§§ 90, 93, 147 AO Article · Legal position 10/2026

Can the German tax office demand my exchange API key?

A data export, yes. An API key or wallet access, not without more. The line between the two decides what you must give the tax office and what you must not.

The essentials
  • No general duty to hand over an API key or wallet credentials.
  • Targeted information, documents and exports are permissible (sections 90, 93, 97 AO).
  • In a tax audit, data access covers only mandatory records (sections 147(6), 200 AO) and is limited by proportionality.
  • A seed phrase or private key is not evidence. It is control over your assets.
  • Note: if you provide nothing, the office may estimate under section 162 AO.

German terms you will meet

These words appear in letters from the tax office.

GermanMeaning
AuskunftsersuchenRequest for information from the tax office
Außenprüfung (Betriebsprüfung)Tax audit at a business, carried out by an auditor
MitwirkungspflichtYour duty to cooperate
SchätzungEstimate: the office assesses the tax itself if you do not provide the facts
SelbstanzeigeVoluntary disclosure of undeclared income

Outside a tax audit: information and documents

The tax office may ask for information. It may not ask for permanent access.

Section 90 AO requires you to disclose all facts that matter for tax completely and truthfully and to name the evidence you know of. For matters abroad, you must use the legal and factual means available to you. The circular usually treats centralised and decentralised exchanges as matters abroad (paragraph 89). Section 93 AO allows requests for information where necessary, and section 97 AO allows the office to ask for existing records and documents. The BFH confirms that the office may ask for information and documents to a reasonable extent in the assessment procedure as well (I B 169/02).

A targeted request for a transaction history, CSV export, exchange statements, wallet addresses or transaction hashes fits these rules. Permanent access through a login or an API secret is not an expressly regulated power.

During a tax audit: sections 147 and 200 AO

The statutory access to data is narrower than many assume.

During a tax audit, section 147(6) AO gives the tax authority three forms of access: viewing the stored data and using the system, machine analysis under its instructions, or transfer of the data in a machine-readable form. This applies only to documents you must keep under section 147(1) AO. If the data sit with a third party such as an exchange, that third party is bound to one of these forms. Nothing in the text obliges you to hand over your own login credentials. Section 200 AO obliges you to assist the auditor.

  • Only mandatory records. Private transactions that you are not required to record, and voluntary records, do not fall under data access merely because they exist digitally (BFH VIII R 80/06).
  • Not blanket. A request that is not sufficiently limited is unlawful. Necessity, proportionality, feasibility and reasonableness must be examined (BFH VIII R 24/18).
  • No online access. The GoBD (paragraphs 159 to 170) describe direct access as read-only access to the taxpayer's own system and exclude remote access by the tax authority. They are administrative instructions and do not extend the statute (GoBD).

For private crypto transactions there is generally no business record-keeping duty for all exchange and wallet data. For business transactions, the scope depends on which records you must actually keep (section 140 AO).

API key, seed phrase, public address

Four things that are often thrown together.

Export

Permissible if targeted

Transaction list, CSV, exchange statement, if necessary and specific. A complete, analysable export can also be the milder means.

Read-only API key

No blanket authorisation

"Read-only" does not replace the proportionality test: the key can open the whole holding and creates a permanent connection. In an audit it is at most defensible if it covers only mandatory records and an export is not enough.

Seed phrase, private key

Not to be handed over

This is not a right to read data. It is control over the assets. Sections 97 and 147 AO do not name it as a document or a form of access.

Public address

On request in individual cases

The ministry circular (paragraph 104) allows requests for wallet addresses and transaction hashes in individual cases. An address alone does not prove ownership (paragraph 87).

We found no decision specifically on read-only API keys or wallet credentials. The standards come from cases on digital accounting data. They are transferable, but they were not decided for crypto.

Protection against self-incrimination (section 393 AO)

The protection is real, but narrower than its reputation.

According to case law, the tax procedure and the criminal tax procedure run side by side. A criminal investigation does not remove your duties of cooperation in the tax procedure (BFH XI B 6/01). But section 393(1) AO forbids coercive measures such as fines for non-compliance, to the extent that you would have to incriminate yourself for a tax offence you committed. Once a criminal procedure has been opened, this applies in every case. You must be told of this where there is reason to.

An estimate is not a forbidden coercive measure

An estimate under section 162 AO is part of the assessment and not a coercive measure. If you provide nothing, you carry the risk of an unfavourable assessment. The office may not, however, knowingly estimate too high to force you to cooperate.

Whether handing over specific credentials would incriminate you depends on the case, for example on whether previously undeclared transactions would come to light. If you suspect that you did not declare income completely, get advice before you react. An effective voluntary disclosure (Selbstanzeige) rules out criminal liability (section 371 AO). See the requirements in our article on DAC8 and voluntary disclosure.

What the ministry circular says

Evidence yes, API access no.

ParagraphContent
87A public wallet key alone does not suffice as proof.
89Transactions on centralised and decentralised exchanges are usually matters abroad (section 90(2) AO). Call up transaction histories regularly and completely. Loss of data lies within your risk area.
90A tax report suffices if plausible and without gaps. Settings and manual corrections must be traceable. A later audit stays possible.
101CSV files and transaction histories. Screenshots only after you have exhausted your own research.
104In individual cases: origin of funds, holdings on a given date, wallet addresses, transaction hashes, exchange accounts.

In these paragraphs the circular says nowhere that API access or the disclosure of credentials must be given. It is also an administrative instruction and not a legal basis for such a demand. Source: circular of 6 March 2025, ref. IV C 1 - S 2256/00042/064/043, paragraphs 87 to 104.

Questions and answers on tax office access

Can the German tax office demand my exchange API key?
There is no general duty to hand over an API key or wallet credentials. The tax office may ask for targeted information, documents and exports (sections 90, 93 and 97 AO). During a tax audit, data access covers only the records you are required to keep (sections 147(6) and 200 AO) and is limited by proportionality.
Do I have to give the tax office my seed phrase or private key?
No. A seed phrase or private key is not a document or evidence. It gives control over the assets. The relevant provisions do not name it as something you must produce.
Is a read-only API key safe to hand over?
Read-only does not replace the proportionality test. The key can open the whole holding and creates a permanent connection. In an audit it is at most defensible where it covers only mandatory records and an export would not do. Get advice before you agree.
What can the tax office legitimately ask for?
Transaction histories, CSV exports, exchange statements, wallet addresses and transaction hashes, in individual cases also holdings on a given date and the origin of funds (circular, paragraphs 87 to 104). The request must be specific and necessary.
What happens if I give the tax office nothing?
The office can estimate the tax under section 162 AO. An estimate is not a forbidden coercive measure, so you carry the risk of an unfavourable result. The office may not knowingly estimate too high only to force cooperation.
Does the protection against self-incrimination apply?
Section 393 AO forbids coercive measures where you would have to incriminate yourself for a tax offence you committed. It does not remove the duty to cooperate in the tax procedure, and an estimate remains possible. If you suspect that you did not declare income completely, get advice before you react.
Responsible for content: Matthias Steger, German certified tax advisor (Steuerberater), nine years as a tax auditor.
Legal position: 10 October 2026. Sources: sections 90, 93, 97, 140, 147, 162, 200, 328, 371, 393 AO; circular of 6 March 2025, paragraphs 87 to 104; GoBD paragraphs 159 to 170; BFH VIII R 80/06, VIII R 24/18, I B 169/02, XI B 6/01.
To our knowledge there is no decision on API keys or wallet credentials; the assessment rests on transferable standards. This article is not advice on an individual case. Where this English text and the German text differ, the German text prevails.

Read on