Obtain an IRS API Client ID and configure certificate-based authentication for e-Services API access
domain: irs.gov · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗
Steps
Complete Secure Access registration for e-Services for both the firm's principal and any delegated users who will use the API
Generate a valid X.509 digital security certificate and a JWKS (JSON Web Key Set) file, since the Client ID application requires providing the JWKS for certificate validation
Submit the API Client ID Application through the e-Services platform, associating it with the firm/organization and the specific API product needed (TIN Matching, Transcript Delivery System/SOR, IVES, or IRIS)
Allow up to 45 calendar days for IRS processing, then sign in to retrieve the issued Client ID(s) for the firm
Implement the ISP App authorization (JWT-based) flow in the application using the issued Client ID and configured certificate to authenticate subsequent API calls
Known gotchas
Client ID issuance can take up to 45 calendar days — this is not an instant self-service developer signup, so it must be planned well ahead of any go-live date
A Client ID is tied to a specific IRS API product; one obtained for TIN Matching does not automatically grant access to IVES or IRIS without a separate product-specific application
Certificate management is the applicant's responsibility — an expired X.509 certificate or mismatched JWKS breaks authentication and requires reconfiguration, not just a token refresh
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?