Skip to main content
Search

Connected Apps

Some products can be accessed with your existing GTR credentials through GTR Single Sign-On (SSO). Instead of registering a separate account, you sign in with your GTR account, review what the app will receive, and give your consent once.

This spares your VASP a second set of credentials to issue, rotate, and audit. Your team signs in with the GTR accounts you already control, and every app you have authorized sits in one place, where you can see what each one receives and cut it off in a single action. Because the authorization belongs to your VASP rather than to a person, it also survives your own staff changes: if the Main Account role moves to a colleague, the connection continues and nobody has to give consent again.

Every app your VASP has authorized in this way is listed under Connected Apps, where you can review when the connection was created, who created it, what is shared, and revoke the access at any time.

Entry point: [My Account] -> [Settings] -> [Other Settings] -> [Connected Apps] tab

Please note: GTR SSO shares only the account details needed to identify your VASP and sign you in. Your GTR password, KYB documents, Due Diligence records, the Travel Rule PII of your customers, your transaction and message history, and your billing details are never shared with a connected app.

Connect an Account

A connection is not created from the Connected Apps page. It is created the first time you sign in to another app using GTR SSO and give your consent.

How the connection is created

  1. Start the sign-in from one of the entry points provided for that app:
    • the "Login with GTR Account" button on the app's own website;
    • the promotion email GTR sends you;
    • the app's entry at the foot of the GTR sidebar, below Settings, which opens in a new browser tab.
  2. Sign in with your GTR email address and password. If Two-Factor Authentication is enabled on your account, complete the 2FA verification as usual (see: Configure 2FA).
  3. GTR checks whether your account is eligible for this app. If it is not, you stay on the GTR website and a message explains what to do next — no account data is sent to the app.
  4. If this is the first time your VASP connects to this app, the consent screen is displayed. It is titled with the name of the app you are connecting to and shows two panels side by side. Both are headed with the real name of that app: a uses panel listing the GTR account data that will be exchanged with it, and a never touches panel listing the GTR data that is never exchanged, under any circumstance. On GTRSafePro, for example, the headings read "GTRSafePro uses" and "GTRSafePro never touches". The two lists are specific to the app you are connecting to — each app declares its own set, so read the panels on the consent screen in front of you rather than assuming the same data is exchanged everywhere. For the lists that apply to GTRSafePro, see GTRSafePro.
  5. Read the app's Terms of Use through the link provided, then tick the acceptance checkbox below the two panels. Agree & Continue stays greyed out until the box is ticked.
  6. Click Agree & Continue to create the connection. You will be redirected to the app and signed in automatically. Alternatively, click Not Now to decline: no connection is created, nothing is recorded against your account, the message "You can enable this anytime." is displayed, and you are returned to where you started from.

Once you have agreed, the connection is established for your VASP. The app now appears on the [Connected Apps] tab, and subsequent sign-ins go through directly without showing the consent screen again.

What the app receives is limited to the account details it declares on its own consent screen — typically identification data such as your login email address, your VASP name and code, your business type, and your role — and never includes your credentials or any of your compliance or customer data. Because the exact set differs from one app to another, the consent screen for each app is the authoritative list.

On the consent screen, where the Business Contact name and email are exchanged, they are shown together on a single line; your Business Contact phone number is never shared. If a feature of the connected app ever needs data outside the uses list, it must ask for your acceptance again at the point where the data is used.

What you should know:

  1. Only the Main Account can give consent. The consent is given on behalf of the whole organization. If you are a Power User or an Operator and your VASP has not connected the app yet, you will be asked to have your Main Account enable it first.
  2. Consent is asked once per organization. After the Main Account has accepted, every eligible member of your VASP signs in without seeing the consent screen again. If the app later requests additional account details, the consent screen is displayed again for the new request.
  3. You can disconnect at any time at [My Account] -> [Settings] -> [Other Settings] -> [Connected Apps]. See Delete a Connected Account. Accepting an app's terms does not require you to re-accept the full GTR terms.
  4. Declining is not permanent. If you click "Not Now", nothing is recorded against your account and you may connect later through the same entry point.
  5. The acceptance survives a change of Main Account. It is held at the account level. If your VASP transfers the Main Account role to another person, or that person changes their own email address, the acceptance stays in place and nobody is asked to accept again. On their first access, the new Main Account sees a non-blocking notice stating the date on which the organization connected the app. The previous Main Account's access and sessions end with the role.
  6. If you hold a role in more than one VASP entity, each entity is checked separately and each entity's own Main Account gives its acceptance. You may therefore qualify through one entity and not through another. Once inside the app, the entity switch lists only the entities that passed the checks and were accepted.

GTRSafePro

GTRSafePro is a separate product operated by the same company as GTR, and it is the first app available through GTR SSO. Access is not open to every GTR account: eligibility is determined by your business type, your subscription, and your GTR mode.

Business TypeEligible for GTRSafePro?Rule
TRSP (Travel Rule Service Provider)Not available-
Direct VASPAvailable, conditionallyYour VASP must hold a valid Professional (Pro) subscription and operate in Advanced Mode. An account still on Trial qualifies as soon as a Professional payment is confirmed. Expired subscriptions and Basic Mode accounts are not eligible.

All three roles — Main Account, Power User and Operator — may use GTRSafePro once the Main Account has accepted the terms on behalf of the organization. Guest accounts are never eligible.

The checks are run every time an access is attempted, so an account that becomes ineligible later (for example when the subscription expires, the mode drops to Basic, or the business type changes) loses access automatically: the entry points disappear and all active sessions are ended for every role. The same applies to an individual who loses a role that may use the app — their own access and sessions end, while the organization's acceptance stays in place. If a check fails, you remain on the GTR website and the following message is displayed, together with an action link that takes you where you can resolve it.

SituationMessage displayedAction link
Your Business Type is TRSPGTRSafePro is available to Direct VASP accounts.GTR Dashboard
Your organization has no approved GTR account yet (Guest)GTRSafePro is available once your organization has an approved GTR account. Apply for a trial to get started.Apply for a trial
You are on Trial with no confirmed Professional paymentGTRSafePro is available on the Pro plan. Upgrade to get access.Upgrade to Pro Plan
Your subscription has expiredYour subscription has expired. Renew it to use GTRSafePro.Renew Subscription
Your VASP operates in Basic ModeGTRSafePro is available in Advanced mode. Upgrade to get access.Upgrade to Advanced
You are a Power User or an Operator, and your VASP has not accepted yetYour Main account holder needs to enable GTRSafePro for your organization first.GTR Dashboard

Data exchanged with GTRSafePro

The consent screen for GTRSafePro declares the following two lists. The left column is everything GTRSafePro receives from your GTR account; the right column is data that stays in GTR and is never exchanged, under any circumstance.

GTRSafePro usesGTRSafePro never touches
Login email addressGTR password
VASP / Business NameKYB documents
VASP codeDue diligence records
Business TypeTravel Rule PII of your customers
Account type and modeTransaction and message history
Role within the accountBilling details
Business Contact Name and Email

For more details on subscription plans, see Subscription Plan. For Basic Mode and Advanced Mode, see Basic Mode vs Advanced Mode.

View Connected Accounts

Entry point: [My Account] -> [Settings] -> [Other Settings] -> [Connected Apps] tab

The tab lists every app your VASP has connected through GTR SSO, one card per app. Each card contains:

  • App name, with a Connected status label.
  • Connection record: the date the consent was given, and the email address of the account holder who gave it, for example "Connected 2026, Sep 22 by admin@xyzcompany.com."
  • Shared data: "Shares: your GTR account details, used to sign you in."
  • The Revoke button, displayed to the Main Account only.

If your VASP has not connected anything yet, the page displays "You have not connected any apps yet."

Please note:

  • The connection belongs to your VASP, not to an individual user. Power Users and Operators can view the list and see who created the connection, but only the Main Account can revoke it.
  • The [Connected Apps] tab is not available to TRSP accounts.

Delete a Connected Account

Revoking an app's access removes the authorization your VASP granted. The app can no longer receive your GTR account details and can no longer sign your members in.

Entry point: [My Account] -> [Settings] -> [Other Settings] -> [Connected Apps] tab

  1. Locate the card of the app you want to disconnect.
  2. Click the Revoke button on the card.
  3. A confirmation dialog asks you to confirm that you want to revoke the app's access, and reminds you that you will be signed out of that app and can reconnect anytime.
  4. Click Revoke to confirm, or Cancel to keep the connection.
  5. Upon success, a message confirms that the app's access has been revoked, and the app is removed from the list.

What you should know:

  1. Revoking applies to your whole VASP. All of your members are signed out of the app, not only the account that performed the revoke.
  2. Only the Main Account can revoke. The Revoke button is not displayed for Power Users and Operators.
  3. Nothing in GTR is affected. Your GTR account, your subscription, and all data stored in GTR remain unchanged. Only the authorization granted to the app is removed.
  4. You can reconnect anytime. Sign in to the app through GTR SSO again; because the previous consent was revoked, the consent screen will be displayed once more and a new connection record is created.