Before you connect

Six things to have ready

Connecting a Creatio system to ctx10 takes about ten minutes once these six things are ready. Each of them has come up in the middle of a setup call at least once, usually as an administrator who was not on the call, or an on-premises instance with no Identity Service for OAuth. Every one is something only you can do inside your own Creatio, because we never write to it, not even to set this up.

Nothing here is a form we can fill in for you.

A package your administrator installs, a permission they grant, an integration user, and a route through the firewall. Send this page to whoever holds those, and the call afterwards is short.

The checklist

In order, with who does it

Items 02 to 05 all need the same person. If you are an implementation partner connecting a client’s instance, that is one conversation with their administrator, and you can have it once.

  1. 01

    A Creatio instance, and its version

    Tell us the version before we start. 8.0.0 and later is supported. Older than that we take one at a time, so say so when you ask.

    you, in one sentence
  2. 02

    Someone who can install an application

    The ctx10 package installs through Application Hub, which needs a Creatio administrator. Once per Creatio system.

    a Creatio administrator
  3. 03

    The export permission, granted

    The operation CanRunExpDataExport granted to the user we connect as. The package denies every call until it is.

    a Creatio administrator
  4. 04

    An integration user

    One Creatio user that exists to be ctx10’s, active and not locked. It never needs write access to anything.

    a Creatio administrator
  5. 05

    Credentials for it

    Either an OAuth 2.0 client on the client-credentials flow, or that user’s username and password. How to choose is further down.

    a Creatio administrator
  6. 06

    A route in

    Your Creatio reachable over HTTPS from ctx10, either openly or by allowlisting our address. Ask and we send the details.

    whoever owns your firewall
01 · Version

Which Creatio versions

8.0.0 and later Supported Every 8.x and 10.x release. We read the version out of Creatio’s own ConfigurationVersion setting on the first capture, and what moves between releases is a handful of platform tables the capture already falls back on.
10.0 Verified A complete pipeline run against a real 10.0 production deployment. This is the version our own hosted instances run on.
8.3.4 Verified The version the engine was built against: a full 21-stage build against a real instance on 10 July 2026 — 425 packages, 1,326 code edges, 640 assemblies.
Earlier than 8.0.0 On request Not refused, and not promised as a band either. Say so when you ask and we will talk it through before anything is connected.

What those two words mean, exactly

02 · The package

One package, installed by an administrator

ctx10 reads your configuration through a small package that runs inside Creatio. You download it from Setup → Download addon package in your workspace, and install it the way you install any Creatio application: Application Hub, or clio install if your team works that way.

Installing an application needs an account that is allowed to, which in practice means a system administrator. This is the step a partner most often cannot do alone on a client’s production, so ask for it early.

It is once per Creatio system. Development, pre-production and production are three systems, so that is three installs. Comparing them against each other is most of what the product is for.

The package only reads. It takes one SELECT at a time and refuses anything else before it reaches the database. The session it runs in is held read-only by the database itself and rolled back afterwards. How read-only is enforced →

03 & 04 · Permission and user

The permission, and who holds it

The package denies every call by default. It is switched on through Creatio’s ordinary permission system: System Designer → Operation permissions, the operation CanRunExpDataExport, granted to the role, or directly to the user, that the connection signs in as. Revoking it later stops us the same way.

Give it to an integration user: one Creatio account that exists to be ctx10’s rather than a person’s login borrowed for the afternoon. Name it so that an audit log a year from now still makes sense. It has to be active and not locked, and it needs no write access to any object.

If you would rather enforce that on your side as well, ask us and we will walk your administrator through putting the account in a read-only role.

05 · Credentials

OAuth, or a username and password

Both reach the same read-only endpoint. The choice comes down to whether this instance has an Identity Service you can reach.

Recommended · the default tab

OAuth 2.0 client credentials

In Creatio: System Designer → OAuth 2.0 client credentials, add a client using the Client Credentials flow. We ask for the identity service URL, the client ID and the client secret, and exchange them for a token at /connect/token on that URL.

The identity service URL is usually your Creatio address with -is before the domain: https://yourcompany-is.creatio.com/. Creatio cloud instances generally have one.

Pick this when you can. Nothing signs in as a person, and the secret can be rotated without touching an account.

Equally supported

Username and password

An ordinary Creatio sign-in as the integration user, with the credentials a person would type.

Pick this when there is no Identity Service, or when there is one but it is not published outside your network, which is common on on-premises installations. The export path and the read-only guarantees are identical.

Do not stand up an Identity Service just for us.

The choice is fixed for that system once it is connected. Editing a connected system can change its URL and rotate its credentials, but it cannot switch method. If you are unsure which you will end up using, ask us before you connect.

06 · Reachability

Outbound only. Ask us for allowlisting details

Allowlisting

Every call ctx10 makes to your Creatio is outbound HTTPS from our platform. If your firewall needs to allowlist us, write to that address and we send your admin the details. We tell you before they change.

Which instance

A test copy is fine

ctx10 reads how your Creatio is set up, not the records inside it. A restored copy of production carries the same configuration and so produces the same answers.

So the first instance you connect can be whichever one is easiest to get approved. Most people start with a test copy and connect production afterwards, once the findings have made the argument for them. The index and the report are the same ones either way.

You will want more than one eventually, because seeing what reached production without going through a release means comparing production against pre-production, and that needs both of them connected.

When you connect

Test connection checks all four

You test before you save, and the Connect button only appears once the test passes, so a system that could never be captured is never stored. Each check reports separately, with the fix for whichever one failed.

  1. 01

    Sign in to Creatio

    The credentials are accepted: an OAuth token comes back, or the login succeeds.

  2. 02

    ctx10 addon installed

    The export service answers. A 404, or Creatio’s login page instead of the service, means the package is not installed.

  3. 03

    Export permission (CanRunExpDataExport)

    The user we signed in as is allowed to run an export. A refusal here is a role change, not a reinstall.

  4. 04

    Run a test export

    One row, one page, exactly the way a real capture asks for it.

If a check fails and the fix it names does not work, send us what it said. The message comes from your Creatio and it is usually enough for us to tell you which of the six above is missing.

How we keep it read-only Ask us something