If you use an ERP, accounting software or other third-party application to access GST services, you can now get greater visibility and control over its API access. The GST Portal allows you to view GSP/ASP access logs, check active tokens and revoke them when required. The changes are designed to give you more control over third-party GST integrations and help you monitor which applications can access your GST data.
How ASP and GSP access works
The GST system allows taxpayers to use third-party applications for GST-related activities instead of relying only on the GST portal. These applications can help you manage invoices, reconcile data, prepare returns and exchange information with the GST system through APIs. GSTN describes the GST Suvidha Provider (GSP) as the technology intermediary that connects third-party applications with the GST system through secure APIs.
An Application Service Provider (ASP) sits at the application layer. It provides the software or interface that you use to manage your GST data. Importantly, GSTN states that ASPs are not separately empanelled. An ASP needs to tie up with a GSP to send its clients' GST data to the GST system or retrieve data from it. In simple terms, the ASP provides the application, while the GSP provides the technical connection to the GST system.
The access flow can therefore be understood as:
Taxpayer → ASP/Application → GSP → GST System
Depending on the service and API being used, you may need to authenticate and authorise access using your GST credentials and other authentication mechanisms. The GSP then handles the API-level communication with the GST system. GSTN's framework also allows taxpayers to choose their application provider and GSP independently.
How were the GST GSP and ASP access controls introduced?
The GST portal's GSP/ASP access controls have been introduced in stages rather than through a single release:
- In July 2025, GSTN announced planned security enhancements covering ASP/GSP access. These included notifications to taxpayers after successful OTP-based consent and facilities to view and revoke active ASP/GSP access.
- Trade Notice No. 20/2026, issued by the CGST Delhi South Commissionerate in connection with the Functionality Deployment Report for October 2025, listed ‘Taxpayer Consent Management and GSP/ASP Access Revocation’ as a Front Office/G2B API change. However, the notice described it as a technical backend change and stated that it did not need to be communicated to States or the CBIC.
- The subsequent Trade Notice No. 21/2026, covering the November 2025 functionality deployment report, provided details of the taxpayer-facing functionality. It states that taxpayers can manage GSP/ASP API access through My Profile > Manage API Access, with three facilities: View Logs, Revoke Active Token and View Revoked Token.
How can you revoke an active GSP or ASP token?
Here is the process in simple steps:
Step 1: Open API access
Log in to the GST Portal and go to My Profile > Manage API Access. You will see three options: View Logs, Revoke Active Token and View Revoked Token.
Step 2: Select active tokens
Click Revoke Active Token. The portal will show the active tokens that were activated during the previous 30 days. The list includes details such as the GSP/ASP name, token activation time, number of refreshes, latest refresh time and token validity.
Step 3: Identify the token
Check the details displayed in the list and find the GSP or ASP token whose access you want to stop. The portal provides a Revoke option against the relevant active token.
Step 4: Give a reason
Click Revoke against the selected token. You will be asked to provide a reason for revocation. Enter the reason and submit the request.
Step 5: Check confirmation
After you submit the revocation request, the system sends an email and an SMS to both you and the concerned GSP. The revoked token is removed from the Active Tokens list and moved to the Revoked Tokens list. The action is also recorded under View Logs.
Step 6: View revoked tokens
The token is moved to the Revoked Tokens list, and the revocation is also recorded under View Logs. You can use View Revoked Token to check tokens revoked during the previous 30 days, along with the activation date, revocation date and the reason provided.
Why should businesses care about this change?
Here is why this change matters for businesses:
Access audit
Many businesses cannot say which third-party tools can read their GST data. Finance teams change ERPs, outsource filing, try reconciliation tools and drop them. Each integration may have left behind a live permission. The log and token views let you check this against your own vendor list.
Access control
Revocation is immediate and sits with the taxpayer. If an employee left, a vendor contract ended, or a tool looks suspicious, you can cut the connection yourself. Under GSTN's advisory, the ASP then needs fresh OTP consent to fetch your data again.
Contact details
Alerts and revocation messages go to registered contacts. If the registered mobile number or email belongs to a former employee or a consultant, the alert goes to the wrong person. Update contact details through the portal's amendment process.
Data hygiene
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and different provisions are scheduled to come into effect in phases in November 2025, November 2026 and May 2027. GST data can include invoice-level information about your customers and suppliers. Knowing who can access this data, and being able to demonstrate that you manage such access, is good practice as broader data protection obligations take effect. Treat the Digital Personal Data Protection framework as a compliance-readiness consideration, not as a GST requirement.
Operational effects
Automated return fetching, GSTR-2B downloads, e-Way Bill and e-Invoice workflows can all fail if a token is revoked at the wrong time. A revoked ASP gets no data until you consent again. Do not revoke during a filing deadline window unless you mean to.
What should businesses do now?
Here are the steps that businesses should follow now:
- Log in: Open Manage API Access and check whether the View Logs, Revoke Active Token and View Revoked Token links appear.
- Prepare a list: Build a list of every ASP you use, including ERP, accounting, reconciliation, filing, lending and analytics tools. Compare it with the active tokens.
- Investigate unfamiliar names: If an ASP or GSP is unrecognised, first check whether it is connected to an ERP, accounting application, filing service or another GST tool used by your business. If you cannot establish a legitimate connection, investigate it internally and consider revoking the relevant active token.
- Keep the session duration practical: Longer sessions are convenient, but they mean fewer OTP prompts and a longer access window. Choose an access duration that matches how frequently the software needs to connect to GST services.
- Fix registered contacts: Make sure the authorised signatory's email and mobile are current and monitored.
- Set a review: Because the relevant access views cover the previous 30 days, a monthly check, perhaps just before GSTR-3B filing, can help you identify recent access activity before it falls outside the available review window.
- Capture evidence: If you revoke access for a security reason, consider saving screenshots or other relevant records of the log entry and revocation reason as part of your internal controls.
Conclusion
Make API access reviews part of your regular GST controls rather than treating them as a one-time exercise. Assign one person from your finance or compliance team to own the review and document any changes made. Before switching accounting or compliance software, check how the new system will connect with GST services and who will manage the access. If you use TallyPrime alongside other GST tools, include all connected workflows in the same review so your technology setup remains organised as vendors and processes change.