Milestone MIP SDK and API Gateway
Compare MIP SDK and API Gateway against the required XProtect workflow. Check supported versions, permissions and deployment before implementing video, event or configuration access.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Inherited check dated 10 September 2026. Supporting evidence for this inherited check has not been independently confirmed.
Recorded scope: The official integration modes page was checked for the protocol, plugin and component integration families. SDK versions, licences and deployment support remain product specific.
Public MIP SDK documentation and release notes reviewed on 25 August 2026; exact XProtect edition/build, API availability, licences, runtime, authentication configuration, media entitlement, and backward compatibility are not asserted.
On this page
Overview#
Vendor APIs / VMS and cloud video / Milestone
The Milestone Integration Platform (MIP) isn't one SDK call surface. It defines three major integration modes: remote protocol integrations, reusable .NET components, and in process plugins hosted by XProtect applications. The API Gateway provides a current front door for selected REST/protocol services. Select the least coupled mode that supplies the required function.
Documented interface map#
| Surface | Execution boundary | Documented capability | Coupling |
|---|---|---|---|
| MIP protocol APIs | Remote process, potentially any OS/language | Configuration, events/alarms, messaging/control, video/audio/metadata, authentication, status and other service families | Lowest host coupling; each protocol has its own contract |
| MIP .NET components | External .NET application | Higher level access to XProtect services and object models | Coupled to supported .NET/package/product versions |
| MIP plugins | Inside Smart Client, Management Client or Event Server | Native UI, configuration and server workflow extensions | Highest privilege, process and upgrade coupling |
| API Gateway | XProtect gateway/front end | REST entry points and selected services, with centralized identity integration | Product/build/configuration and API availability apply |
The public MIP documentation explicitly describes protocol integrations as usable across operating systems and languages, while components and plugins are .NET centered. Because this page contains no code, languages: [] records example coverage, not SDK language support.
Capability families#
The official API overview groups integration needs including configuration, events and alarms, messaging and control, video/audio/metadata, authentication, access control, licensing and system status. Availability isn't uniform. Build a capability manifest against the installed XProtect product rather than selecting a library simply because a similarly named API appears in the documentation tree.
For media, record the selected service/protocol, stream profile, codec, transport, timestamp basis, playback/live distinction and authorisation lifetime. For events, record initial subscription position, filters, renewals, ordering, duplicate/gap behaviour and replay/reconciliation support. For control, document target state, preconditions, timeout outcome and audit correlation.
Authentication and authorisation#
Milestone documents Basic, Windows and OAuth related authentication paths in its environment/login guidance; the available method depends on integration mode and system configuration. The API Gateway uses the XProtect identity provider/OAuth/OIDC architecture for supported services.
- Prefer a non human workload identity where the supported flow allows.
- Use HTTPS and validate the server identity; don't disable
secureOnlyor certificate checks to make an example connect. - Scope privileges by site/device and capability: configuration, live, playback, export, audio, PTZ and administration are different rights.
- Keep client secrets and refresh/access tokens outside source, plugin packages and logs.
- Re authorise and reconcile after token expiry, management server failover or service restart.
Never infer that authentication to one MIP service grants access to every API behind the gateway.
Choosing an integration mode#
Use a remote protocol/API when service isolation, language choice and independent deployment matter. Use a component when the supported .NET abstraction removes meaningful protocol complexity. Use a plugin only when the workflow must be native to an XProtect client/server and the operational owner accepts host process risk.
For plugins:
- verify signing/distribution and supported host locations;
- avoid blocking host UI or Event Server threads;
- bound memory, media and event queues;
- use the host’s supported configuration and credential services;
- handle disable/uninstall and partial upgrade;
- test compatibility for every XProtect release the deployment supports.
Release and licence contract#
The public documentation tree showed MIP SDK 2026 R1 as a current documentation/release line on 25 August 2026, alongside earlier release trees. This is a dated documentation observation, not a claim that all customers should or can deploy it. The target XProtect edition, installed product build, device licence, integration licence and enabled gateway services determine availability.
Don't assume forward or backward binary compatibility. Read the exact MIP and XProtect release notes, breaking changes, runtime requirements and known limitations. Maintain an upgrade matrix and rollback plan.
Primary sources#
- MIP VMS API documentation, current public documentation root.
- MIP SDK architecture and integration modes, protocol/component/plugin boundaries.
- MIP API overview, capability families.
- Protocol APIs and API Gateway, official protocol catalogue.
- Environment login and authentication, identity modes and secure connection guidance.
- MIP SDK 2026 R1 introduction and release tree, dated lifecycle evidence.