User Personas: Admin | Project Manager
The Public API is a feature that lets your organization connect eSUB Fusion to other business systems your company uses, such as accounting platforms or ERPs, so data can flow between them automatically instead of relying on manual exports.
This article covers the basics: what the Public API is, how to turn it on, how to create and manage API credentials, how to configure the API settings that control document handoff, and which permissions control access. eSUB is actively expanding the Public API with new resources and capabilities. For the full technical reference, including authentication, available endpoints, and field-level schemas, see the eSUB Public API Reference, which is updated as new features are released.
You will need the appropriate Integrations - API permissions to enable, configure, or use the Public API. See the Permissions table at the end of this article. Permissions will vary depending on your role in configuring and using the API.
Use the links below to jump to a topic:
- What Is the Public API
- Getting Access
- Configure API Settings
- Submit and Lock Settings on Project Documents
- Integration Acknowledgement and the Error Log
- Available Resources
- Permissions
- FAQ
What Is the Public API
The Public API exposes core eSUB Fusion data, such as Projects, Vendors, Cost Codes, and Purchase Orders, to external systems, and lets select resources be written back into eSUB. Access is secured with OAuth 2.0. It was built to support real customer integrations and continues to be expanded with new resources and capabilities.
Every organization gets its own credentials, so one company's integration never sees another company's data.
Getting Access
Enable the API module
The API module is off by default. Contact your eSUB representative or eSUB Support to have it enabled for your organization.
Once enabled, a new API area becomes available under Settings > Integrations for users with the right permissions. This area holds two things:
- API Credentials tab for managing credentials
- Document Settings tabs for controlling how various documents are handed off to your integration (e.g. Change Orders, Purchase Orders, etc.)
| The API module and the Integrations module (used for accounting integrations such as QuickBooks Online) cannot both be enabled in the same company/account. Enabling one requires disabling the other. Contact your eSUB representative if you are not sure which one your organization currently has, or if you need to discuss switching. |
Provision API credentials
Once the module is enabled, users with the Secrets Management permission can create, rotate, revoke, and edit API credentials themselves under Settings > Integrations > API, on the API Credentials tab. You do not need to involve eSUB Support for day-to-day credential management. The credential list shows each credential's label, Client ID, created date, and status. The same screen links out to the API documentation from the Actions button, in case you need to hand technical details to a developer building your integration.
To create a credential:
- Go to Settings > Integrations > API. The API Credentials tab opens by default.
-
Select Actions, then Create Credential.
The Create Credential option from the Actions Button. -
Enter a label, such as the name of the system you are connecting, and select Create Credential to confirm.
Labeling a new API credential. - The credential will then be created. The Client ID and Client Secret can be toggled to Show/Hide as well as copied into your own organizations documentation (e.g. Secret Managing Software). The Client Secret will appear only once in this modal- it is absolutely paramount to save your Client Secret at this step!
-
Confirm by selecting the checkbox that you have stored the Client Secret in a safe place, then select Done.
Created credentials will be logged for easy management in the API Credentials tab.
| The new Client Secret is shown exactly once, with options to copy or download it. You must confirm you have saved it before the dialog will close. eSUB cannot retrieve it for you afterward. If you lose it, rotate the credential for a new one. |
Rotate, Revoke, or Edit a credential
From the API Credentials log, managing an individual credential is done by selecting the 3-dot menu. The menu opens to allow you to:
- Rotate - Generates a new Client Secret for an existing credential. A confirmation dialog will appear to confirm the Rotate.The Client ID stays the same, only the Client Secret changes, and the new secret is shown the same one-time way as when the credential was created.
- Revoke - Permanently disables a credential. After selection from the 3-dot menu, to prevent accidental revocation, you must type the Credential Label in the confirmation dialog to unlock the Revoke Credential button. The credential briefly shows a Revoking status before settling to Revoked. This is expected. Revoking cannot be undone, so create a replacement credential first if an integration is still using it.
- Edit - Lets you change a credential's label. The Client ID and secret cannot be changed this way. Rotate the credential if you need a new secret.
| Rotating is not immediate revocation. Tokens already issued under the old secret keep working until they expire (up to 1 hour), so plan your integration's cutover accordingly. |
Configure API Settings
The API Settings view controls how eSUB documents are handed off to your integration. Open it from Settings > Integrations > API. Anyone with API Settings - View permissions can see the settings, and users with API Settings - Edit can change them. See the API permissions table for more information.
Settings are split across two tabs for any document specific settings, e.g. Change Orders and Purchase Orders, so each document type can be configured on its own.
Integration Pickup: Manual Submit and Lock on Submit
Each tab has an Integration Pickup section with two settings. Hover the info icon next to any value for a plain-language explanation of what it means.
Setting |
Options |
What it controls |
Manual Submit for Integration Pickup |
Enabled Disabled |
Whether a document must be submitted (using the Submit button) before an integration is allowed to pick it up. When disabled, documents are available to the integration as they change. |
Lock on Submit for Integration Pickup |
No Partial Lock Full Lock |
How much of a document is locked from further editing in eSUB once it is submitted for pickup. |
| These settings prepare your organization for the submit and lock workflow on your various documents. |
Edit API Settings
Users with API Settings - Edit permissions access will see an Edit button that opens the edit page. Each setting becomes a dropdown that spells out exactly what each choice does, so it is clear what you are turning on before you save.
- On the API Settings view, select the desired document API Settings tab (e.g. Change Orders, Purchase Orders).
- Select Edit.
- Choose an option for Manual Submit for Integration Pickup and Lock on Submit for Integration Pickup.
- Select Save to keep your changes, or Cancel to discard them. If you cancel with unsaved changes, a dialog will ask you to confirm before discarding.
Submit and Lock on Project Documents
When your organization has the Manual Submit option Enabled, a document (e.g. COR, PO, etc.) can be edited freely until it reaches a final status. At that point, a user with the API Settings - Submit permission marks it ready for your integration to pick up.
If Manual Submit is Disabled, a document is available to be picked-up by integration as the document is edited and managed in eSUB.
Submitting a Document: Manual Pickup
A Submit action appears on the document view and in the individual document's log once the document reaches a final status and the user has the Submit permission.
- Purchase Orders: available at the Open, Partial Shipment, Received in Full, or Complete status.
- Change Orders: available at the Approved status.
Selecting Submit opens a confirmation dialog explaining that this marks the document as ready for integration pickup. On confirmation, eSUB flags the document as ready and locks it according to your API Settings.
Locking a Document after Submitting
After submitting a document, the Lock on Submit option controls the editability and useability of the document. Review the options when configuring in the API Settings for your specific document, as locking features for each document can vary.
Lock level |
What stays editable |
No Lock |
The document stays fully editable everywhere. |
Partial Lock |
General Info becomes read-only except for Notes, Status (you cannot move it back to the earlier draft or pending statuses), Attachments, and the date fields. On a:
|
Full Lock |
Nothing on the document is editable, including its Status, lines, worksheet, or summary. Track further changes with a revision. |
Revisions and Unlocking
A locked document is not a dead end. You can create a new revision of a document (R1, R2, etc.). The revision is a new, fully editable document with its own status workflow, and eSUB keeps the original and every revision as separate records to be re-submitted and picked up by the integration.
Admins with the API Settings - Unlock permission can override a lock and unlock a document so it can be edited and re-submitted. Unlocking is an exception to the normal process.
| An unlocked document returns to fully editable document and shows a clear warning if it was already picked up by an integration. It can be submitted again, which overwrites the previous submission details. |
Integration Acknowledgement and the Error Log
After a document is picked up, your integration should send an acknowledgement back through the API. This one signal drives everything eSUB shows about a document's integration status, so your team can track it without opening the document itself. For each document, the integration either:
- confirms your external system picked it up and processed it, or
- reports an error or issue.
When the acknowledgement confirms success, eSUB shows a visual indicator on the document, along with a timestamp, so you can see it reached your external system.
When the acknowledgement reports a problem, it surfaces on the Error Log tab in the API Settings view. The Error Log lists the affected documents with a description of the issue shown in place of their Submitted or Picked Up status, so anyone with the right permissions can troubleshoot in one place instead of checking each document's log.
| eSUB does not detect integration errors on its own. The Error Log only shows what your integrator sends back through the acknowledgement API. If a document is never acknowledged, nothing surfaces for it. See integration-submissions in the API documentation for more information. |
Available Resources
The table below shows what the Public API currently supports. eSUB continues to roll out new resources, and some may return sample data for a period before switching over to your organization's live data. For the full, current list of endpoints and fields, see the eSUB Public API Reference.
| Resource | Read |
Create |
Delete |
Schema Exposes |
| Projects | Yes |
No |
No |
Read, Create, Update, Delete |
| AP Vendors | Yes |
No |
No |
Read, Create, Update, Delete |
| Contacts | Yes |
No |
No |
Read, Create, Update, Delete |
| Project Budgets | Yes |
No |
No |
Read, Update |
| Units of Measure | Yes |
No |
No |
Read, Create, Update, Delete |
| Market Areas | Yes |
No |
No |
Read, Create, Update, Delete |
| Crew Members | Yes |
No |
No |
Read, Create, Update, Delete |
| Cost Codes | Yes |
No |
No |
Read, Create, Update, Delete |
| Purchase Orders | Yes |
Yes |
Yes |
Read, Create, Delete |
| Change Order Requests | Yes |
Yes |
Yes |
Read, Create, Delete |
| Time | Yes |
No |
No |
Read |
Last Update: 7/22/26
Integrations can also request only the records that changed since they last checked, instead of re-fetching everything. See the eSUB Public API Reference for details.
Permissions
The Integrations - API permission section controls access to the Public API settings and credentials. This section appears only when your organization has the API module enabled.
| Action | Required Permission |
| View API Settings | API Settings - View |
| Edit API Settings | API Settings - Edit |
| Create, rotate, revoke, or edit API credentials | Secrets Management - Yes/No |
| Submit documents for integration pickup | Submit - Yes/No |
| Ability to unlock documents previously submitted | Unlock - Yes/No |
If a user does not see an action described in this article, review their Integrations permissions. Admins can adjust permissions from User Permissions.
FAQ
How do I turn on the Public API for my organization?
Contact your eSUB representative or eSUB Support. Once the module is enabled, credential management is self-service. See Getting Access.
Can we have the Public API and our existing accounting integration (like QuickBooks Online) enabled at the same time?
No. The API module and the Integrations module are mutually exclusive on an organization. Contact your eSUB representative to discuss switching.
Who can create or manage API credentials?
Any user with the Secrets Management permission, once the module is enabled. You do not need to involve eSUB Support.
Can I see my Client Secret again after I create or rotate it?
No. It is shown once, at creation or rotation. If you lose it, rotate the credential to get a new one.
What happens to requests made with my old secret after I rotate it?
Tokens already issued keep working until they expire (up to 1 hour). After that, only the new secret works.
What are the Change Orders and Purchase Orders tabs under API Settings?
They let you configure Integration Pickup separately for each document type. Manual Submit controls whether a document must be submitted before your integration can pick it up, and Lock on Submit controls how much of the document is locked once it is submitted. See Integration Pickup.
I revoked a credential and it still shows "Revoking." Is that normal?
Yes. Revoking briefly moves through a Revoking status before settling to Revoked. This cannot be undone.
Why does data from the API look like sample data instead of our real data?
Some resources are still being rolled out and may return sample data for a period before switching to live data. Check the eSUB Public API Reference for current status, or contact eSUB Support if you are unsure.
Where do I find technical documentation for a developer building our integration?
See the eSUB Public API Reference for authentication details, available endpoints, and field-level schemas.
Can Crew Members log into eSUB through the API?
Not yet. Crew Members can be read through the API, but provisioning them as users who can log in is not supported today.