Certificate of Origin can now be filed through an Open API from the exporter’s own ERP: DGFT Trade Notice No. 25/2026-27
DGFT has released an Open API facility for Certificates of Origin on the Trade Connect e-Platform. Exporters can connect their ERP, accounting or other software to DGFT’s CoO system to submit applications and verify certificates electronically. The trade notice carries a help manual with the technical steps.
Key facts
- In force
- Facility released by trade notice dated 7 September 2026
- Who it affects
- Exporters applying for Certificates of Origin, ERP and software vendors, CoO issuing agencies, Export Promotion Councils
- What it is
- New facility
- Section
- Foreign Trade
- Published
- 7 September 2026
In 30 seconds
- Trade Notice No. 25/2026-27 is dated 7 September 2026.
- The Open API lets exporters integrate ERP, accounting or other software with DGFT’s Certificate of Origin system.
- Onboarding is through “API Management for Exporters” on the Trade Connect e-Platform Certificate of Origin page.
- Credentials, IP whitelisting and a document signer are prerequisites; the access token is valid for 60 minutes.
- Both preferential and non-preferential Certificates of Origin are supported.
हिंदी में सार
DGFT ने Trade Notice 25/2026-27 (7 सितंबर 2026) से Trade Connect e-Platform पर Certificate of Origin के लिए Open API सुविधा शुरू की है। निर्यातक अपने ERP या अकाउंटिंग सॉफ़्टवेयर को सीधे CoO सिस्टम से जोड़कर आवेदन भेज सकते हैं और सर्टिफ़िकेट सत्यापित कर सकते हैं। इसके लिए API Management से क्रेडेंशियल, IP whitelisting और डिजिटल साइनर ज़रूरी है; access token 60 मिनट तक मान्य रहता है।
What DGFT has introduced
By Trade Notice No. 25/2026-27 dated 7 September 2026, DGFT has informed exporters, designated CoO issuing agencies, Export Promotion Councils, trade and industry associations and its Regional Authorities that an Open API facility for issuance of Certificates of Origin (CoO) has been introduced on the Trade Connect e-Platform and is available for use by eligible exporters and systems.
The objective is to let exporters integrate their Enterprise Resource Planning (ERP), accounting or other software with DGFT’s Certificate of Origin system for electronic submission and exchange of CoO-related information, reducing manual data entry.
Where to start
The process for registration, API access, authentication, technical integration and use is on the Trade Connect e-Platform at https://www.trade.gov.in/pages/certificate-of-origin → API Management for Exporters. A help manual is annexed to the trade notice as Annexure-I.
Prerequisites in the help manual
- Obtain onboarding credentials from the API Management section of the CoO Portal.
- Add the public IP address(es) to the IP Whitelist; only calls from whitelisted IPs are permitted.
- Configure a document signer in the user system for digitally signing the payload before transmission.
How the flow works
| Step | What happens |
|---|---|
| Credentials | User ID, Password, X-API-Key and CoO Public Key are provided through the API Management section; password and keys can be viewed after OTP validation on the registered mobile number and email |
| Password | Hashed using PBKDF2 with a 32-byte dynamic salt, iteration count 65,536 and key length 256 bits |
| Authentication | The generateAuthToken API returns an access token after validating User ID, password and IP address; the token is valid for 60 minutes and may be cached and reused |
| CoO File API | The application is submitted in the prescribed format; the certificate and associated data are received in response |
| CoO Verify API | Verifies a certificate using file number, file date, certificate number and certificate date; returns validity status, certificate PDF URL and remarks |
| Ledger | Each API transaction is recorded with a status: Draft, In Process, Approved, Certificate Issued or Rejected |
All requests and responses are to be digitally signed using SHA-256 RSA digital signature with 2048-bit X.509 certificates.
Agreements supported
The manual lists, among key agreements: India-Japan CEPA, India-Korea CEPA, SAFTA, SAPTA, ASEAN-India FTA, India-Singapore CECA, India-Malaysia CECA, India-Chile PTA, India-Mercosur PTA, India-UAE CEPA, India-Australia ECTA, India-Oman CEPA, India-EFTA TEPA, India-UK CETA, the Generalized System of Preferences (GSP) and the Non-Preferential CoO Scheme. The API validates each application dynamically according to the agreement selected.
What exporters should do
DGFT encourages stakeholders to undertake the technical integration and use the facility as per the prescribed process and specifications. Exporters who file many certificates can ask their ERP or software team to read Annexure-I and the API Help tab under API Management. Queries go to the DGFT Helpdesk through its toll-free numbers or by email.
Questions and answers
What is the CoO Open API?
It is a facility on DGFT’s Trade Connect e-Platform that lets exporters integrate their ERP, accounting or other software with the Certificate of Origin system for electronic submission and exchange of CoO-related information.
Where do exporters register for it?
On the Trade Connect e-Platform at https://www.trade.gov.in/pages/certificate-of-origin, under API Management for Exporters.
What is needed before integration?
Onboarding credentials from the API Management section, whitelisting of the public IP address(es) from which calls will be made, and a document signer configured to digitally sign the payload.
How long is the access token valid?
60 minutes. The help manual says the user may cache and reuse the token during its validity period.
Does it cover both preferential and non-preferential certificates?
Yes. The help manual says the platform supports Preferential Certificates of Origin under FTAs, RTAs and PTAs, and Non-Preferential Certificates of Origin.
Published 7 September 2026. Updated 7 October 2026. This report is for general information and is not professional advice. Read the source document before acting on it.