The API Report CardAPI Index
Building Engines

Building Engines API

Commercial building operations and work order management · buildingengines.com

Prism has a real public REST API: a Swagger spec with 857 paths, Redoc reference and signed webhooks for work orders and visitors. The gate is credentialing: keys are registered through Building Engines, auth is password based JWT, and there is no sandbox or SDK.

Last verified: September 2026Real Estate & PropertyNO MCP
API GRADE
C
VERIFIED SEP 2026

SCORECARD

ExistenceGOODPublic Swagger 2.0 spec at api.connect.buildingengines.com plus a JLL hosted developer portal and Redoc reference.
AccessPOORProduction API keys are registered through Building Engines (integrations@buildingengines.com); no self-serve key page.
CoverageGOOD1,365 operations incl. 383 POST; HMAC signed webhooks for work order status, assignee, comments and visitor check in.
AuthMIXEDX-Prism-App application key plus a user JWT from POST /auth/login with email and password; OIDC SSO optional.
Docs & DXMIXEDStrong reference (Redoc, Swagger, how to guides) but no sandbox environment and no official client libraries.
StabilityMIXEDSpec is labeled Prism API 1.0 with a small v2 tag group; no public changelog, one leaked deprecation note with a 2026 sunset.
MCPNONENo official or community MCP server found for this platform.
What you can do
Create and update work orders with charges60 work order operations
Receive signed webhooks on work order eventsHMAC SHA-256 payloads
Read and write visitors, COIs, contracts, PM tasksFull CRUD across 98 tags
Pull accounting batches for GL exportBatch and export endpoints
What you can't
Generate an API key from the portalRegister with the vendor
Test in a sandbox environmentNone documented
Use an official SDKGenerate from the spec
Rely on documented rate limitsNot published
Supergood turns hard-to-integrate enterprise software into clean REST APIs and MCP tools: stable endpoints, normalized JSON, managed auth.

Frequently asked questions

Building Engines scores C on Supergood's API Report Card. Prism has a real public REST API: a Swagger spec with 857 paths, Redoc reference and signed webhooks for work orders and visitors. The gate is credentialing: keys are registered through Building Engines, auth is password based JWT, and there is no sandbox or SDK.

Tried to integrate with Building Engines?
SOURCES
A property management company reviewer says integrating Building Engines with existing software and systems "presented some challenges." spotsaas.com
HqO's integration guide requires each site to create a Prism API admin user and share its email and password with HqO, with a two to three week setup timeline. helphub.hqo.com
A five year user reports guest arrival notifications failing every year and support closing tickets as user error before the issue is fixed. softwareadvice.com
Administrators must contact support to grant another administrator permissions, and subcontractor COI tracking forces a full vendor profile setup. softwareadvice.com
A G2 reviewer calls the Prism service request design poor, says it generates an enormous number of unnecessary emails, and that preventive maintenance scheduling and reporting are still being built. spotsaas.com
Tenants get no status updates between submitting a request and the technician arriving. softwareadvice.com