Registration & TCC

How to Get an IRIS TCC: The Full Application Guide

Every business that e-files information returns through IRIS needs a Transmitter Control Code — and the application takes far longer than most filers expect. Here is the entire path, from e-Services and ID.me through the API Client ID and consent flow, with the traps that quietly reset the clock along the way.

At a glance

An IRIS TCC is the five-character credential the IRS assigns once your organization is approved to e-file 1099-series returns through the Information Returns Intake System. You apply inside IRS e-Services after every named person clears ID.me identity verification, and the IRS suitability check runs in the background before your code is issued. Your old FIRE TCC does not carry over, and if you intend to file machine-to-machine there is a second application — the API Client ID — that only opens after your TCC is in hand. If your deadline is too close to absorb that timeline, a provider that already holds an IRIS TCC can file on your behalf today.

In this story

What an IRIS TCC Actually Is

A Transmitter Control Code is a five-character identifier the IRS assigns to an organization that has been approved to send information returns electronically. Think of it as your filing license: until IRIS can tie an incoming submission to an approved TCC, the system has no way to know who you are or that you have cleared the agency's suitability checks. The code that begins with the letter D on your approval letter is the thing that makes everything else possible.

There is one detail that catches almost everyone, including filers who have transmitted for years: your FIRE TCC does not transfer to IRIS. Publication 5717 is explicit that a TCC obtained for FIRE, AIR, or any other system cannot be used in the IRIS Taxpayer Portal, and there is no conversion path between them. A brand-new IRIS application is the only way in, which means a seasoned FIRE transmitter and a first-time filer start the IRIS clock at exactly the same place — zero — and on exactly the same timeline.

It helps to read this guide alongside the broader IRIS registration and TCC overview, which sets the application in the context of the whole migration. What follows here is the deep version: every requirement, in the order you will actually hit it, with the regulatory source for each claim so you can verify it against the IRS yourself.

Official sources Pub 5717 / 5718

The authoritative walkthrough for the web channel is the IRIS Taxpayer Portal User Guide (Publication 5717). Anyone planning to file machine-to-machine should also work through the IRIS A2A Specifications (Publication 5718), which defines the API Client ID and consent steps covered later in this post. Both applications themselves live inside IRS e-Services.

TP or A2A: Which TCC Do You Need?

IRIS gives you two ways to file, and each runs on its own kind of TCC. The Taxpayer Portal (often shortened to TP) is the web channel, where you key returns in by hand or upload a CSV. Application-to-Application (A2A) is the developer channel, where your own software sends XML directly to the IRS over an authenticated API. Deciding between them is the first real fork in the road, because the two TCCs are not interchangeable and choosing the wrong one is a common reason an otherwise-valid application has to be redone.

IRIS-TP (Taxpayer Portal)IRIS-A2A (Application-to-Application)
How you fileWeb portal — manual entry or CSV uploadYour software sends IRIS XML over an authenticated API
Best forLow-to-mid volume; no developers requiredHigh volume; software developers and large transmitters
Roles on the applicationOne role per application: Issuer or TransmitterUp to three roles: Software Developer, Transmitter, Issuer
Extra steps before you can fileNone beyond the approved TCCAn API Client ID application, a JWKS key upload, the consent grant, and ATS testing
Interchangeable?No — a Taxpayer Portal TCC cannot be used for A2A, and an A2A TCC cannot be used in the Portal. If you need both channels, you complete both applications.

If you are weighing this against your current setup, our breakdown of how the IRIS TCC differs from your old FIRE TCC walks through what changes and what you can do with the code you already have. For everyone else, pick the channel that matches how you will really file, because that choice drives the roles you select and the steps that come after approval.

Before You Start: The Prerequisites

The application form itself is short. The work is in everything you have to line up before you open it, and missing any one of these is what turns a one-hour task into a multi-week round trip. Have the following ready and the application moves quickly.

  • An IRS e-Services account for every person named on the application. External users must register with the IRS credential service provider before they can touch the IRIS Application for TCC, so each Responsible Official, Contact, and Authorized Delegate needs their own login.
  • ID.me identity verification completed for each of those people. The IRS routes e-Services sign-in through ID.me, which means a government photo ID plus a selfie match for every individual on the application — this is the gate that stops most first attempts.
  • Your organization's legal name and EIN, exactly as the IRS has them. Publication 5717 requires the firm's legal business name, business structure, and EIN, and it will not accept an SSN or ITIN in the EIN field. A single mismatched character here is the number-one cause of rejection.
  • A real Responsible Official with authority to act for the organization, along with their date of birth, SSN or ITIN, and contact details — because the RO is the person who electronically signs and submits the application under penalty of perjury.
  • The five-digit PIN each Responsible Official created on first sign-in, since that PIN is the electronic signature used to accept the terms of agreement.

Responsible Officials, Delegates, and the Three Roles

Before you start clicking through the form, it is worth understanding who the application expects you to name and what each role can do, because these terms recur throughout e-Services and they have precise meanings. Getting a person assigned to the wrong role is a quiet source of delay that surfaces only when someone tries to act and the system refuses them.

The people on the application

A Responsible Official (RO) is an individual with authority over the organization who initiates, signs, and submits the IRIS Application for TCC. At least one RO is required, and each one signs the terms of agreement with the five-digit PIN created at first sign-in. An Authorized Delegate (AD) is an optional helper the RO can add to maintain the application; depending on the change, ADs may also need to re-sign the submission page when the application is revised. A Contact is simply the person the IRS reaches out to with questions. Naming two Responsible Officials rather than one is a practical safeguard: if the only RO leaves the organization, an application with a single official can be left stranded.

The roles you request

Separate from who is on the application is what the organization is asking to do. On the Portal application, Publication 5717 has the RO select one role — Issuer if you are filing only for your own business (your EIN must match the EIN on the application), or Transmitter if you are sending returns on behalf of others. The A2A application in Publication 5718 is broader and lets a single firm request up to three roles at once: Software Developer for an organization writing origination or transmission software to IRS specifications, Transmitter for a third party sending data directly to the IRS, and Issuer for a business filing its own returns. Choose the roles that describe what you will genuinely do, because they shape both your TCC and the testing the IRS will expect of you.

How to Apply, Step by Step

Once your prerequisites are in place, the IRIS Application for TCC runs in a predictable order. You do not have to finish in a single sitting — the application saves and issues a tracking number — but the sequence below is the path from a blank form to a code that begins with D.

1

Sign in to e-Services and verify with ID.me

Create or access your e-Services account and complete ID.me for yourself and every person you will name. Nothing else proceeds until identity proofing is finished, so do this first for the whole team rather than discovering a missing verification mid-application.

~5–15 min per person
2

Open the IRIS Application for TCC

From the e-Services dashboard, start a new IRIS Application for TCC. This is where you choose your channel — the Taxpayer Portal application and the A2A application are separate forms, so open the one that matches how you plan to file (or both, if you need both).

~5 min
3

Enter your organization details

Provide the firm's business structure, legal name, EIN, business address (a physical location, not a PO box), and a doing-business-as name if it differs. These must match IRS records exactly; if your EIN was issued under a slightly different name, use that name rather than the one on your storefront.

~10 min
4

Add Responsible Officials, Delegates, and Contacts

Name at least one Responsible Official (two is the safe choice), any Authorized Delegates, and a Contact, supplying each person's SSN or ITIN, date of birth, title, and contact information. Each must already be verified through ID.me and associated with the organization.

~15 min
5

Choose your roles and transmission method

Select the role or roles you are requesting — Issuer or Transmitter on the Portal, or any of Software Developer, Transmitter, and Issuer on A2A — and confirm the channel. A2A applicants are committing here to the additional setup and ATS testing that follow approval.

~5 min
6

Sign the terms of agreement and submit

Each Responsible Official signs the Application Submission page using their five-digit PIN, which is the electronic signature that submits the application for review. After submission the application moves into a review status while the IRS runs its suitability checks.

~5 min
7

Watch for assignment, then use your TCC

When approved, a TCC beginning with D is assigned and an approval letter is mailed by USPS to the address on the application. You can begin using the TCC as soon as it is assigned — you do not have to wait for the paper letter to arrive.

Review runs in the background

The Suitability Review — and Why It Governs Your Deadline

After you submit, the IRS runs a suitability check on the organization and the people named on it before any code is issued. This is not instant. Publication 5717 instructs filers whose application sits in Submitted Pending Review status for more than 45 days to contact the Help Desk — which tells you, in the IRS's own words, that a month and a half of waiting is within the normal range, not a sign that something has gone wrong. The review cannot be expedited, and refiling does not speed it up.

Stack the realistic pieces together — ID.me for every person, the application itself, the suitability window, and any IRS follow-up — and the honest end-to-end runway is measured in months, not weeks. That single fact should reshape how you plan your filing season.

The deadline that actually governs you isn't printed on any IRS calendar — it's the day you must start the TCC process so it can clear before filing season. Count backward from January 31, not forward from today.— — e1099f compliance desk
Do the math backward

Begin the application in the fall and the review may not clear before the January 31 deadline for 1099-NEC. If you are reading this in the fourth quarter, treat your own-TCC timeline as already tight and have a fallback ready, because there is no way to buy back the weeks the suitability check needs.

A2A Only: The API Client ID, JWKS, and Consent

If you chose the Taxpayer Portal, your TCC is the finish line — you can skip ahead to the rejection reasons. A2A filers, though, have a whole second act that many people do not realize exists until their TCC arrives and they discover they still cannot transmit. Publication 5718 lays out four more gates: a separate API Client ID application, a cryptographic key upload, a consent grant, and assurance testing. None of them can begin until your A2A TCC is approved.

1. Apply for an API Client ID

The API Client ID is what lets your software actually talk to IRS systems, and it lives in a different application from your TCC. Publication 5718 directs you to irs.gov/iris, where you choose Get an API Client ID, sign in, select Individual on the organization page, and start a new API Client ID Application with the IRIS box checked under Select APIs. One caution worth repeating from the Pub: keep selecting Individual each time you return to the application until it reaches completed status, because picking the wrong organization context strands the work you have already done.

2. Upload a JWKS built on a valid X.509 certificate

Before the Client ID is issued, you must upload a JSON Web Key Set (JWKS) — the file that carries the public key the IRS will use to verify everything your software signs. Publication 5718 is specific about what it must contain: a public key using the RSA algorithm, and an X.509 certificate expressed through both the x5t (SHA-1 thumbprint) and x5c (certificate chain) parameters. Self-signed certificates are not allowed, but you may reuse the same public certificate you already use for other IRS programs such as MeF or AIR. The certificate is validated during the application, and only then is your Client ID released.

Under the hood, this key is what makes the OAuth flow work. As Publication 5718 describes, your software authenticates with your Client ID and a pair of signed JWTs — one proving the client application, one proving the user — which the IRS verifies against your uploaded key before returning a short-lived access token your software then uses to call the intake API.

3. Grant consent in the IRS Consent App

A Client ID that exists is not yet a Client ID that is allowed to act. Publication 5718 requires the Transmitter to log in to the IRS Consent App and explicitly authorize the Client ID to operate on the organization's behalf. The Pub flags the one step everyone gets wrong on the first pass: on the Select Your Organization page, choose the organization tied to your IRIS TCC application — not the API application itself. From the API Authorization Management page you select Setup, enter your IRIS Client ID, and then grant access twice: once to TEST so you can run ATS, and once to PROD so you can transmit live returns.

When consent completes, the app hands you your full IRIS UserID — a value in a form like dasmith-345870 — which your software must use when generating access tokens. Write it down; you will need it the moment you start testing.

4. Pass ATS, then go live

The last gate is the Assurance Testing System. Using your TEST consent, you submit defined test scenarios so the IRS can confirm your XML is well-formed and your transmission behaves correctly before any real taxpayer data flows. Our walkthrough of IRIS ATS testing covers the scenarios and the common failures in depth; the point here is simply that ATS is mandatory for A2A and that it sits between your approved TCC and your first production filing.

Every production transmission is wrapped in a manifest that carries your TCC and identifies the payload, and the IRS validates that envelope before it ever looks at your returns. A representative shape looks like this:

<TransmissionManifest> <TCC>A1B2C</TCC> <TestFileCd>T</TestFileCd> <!-- T during ATS, P in production --> <FormTypeCd>1099-NEC</FormTypeCd> <TotalPayeeRecordCnt>250</TotalPayeeRecordCnt> </TransmissionManifest>

That snippet is illustrative — the exact element names and the full schema are defined in Publication 5718, and you should treat the Pub as the source of truth rather than any example. The practical takeaway is that A2A is not a single approval but a chain of them, and each link has to be in place before the next one will function.

A Sensible Companion: Enrolling in TIN Matching

TIN Matching is a separate e-Services program, not part of the TCC application, but it is worth setting up in the same pass because it prevents a category of penalty before you ever file. It lets an authorized payer check a TIN, name, and TIN-type combination against IRS records, so you catch a mismatched recipient name or number before it becomes a B-notice or a rejected return.

Publication 2108-A describes the enrollment path, and the prerequisites overlap neatly with what you have already done for the TCC. Every user in the firm needs an ID.me account to reach e-Services, after which the firm's Principal — defined as a partner or someone owning at least five percent of the firm, or a corporate officer — completes the Application to TIN Match and assigns roles such as Responsible Official, authorized agent, and delegated user to everyone else who needs access. Because the identity proofing is shared, enrolling here while your team is already verified is far easier than coming back to it later under deadline.

Common Rejection Reasons (and How to Avoid Them)

Most TCC problems trace back to a short list of fixable causes, and because a fresh submission restarts the review, each one effectively costs you weeks. These are the ones worth getting right the first time.

EIN / legal-name mismatch most common

Cause: The legal name on the application does not match the name the IRS has tied to your EIN. Fix: Use the exact legal business name from your EIN assignment notice (the CP 575), not a DBA or a shortened trade name — and remember the EIN field will reject an SSN or ITIN.

Responsible Official not verified or not associated

Cause: The named RO never finished ID.me, or is not linked to the organization in IRS records, so the application cannot be signed and submitted. Fix: Name a real person with authority over the firm and confirm their ID.me verification is complete and their five-digit PIN is set before you submit.

Resubmitting because you haven't heard back

Cause: Filing a second application out of impatience flags the account and only adds to the review backlog rather than jumping the queue. Fix: Submit once and monitor the status in e-Services; if it sits in Submitted Pending Review past 45 days, contact the Help Desk rather than refiling.

Wrong channel or missing role

Cause: Requesting a Taxpayer Portal TCC when you actually need A2A (or the reverse), or omitting the Transmitter role you require, leaves you with a code you cannot use the way you intended. Fix: Match the channel and roles to how you will really file, and apply for both channels if you genuinely need both — the two TCCs are not interchangeable.

A2A stalls: self-signed cert or wrong consent context

Cause: Uploading a self-signed certificate, or granting consent against the API application instead of the IRIS TCC organization, leaves an approved TCC that still cannot transmit. Fix: Use a valid X.509 certificate with the x5t and x5c parameters, and in the Consent App select the organization tied to your IRIS TCC — not the API application — then grant both TEST and PROD.

Skip the TCC Entirely: The e1099f Advantage

Everything above is required only if you intend to become a registered transmitter yourself. There is a second, legitimate path: file through an IRS-authorized provider that already holds an IRIS TCC, which removes the application, the wait, and the A2A setup from your plate entirely.

No suitability wait

We already hold an IRIS TCC and an approved A2A connection, so you create an account and file now — no application, no review window, no ID.me.

No keys to manage

The Client ID, JWKS, X.509 certificate, and consent grants are ours. You never build the OAuth flow or babysit a certificate expiry.

Validation built in

Every record is checked against the IRS business rules before submission, and you get a Receipt ID back instead of a rejection to decode.

If you would rather not become a registered transmitter, this is the fastest compliant path to IRIS — CF/SF included.

Frequently Asked Questions

Can I reuse my FIRE TCC for IRIS?
No. Publication 5717 states that a TCC obtained for FIRE, AIR, or A2A cannot be used in the IRIS Taxpayer Portal, and there is no conversion path. You must submit a new IRIS Application for TCC through e-Services.
How long does IRIS TCC approval really take?
The IRS does not publish a fixed turnaround, but Pub 5717 tells filers to contact the Help Desk only after an application has been in Submitted Pending Review for more than 45 days — so plan for at least that, and realistically 2–4 months end to end once you add ID.me and any follow-up.
Do I need ID.me?
Yes. e-Services sign-in is routed through ID.me, so the Responsible Official and every person named on the application must complete identity verification before the application can be signed and submitted.
Is there a fee for an IRIS TCC?
The IRS does not charge for the TCC itself. Your real costs are the time to apply and, for A2A filers, the software development and ATS testing effort. TIN Matching is also free through e-Services.
What's the difference between a Portal TCC and an A2A TCC?
A Taxpayer Portal TCC lets you file through the IRIS website by hand or CSV; an A2A TCC lets your software transmit XML over the API. They are separate, non-interchangeable codes — apply for both if you need both channels.
Why can't I transmit even though my A2A TCC is approved?
Because the TCC is only the first of several A2A gates. Per Pub 5718 you still need an API Client ID, a validated JWKS upload, a consent grant for TEST and PROD in the IRS Consent App, and passing ATS results before you can send live returns.
What is the API Client ID and how is it different from my TCC?
The TCC identifies your organization as an approved filer; the API Client ID identifies your software to the IRS authentication gateway. You apply for the Client ID separately at irs.gov/iris, and only after your A2A TCC is approved.
What kind of certificate does the JWKS require?
Pub 5718 requires a public RSA key in an X.509 certificate carried by both the x5t and x5c parameters. Self-signed certificates are not accepted, but you may reuse the same public certificate you already use for IRS programs like MeF or AIR.
How many Responsible Officials should I name?
At least one is required, but naming two is wise. A Responsible Official signs and maintains the application, and an account with a single RO can be left stranded if that person leaves the organization.
What if my application is rejected?
The IRS notifies you through e-Services with a reason — commonly an EIN/legal-name mismatch or an RO identity issue. You can correct it and reapply, but the suitability review starts over, which is exactly why the first submission needs to be right.
Should I enroll in TIN Matching at the same time?
It is sensible to. TIN Matching is a separate e-Services program described in Pub 2108-A, but it shares the ID.me prerequisite, so enrolling while your team is already verified is far easier than returning to it later.
Do I need a TCC at all if I file through e1099f?
No. e1099f files under its own IRIS TCC and A2A connection, so you skip the application, the suitability wait, ID.me, the API Client ID, the keys, and ATS testing entirely.
DM
Dariel Montesino
Founder, e1099f · Reviewed by a licensed CPA

Dariel writes e1099f's technical coverage of the FIRE-to-IRIS migration, drawing on IRS Publications 5717–5719 and 2108-A and hands-on IRIS A2A integration work, including the OAuth, JWKS, and consent flow described above.

Not tax advice. This guide is general information about IRS procedures and may change as the IRS updates IRIS. The official IRS publications linked above are authoritative; confirm current requirements there and consult a tax professional for your situation.

Deadline closer than the suitability review? File through IRIS today.

Keep your existing files, skip the TCC application and the wait. Free to start — no credit card.

An unhandled error has occurred. Reload ×

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.