HMRC filing, one REST API away.
One signed REST API for MTD VAT and Income Tax filings. #GoFile owns the last mile to HMRC — agent authorisation, fraud-prevention headers, the hosted human approval, submission, receipts and audit evidence.
Free sandbox with a built-in HMRC simulator · no card required · pay only for successful live filings
POST /api/v1/vat/prepare { "connection_id": "hmc_...", "vat_number": "999999999", "software_user_login": "[email protected]", "software_user_id": "agent-42", "return": { "net_vat_due_pence": 123456, … } } → 201 Created { "request_id": "req_...", "fetched_at": "2026-09-17T09:00:00Z", "state": "awaiting_approval", "data": { "id": "vfs_...", "continue_url": "https://api.gofile.co.uk/client/v1/actions/act_.../execute#token=gfc_...", ... } } # send your user to the URL — we handle the moment that legally matters
Three tax operations after authorisation
Per tax service the API is deliberately tiny: one status read that returns everything, one prepare call that validates inline, and one read for the outcome. When a human is needed, the response hands you the exact hosted URL — you never rebuild our workflow.
Read everything in one call
Authorisation standing (with a hosted fix-it URL when it lapses), open and fulfilled obligations with filed nine-box figures, liabilities and payments — served from our ledger, fast, never spending HMRC rate budget.
POST /api/v1/vat
Prepare the filing
Canonical validation inline with structured errors, validate_only for a stateless rehearsal, idempotency keys honoured. A 201 returns data.continue_url and the hosted confirm-and-submit page.
POST /api/v1/vat/prepare
Collect the receipt
The hosted page shows HMRC's result immediately. The signed POST read and optional webhooks are optional recovery/read-back, with the receipt attached. Every wire call is captured as immutable audit evidence you can point an inspector at.
POST /api/v1/vat
{"connection_id":"hmc_...","vat_number":"999999999","submission_id":"vfs_..."}
The product story in one line
Authorise with HMRC, save the connection ID, read tax information, prepare figures, then send the user to GoFile to approve.
The hard parts of HMRC, handled
Making Tax Digital compliance is mostly invisible plumbing — agent OAuth, fraud-prevention headers, rate budgets, duplicate defence, evidence. It is our whole product so it doesn't have to be yours.
Fraud-prevention headers
HMRC's FPH regime — device facts, network facts, MFA evidence — captured, frozen and sent correctly for every profile: browser action, hosted approval, background sync.
Hosted approval journey
The legally-significant moment happens on our page: declaration text, approver identity and payload hash recorded permanently. Your app just links to it.
Ledger-backed reads
We continuously sync obligations, filed returns, liabilities and payments into our own ledger. Your status reads are instant and never rate-limited by HMRC.
Connections per customer
Each HMRC connection belongs to your integration, service and environment. Your software maps connection IDs to customers; GoFile enforces access boundaries.
Signed webhooks
Lifecycle events with HMAC signatures, timestamped replay defence, dual-signing for 24h after secret rotation and eight backoff retries with a stable event id.
Duplicate defence
Idempotency keys, one in-flight session per VRN and period, cross-tenant claims at the submit chokepoint, and HMRC's own duplicate oracle — a return cannot be filed twice.
Audit evidence
Every filing keeps its frozen payload versions, approval record and the exact headers sent to HMRC, chained into an append-only SHA-256 audit log.
Sandbox that behaves
A built-in HMRC simulator with magic VRNs: run the entire journey — authorisation, status, filing, approval, webhooks — free, deterministically, with no HMRC test account.
AI-agent ready, out of the box
The official MCP server exposes six tools for VAT and Income Tax. Consent fixes one HMRC connection and environment. An assistant can prepare figures; the user approves on the hosted page.
- Official remote MCP server at
/mcp— OAuth 2.1, PKCE, rotating one-time refresh tokens - OpenAPI 3.1 spec and JSON Schemas for codegen and validation
llms.txtand Markdown twins of every docs page for model context- Flat-rate pricing that doesn't punish exploratory agent traffic
vat.get_status everything about a client's VAT vat.prepare_filing validate + hosted human approval vat.get_filing_status state, receipt itsa.get_status a person's Income Tax year itsa.prepare_quarterly_update freeze cumulative totals itsa.get_quarterly_update_status outcome # no submit tool exists — humans approve on the hosted page
Fail-closed by design
Tax data deserves bank-grade paranoia. The defaults are the strict path — everything below is standing behaviour, not an enterprise add-on.
Pay for outcomes, not API calls
One flat platform fee. A usage charge only when a live filing actually succeeds.
No card needed until you enable live filing. Rate limits protect tenants and HMRC capacity — they are not billing meters.
File your first sandbox return in five minutes
Create an account, grab sandbox keys, and run the whole journey — authorisation, VAT number, figures, approval, receipt — against the built-in simulator.
