REST API · Webhooks · OAuth 2.0

COI Tracking API for Contractor and Vendor Compliance

Your contractors' compliance status, in the systems that pay them and put them on site.

Read each sub's compliance status and the reasons behind it, add contractors from your own tools, email them their upload link, and get a webhook the moment a certificate of insurance or a licence nears expiration. JSON over HTTPS, an API key or OAuth 2.0, and the same rules as the app.

GET /api/v1/contractors?email=office@ridgeline.example
{
  "data": [{
    "id": 412,
    "name": "Ridgeline Electric",
    "email": "office@ridgeline.example",
    "active": true,
    "compliance_status": "not_compliant",
    "compliance_reasons": [
      "The certificate from Travelers expired Sep 1, 2026"
    ],
    "url": "https://trackmyvendor.com/app/vendors/412"
  }],
  "meta": {
    "page": 1, "per_page": 25,
    "total": 1, "has_more": false
  }
}

How the COI tracking API works

TrackMyVendor still does the collecting: subs upload through a link, certificates are read automatically, licences are checked against state databases. The API is how that result reaches your other systems.

1

Authenticate

Use the workspace's API key for your own scripts, or OAuth 2.0 for an app people connect to their account. Either one acts in exactly one workspace.

2

Read and write contractors

Look up a contractor's compliance status before you pay them or send them to site; add contractors and request their documents from the tool where they first appear.

3

Subscribe to events

Register an HTTPS URL for certificate, licence, W-9 and status events. Each delivery is signed, so you can check it came from us.

What the vendor compliance API gives you

Every call goes through the same code as the screens, so the API cannot disagree with what your team sees.

Compliance status for every contractor

Each contractor comes back with the same badge your team sees — compliant, not_compliant or no_documents — and the reasons behind it, with your required documents and project requirements counted.

Certificate of insurance expiration events

contractor.coi_expiring fires when a certificate, or one policy on it, enters one of your alert windows, carrying the carrier, the policy and the date. License expirations arrive the same way.

Add and update contractors

Create a contractor from your CRM, onboarding form or ERP, and change their contact details, active flag or auto-reminders later. Your plan's contractor limit and unique names apply, exactly as on screen.

Request documents

Email a contractor their upload link — the same email as Request Documents in the app, listing everything they owe. They upload COIs, W-9s and licences from their phone, with no account.

Subscribe and unsubscribe webhooks

Point an HTTPS URL at any of the five events and remove it again, from code. Deliveries are signed, retried, and carry a stable event id so you can deduplicate.

Sample events on demand

Ask for an example of any event, built from your own contractors in exactly the shape a delivery arrives in, so you can build the receiving end without waiting for a certificate to lapse.

Endpoints and webhook events

At a glance. Parameters, response shapes and every error code are in the API reference.

EndpointWhat it does
GET /api/v1/me Which workspace the credential acts in
GET /api/v1/contractors Contractors with their compliance status — filter, search, sort, page
GET /api/v1/contractors/:id One contractor
POST /api/v1/contractors Add a contractor, optionally emailing their upload link
PATCH /api/v1/contractors/:id Change a contractor
POST /api/v1/contractors/:id/document_requests Email a contractor their upload link
GET /api/v1/events?type= Example events built from your data
POST /api/v1/hooks Subscribe a URL to an event
DELETE /api/v1/hooks/:id Unsubscribe it
EventFires when
contractor.created A contractor is added, any way
contractor.compliance_changed Their compliance badge changes — checked each morning
contractor.coi_expiring A certificate or one of its policies enters an alert window
contractor.license_expiring A licence enters an alert window
contractor.w9_missing A contractor no longer has a W-9 on file

Expiring events fire at each of your alert windows — 90, 60, 30 and 7 days out by default.

What teams build with it

Small pieces of glue, not an implementation project.

Hold a payment until the COI is current

Before a bill is approved in your accounting system or ERP, check the contractor's compliance_status and show the approver the reason when it is not compliant.

Onboard from the form you already use

When a sub fills in your prequalification or onboarding form, create them here with request_documents set, and their upload link goes out at once.

Open a ticket before a certificate lapses

Route contractor.coi_expiring into your ticketing or project tool, assigned to whoever owns that sub, with the policy and the date in the ticket.

Keep a compliance column in your own reports

Page through contractors nightly into your warehouse or BI tool, so a roster report anywhere in the business carries the current status.

What the API does, and what it doesn't

  • Same rules as the app. Your contractor limit, unique names and the 48-hour pause between emails to one contractor all hold; a send inside the pause answers 409 cooldown unless you force it. Changes show in the contractor's activity, marked as coming from the API.
  • One workspace per credential. An API key or token never reaches another workspace, and a token stops working the moment its person loses access or disconnects the app.
  • Safe webhook targets only. Addresses on private networks are refused when you subscribe and again before every delivery.
  • No document files, yet. The API does not upload or download COI, W-9 or licence files. Contractors upload through their link, and the API tells you the result.
  • OAuth apps are registered by us. The API key is self-serve; an OAuth client for an app other people will connect is set up on request.

Simple, transparent pricing

The API, webhooks and the QuickBooks Online connection are part of Pro. Every plan starts free, and paid plans include a 30-day trial.

30-DAY FREE TRIAL — No credit card required

Free

$0
Up to 25 subcontractors · 1 user

Free forever. No credit card. No expiration date on the free tier.

  • ✓AI COI parsing and AI W-9 parsing — carrier, limits, policy dates, name, TIN and tax classification read for you
  • ✓Any other document, filed by category — contracts, financials, licensing, insurance
  • ✓License tracking in all 50 states, plus automated daily state-database verification
  • ✓Magic link uploads — your subs send documents without an account
  • ✓Expiration tracking across every license, certificate and W-9
  • ✓Weekly compliance digest by email
  • ✓Timestamped audit trail

Starter

$39/mo
Unlimited subcontractors · 2 users

Solo GC or property manager tired of chasing renewals manually — less than the cost of discovering one expired license on inspection day.

  • ✓Everything in Free
  • ✓Unlimited subcontractors — no 25-record ceiling
  • ✓Automated email alerts at 90/60/30/7 days — sent to your team and the contractor
  • ✓Calendar feed — subscribe every deadline into Google Calendar, Outlook or Apple Calendar
  • ✓Bulk import — add your roster from CSV or a certificate archive
  • ✓Invite a second user to your account
Most Popular

Pro

$59/mo
Unlimited subcontractors · Unlimited users

Multiple job sites or properties, with a foreman or office manager who also needs access.

  • ✓Everything in Starter
  • ✓AI-parsed endorsements — additional insured, waiver of subrogation, primary & non-contributory, read off the endorsement pages
  • ✓Projects — group subs by job or property, with per-project coverage requirements
  • ✓Unlimited users & team roles
  • ✓Integrations — QuickBooks Online, Zapier, Make, Slack and Teams
  • ✓Compliance reports (PDF & Excel)

No contracts. Cancel anytime. See the full plan comparison →

COI tracking API: common questions

Is there a certificate of insurance API?
Yes. The TrackMyVendor API returns each contractor's compliance status — worked out from their certificates of insurance, licences, W-9s and your required documents — and sends a contractor.coi_expiring webhook when a certificate or one of its policies enters an alert window, with the carrier, policy and expiration date. It does not take or return the certificate PDF itself: certificates arrive through the contractor's upload link and are read there.
How does the API authenticate?
Two ways, both as a Bearer token in the Authorization header. An API key, generated by a workspace owner, is for your own scripts. OAuth 2.0 (authorization code, with refresh tokens and PKCE) is for apps people connect to their account; OAuth clients are registered by us rather than self-serve, so get in touch with your app's name and redirect URI.
Which plan includes the API?
Pro. The API key, OAuth connections, webhooks and the QuickBooks Online connection are all part of Pro, which has a 30-day free trial with no credit card. If a workspace's plan stops including integrations, requests are refused until it does again; nothing is deleted.
Can I hold a payment when a contractor's COI has lapsed?
Yes, from your side. Look the contractor up by email or name before a bill is approved and check compliance_status; compliance_reasons says what is wrong in words you can show the approver. Teams on QuickBooks Online can skip the code: the native connection puts the same status on the vendor record.
What are the rate limits?
120 requests a minute per workspace. Over that, the API answers 429 with the code rate_limited. Lists page at up to 100 contractors a request.
Can I upload a COI or W-9 through the API?
Not yet. The API can email a contractor their upload link, and the contractor uploads from their phone without an account; the certificate is then read automatically. Uploading a file through the API itself is planned but not built.
Does it work with Zapier and Make?
Yes. The same five events reach Zapier and Make through webhooks today, with no code, and the setup guides on the integrations page walk through each one.

Put compliance status where the decisions get made

Start free, switch on Pro for 30 days, and make your first call in minutes.

Get started free — no credit card