Product Data Sheet
Activity Statement API
This Product Data Sheet describes the Intaxio Activity Statement API for Activity Statement 2025, also referred to as AS2025. It should be read with the Customer API Agreement, short-form MSA, DPA, Security Overview and SLA.1. Product Summary
| Product name | Activity Statement API |
| Product code | AS2025 |
| Jurisdiction | Australia |
| Service category | Tax and business accounting |
| Primary use | Activity Statement discovery, pre-lodgment validation, lodgment and receipt handling |
| ATO service | Activity Statement 2025 via ATO PLS / SBR2 |
| Deployment model | SaaS, multi-tenant, hosted in Australian AWS regions (or available as a managed service) |
| Data retention | Submitted Activity Statement payloads retained for 7 days; ATO receipts retained for 12 months |
2. Product Description
The Activity Statement API enables customer platforms to integrate Activity Statement workflows into their own products without directly implementing the ATO SBR2 transport stack.
3. Included Components
| SKU |
Product Name |
Product Description |
| AS25TEST | Activity Statement API – Test | Non-production API access for development, integration testing and validation workflow testing. |
| AS25PROD | Activity Statement API – Production | Production API access for live Activity Statement validation, lodgment, status retrieval and receipt handling. |
| AS25LIST | Activity Statement List API | API capability for discovering available Activity Statement obligations or statements through Intaxio APIs. Included in the Activity Statement API. |
| ATOGW | ATO Gateway | Managed ATO gateway for AS2025 pre-lodgment validation and lodgment through ATO PLS / SBR2. |
| DEVESL | Intaxio Developer Portal – Enterprise Site Licence | Developer Portal access for documentation, credentials, telemetry and integration tooling. |
4. Functional Scope
The Activity Statement API includes the following core capabilities:
- Activity Statement list discovery;
- Activity Statement API access in test and production environments;
- AS2025 payload preparation and transformation;
- local validation before ATO submission;
- pre-lodgment validation;
- lodgment;
- ATO Gateway handling;
- receipt capture;
- status and result retrieval;
- Developer Portal access where licensed.
Webhook delivery may be supported in future, but webhook behaviour, signing, retry handling and delivery guarantees are not included unless separately agreed.
5. Data Handling and Retention
The product is operated as an Intaxio-hosted SaaS service in Australian AWS regions.
- Submitted Activity Statement payload: 7 days
-
ATO receipt: 12 months
Activity Statement data may include business tax information, tax identifiers, reporting obligations, lodgment content and ATO response data. Customers should treat this information as sensitive business and tax information.
6. Customer Responsibilities
The customer is responsible for:
- integrating its platform with the Intaxio Activity Statement API;
- mapping its own user interface, data model or Activity Statement workflow to the Intaxio API contract;
- ensuring users have authority to access, validate or lodge Activity Statements;
- presenting validation, lodgment and receipt outcomes to users;
- handling user declarations, confirmations and consent flows where required;
- protecting API credentials and secrets;
- ensuring the correctness and completeness of submitted data.
7. ATO and Regulatory Dependencies
Use of the product depends on:
- availability of the relevant ATO PLS / SBR2 services;
- availability of the AS2025 service;
- applicable ATO service restrictions;
- successful customer, taxpayer, agent or intermediary authorisation;
- ATO validation and lodgment processing;
- ATO service windows, outages and change releases;
- applicable ATO service documentation, validation rules and technical artefacts.
8. Support Obligations
Intaxio will provide reasonable support for the Activity Statement API to the extent necessary for the customer to integrate with and use the licensed services.
Support includes:
- access to applicable test and production API environments;
- API documentation and Developer Portal access where licensed;
- API credential setup and onboarding support;
- reasonable integration support for the test environment;
-
issue triage for Intaxio-controlled API, gateway, validation, transformation, lodgment, response-handling and receipt-handling services;
-
support for ATO conformance, onboarding or service activation artefacts where required for the supported Activity Statement API service and
within Intaxio’s responsibility;
- monitoring and implementation of applicable ATO AS2025 service updates for the supported product scope;
- operational support for production incidents in accordance with the applicable SLA.
9. Exclusions
Unless expressly included in the applicable order form, statement of work or product schedule, the product does not include:
- customer-side Activity Statement user interface development;
- tax, accounting, legal or BAS-agent advice;
- responsibility for the correctness of customer-entered or customer-calculated Activity Statement values;
- responsibility for customer platform mapping errors;
- direct customer access to ATO systems outside Intaxio-supported APIs;
- guaranteed ATO acceptance of any validation or lodgment request;
- guaranteed ATO service availability;
- customer-side user identity management;
- customer-side audit-log retention;
-
support for unsupported ATO services, unsupported Activity Statement versions or retired ATO message formats unless separately agreed.
10. SLA Exclusions
The SLA excludes downtime, delays, degraded responses, incorrect responses or failed transactions attributable to:
- ATO outages, maintenance windows, change windows or service degradation;
- ATO validation rule, schema, message or service changes outside the supported product scope;
- third-party network, platform or infrastructure failures outside Intaxio’s control;
- customer platform defects or customer-side integration errors;
- incorrect, incomplete or unauthorised customer data;
- customer mapping errors or assumptions outside the Intaxio-supported API contract;
- customer credential, permission or authorisation failures;
- force majeure events;
- any other exclusions set out in the Customer API Agreement, MSA, DPA, Security Overview or SLA.