Before you connect
Six things to have ready
Connecting a Creatio system to ctx10 takes about ten minutes
once these six things are ready. Each of them has come up in the middle of a setup call at least
once, usually as an administrator who was not on the call, or an on-premises instance with no
Identity Service for OAuth. Every one is something only you can do inside your own Creatio,
because we never write to it, not even to set this up.
Nothing here is a form we can fill in for you.
A package your administrator installs, a permission they grant, an integration user, and a
route through the firewall. Send this page to whoever holds those, and the call afterwards is
short.
The checklist
In order, with who does it
Items 02 to 05 all need the same person. If you are an implementation partner connecting a
client’s instance, that is one conversation with their administrator, and you can have
it once.
- 01
A Creatio instance, and its version
Tell us the version before we start. 8.0.0 and later is supported. Older than that we take one at a time, so say so when you ask.
you, in one sentence - 02
Someone who can install an application
The ctx10 package installs through Application Hub, which needs a Creatio administrator. Once per Creatio system.
a Creatio administrator - 03
The export permission, granted
The operation CanRunExpDataExport granted to the user we connect as. The package denies every call until it is.
a Creatio administrator - 04
An integration user
One Creatio user that exists to be ctx10’s, active and not locked. It never needs write access to anything.
a Creatio administrator - 05
Credentials for it
Either an OAuth 2.0 client on the client-credentials flow, or that user’s username and password. How to choose is further down.
a Creatio administrator - 06
A route in
Your Creatio reachable over HTTPS from ctx10, either openly or by allowlisting our address. Ask and we send the details.
whoever owns your firewall
01 · Version
Which Creatio versions
| 8.0.0 and later | Supported | Every 8.x and 10.x release. We read the version out of Creatio’s own ConfigurationVersion setting on the first capture, and what moves between releases is a handful of platform tables the capture already falls back on. |
| 10.0 | Verified | A complete pipeline run against a real 10.0 production deployment. This is the version our own hosted instances run on. |
| 8.3.4 | Verified | The version the engine was built against: a full 21-stage build against a real instance on 10 July 2026 — 425 packages, 1,326 code edges, 640 assemblies. |
| Earlier than 8.0.0 | On request | Not refused, and not promised as a band either. Say so when you ask and we will talk it through before anything is connected. |
What those two words mean, exactly
- Supported is the band we stand behind. Nothing in the product checks your
version and turns you away, and 8.0.0 and later is what we connect without asking anybody
first.
- Verified is narrower, and it is evidence. One exact version, a complete
pipeline run against a real instance of it, and the resulting numbers written down. A
version being supported but not verified means the first index is watched: when a build
stage trips on a shape we have not seen before, we fix it on our side.
- You do not have to be precise. We read the version out of Creatio’s own
ConfigurationVersion setting on the first capture. Telling us up front only
decides how closely we watch.
- Your instance may be the one that verifies its version. That is how the
list grows, and it costs you nothing either way.
02 · The package
One package, installed by an administrator
ctx10 reads your configuration through a small package that runs
inside Creatio. You download it from Setup → Download addon package in your
workspace, and install it the way you install any Creatio application: Application
Hub, or clio install if your team works that way.
Installing an application needs an account that is allowed to, which in practice means a
system administrator. This is the step a partner most often cannot do alone on a client’s
production, so ask for it early.
It is once per Creatio system. Development, pre-production and production are
three systems, so that is three installs. Comparing them against each other is most of what the
product is for.
The package only reads. It takes one SELECT at a time and refuses anything else
before it reaches the database. The session it runs in is held read-only by the database
itself and rolled back afterwards. How read-only is enforced →
03 & 04 · Permission and user
The permission, and who holds it
The package denies every call by default. It is switched on through Creatio’s ordinary
permission system: System Designer → Operation permissions, the operation
CanRunExpDataExport, granted to the role, or directly to the user, that the connection
signs in as. Revoking it later stops us the same way.
Give it to an integration user: one Creatio account that exists to be
ctx10’s rather than a person’s login borrowed for the
afternoon. Name it so that an audit log a year from now still makes sense. It has to be
active and not locked, and it needs no write access to any object.
If you would rather enforce that on your side as well, ask us and we will walk your
administrator through putting the account in a read-only role.
05 · Credentials
OAuth, or a username and password
Both reach the same read-only endpoint. The choice comes down to whether this instance has
an Identity Service you can reach.
Recommended · the default tab
OAuth 2.0 client credentials
In Creatio: System Designer → OAuth 2.0 client credentials, add a client
using the Client Credentials flow. We ask for the
identity service URL, the client ID and the
client secret, and exchange them for a token at
/connect/token on that URL.
The identity service URL is usually your Creatio address with -is before the
domain: https://yourcompany-is.creatio.com/. Creatio cloud instances generally
have one.
Pick this when you can. Nothing signs in as a person, and the secret can be
rotated without touching an account.
Equally supported
Username and password
An ordinary Creatio sign-in as the integration user, with the credentials a person would
type.
Pick this when there is no Identity Service, or when there is one but it is
not published outside your network, which is common on on-premises
installations. The export path and the read-only guarantees are identical.
Do not stand up an Identity Service just for us.
The choice is fixed for that system once it is connected. Editing a connected
system can change its URL and rotate its credentials, but it cannot switch method. If you are
unsure which you will end up using, ask us before you connect.
06 · Reachability
Outbound only. Ask us for allowlisting details
Allowlisting
Every call ctx10 makes to your Creatio is outbound HTTPS from our
platform. If your firewall needs to allowlist us, write to that address and we send your admin
the details. We tell you before they change.
- Nothing dials in. We make outbound HTTPS requests to your Creatio URL, and to
your identity service URL if you chose OAuth. There is no inbound rule to open and no
callback.
- If your instance is IP-allowlisted, ask us for the allowlisting details before
you connect. Add them and run the connection test in your workspace, which tells you straight
away whether it took.
- If your instance is on-premises or VPN-only, it has to be reachable from the
public internet for us to read it. There is no ctx10 agent that
runs inside your network today. The arrangement that works is the ordinary one:
published, and restricted to the addresses we give you.
- If that is not going to happen, and for some productions it will not,
connect a copy instead. It is the easier ask anyway.
Which instance
A test copy is fine
ctx10 reads how your Creatio is set up, not the records
inside it. A restored copy of production carries the same configuration and so produces the same
answers.
So the first instance you connect can be whichever one is easiest to get approved. Most people
start with a test copy and connect production afterwards, once the findings have made the
argument for them. The index and the report are the same ones either way.
You will want more than one eventually, because seeing what reached production without going
through a release means comparing production against pre-production, and that needs both of them
connected.
When you connect
Test connection checks all four
You test before you save, and the Connect button only appears once the test
passes, so a system that could never be captured is never stored. Each check reports
separately, with the fix for whichever one failed.
- 01
Sign in to Creatio
The credentials are accepted: an OAuth token comes back, or the login succeeds.
- 02
ctx10 addon installed
The export service answers. A 404, or Creatio’s login page instead of the service, means the package is not installed.
- 03
Export permission (CanRunExpDataExport)
The user we signed in as is allowed to run an export. A refusal here is a role change, not a reinstall.
- 04
Run a test export
One row, one page, exactly the way a real capture asks for it.
If a check fails and the fix it names does not work, send us what it said. The message comes
from your Creatio and it is usually enough for us to tell you which of the six above is missing.
How we keep it read-only → Ask us something →