Certificate of Origin Open API Framework: A Digital Shift in Trade Connect

The Certificate of Origin (CoO) Open API framework enables secure integration between user systems and the CoO Trade Connect ePlatform for the submission, processing, issuance and verification of Certificates of Origin. The framework is designed to reduce manual intervention, eliminate duplicate data entry, improve data accuracy and facilitate seamless information exchange between exporters, certifying agencies and regulatory authorities.

What Is the CoO Open API Framework?

The CoO Open API framework allows exporters and authorised agencies to integrate their systems directly with the CoO Trade Connect ePlatform.

It supports both:

Preferential Certificate of Origin

Preferential CoOs are issued under FTAs, RTAs and PTAs and enable exporters to obtain applicable tariff concessions in importing countries.

Non-Preferential Certificate of Origin

Non-Preferential CoOs support compliance, customs clearance, trade remedy implementation and other trade-related requirements without providing preferential tariff benefits.

How the CoO API Process Works

Before integration, agencies need to obtain API onboarding credentials, whitelist their relevant public IP addresses and configure a document signer for digitally signing payloads.

The process broadly involves:

  1. Obtaining the API credentials.
  2. Encrypting the password using PBKDF2 with a dynamic salt.
  3. Calling the Authentication API to generate an access token.
  4. Submitting CoO applications through the CoO File API.
  5. Receiving the certificate and associated data.
  6. Verifying issued certificates through the CoO Verify API.

Access Token Validity

The generated access token remains valid for 60 minutes and can be cached and reused during its validity period.

API Credentials and Security Requirements

The API Management section provides the required credentials, including the X-API-Key, User ID, Password and CoO Public Key.

Only API calls originating from whitelisted public IP addresses are permitted by the CoO system. Password processing uses PBKDF2 with a 32-byte dynamic salt, 65,536 iterations and a 256-bit key length.

Digital Signature Requirement

All API requests and responses are required to be digitally signed using:

  • SHA-256 RSA Digital Signature
  • 2048-bit X.509 Certificates

This is intended to ensure data integrity, sender authentication and non-repudiation.

Note: API credentials, IP whitelisting and digital-signing configuration should be completed before API transactions are initiated.

What Information Is Submitted Through the CoO File API?

The CoO File API is the primary transaction API for submitting applications. It captures information across several sections.

Applicant Information

This includes:

  • IEC Number
  • Firm Name
  • Branch Details
  • GSTIN
  • Address
  • State and District
  • Declaration status
  • Postal delivery requirement

Certificate and Importer Information

The application can include certificate type, trade agreement, request type, issuing office, importer name, country, address and email information.

Invoice and Product Information

The API captures invoice number and date, currency, exchange rates, ITC HS codes, product description, quantity, unit of measurement, invoice value, FOB value, packaging details and preference criteria.

Shipment and Supporting Documents

Shipment information includes the mode of transport, shipment documents, port of shipment, port of discharge, route, vessel details and departure date. Supporting documents can include attachment type, upload URL, remarks and attestation requirements.

Trade Agreements Supported

The framework supports multiple trade agreements and certification schemes, including:

  • India-Japan CEPA
  • India-Korea CEPA
  • SAFTA
  • ASEAN-India FTA
  • India-Singapore CECA
  • India-Malaysia CECA
  • India-Chile PTA
  • India-Mercosur PTA
  • India-UAE CEPA
  • India-Australia ECTA
  • India-Oman CEPA
  • India-EFTA TEPA
  • India-UK CETA
  • GSP
  • Non-Preferential CoO Scheme

Dynamic Validation

The selected agreement determines applicable mandatory and optional fields, business validations, product-origin criteria, shipment requirements and producer/exporter declarations. The API dynamically validates applications according to the selected agreement.

Certificate Verification API

The Certificate Verification API enables verification using details such as:

  • File Number
  • File Date
  • Certificate Number
  • Certificate Date

The system returns the validity status, Certificate PDF URL and verification remarks.

Conclusion

The CoO Open API framework provides a structured digital mechanism for integrating exporter systems with the CoO Trade Connect ePlatform. By supporting application submission, certificate issuance data exchange and certificate verification through APIs, the framework aims to reduce manual intervention and duplicate data entry while improving data accuracy and information exchange.

Notification Reference:

DGFT
Trade Notice No. 25/2026-27
07/09/2026

Scroll to Top