# Finalcad One API > Finalcad One is a construction field-management platform (mobile, web, CAD plugin) used to run > punch lists, quality and safety inspections, site meetings, plans and documents on building > projects. The Finalcad One API exposes the platform's organization, project, library, content and > media surface over REST so an ERP, HRIS, CRM, EDM or BI tool can drive project setup and read site > data back. Finalcad is a solution of Orisha Construction following Orisha's March 2025 acquisition > of Advae (the Finalcad + Wizzcad merger). GENERATED by API Evangelist from the provider's public surface on 2026-08-17. Finalcad does not publish an llms.txt of its own (https://developer.finalcad.com/llms.txt returns 404). Nothing here is invented; every fact is traceable to the developer portal, the help centre, or a live probe. ## Access - API access requires the client organization to hold a Finalcad One **Enterprise** licence. - The API key is issued by Finalcad after it validates the organization's eligibility, then generated by the customer from the user menu of the Finalcad One web app. There is no self-service developer signup and no free tier. - Every call carries two headers: `X-API-Key: ` identifies the organization, and `Authorization: token ` (or the legacy `Authorization: bearer `) carries the caller's rights. - Base URL: `https://developer.finalcad.cloud/api` - Sandbox: `https://developer.sandbox.finalcad.cloud/api` ## Documentation - Developer portal (Postman public documenter, the authoritative reference): https://developer.finalcad.com/ - Postman collection JSON (201 requests): https://developer.finalcad.com/api/collections/10995648/Tz5v1Es2 - Help centre — Public API collection: https://help.finalcad.com/en/collections/20-public-api - Introductory guide to APIs: https://help.finalcad.com/en/articles/43-introductory-guide-to-apis - Get your API key: https://help.finalcad.com/en/articles/86-get-your-api-key - Status: https://status.finalcad.cloud/ and https://finalcad.statuspage.io/ - Web app login (EU): https://finalcadone-web.eu.finalcad.com/login - Web app login (APAC): https://finalcadone-web.ap.finalcad.com/login ## Surface 201 published requests across six areas: - **Authentication** (2) — legacy user-token exchange, get connected user. - **Libraries** (5) — module colors, module icons, module suggestions, languages, time zones. Read-only reference data you must resolve before creating content. - **Medias** (7) — single-shot upload for files up to 5 MB, chunked upload (init / append / terminate / abort) above that, media resource lookup and downloadable URL. - **Organization management** (65) — workspaces, members and roles, observation status / trade / common-observation / priority / form-template libraries, form and observation module types, data referentials, and daily Parquet dataset configuration for BI. - **Project** (115) — project details, project libraries, members, locations (folders, plans, IFC and RVT upload), discussion groups, companies, modules (observations / forms / meetings), observations, forms and form answers, documents, phases, meetings, and XLSX / PDF exports. - **Webhooks** (6) — list event codes, create, read, update and delete hooks. ## Core model Organization → Workspace (optional) → Project → Module → Item (Observation | Form | Meeting). Two independent folder trees hang off a project: Locations (folders → plans) and Documents (folders → documents). A project inherits its organization's or workspace's libraries at creation. ## Conventions an agent must know - **Pagination and change feed are the same mechanism.** Send `limit` (default 50); the response carries `need_to_relaunch`, `continuous_token`, `count` and `total_count`. Page forward while `need_to_relaunch` is true. Keep the final `continuous_token`, call again later, and you get only what was added, modified or deleted since — a delta feed with no separate endpoint. If you use `offset` instead, it must be a multiple of `limit` or the call 400s. - **There is no idempotency key.** Retry safety is signalled after the fact by the error code suffix: `_ERR{n}` means the endpoint rolled back (safe to replay), `_WRN{n}` means it could not roll back (replaying will duplicate). Bulk operations that partially succeed return **206**. - **Errors are proprietary, not RFC 9457.** Body shape is `{"statut": , "api_code": "", "message": "", "data": {...}}` as `application/json`. Gateway-level 401/403 use a different shape (`{"message": "..."}`) with no `api_code`, so parse for both. - **Set `Accept-Language`** to pick the API's operating language; allowed values come from `GET /languages`, default `en`. Content names are separately multilingual — objects carry a `names[]` array of `{language, translation}`. - **No rate limits are published**, no `RateLimit-*` headers are returned, and no 429 is documented. - **Path-variable naming is inconsistent** across endpoints (`:organization_id`, `:organizationId`, `:organizationid`; `:project_id`, `:projectId`). Do not assume one form. - **Some reads are POSTs** — `POST /organizations/{organization_id}/members` and `POST /projects/{project_id}/observations/filter` are both queries. - **Bulk export is the better read path for analysis.** Fifteen-plus datasets regenerate daily at 06:00 and download as Parquet via `GET /organizations/{organization_id}/data/config/dataseturl?name=`. Finalcad ships a Power BI template for it. ## What Finalcad does NOT publish - No OpenAPI, no AsyncAPI, no GraphQL, no gRPC. The Postman collection is the only machine-readable contract. - No SDK or client library on npm, PyPI or RubyGems, in any language. - No MCP server and no A2A agent card. - No `/.well-known/` documents of any kind on any host — no `security.txt`, no `openid-configuration`, no `api-catalog`. - No published rate limits, no published prices or plans, no SLA, no trust centre and no named certifications. - No webhook payload schemas, no callback signature, and no documented retry policy; the full event code list is only readable with an API key. - No deprecation policy — superseded endpoints are labelled "OBSOLETE" in the documentation and left in place. ## Repository artifacts - collections/finalcad.postman_collection.json — the provider's own collection, saved - openapi/ — six OpenAPI 3.1 documents derived from that collection (200 operations) - authentication/, conventions/, errors/, lifecycle/, changelog/, data-model/, conformance/ - asyncapi/finalcad-webhooks.yml — the webhook catalog and its gaps - sandbox/, plans/, rate-limits/, packages/, well-known/, security/, mcp/, skills/