Why Your Tax Software Asks for More Than HMRC's Website Does

- 6 min read

If you have ever wondered why filing through software feels like it collects more about you than typing the same numbers into HMRC's website, there is a specific answer, and it is not the software vendor being nosy. HMRC requires it.

What HMRC requires

Every call Making Tax Digital software makes to HMRC has to carry a set of HTTP headers describing how the submission reached HMRC and from what. HMRC publishes the specification, monitors whether vendors comply with it, and follows up with the ones who get it wrong.

The headers describe the connection and the device, not the contents of your return. They include things like the route the submission took, the vendor and product version, a device identifier, and the public IP the request originated from with a timestamp.

  • How the submission reached HMRC, for example a web app calling through a vendor's server
  • Which product and version made the call
  • An identifier for the device the submission originated from
  • The originating public IP address and the time it was observed

Why HMRC wants it

The MTD API accepts filings on your behalf. That is enormously convenient and it is also an attack surface: if returns can be submitted by software, returns can be submitted by software that is not yours.

The headers give HMRC a way to see patterns across submissions that a single return cannot reveal. A thousand unrelated businesses filing from one device, or a submission whose stated route does not match how it actually arrived, look different in aggregate even when each individual return looks fine.

The headers describe the connection, not the return. Nothing in them tells HMRC anything about your figures that the return itself does not already say.

What it means for you in practice

Mostly nothing, which is the point: it happens on every call without asking you anything. It is worth knowing about for two reasons.

First, so that the request looks like compliance rather than surveillance when you notice it. Second, because getting the headers wrong is a real way for software to be non-compliant while appearing to work perfectly. A return can be accepted and the vendor can still be out of step with the specification, which is precisely why HMRC monitors it separately from whether submissions succeed.

The wider point about authorisation

The headers sit alongside the other thing MTD software needs, which is your authorisation. You grant that at HMRC's own sign-in, and it produces a token scoped to a specific tax, rather than handing your Government Gateway password to a vendor.

Both mechanisms exist for the same reason. Filing on someone's behalf is a serious permission, and the design assumes that at some point somebody will try to abuse it. You can withdraw the authorisation from your own HMRC account whenever you like, without going through the vendor, which is the part worth remembering.