To view and manage Application Service Provider (ASP) access on the GST portal, log in and open My Profile > Manage API Access. There, you will find options to show who requested access to your GST data, which tokens are still live and which ones you have revoked. Once you revoke a token, the ASP needs a fresh OTP to connect again.
Where do you find ASP access settings on the GST portal?
Every ASP reaches the GST portal through a GST Suvidha Provider (GSP). Each connection runs on a token that starts when you verify an OTP in your software. Manage API Access controls these tokens.
Before any ASP can request an OTP, you need to authorise its GSP-ASP pair.
- Log in to gst.gov.in with your user ID and password.
- Click your name at the top right and select My Profile.
- Click Manage API Access.
- Set Enable API Request to Yes.
- Choose the GSP, ASP and duration.
- Click Select and confirm.
Repeat these steps for each GSTIN that uses third-party software.
How do you check which ASPs have accessed your GST data?
Click View Logs under Manage API Access to see every token request made in the last 30 days. Each row shows the GSP and ASP name, the date and time, the auth action and whether it succeeded or failed. One session can create several rows because every action gets its own entry.
|
Auth action |
What it means |
|---|---|
|
OTP Initiated |
The ASP asked the portal to send you an OTP. |
|
OTP Verified |
The OTP was entered, and a token became active. |
|
Refresh |
The ASP renewed an active token without a new OTP. |
|
Logout |
The session was logged out. |
|
Revoked |
You ended the token from the portal. |
How do you revoke an ASP’s access?
Revoke Active Token lists the live tokens activated in the last 30 days. Taxpayers can view active tokens issued in the last 30 days. The details include the GSP and ASP names, token activation date and time, number of refreshes, last refresh date and time, refresh validity and token expiry date and time. Each active token also has a Revoke option.
- Click Revoke Active Token under Manage API Access.
- Find the token by its GSP and ASP name.
- Click Revoke next to the token.
- Enter a reason and submit.
The portal then sends an email and SMS to you and the GSP. The token moves to View Revoked Token and shows up in View Logs as Revoked. The ASP cannot reach your data again until you enter a fresh OTP.
View Revoked Token lists tokens revoked in the last 30 days with the GSP and ASP name, activation time, revoke time and the reason you gave (if any).
What mistakes should you avoid while managing ASP access?
Most problems come from revoking the wrong token or checking too rarely.
- Confirm with your accountant before you revoke a token. A revoked token stops an upload or filing in progress.
- Check View Logs at least once a month. Entries older than 30 days drop off the list.
- Treat an OTP Initiated entry from an unknown ASP as a warning. Revoke its token and change your portal password.
- Keep the email and mobile number on your registration current so revoke alerts reach you.
Revoking a token blocks future access only. Data the ASP already holds is covered by your agreement with the provider.
Conclusion
Managing ASP access on the GST portal helps you keep track of third-party connections to your GST data. The Manage API Access section lets you review recent token activity, check active connections and revoke tokens when required. Regularly reviewing these records can help you identify unfamiliar requests and avoid accidentally disrupting legitimate software access. If you use accounting software for GST compliance, TallyPrime can help streamline accounting, GST reporting and related business processes from one place.