DGFT Open API for Certificate of Origin 2026: What Exporters Need to Know

For many Indian exporters, the Certificate of Origin (CoO) is one of those documents that sits quietly in the export-compliance process until a shipment is ready to move. Then suddenly, accuracy matters, the importing buyer is waiting, and even a small mismatch in invoice, product or origin details can create unnecessary follow-up.

The Directorate General of Foreign Trade (DGFT) has now taken an important step to make this process more integrated.

On 7 September 2026, DGFT introduced an Open Application Programming Interface (API) facility for Certificate of Origin through the Trade Connect e-Platform. The facility allows eligible exporters to connect their ERP, accounting software or other business systems directly with the DGFT Certificate of Origin system.

The practical significance is bigger than simply having a new technical facility.

An exporter that currently enters the same invoice, product, buyer, shipment and origin information into multiple systems may now be able to transfer relevant data electronically from its own software to the DGFT platform. This can reduce duplicate data entry, improve consistency and make application tracking easier.

For businesses handling a large number of export shipments, this can become a meaningful compliance improvement.

This article explains what has changed, who can benefit, what the new API actually does, what exporters should prepare before integration, and what accounting, export and compliance teams should watch carefully.

What Has DGFT Changed in September 2026?

DGFT has introduced an Open API facility for issuance and verification of Certificates of Origin through the Trade Connect e-Platform.

The announcement was made on 7 September 2026 through DGFT Trade Notice No. 25/2026-27. The facility is available for eligible exporters and systems that complete the prescribed registration, authentication and technical integration process.

Previously, an exporter could maintain detailed commercial information in its ERP or accounting software and then separately enter relevant information into the government CoO platform.

That creates a familiar problem.

The same data may exist in:

  • ERP software
  • Accounting software
  • Export documentation systems
  • Shipping or logistics systems
  • Internal compliance records
  • DGFT’s CoO platform

Every additional manual entry creates another opportunity for a mismatch.

The new API approach is intended to allow system-to-system transfer of CoO-related information.

In simple terms, instead of an employee repeatedly copying information from the company’s software into the government portal, the company’s system can communicate electronically with the CoO platform after the required onboarding and authentication.

Why Is the Certificate of Origin Important for Exporters?

A Certificate of Origin establishes the origin of goods for trade-related purposes.

This becomes particularly important where the importing country or trade arrangement requires origin documentation.

There are two broad categories relevant to the new facility:

Type of Certificate of OriginBroad purpose
Preferential CoOUsed under applicable FTAs, RTAs and PTAs to support eligibility for preferential tariff treatment
Non-Preferential CoOUsed for customs clearance, compliance, trade remedies and other trade purposes where preferential tariff treatment is not being claimed

The distinction matters.

A preferential Certificate of Origin is not merely a general statement that goods were exported from India. It is connected with the applicable trade agreement and the origin criteria prescribed under that framework.

For example, if an Indian manufacturer exports eligible goods under a trade agreement that provides a tariff concession, the importer may need the appropriate preferential CoO to support the claim.

Therefore, automation of the application process does not mean that the exporter can stop checking origin eligibility.

The technology can automate data movement.

It cannot replace the underlying compliance judgment.

Who Can Benefit Most From the New CoO API?

The facility is likely to be particularly useful for exporters with repetitive or high-volume Certificate of Origin applications.

A small exporter making only a handful of shipments each year may find the existing process perfectly manageable.

But consider a manufacturer issuing hundreds of export invoices every month.

Suppose the company maintains the following information in its ERP:

  • Exporter details
  • Importer details
  • Invoice number
  • Invoice date
  • Product description
  • HS classification
  • Quantity
  • Value
  • Country of destination
  • Shipment details
  • Origin-related information

If the same information must then be manually entered into another platform for every CoO application, the compliance team spends time on data transcription rather than actual review.

The API facility can potentially make the process much more efficient.

Businesses most likely to benefit include:

Manufacturers with regular exports

Manufacturing businesses often have structured product, invoice and customer data already maintained in ERP systems.

Export houses

Export houses dealing with multiple customers and repeated shipments can benefit from automated data transfer and tracking.

MSME exporters

An MSME with a small compliance team may be able to reduce repetitive administrative work if its accounting or ERP system supports the required integration.

Businesses with dedicated ERP systems

Companies already investing in ERP-based export documentation may find it easier to build CoO integration into their existing workflow.

High-volume exporters

The commercial benefit is potentially greatest where CoO applications are frequent enough for manual entry to become a recurring operational burden.

What Can the New API Do?

DGFT has made available three principal API components under the new framework.

Authentication Token API

This is used for secure authentication and access.

The exporter must complete the prescribed onboarding process and obtain the necessary credentials.

The system uses access controls and security measures rather than treating the API as an unrestricted public connection.

CoO File API

This is the core application-related interface.

It facilitates submission of CoO-related information and receipt of certificates through the integrated system.

For an exporter, this is the part that can potentially eliminate repetitive portal data entry.

Certificate Verification API

The facility also supports verification of issued Certificates of Origin.

This can be useful where a business or authorised system needs to verify certificate-related information electronically.

DGFT’s framework also provides transaction-level tracking information, including application status and identifiers such as acknowledgement ID, file number and certificate number.

What Information Should Exporters Prepare Before Integration?

An exporter should not approach API integration as simply an IT project.

It is equally a finance, export documentation and compliance project.

Before connecting an ERP or accounting system, the business should identify exactly where the source information comes from.

For example:

InformationPossible internal source
Exporter detailsMaster data
Importer detailsCustomer master
Invoice detailsERP/accounting system
Product detailsItem master
HS classificationProduct/export master
Quantity and valueSales/export invoice
Shipment informationLogistics/export documentation
Origin-related informationExport compliance records
Supporting documentsDocument management system
Trade agreement selectionExport compliance process

The most important question is not:

“Can our ERP connect to the API?”

The better question is:

“Is the information inside our ERP accurate enough to be sent automatically?”

Automation makes good data move faster.

It can also make bad data move faster.

Data Accuracy Becomes Even More Important

Imagine an exporter has an incorrect product description in its ERP.

Previously, an employee might notice the error while manually preparing a CoO application.

With an automated integration, the incorrect description may be transferred directly into the application unless appropriate validation controls exist.

That is why exporters should establish master-data controls before switching to automated submission.

At minimum, businesses should review:

  • Product descriptions
  • HS codes
  • Country information
  • Customer/importer master
  • Invoice numbering
  • Export values
  • Unit of measurement
  • Origin-related data
  • Trade agreement selection
  • Supporting documentation
  • Authorised signatory details

A good API implementation should therefore include a human review point before final submission, particularly during the initial phase.

Preferential CoO Requires More Than Correct Data Entry

This is an important practical distinction.

Suppose an Indian manufacturer exports a product to a country where a preferential trade agreement may apply.

The ERP may correctly show:

  • Product
  • Quantity
  • Invoice value
  • Destination
  • Buyer
  • Shipment details

But that does not automatically establish that the product qualifies for preferential origin treatment.

The exporter still needs to apply the applicable origin rules.

Depending on the relevant agreement, origin determination may involve requirements concerning:

  • Wholly obtained goods
  • Manufacturing or processing
  • Tariff classification
  • Value addition
  • Non-originating materials
  • Specific processing requirements
  • Product-specific rules

Therefore, API integration should be viewed as process automation, not as an automated origin-certification decision.

The responsibility for the underlying accuracy and eligibility should continue to sit with the exporter and its compliance process.

DGFT’s Security Controls for the API

Because the API connects a private business system with a government platform, security is a major consideration.

DGFT’s announced framework includes several security measures.

The system uses:

  • API credentials
  • IP address whitelisting
  • Digitally signed requests and responses
  • SHA-256 RSA digital signatures
  • 2048-bit X.509 certificates
  • PBKDF2 password protection with dynamic salt
  • Access tokens with limited validity

DGFT has stated that each access token remains valid for 60 minutes.

For an exporter, this means the IT team should not treat the API credentials like an ordinary username and password.

The business should establish internal controls over:

  • Who can generate credentials
  • Who can access API keys
  • Which IP addresses are authorised
  • Where certificates are stored
  • Who can modify integration settings
  • How failed API calls are monitored
  • How credentials are revoked or replaced
  • How logs are maintained

The finance or export team should also know whom to contact if the integration stops working.

What Is the Transaction Ledger?

One useful feature of the new framework is transaction-level tracking.

The system maintains a ledger for applications and records relevant application information.

The status can move through stages such as:

Draft → In Process → Approved → Certificate Issued

An application can also be rejected.

The transaction information can include acknowledgement ID, file number, file date and certificate number.

This matters from a compliance perspective because exporters should not rely solely on an internal ERP status.

For example, an internal system might show that an application was successfully transmitted.

That does not necessarily mean the Certificate of Origin has been issued.

The compliance team should reconcile the internal status with the government platform response.

A Practical Example

Consider an Indian engineering company exporting machinery components to multiple overseas buyers.

The company processes approximately 150 export shipments every month.

Its ERP already contains:

  • Customer information
  • Product information
  • Invoice details
  • Quantity
  • Value
  • Destination
  • Shipping information

Under the manual process, an employee separately enters relevant information into the CoO platform.

Assume even five minutes of repetitive data entry and checking per application.

For 150 applications, that is more than 12 hours a month spent on repetitive activity.

The company decides to integrate its ERP with the CoO API.

The new workflow could look like this:

Step 1: Export invoice is created in ERP.

Step 2: Relevant CoO information is mapped from the ERP.

Step 3: The compliance employee reviews the information.

Step 4: The system submits the application through the prescribed API process.

Step 5: Application status is received and recorded.

Step 6: Once the certificate is issued, the certificate number and related information are reconciled with the ERP.

The real benefit is not simply saving 12 hours.

The bigger benefit is creating a more controlled export-documentation process.

Should Every Exporter Immediately Implement the API?

No.

There is no reason for a small exporter to invest heavily in API integration merely because the facility is available.

The decision should depend on volume, technology, internal resources and cost.

A business should consider integration where:

  • CoO applications are frequent.
  • The same information is already available electronically.
  • The ERP or accounting system can support integration.
  • Manual data entry consumes significant staff time.
  • The company has technical support.
  • Strong master-data controls already exist.
  • The expected efficiency gain justifies the implementation cost.

For a business with ten CoO applications a year, manual processing may remain simpler.

For a business with hundreds or thousands of applications, automation can be much more attractive.

What Should the Finance and Compliance Team Do Now?

The best approach is to treat September 2026 as an opportunity to review the existing CoO process.

Step 1: Map the existing process

Document how a CoO application currently moves from sales invoice to certificate.

Identify every manual step.

Step 2: Identify the source of each field

For every CoO field, identify whether the information comes from:

  • ERP
  • Accounting software
  • Export documentation
  • Customer master
  • Product master
  • Logistics system
  • Compliance team

Step 3: Clean master data

Correct duplicate customers, incorrect addresses, inconsistent product descriptions and outdated HS information.

Step 4: Review origin controls

Document how the business determines whether a product qualifies under the applicable preferential origin rules.

Step 5: Involve IT and tax/export professionals together

Do not leave the project exclusively with the IT team.

IT understands integration.

The export and compliance team understands the business rules.

Both are required.

Step 6: Establish approval controls

Even after automation, decide who reviews and authorises applications.

Step 7: Test before going live

Start with controlled testing rather than immediately shifting the entire export operation.

Step 8: Reconcile issued certificates

Make sure certificates received through the system are correctly recorded against the relevant export transaction.

Common Mistakes Exporters Should Avoid

Treating API integration as automatic compliance

The API transfers information. It does not make an otherwise ineligible product eligible for preferential treatment.

Sending unverified master data

Incorrect ERP data can create incorrect government applications.

Ignoring HS classification

Product classification remains a substantive compliance issue.

Assuming “submitted” means “issued”

The exporter should track the complete application lifecycle.

Sharing API credentials casually

Credentials, certificates and access controls should be restricted to authorised personnel.

Forgetting audit trails

Businesses should retain sufficient internal records to demonstrate what information was submitted and how it was approved.

Automating without exception handling

A robust system should have a process for rejected applications, validation failures, API downtime and unusual transactions.

What Does This Mean for Export Documentation Teams?

The role of export documentation staff may gradually shift.

Instead of spending most of their time typing information into government portals, they may increasingly spend more time reviewing:

  • Data accuracy
  • Origin eligibility
  • Exceptions
  • Rejections
  • Supporting documents
  • Trade-agreement requirements
  • Reconciliation
  • Audit trails

That is actually a positive change.

The value of a compliance professional is not in manually copying invoice information.

It is in identifying whether the information is correct and whether the transaction satisfies the applicable legal requirements.

How Does This Fit Into the Broader Export Compliance Process?

Certificate of Origin compliance should not be viewed in isolation.

An exporter may simultaneously need to consider:

  • GST treatment of exports
  • Export invoices
  • Shipping bills
  • LUT/bond requirements where applicable
  • Foreign exchange realisation
  • FEMA requirements
  • Customs documentation
  • Product classification
  • Import-country requirements
  • Trade agreement origin rules
  • Customer documentation requirements
  • Export incentives, where applicable

Therefore, an automated CoO process should ideally become one controlled component of the broader export-compliance workflow.

For example, the invoice used for CoO purposes should be consistent with the company’s accounting records and export documentation.

If different systems show different values or descriptions, automation alone will not solve the problem.

Frequently Asked Questions

What is the DGFT Open API for Certificate of Origin?

It is a system-to-system integration facility introduced by DGFT through the Trade Connect e-Platform. Eligible exporters can connect ERP, accounting or other business software with the CoO system for electronic submission and exchange of CoO-related information.

When was the new CoO API facility introduced?

DGFT announced the facility on 7 September 2026 through Trade Notice No. 25/2026-27.

Does the API cover preferential Certificates of Origin?

Yes. The announced framework covers both preferential and non-preferential Certificates of Origin.

Does API integration automatically determine whether goods qualify as originating goods?

No. The exporter remains responsible for satisfying the applicable origin criteria. The API is an integration and processing mechanism, not a substitute for origin analysis.

Can an accounting software system be connected?

DGFT has specifically stated that exporters can integrate their ERP, accounting or other business software with the CoO system, subject to the prescribed technical and onboarding requirements.

Is API integration compulsory for exporters?

The September 2026 announcement introduces the facility for eligible exporters and systems. It should not be confused with a general requirement that every exporter must implement an API integration.

What security controls are used?

DGFT has specified controls including IP whitelisting, digital signatures, 2048-bit X.509 certificates, PBKDF2 password protection and time-limited access tokens.

What should a small exporter do?

A small exporter should first assess its CoO volume and current administrative burden. If applications are limited, manual processing may remain practical. If volumes increase, API integration can be evaluated as part of the company’s technology and compliance strategy.

Key Takeaways

  • DGFT introduced an Open API facility for Certificate of Origin on 7 September 2026.
  • The facility works through the Trade Connect e-Platform.
  • Eligible exporters can connect their ERP, accounting or other business software with the CoO system.
  • The facility covers preferential as well as non-preferential Certificates of Origin.
  • Three important API components cover authentication, CoO file processing and certificate verification.
  • The system provides transaction-level status and certificate information.
  • Security controls include IP whitelisting, digital signatures and time-limited access tokens.
  • Automation can reduce duplicate data entry and improve operational efficiency.
  • However, API integration does not remove the exporter’s responsibility for correct product, invoice and origin information.
  • Preferential CoO claims still require careful examination of the applicable trade agreement and origin criteria.
  • Exporters should clean their master data and establish review controls before implementing automation.
  • High-volume exporters are likely to see the greatest operational benefit.

Conclusion

The DGFT Open API facility for Certificates of Origin is a practical development for India’s increasingly digital export ecosystem.

For an exporter processing a large number of applications, the ability to connect existing ERP or accounting data with the CoO system can remove a considerable amount of repetitive work. More importantly, it creates the possibility of a more integrated and traceable export-documentation process.

But businesses should avoid looking at the change simply as an IT upgrade.

The real question is whether the company’s commercial data, accounting data and export-compliance data are properly aligned.

A well-designed integration can make a good compliance process faster and more reliable. A poorly controlled integration can simply automate existing errors.

For exporters, the sensible approach is therefore to review the current CoO workflow, clean the underlying data, document origin controls, involve both IT and compliance teams, establish approval procedures and then assess whether API integration makes commercial sense.

The September 2026 change is ultimately another step towards reducing manual government-portal work and moving Indian export compliance towards more connected, system-driven processes.

Need professional assistance with taxation, GST, accounting, audit or business compliance? Explore our professional CA services →

Resources

Leave a Comment

Your email address will not be published.


Related Updates

More updates will appear here as they are published.

Call WhatsApp Enquiry