Security & Data

Managing your HMRC credentials

5 min read

Secure Storage

WeFile securely stores your Government Gateway ID and passwords using robust AES-256 encryption. These credentials are only ever decrypted at the exact millisecond of transmitting your submission to the government API. For developers using the WeFile API, credentials can optionally be supplied per request at submission time, in which case they are used for that single transmission and never written to our database.

Updating Credentials

If you change your HMRC or Companies House passwords, you must update them within WeFile immediately to prevent future submission failures. You can safely update these details at any time in the filing's Credentials step or Credentials tab.

Credential Expiration

Be aware that HMRC Government Gateway passwords can expire or require forced resets if you haven't logged into the official portal for a long time. If WeFile reports an authentication error, log directly into HMRC to verify your credentials are still active.

Credential Isolation

We strictly isolate credentials per individual filing. This ensures that a filing can never inadvertently use the authentication details of another filing or another entity, protecting you from cross-contamination errors.