DGFT Introduces Open API Integration for Certificate of Origin through
Trade Connect e-Platform, Certificate Issuing Agency like Chamber of Commerce/
Export Inspection Agency will Issue COO
·
No Safety Guarantee for Data Hacking by Insiders and
Outsiders
·
DGFT has introduced an Open API facility for
issuance of Certificates of Origin (CoO) through the Trade
Connect e-Platform. It is available to eligible exporters/systems subject
to prescribed onboarding and technical requirements.
·
Purpose: Exporters can integrate their ERP,
accounting or other software systems directly with DGFT's CoO system for electronic submission and exchange of CoO information. This is intended to:
o
reduce manual data entry;
o
eliminate duplicate data entry;
o
improve data accuracy; and
o
make the CoO application
process more efficient.
·
Two types of CoO are
supported:
1.
Preferential CoO — under
FTAs, RTAs and PTAs, enabling exporters to claim tariff concessions.
2.
Non-Preferential CoO — for
compliance, customs clearance, trade-remedy implementation and other trade
purposes.
API
onboarding & authentication
·
Exporters/agencies must obtain API credentials,
whitelist their public IP address(es) and have a document signer
configured for digitally signing payloads.
·
Credentials include User ID, Password, X-API Key
and Public Key.
·
Password authentication uses PBKDF2 with a
32-byte dynamic salt, 65,536 iterations and a 256-bit key length.
·
Only API calls originating from the whitelisted
public IP addresses will be permitted.
·
The access token remains valid for 60 minutes
and may be cached/reused during its validity period.
Digital
security
·
All API requests and responses must be digitally
signed using:
o
SHA-256 RSA Digital Signature
o
2048-bit X.509 Certificates.
·
The system is designed to ensure data integrity,
sender authentication and non-repudiation.
CoO
application through API
The CoO File API will capture comprehensive
application information, including:
·
IEC, firm name, branch, GSTIN and address;
·
certificate type and applicable trade agreement;
·
importer and producer details;
·
invoice number, date, currency and exchange-rate
information;
·
ITC HS code, product description, quantity, UOM,
invoice value and FOB value;
·
preference criteria;
·
mode of transport, shipment documents, ports and
route;
·
vessel and departure details;
·
supporting documents and declarations.
Trade
agreements covered
The
framework currently supports, among others:
·
India-Japan CEPA
·
India-Korea CEPA
·
SAFTA / SAPTA
·
ASEAN-India FTA
·
India-Singapore CECA
·
India-Malaysia CECA
·
India-Chile PTA
·
India-Mercosur PTA
·
India-UAE CEPA
·
India-Australia ECTA
·
India-Oman CEPA
·
India-EFTA TEPA
·
India-UK CETA
·
GSP
·
Non-Preferential CoO
Scheme.
·
Dynamic validation will
apply according to the selected agreement, covering mandatory/optional fields,
business validations, origin criteria, shipment requirements and
producer/exporter declarations.
Transaction
tracking & verification
·
A ledger must be maintained for every API
transaction, with statuses including:
Draft → In Process → Approved → Certificate Issued /
Rejected.
·
The Certificate Verification API allows
verification using:
o
File Number
o
File Date
o
Certificate Number
o
Certificate Date.
·
The system returns the validity status,
Certificate PDF URL and verification remarks.
Key
takeaway
DGFT has moved CoO processing towards direct system-to-system integration,
allowing exporters to connect their internal ERP/accounting systems with the
Trade Connect CoO platform. This should significantly
reduce repetitive data entry and manual intervention while enabling automated
submission, processing and verification of Certificates of Origin.
API access/onboarding: Trade
Connect e-Platform → Certificate of Origin → API Management for
Exporters.
[DGFT Trade Notice No. 25/2026-27
dated 7 September, 2026]