API access is a switch on the GST portal. While it is on, software that connects through a GST Suvidha Provider (GSP, a company licensed by the GST Network to connect apps to the portal) can sign in for your GSTIN (your 15-character GST number), read your returns and file them, once you confirm with a one-time code. While it is off, no app can sign in, however correct your username is.
You do not need API access to file on gst.gov.in yourself. You need it the moment an app, an accounting tool or a filing service does any part of the work for you.
How do I enable API access on the GST portal?
- Go to gst.gov.in and log in with the GSTIN's username and password.
- Open My Profile from the menu under your name, at the top right of the dashboard.
- In the quick links on the right, choose Manage API Access.
- Against "Enable API Request", select Yes.
- Choose a duration from the list, from 6 hours up to 30 days, and press Confirm.
That is all. Nothing is sent to the app; the portal simply allows sign-in requests for your GSTIN for the period you chose.
How long does API access last?
As long as the duration you pick, and never more than 30 days. When the period ends, the portal switches API access off on its own, and any app connected to your GSTIN loses its session.
This is the part most guides leave out, and the reason filing apps "suddenly" stop working. A seller who files once a month and chose 30 days last month will find, this month, that the switch is off again. Turning it on takes a minute; you only have to remember to do it.
What happens after I turn it on?
When the app asks to connect, it sends your GST username to the portal through its GSP. The portal then sends a one-time code (OTP) to the mobile number and email registered for your GSTIN. You type that code into the app, and the app gets a session that it can keep alive for the period you chose, without asking for a new code each time.
Two codes are easy to confuse:
| Code | Sent when | Used for |
|---|---|---|
| Sign-in code | An app connects to your GSTIN | Starting the app's session with the portal |
| EVC (electronic verification code) | You file a return | Signing the return in place of a digital signature |
The filing code goes to the authorised signatory's mobile and email. It can contain letters as well as digits; type it exactly as it arrives.
Why does my app say API access is denied, or no code arrives?
Check these in order:
- API access is off or has expired. Log in to the portal and look at Manage API Access. If it says No, switch it on again.
- The username is wrong. The app needs the portal username, not the GSTIN, and not your email.
- The code went to a different phone. The portal sends it to the mobile number registered against the GSTIN. If that number belongs to someone who has left, or to your accountant, update the authorised signatory's details on the portal first.
- The session ended early. The portal sometimes closes sessions after maintenance. Connect again and enter the new code.
Is API access safe?
The app never sees your GST portal password. It can sign in only after you type a code that the portal sends to your own phone, and only while API access is on. You can switch it off at any time from the same page by choosing No. A shorter duration means fewer days in which a connected app can act, and more codes to type.
Which duration should I choose?
If you file once a month through an app, choose 30 days on the day you file. If you only want an app to fetch data once, 6 hours is enough. Whatever you choose, it ends on its own.