Skip to main content

Overview

The Credentials API provides secure storage for login credentials to government portals and systems, including tax filing portals, corporate registries, payroll systems, and banking portals. Credentials can be linked to business entities and registrations, and shared with accountants and service providers.

Core endpoints

List credentials

Get the credentials shared with a business entity.
Query parameters A credential appears here once it has been linked to the business entity. Secure string values are never returned by this endpoint; use Get credential with includeSecrets=true to read them. Response
createdAt, updatedAt and lastUpdateAt are Unix timestamps in milliseconds.

Get credential

Retrieve a single credential by ID.
Path parameters Query parameters Response The credential has the same shape as an entry of List credentials, without isUsed; the example below is trimmed. registrations is null unless you pass includeRegistrations=true.

Create credential

Add a new credential. Either name a credential from the country’s supported credentials with internalIdentifier, or describe a custom one with name and country.
Request body
Response Returns 201 Created.

Update credential

Update an existing credential.
Path parameters Request body Blocks are updated by id. blocks is required; send an empty array to change only other fields.
A block ID that does not belong to the credential returns 400 Bad Request. Response Returns 200 OK.

Delete credential

Remove a credential.
Path parameters Response Returns 204 No Content on success.

Supported credentials

Get supported credential types

Get the credentials Commenda supports for a country.
Query parameters Response Each entry describes one block of a supported credential, so a credential with a user name and a password appears twice under the same internalIdentifier. count is the number of entries.

Credential types

The credentialType field takes one of CORPORATE_TAX, INDIRECT_TAX, PAYROLL_TAX, COMPANY_SECRETARIAL, SOCIAL_SECURITY, BANKING or OTHER.

Corporate tax portals

Federal/national income tax filing systems:
  • US: IRS e-Services, state tax portals
  • UK: HMRC online services
  • India: Income Tax e-Filing portal
  • Canada: CRA My Business Account
  • Singapore: myTax Portal

Indirect tax portals

VAT/GST/sales tax filing systems:
  • US: State sales tax portals
  • UK: HMRC VAT online
  • India: GST portal
  • Singapore: myTax GST
  • UAE: Federal Tax Authority portal

Payroll tax portals

Withholding and unemployment insurance systems:
  • US: State withholding portals, SUTA portals
  • UK: HMRC PAYE online
  • India: ESIC, EPFO portals
  • Singapore: CPF portal

Company secretarial portals

Business registry filing systems:
  • US: State Secretary of State portals
  • UK: Companies House WebFiling
  • India: MCA portal
  • Singapore: BizFile+

Social security portals

Employee benefit systems:
  • US: Social Security Business Services Online
  • India: ESIC, EPFO
  • Singapore: CPF Board

Banking portals

Financial institution access:
  • Bank online banking
  • Payment processing portals
  • Treasury management systems

Credential blocks

Credentials consist of flexible blocks that can store different types of information. Each block has a key (its label), a type and a value:

Plain text blocks

Store non-sensitive information:
  • Usernames
  • Account numbers
  • Email addresses
  • User IDs
  • Reference numbers

Secure string blocks

Store sensitive information (encrypted at rest):
  • Passwords
  • PINs
  • Access tokens
  • API keys
  • Security answers
Responses show the last two characters of a secure string as secretMask, and return its value only when you get the credential with includeSecrets=true.

Custom blocks

Add jurisdiction-specific fields as needed by setting isCustomBlock: true on the block. A custom block does not have to match a block of the supported credential, so the block structure can accommodate any credential format.

Linking credentials

Associate a credential with a business entity:
This makes the credential accessible when viewing the business entity, and lists it under List credentials for that entity. Returns 200 OK:
Associate a credential with a specific registration:
This links the credential to a specific government registration, enabling automated filing workflows. Returns 200 OK with the same body as above.

Security

  • Encryption: Secure string blocks are encrypted at rest using industry-standard encryption
  • Access control: Credentials are only accessible to authorized users
  • Audit logging: All credential access and modifications are logged
  • Sharing: Credentials can be shared with accountants and service providers

Sharing with accountants

Credentials can be shared with external accountants and service providers who need portal access for filing and compliance work. The sharing mechanism ensures proper authorization and audit trails.