Pricing
About Us Careers Tally Together Media & News
Select Country

    GST Portal to Notify Taxpayers About ASP Access: What Changes for Businesses?

    Abilash S

    Updated on Oct 6, 2026

    30 second summary | GST API access is becoming easier to track and control as businesses rely on ERPs, accounting software and other third-party tools. Taxpayers can review recent access activity, identify active tokens and revoke unwanted connections. Regular checks keep vendor access organised, avoid unexpected workflow disruptions and maintain a clear record of changes to GST integrations.

    If you use an ERP, accounting software or other third-party application to access GST services, you can now get greater visibility and control over its API access. The GST Portal allows you to view GSP/ASP access logs, check active tokens and revoke them when required. The changes are designed to give you more control over third-party GST integrations and help you monitor which applications can access your GST data.

    How ASP and GSP access works

    The GST system allows taxpayers to use third-party applications for GST-related activities instead of relying only on the GST portal. These applications can help you manage invoices, reconcile data, prepare returns and exchange information with the GST system through APIs. GSTN describes the GST Suvidha Provider (GSP) as the technology intermediary that connects third-party applications with the GST system through secure APIs.

    An Application Service Provider (ASP) sits at the application layer. It provides the software or interface that you use to manage your GST data. Importantly, GSTN states that ASPs are not separately empanelled. An ASP needs to tie up with a GSP to send its clients' GST data to the GST system or retrieve data from it. In simple terms, the ASP provides the application, while the GSP provides the technical connection to the GST system.

    The access flow can therefore be understood as: 

    Taxpayer → ASP/Application → GSP → GST System

    Depending on the service and API being used, you may need to authenticate and authorise access using your GST credentials and other authentication mechanisms. The GSP then handles the API-level communication with the GST system. GSTN's framework also allows taxpayers to choose their application provider and GSP independently.

    How were the GST GSP and ASP access controls introduced?

    The GST portal's GSP/ASP access controls have been introduced in stages rather than through a single release:

    1. In July 2025, GSTN announced planned security enhancements covering ASP/GSP access. These included notifications to taxpayers after successful OTP-based consent and facilities to view and revoke active ASP/GSP access.
    2. Trade Notice No. 20/2026, issued by the CGST Delhi South Commissionerate in connection with the Functionality Deployment Report for October 2025, listed ‘Taxpayer Consent Management and GSP/ASP Access Revocation’ as a Front Office/G2B API change. However, the notice described it as a technical backend change and stated that it did not need to be communicated to States or the CBIC.
    3. The subsequent Trade Notice No. 21/2026, covering the November 2025 functionality deployment report, provided details of the taxpayer-facing functionality. It states that taxpayers can manage GSP/ASP API access through My Profile > Manage API Access, with three facilities: View Logs, Revoke Active Token and View Revoked Token.

    How can you revoke an active GSP or ASP token?

    Here is the process in simple steps:

    Step 1: Open API access

    Log in to the GST Portal and go to My Profile > Manage API Access. You will see three options: View Logs, Revoke Active Token and View Revoked Token.  

    Step 2: Select active tokens

    Click Revoke Active Token. The portal will show the active tokens that were activated during the previous 30 days. The list includes details such as the GSP/ASP name, token activation time, number of refreshes, latest refresh time and token validity.  

    Step 3: Identify the token

    Check the details displayed in the list and find the GSP or ASP token whose access you want to stop. The portal provides a Revoke option against the relevant active token.  

    Step 4: Give a reason

    Click Revoke against the selected token. You will be asked to provide a reason for revocation. Enter the reason and submit the request.  

    Step 5: Check confirmation

    After you submit the revocation request, the system sends an email and an SMS to both you and the concerned GSP. The revoked token is removed from the Active Tokens list and moved to the Revoked Tokens list. The action is also recorded under View Logs.

    Step 6: View revoked tokens

    The token is moved to the Revoked Tokens list, and the revocation is also recorded under View Logs. You can use View Revoked Token to check tokens revoked during the previous 30 days, along with the activation date, revocation date and the reason provided.

    Why should businesses care about this change?

    Here is why this change matters for businesses:

    Access audit

    Many businesses cannot say which third-party tools can read their GST data. Finance teams change ERPs, outsource filing, try reconciliation tools and drop them. Each integration may have left behind a live permission. The log and token views let you check this against your own vendor list.

    Access control

    Revocation is immediate and sits with the taxpayer. If an employee left, a vendor contract ended, or a tool looks suspicious, you can cut the connection yourself. Under GSTN's advisory, the ASP then needs fresh OTP consent to fetch your data again.

    Contact details

    Alerts and revocation messages go to registered contacts. If the registered mobile number or email belongs to a former employee or a consultant, the alert goes to the wrong person. Update contact details through the portal's amendment process.

    Data hygiene

    The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and different provisions are scheduled to come into effect in phases in November 2025, November 2026 and May 2027. GST data can include invoice-level information about your customers and suppliers. Knowing who can access this data, and being able to demonstrate that you manage such access, is good practice as broader data protection obligations take effect. Treat the Digital Personal Data Protection framework as a compliance-readiness consideration, not as a GST requirement.

    Operational effects

    Automated return fetching, GSTR-2B downloads, e-Way Bill and e-Invoice workflows can all fail if a token is revoked at the wrong time. A revoked ASP gets no data until you consent again. Do not revoke during a filing deadline window unless you mean to.

    What should businesses do now?

    Here are the steps that businesses should follow now:

    • Log in: Open Manage API Access and check whether the View Logs, Revoke Active Token and View Revoked Token links appear.
    • Prepare a list: Build a list of every ASP you use, including ERP, accounting, reconciliation, filing, lending and analytics tools. Compare it with the active tokens.
    • Investigate unfamiliar names: If an ASP or GSP is unrecognised, first check whether it is connected to an ERP, accounting application, filing service or another GST tool used by your business. If you cannot establish a legitimate connection, investigate it internally and consider revoking the relevant active token.
    • Keep the session duration practical: Longer sessions are convenient, but they mean fewer OTP prompts and a longer access window. Choose an access duration that matches how frequently the software needs to connect to GST services.
    • Fix registered contacts: Make sure the authorised signatory's email and mobile are current and monitored.
    • Set a review: Because the relevant access views cover the previous 30 days, a monthly check, perhaps just before GSTR-3B filing, can help you identify recent access activity before it falls outside the available review window.
    • Capture evidence: If you revoke access for a security reason, consider saving screenshots or other relevant records of the log entry and revocation reason as part of your internal controls.

    Conclusion

    Make API access reviews part of your regular GST controls rather than treating them as a one-time exercise. Assign one person from your finance or compliance team to own the review and document any changes made. Before switching accounting or compliance software, check how the new system will connect with GST services and who will manage the access. If you use TallyPrime alongside other GST tools, include all connected workflows in the same review so your technology setup remains organised as vendors and processes change.

    Verify GSTIN details online

    Enter a GSTIN/UIN to check the business name, registration status, taxpayer type and more.

    cta banner image

    FAQs

    Yes. GSTN's framework allows you to choose your application provider and GSP independently. This gives you flexibility when selecting the software and connectivity arrangement that fits your business.

    Yes. GSTN's framework allows an application provider and GSP to be the same entity. You should therefore not assume that two different companies will always be involved in your GST software setup.

    No. Revoking a GSP/ASP API token only stops the relevant API access. Your GST registration and records on the GST Portal are not cancelled merely because you revoke an application's token.

    No. You can continue using the GST Portal for your GST activities. The revocation concerns the authorised API connection associated with the relevant application or service.

    First, check whether the name is connected to an ERP, accounting application, filing service or other GST tool used by your business. If you cannot establish a legitimate connection, investigate it internally and consider revoking the relevant active token.

    Published on October 6, 2026

    left-icon
    1

    of

    4
    right-icon

    India’s choice for business brilliance

    Work faster, manage better, and stay on top of your business with TallyPrime, your complete business management solution.

    Get 7-days FREE Trial!

    I have read and accepted the T&C
    Submit