Finocket already builds your GST returns — GSTR-1 sections, the GSTR-3B summary, GSTR-2B reconciliation and IMS actions — as portal-ready working figures you or your CA upload to gst.gov.in. Filing those returns directly from the app, over the government's returns API, needs a licensed GSP (GST Suvidha Provider) in the middle.
What is live today
A GSP is connected. What it gives you today is the reading half of the returns API, not the filing half — and the difference matters, so here it is plainly:
- Live now: looking a GSTIN up on the GST portal. Type a client or supplier's GSTIN and their legal name, trade name and address come back from the register, along with whether the registration is active. If it has been cancelled, Finocket warns you before you claim input tax credit against it — credit claimed on a cancelled registration can be reversed with interest. If they are on the composition scheme, it warns you that they cannot pass you credit at all. Neither fact is knowable from the GSTIN number itself. See Filling a client in from their GSTIN.
- Not live: pushing a return. Finocket does not submit GSTR-1 or GSTR-3B to GSTN, and does not auto-fetch your GSTR-2B or IMS inbox. Filing needs a second, stronger consent than reading does — a portal session for your own GSTIN plus an EVC OTP for each submission — and that flow is not finished. Until it is, those calls refuse outright rather than returning a blank result: an empty GSTR-2B looks exactly like a month with no purchases, and filing a return on one would cost you the credit.
- Connecting your own provider: you can enter a provider’s API key and secret yourself on GST → Filing provider. The keys are checked against the provider before they are saved, so a mistyped or expired one is refused on the spot with the provider’s own explanation, rather than sitting in storage and failing later somewhere else. Only the company owner can manage them.
- How the keys are held: in an encrypted credential vault (AES-256-GCM), bound to your company so a copied row cannot be decrypted anywhere else. The secret never comes back out to the browser — the screen can tell you a credential exists, never what it is.
Why a GSP is required at all
GSTN does not expose its returns API to businesses directly — every automated filing and every portal lookup flows through a government-appointed GSP. That is why the GSTIN lookup above is a real integration rather than a lookup table, and why the filing half cannot simply be switched on without the taxpayer consent step that goes with it.
What to do in the meantime
- Generate and download portal-ready GSTR-1 files, the GSTR-3B summary and the GSTR-2B reconciliation from GST → Returns, then upload them on the portal.
- Run the DRC-01B / DRC-01C self-check on your own figures before you file, so a liability or ITC gap surfaces before a notice does.
- For B2B e-invoicing (IRN + e-way bill), which submits live through its own separate provider, see E-invoicing (IRN).
Claims discipline: a GSP returns-API vendor is connected and GSTIN lookup runs through it live. Finocket does not file GSTR-1/3B and does not fetch 2B/IMS directly today. We will keep saying exactly which half is which rather than rounding it to “connected” or to “not connected” — both would be wrong.
