Certificate of Origin Open API Framework: A Digital Shift in Trade Connect
The Certificate of Origin (CoO) Open API framework enables secure integration between user systems and the CoO Trade Connect ePlatform for the submission, processing, issuance and verification of Certificates of Origin. The framework is designed to reduce manual intervention, eliminate duplicate data entry, improve data accuracy and facilitate seamless information exchange between exporters, certifying agencies and regulatory authorities.
What Is the CoO Open API Framework?
The CoO Open API framework allows exporters and authorised agencies to integrate their systems directly with the CoO Trade Connect ePlatform.
It supports both:
Preferential Certificate of Origin
Preferential CoOs are issued under FTAs, RTAs and PTAs and enable exporters to obtain applicable tariff concessions in importing countries.
Non-Preferential Certificate of Origin
Non-Preferential CoOs support compliance, customs clearance, trade remedy implementation and other trade-related requirements without providing preferential tariff benefits.
How the CoO API Process Works
Before integration, agencies need to obtain API onboarding credentials, whitelist their relevant public IP addresses and configure a document signer for digitally signing payloads.
The process broadly involves:
- Obtaining the API credentials.
- Encrypting the password using PBKDF2 with a dynamic salt.
- Calling the Authentication API to generate an access token.
- Submitting CoO applications through the CoO File API.
- Receiving the certificate and associated data.
- Verifying issued certificates through the CoO Verify API.
Access Token Validity
The generated access token remains valid for 60 minutes and can be cached and reused during its validity period.
API Credentials and Security Requirements
The API Management section provides the required credentials, including the X-API-Key, User ID, Password and CoO Public Key.
Only API calls originating from whitelisted public IP addresses are permitted by the CoO system. Password processing uses PBKDF2 with a 32-byte dynamic salt, 65,536 iterations and a 256-bit key length.
Digital Signature Requirement
All API requests and responses are required to be digitally signed using:
- SHA-256 RSA Digital Signature
- 2048-bit X.509 Certificates
This is intended to ensure data integrity, sender authentication and non-repudiation.
Note: API credentials, IP whitelisting and digital-signing configuration should be completed before API transactions are initiated.
What Information Is Submitted Through the CoO File API?
The CoO File API is the primary transaction API for submitting applications. It captures information across several sections.
Applicant Information
This includes:
- IEC Number
- Firm Name
- Branch Details
- GSTIN
- Address
- State and District
- Declaration status
- Postal delivery requirement
Certificate and Importer Information
The application can include certificate type, trade agreement, request type, issuing office, importer name, country, address and email information.
Invoice and Product Information
The API captures invoice number and date, currency, exchange rates, ITC HS codes, product description, quantity, unit of measurement, invoice value, FOB value, packaging details and preference criteria.
Shipment and Supporting Documents
Shipment information includes the mode of transport, shipment documents, port of shipment, port of discharge, route, vessel details and departure date. Supporting documents can include attachment type, upload URL, remarks and attestation requirements.
Trade Agreements Supported
The framework supports multiple trade agreements and certification schemes, including:
- India-Japan CEPA
- India-Korea CEPA
- SAFTA
- ASEAN-India FTA
- India-Singapore CECA
- India-Malaysia CECA
- India-Chile PTA
- India-Mercosur PTA
- India-UAE CEPA
- India-Australia ECTA
- India-Oman CEPA
- India-EFTA TEPA
- India-UK CETA
- GSP
- Non-Preferential CoO Scheme
Dynamic Validation
The selected agreement determines applicable mandatory and optional fields, business validations, product-origin criteria, shipment requirements and producer/exporter declarations. The API dynamically validates applications according to the selected agreement.
Certificate Verification API
The Certificate Verification API enables verification using details such as:
- File Number
- File Date
- Certificate Number
- Certificate Date
The system returns the validity status, Certificate PDF URL and verification remarks.
Conclusion
The CoO Open API framework provides a structured digital mechanism for integrating exporter systems with the CoO Trade Connect ePlatform. By supporting application submission, certificate issuance data exchange and certificate verification through APIs, the framework aims to reduce manual intervention and duplicate data entry while improving data accuracy and information exchange.
Notification Reference:
DGFT
Trade Notice No. 25/2026-27
07/09/2026