Permissible if targeted
Transaction list, CSV, exchange statement, if necessary and specific. A complete, analysable export can also be the milder means.
A data export, yes. An API key or wallet access, not without more. The line between the two decides what you must give the tax office and what you must not.
These words appear in letters from the tax office.
| German | Meaning |
|---|---|
| Auskunftsersuchen | Request for information from the tax office |
| Außenprüfung (Betriebsprüfung) | Tax audit at a business, carried out by an auditor |
| Mitwirkungspflicht | Your duty to cooperate |
| Schätzung | Estimate: the office assesses the tax itself if you do not provide the facts |
| Selbstanzeige | Voluntary disclosure of undeclared income |
The tax office may ask for information. It may not ask for permanent access.
Section 90 AO requires you to disclose all facts that matter for tax completely and truthfully and to name the evidence you know of. For matters abroad, you must use the legal and factual means available to you. The circular usually treats centralised and decentralised exchanges as matters abroad (paragraph 89). Section 93 AO allows requests for information where necessary, and section 97 AO allows the office to ask for existing records and documents. The BFH confirms that the office may ask for information and documents to a reasonable extent in the assessment procedure as well (I B 169/02).
A targeted request for a transaction history, CSV export, exchange statements, wallet addresses or transaction hashes fits these rules. Permanent access through a login or an API secret is not an expressly regulated power.
The statutory access to data is narrower than many assume.
During a tax audit, section 147(6) AO gives the tax authority three forms of access: viewing the stored data and using the system, machine analysis under its instructions, or transfer of the data in a machine-readable form. This applies only to documents you must keep under section 147(1) AO. If the data sit with a third party such as an exchange, that third party is bound to one of these forms. Nothing in the text obliges you to hand over your own login credentials. Section 200 AO obliges you to assist the auditor.
For private crypto transactions there is generally no business record-keeping duty for all exchange and wallet data. For business transactions, the scope depends on which records you must actually keep (section 140 AO).
Four things that are often thrown together.
Transaction list, CSV, exchange statement, if necessary and specific. A complete, analysable export can also be the milder means.
"Read-only" does not replace the proportionality test: the key can open the whole holding and creates a permanent connection. In an audit it is at most defensible if it covers only mandatory records and an export is not enough.
This is not a right to read data. It is control over the assets. Sections 97 and 147 AO do not name it as a document or a form of access.
The ministry circular (paragraph 104) allows requests for wallet addresses and transaction hashes in individual cases. An address alone does not prove ownership (paragraph 87).
We found no decision specifically on read-only API keys or wallet credentials. The standards come from cases on digital accounting data. They are transferable, but they were not decided for crypto.
The protection is real, but narrower than its reputation.
According to case law, the tax procedure and the criminal tax procedure run side by side. A criminal investigation does not remove your duties of cooperation in the tax procedure (BFH XI B 6/01). But section 393(1) AO forbids coercive measures such as fines for non-compliance, to the extent that you would have to incriminate yourself for a tax offence you committed. Once a criminal procedure has been opened, this applies in every case. You must be told of this where there is reason to.
An estimate under section 162 AO is part of the assessment and not a coercive measure. If you provide nothing, you carry the risk of an unfavourable assessment. The office may not, however, knowingly estimate too high to force you to cooperate.
Whether handing over specific credentials would incriminate you depends on the case, for example on whether previously undeclared transactions would come to light. If you suspect that you did not declare income completely, get advice before you react. An effective voluntary disclosure (Selbstanzeige) rules out criminal liability (section 371 AO). See the requirements in our article on DAC8 and voluntary disclosure.
Evidence yes, API access no.
| Paragraph | Content |
|---|---|
| 87 | A public wallet key alone does not suffice as proof. |
| 89 | Transactions on centralised and decentralised exchanges are usually matters abroad (section 90(2) AO). Call up transaction histories regularly and completely. Loss of data lies within your risk area. |
| 90 | A tax report suffices if plausible and without gaps. Settings and manual corrections must be traceable. A later audit stays possible. |
| 101 | CSV files and transaction histories. Screenshots only after you have exhausted your own research. |
| 104 | In individual cases: origin of funds, holdings on a given date, wallet addresses, transaction hashes, exchange accounts. |
In these paragraphs the circular says nowhere that API access or the disclosure of credentials must be given. It is also an administrative instruction and not a legal basis for such a demand. Source: circular of 6 March 2025, ref. IV C 1 - S 2256/00042/064/043, paragraphs 87 to 104.