HMRC Online Service login page change

29 February 2016

HMRC’s Software Developers Support Team (SDST) has provided information about changes to HMRC’s Government Gateway login page:

What is this change?

  • We have updated the existing HMRC Government Gateway login page to provide a more secure page for all users. To do that we have created a new URL, improved the page design and introduced JavaScript-based security features on the new login page.

Why is HMRC making this change?

  • The first reason is to improve security by resolving issues arising from vulnerabilities known to affect most username and password-based websites.
  • The second reason is to improve stability and performance of the Government Gateway login service by significantly reducing the authentication load on Government Gateway.

What is the potential impact to software developers or software applications based on feedback we have received?

  • It is apparent that some software applications include 'silent login' or background login mechanisms to log into the HMRC website (with Government Gateway Usernames and Passwords).
  • If your software application uses the existing HMRC Government Gateway login page in this way, you will need to update your mechanism to point to and work with the new login page.
  • Please note, existing submissions to the Government Gateway API(Submission Protocol)will not be affected by this change.

When will this change happen?

  • We have already created the new login page in live and it can be found here.
  • Based on the feedback we have received, we believe a 3 month window will allow software developers to update their applications to point to and work with the new login page.
  • Until31 May 2016 we will continue to run the existing HMRC Government Gateway login page so that your application is not disrupted.
  • After31 May 2016 we will be removing access to the existing HMRC Government Gateway login page, so any changes needed to your applications will need to be implemented by this date if you want them to continue running normally.

If you have further questions or are unsure whether this affects you, please get in touch with us and we'll endeavour to help you - [email protected].