Understand agent OAuth versus client-agent authorisation
Distinguish software OAuth from the separate legal HMRC relationship between an agent and each client. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.
What you’ll accomplish
Distinguish software OAuth from the separate legal HMRC relationship between an agent and each client. The MTD module stores tax profiles, HMRC authority, obligations, frozen filing snapshots, approvals and audit evidence, while Accounting remains the primary financial record system.
Follow these steps
- Go to Tax Centre → Settings → Profiles & HMRC authority.
- Verify you are working on the correct taxpayer profile and tenant before you understand agent oauth versus client-agent authorisation.
- Follow the on-screen workflow for understand agent oauth versus client-agent authorisation and keep the underlying Accounting records unchanged unless a genuine bookkeeping correction is required.
- Check any blocker or warning before continuing; a blocker must not be bypassed by manually re-keying tax totals.
- Keep client approval, professional review and HMRC authority requirements separate and complete each one that applies to the filing mode.
- Use the Audit Trail and frozen snapshot details to verify what was prepared, approved and submitted.
Checks before you continue
Technical basis for this guidance
This guide was checked against controllers/Mtd_hmrc_oauth.php; libraries/Mtd_hmrc_oauth_service.php; libraries/Mtd_hmrc_crypto.php; libraries/Mtd_hmrc_fraud_header_service.php. The user instructions describe only behaviour exposed or enforced by the supplied module. Internal secrets, encrypted token values and database identifiers are intentionally not shown to ordinary users.
Compliance and operational boundaries
- Britixo Accounting & Bookkeeping remains the authoritative ledger; the MTD module is a tax preparation/submission layer.
- Government Gateway usernames and passwords must never be entered into or stored by Britixo.
- A tax filing must not proceed when transaction-level digital lineage cannot be proven.
- Agent OAuth authorises the software connection only; the supplied v1.0.0 module does not create the legal HMRC client-agent relationship. Establish/verify that relationship separately through the appropriate HMRC process.
