Pricing
About Us Careers Tally Together Media & News
Select Country

    How to View and Manage ASP Access on the GST Portal

    Abilash S

    Oct 6, 2026

    30 second summary | Taxpayers can view and manage Application Service Provider (ASP) access from My Profile > Manage API Access on the GST portal. View Logs shows token activity from the past 30 days. To end an active session, select Revoke Active Token and provide a reason. View Revoked Token displays details of previously revoked tokens.

    To view and manage Application Service Provider (ASP) access on the GST portal, log in and open My Profile > Manage API Access. There, you will find options to show who requested access to your GST data, which tokens are still live and which ones you have revoked. Once you revoke a token, the ASP needs a fresh OTP to connect again.

    Where do you find ASP access settings on the GST portal?

    Every ASP reaches the GST portal through a GST Suvidha Provider (GSP). Each connection runs on a token that starts when you verify an OTP in your software. Manage API Access controls these tokens.

    Before any ASP can request an OTP, you need to authorise its GSP-ASP pair.

    1. Log in to gst.gov.in with your user ID and password.
    2. Click your name at the top right and select My Profile.
    3. Click Manage API Access.
    4. Set Enable API Request to Yes.
    5. Choose the GSP, ASP and duration.
    6. Click Select and confirm.

    Repeat these steps for each GSTIN that uses third-party software.

    How do you check which ASPs have accessed your GST data?

    Click View Logs under Manage API Access to see every token request made in the last 30 days. Each row shows the GSP and ASP name, the date and time, the auth action and whether it succeeded or failed. One session can create several rows because every action gets its own entry.

    Auth action

    What it means

    OTP Initiated

    The ASP asked the portal to send you an OTP.

    OTP Verified

    The OTP was entered, and a token became active.

    Refresh

    The ASP renewed an active token without a new OTP.

    Logout

    The session was logged out.

    Revoked

    You ended the token from the portal.

    How do you revoke an ASP’s access?

    Revoke Active Token lists the live tokens activated in the last 30 days. Taxpayers can view active tokens issued in the last 30 days. The details include the GSP and ASP names, token activation date and time, number of refreshes, last refresh date and time, refresh validity and token expiry date and time. Each active token also has a Revoke option.

    1. Click Revoke Active Token under Manage API Access.
    2. Find the token by its GSP and ASP name.
    3. Click Revoke next to the token.
    4. Enter a reason and submit.

    The portal then sends an email and SMS to you and the GSP. The token moves to View Revoked Token and shows up in View Logs as Revoked. The ASP cannot reach your data again until you enter a fresh OTP.

    View Revoked Token lists tokens revoked in the last 30 days with the GSP and ASP name, activation time, revoke time and the reason you gave (if any).

    What mistakes should you avoid while managing ASP access?

    Most problems come from revoking the wrong token or checking too rarely.

    • Confirm with your accountant before you revoke a token. A revoked token stops an upload or filing in progress.
    • Check View Logs at least once a month. Entries older than 30 days drop off the list.
    • Treat an OTP Initiated entry from an unknown ASP as a warning. Revoke its token and change your portal password.
    • Keep the email and mobile number on your registration current so revoke alerts reach you.

    Revoking a token blocks future access only. Data the ASP already holds is covered by your agreement with the provider.

    Conclusion

    Managing ASP access on the GST portal helps you keep track of third-party connections to your GST data. The Manage API Access section lets you review recent token activity, check active connections and revoke tokens when required. Regularly reviewing these records can help you identify unfamiliar requests and avoid accidentally disrupting legitimate software access. If you use accounting software for GST compliance, TallyPrime can help streamline accounting, GST reporting and related business processes from one place.

    Verify GSTIN details online

    Enter a GSTIN/UIN to check the business name, registration status, taxpayer type and more.

    cta banner image

    FAQs

    No. View Logs, Revoke Active Token and View Revoked Token each cover only the last 30 days. Keep your own record if you need a longer history.

    It cannot connect to the GST portal until you verify a fresh OTP in the software.

    Yes. Each token is listed separately with its GSP and ASP name, so the others keep running.

    The revoke screen asks for one. View Revoked Token later shows the reason, if you gave it.

    A failed status means that the request did not succeed. Repeated failures from an ASP you do not use need a closer look.

    Published on October 6, 2026

    left-icon
    1

    of

    4
    right-icon

    India’s choice for business brilliance

    Work faster, manage better, and stay on top of your business with TallyPrime, your complete business management solution.

    Get 7-days FREE Trial!

    I have read and accepted the T&C
    Submit