Key steps and distinctions
Software developers first onboard through APEX using Corppass, create an application, generate its API key, create an OAuth 2.1 client and subscribe to the sandbox service. Production access requires IRAS approval after successful sandbox testing; production must not be used for tests. Obtain a Corppass authorisation token with the EmpIncomeSub scope and distinguish an employer acting for itself from a tax agent acting for a client. The service uses server-to-server POST requests, an APEX API key, Bearer token and application/json content type. Each payload may contain no more than 2,000 employee records and 8 MB. Divide larger submissions into batches; when one batch fails, correct and resubmit that failed batch rather than repeating already accepted batches. The application limit is 3,000 requests per hour; a 429 response requires retrying in the next hour. Payload fields are case-sensitive, dates use ISO-8601 and the separate data-items workbook provides field-level validation. Preserve the acknowledgement and inspect error or warning responses. The September edition also records response-code fields as strings and removes an unused message-code field, making version control important for payroll integration.
Official source
A concise, independent Apex Gateway guide based on the official English source, not a reproduction of the complete document. Consult the original for full conditions, exceptions and subsequent updates.
Read the official PDF ↗
