration assets
Teams can expose normalized APIs, reuse mappings and workflow logic, and keep credentials in environment configuration. This supports multiple target applications without duplicating SafetyCulture-specific behavior.
Operate reliably
Scheduled checkpoints, pagination, idempotent upserts, retries, validation, and workflow monitoring provide operational controls that are difficult to maintain consistently in isolated point-to-point scripts.