Pricing
About Us Careers Tally Together Media & News
Select Country

    GST/ASP Consent: What Is It and How Will It Work for Taxpayers?

    Abilash S

    Oct 6, 2026

    30 second summary | GST/ASP consent is the OTP-based permission that lets an Application Suvidha Provider (ASP) reach your GST data through a GST Suvidha Provider (GSP). Under Manage API Access, taxpayers pick the GSP-ASP pair and duration, view 30 days of token logs and revoke any active token with a reason.

    GST/ASP consent allows taxpayers to authorise a GST Suvidha Provider (GSP) to access and process GST-related data through authorised APIs. This consent creates a secure link between the taxpayer, GSP and GST system for services such as return filing, reconciliation and compliance. 

    Understanding how consent works is important because taxpayers may need to review and approve access before an Application Service Provider (ASP) can use GST data on their behalf. Here’s what GST/ASP consent means, how it works and what taxpayers need to know.

    What is GST/ASP consent?

    GST/ASP consent is the taxpayer’s authorisation for an ASP, GSP or other solution provider to access GST services through APIs on the taxpayer’s behalf. An ASP is a software provider that routes a taxpayer’s GST data to the GST system through a GSP.

    How do you give ASP consent on the GST portal?

    Your software can request an OTP only after you authorise its GSP-ASP pair. Follow these steps:

    1. Log in to gst.gov.in.
    2. Go to My Profile > Manage API Access.
    3. Set Enable API Request to Yes.
    4. Choose the GSP, the ASP and the duration.
    5. Click Select and confirm.

    Repeat this for every GSTIN that uses the software.

    What can taxpayers see and do under Manage API Access?

    The November 2025 Functionality Deployment Report, shared through Trade Notice No. 21/2026, added three options to this screen:

    Option

    What it shows

    View Logs

    Every token request in the last 30 days with GSP and ASP name, date, time, auth action (OTP Initiated, OTP Verified, Refresh, Logout or Revoked) and status

    Revoke Active Token

    Tokens activated in the last 30 days with activation time, refresh count, last refresh, refresh validity and expiry time

    View Revoked Token

    Tokens revoked in the last 30 days with activation time, revoke time and your reason

    Each auth action is a separate row in View Logs, so one session can show several entries.

    Who are the GSP and the ASP in this process?

    An ASP is the company whose software you use for GST-related transactions. A GSP is the authorised intermediary that carries data between that software and the GST portal. Each API session runs on a token that starts when you verify the OTP and can be refreshed until its validity ends. Anyone holding an active token can keep pulling your data. 

    What happens when you revoke an ASP token?

    Click Revoke next to the token and enter a reason (if any). The portal notifies both you and the GSP by email and SMS. The token then moves to View Revoked Token, while View Logs records the action. Taxpayers can view all tokens revoked in the last 30 days, along with the GSP and ASP names, activation and revocation dates and times, and the reason for revocation.

    What should taxpayers watch out for?

    A quick check of your GSP/ASP access can help you spot unwanted activity and avoid disrupting legitimate GST work.

    • Revoking an active token: If your accountant is using the token to upload data, revoking it can interrupt the process.
    • Checking logs regularly: The portal keeps logs for only 30 days, so review them at least once a month.
    • Unrecognised OTP requests: If you see an OTP-initiated entry from an ASP you do not use, investigate it. Revoke the related token and consider changing your GST Portal password.
    • Keeping contact details updated: Revoke alerts are sent to the email address and mobile number linked to your GST registration. Make sure they are current.
    • Checking each GSTIN separately: Tokens and logs are maintained separately for each GSTIN. If you have multiple registrations, review each one.

    Conclusion

    GST/ASP consent gives taxpayers greater visibility and control over third-party access to their GST data. By using Manage API Access, you can authorise API access, review recent activity and revoke active tokens when needed. Regularly checking these records can help you identify unfamiliar access and avoid disruptions to legitimate GST work. If you use accounting software for GST compliance, keeping your API access and GST records organised can make day-to-day processes easier. Explore TallyPrime to simplify your accounting and GST compliance workflow

    Verify GSTIN details online

    Enter a GSTIN/UIN to check the business name, registration status, taxpayer type and more.

    cta banner image

    FAQs

    Only if you file or download GST data through third-party software. Returns filed directly on the GST portal need no ASP consent.

    View Logs and View Revoked Token both cover the last 30 days.

    Yes. The portal sends an email and SMS to both you and the GSP.

    Yes. Active tokens are listed with their GSP and ASP names, so you can revoke one and leave the others running.

    The ASP renewed its token without a fresh OTP. Revoke Active Token shows the refresh count and how long refreshes stay valid.

    Published on October 6, 2026

    left-icon
    1

    of

    4
    right-icon

    India’s choice for business brilliance

    Work faster, manage better, and stay on top of your business with TallyPrime, your complete business management solution.

    Get 7-days FREE Trial!

    I have read and accepted the T&C
    Submit