How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

CMIS

OASIS’s standard interface to enterprise content repositories — folders, documents, versioning, ACLs, a SQL-like query language and a change log — with a JSON “Browser” binding over HTTP, an AtomPub binding and a SOAP binding. CMIS 1.0 shipped in 2010 and 1.1 in 2013; the committee has been quiet since, but it is implemented by Alfresco, SharePoint, Nuxeo, OpenText and IBM FileNet, and it remains the fullest industry-wide specification of a document namespace over HTTP.

CMIS is what the enterprise content management vendors agreed on when every one of them had a different API to the same thing: a tree of folders and documents with metadata, versions and permissions. It defines a domain model and then three ways to reach it over HTTP, and the Browser binding — plain JSON, designed so a web page could call it — is the one still worth reading.

  • Folders and documents - Create, update, move, delete, and getObject for metadata without content. Documents carry a content stream and typed properties.
  • Versioning built in - Check out, check in, version series, and private working copies. Most file protocols leave this out; CMIS made it core.
  • CMIS Query Language - A SQL-like query over object types and properties, so searching happens on the server instead of by walking the tree.
  • Change log - getContentChanges with a change-log token returns what was created, updated, deleted or had its security changed since the token. Delta sync was in the standard in 2010.

I include CMIS because it answers a question that keeps coming back in 2026: what does a file-system-shaped API look like when a whole industry, not one vendor, has to agree on it? The answer had search, versions, ACLs and a change feed in it from the start, and ran over HTTP with AtomPub and JSON bindings. The committee has not published since 2013, and nobody designing an agent-facing file surface today reads it, which is a shame, because the Model Context Protocol file-system charter is slowly re-deriving its operations list. CMIS is the dormant, over-complete version of the thing; it is useful precisely as a checklist of what was found necessary last time.