Who Registers You on Peppol: You, Your Provider, or the Tax Authority?
Three ways a Peppol registration happens: your provider makes it, you buy it on its own, or a tax authority creates it centrally. How to tell which is yours.
In most countries your service provider registers you, and you never see it happen. In some you can buy the registration on its own. In a few the tax authority does it and nobody sells it to you at all. Which of the three applies decides what you can control, what you should be asking your provider for, and whether "registration" is even something you can purchase. This article sets out all three, and how to tell which one you are in.
If the mechanics themselves are new, how do you join the Peppol network covers the parts and the order they go in. This article is about the people, not the parts.
Who actually registers you on Peppol?
Somebody with a Service Metadata Publisher — the registry that holds your record — and it is almost never you.
A registration is not a form you file. It is an entry published somewhere a stranger's software can find: your participant identifier, each document type you are willing to receive, the process each belongs to, and the address and certificate of the access point that will take delivery. Publishing that entry requires an accredited publisher holding Peppol certificates, which is why the question is who does it for you rather than how you do it yourself.
There are three answers, and they are not variations of one another.
Model one: your service provider registers you
This is the normal case, and for most companies it is the right one.
You sign with a provider, hand over your business number, and they publish the record as part of onboarding. The access point named inside it is theirs, because they are the ones receiving for you. It usually takes minutes, and the reason so few people know how Peppol registration works is that this model asks nothing of them.
Two things follow from it that are worth knowing before they matter:
- Your discoverability is attached to their infrastructure. The record names their endpoint and their certificate. That is not a trap — it is what "they receive for you" means — but it does mean the record moves when you move.
- You cannot see it unless you look. Nothing tells you the registration happened, or that it lists the document types you can actually process. The check takes about thirty seconds and is in the section below.
Model two: you buy the registration on its own
Here the registry and the transmission are two purchases rather than one.
A publisher registers your identifier and points the record at whichever access point you name — including the one your current provider already runs. You give them the provider's AS4 endpoint address and public certificate, which every provider supplies routinely, and your documents keep arriving exactly where they do today.
This is the model people are usually looking for when they search for how to register, and it is what our own registration service does: $29 a month per organisation, up to 50 registered participants, with traffic going to the access point you name rather than through us by default. GoRoute is operated by ClayDesk LLC, a Peppol-certified Access Point and Service Metadata Publisher under Seat ID POP000991.
It is worth being plain about when this is not the useful answer. If one provider already sends, receives and registers for you, and the record is correct, buying registration separately buys you nothing today. What it buys is separability later: the ability to change who transmits without renegotiating who holds your identity on the network.
Model three: the tax authority registers you centrally
In some countries the authority operates the registry itself, and the whole question of who to buy registration from disappears.
Oman works this way, and it is the clearest published example we work with. The sequence, from the Tax Authority's own SMP specification and the programme's solution architecture, is: the taxpayer selects a provider on the Fawtara portal, the provider accepts, and then the Authority creates the participant identifier and the service group in its central registry, checking uniqueness in the network's root directory and adding the record there. Only after that does the provider publish what it can receive, through the Authority's own secured interface. The service levels are set in the same specification: three working days to add a participant after an accepted relationship, and one working day to remove one on termination.
Nobody sells you registration in that model, because the Authority performs it. A provider selling "registration" into a country like this is selling either accreditation to be selected on the portal, or transmission — both real things, and neither the same as holding your record.
We are describing Oman here as an example of the model. It is not a market for the registration service in this article, for exactly the reason above.
What does a Peppol Authority do, then?
It decides who may operate in a country. It does not normally hold your record.
Every Peppol jurisdiction has a national Peppol Authority — the body that signs the Peppol Authority agreement with OpenPeppol and takes responsibility for who may act as a service provider there. The Australian Taxation Office is Australia's, MBIE is New Zealand's, IMDA is Singapore's, MDEC is Malaysia's; OpenPeppol names them all on its own who-is-who register.
Accrediting providers and operating a registry are different jobs, and conflating them is the commonest confusion in this subject. An authority that accredits providers has still left your record with a provider. An authority that operates the registry has taken it. Oman is the second kind; most Peppol countries are the first.
"My provider already handles that" — is it true?
Almost always yes. Check it anyway, because the failure is silent.
Look your own identifier up the way a sender would. A registered participant returns a service group: the document types you accept, and the endpoint that receives them. An unregistered one returns a 404 — not an error, but the network reporting accurately that nobody by that identifier is reachable. You can run it free and without an account on our Peppol lookup.
Three ways a registration that exists is still not doing its job:
- It lists document types you cannot process. Senders use what the record advertises. A type registered before the system could handle it is an invoice arriving into nothing.
- It points at an endpoint nobody watches. Delivery succeeds, the document lands, and a payment deadline passes unread. This is the expensive one, and it looks like success from the outside.
- You are registered twice, under two identifiers. A group parent or a provider engaged years ago put you on the network once already. Senders find whichever one their software knows about. If you are unsure which number is even yours, which Peppol identifier is yours answers that first.
Can two providers register you at once?
No, and the reason is structural rather than contractual.
The network's root directory resolves a participant identifier to exactly one publisher, using a name derived from the identifier itself. One identifier, one record, one holder. So a change of provider is a hand-over — deregistration on one side, republication on the other — and not a second registration running alongside the first.
That is also why registering twice under two different numbers is worse than it sounds. Both records resolve, both look healthy, and which one a sender uses depends on what their system happens to hold. One identifier per legal entity, recorded wherever your finance team records the bank details.
Which model are you in?
Answer in this order; the first "yes" is your model.
- Does your country's tax authority run the registry and require you to nominate a provider on its own portal? Then it registers you, and your decision is which provider to nominate, not where to register.
- Do you already have a provider that sends and receives for you? Then they almost certainly registered you. Verify the record rather than buying a second one.
- Do you need to be reachable without changing, or without having, a transmission provider? Then registration bought on its own is the model that fits, and it is the one this site sells.
What to do next
If you are in the third case, register your business on Peppol and name your existing access point in the process — the record points where you tell it to. If you are in the second, run the lookup before anything else; a working registration means the job is already done and the only thing worth checking is whether the document types match what your system can genuinely handle today.
Sources: OpenPeppol eDelivery specifications — Peppol Service Metadata Publishing v1.4.0 and Service Metadata Locator v1.3.0, both valid from 1 November 2025 · OpenPeppol Policy for use of Identifiers v4.4.0 (6 February 2025) · OpenPeppol Peppol Authorities register · Oman Tax Authority, Oman SMP API Specifications v1.0 (4 June 2026) and the Fawtara solution architecture §3.1, as recorded in our own Oman registration handoff of 17 June 2026 · GoRoute Access Point and SMP certification, Seat ID POP000991.
Frequently asked questions
- Who registers you on the Peppol network?
- In most countries your service provider does it, as part of onboarding. In some countries you can buy the registration on its own and keep a different provider for sending and receiving. And in a few countries the tax authority operates the registry itself and creates your record centrally once you nominate a provider on its portal. Nobody registers directly with OpenPeppol in any of the three.
- Can I register myself on Peppol?
- Not directly with OpenPeppol, and not without a Service Metadata Publisher. Publishing a record requires an accredited publisher with Peppol certificates, so what you can do is buy the registration as its own service rather than take it bundled with transmission. That is a real choice in most Peppol countries and not a choice at all where the authority runs the registry.
- My provider says they already handle registration. Is that true?
- Usually yes, and it is worth checking rather than assuming. Look your own identifier up the way a sender would. A registered participant returns the document types it accepts and a receiving endpoint. If the lookup returns nothing, or returns document types your system cannot actually process, the registration is not doing the job you think it is.
- What is a Peppol Authority, and does it register me?
- A Peppol Authority is the national body that signs an agreement with OpenPeppol and decides who may operate as a service provider in its jurisdiction — the ATO in Australia, MBIE in New Zealand, IMDA in Singapore, MDEC in Malaysia. Accrediting providers is not the same as operating a registry, and in most Peppol countries the authority does not hold your record. Oman is the exception in our own work.
- Who registers a taxpayer in Oman?
- The Oman Tax Authority. The taxpayer selects a provider on the Fawtara portal, the provider accepts, and the Authority then creates the participant identifier and the service group in its own central registry before the provider publishes what it can receive. The Authority's own specification sets three working days to add a participant after an accepted relationship and one working day to remove one on termination.
- Can two providers register me at the same time?
- No. The network's root directory resolves your identifier to exactly one publisher, so one identifier means one record and one holder of it. That is why moving provider is a hand-over rather than a second registration, and why registering twice under two different identifiers creates a company nobody can reliably reach.
- What happens to my registration if I leave my provider?
- It has to be moved or removed, and someone has to do it. If the provider published your record it holds it, and a switch means deregistering there and republishing elsewhere. Where you bought the registration separately, the record stays with the publisher and only the access point named inside it changes — which is the practical argument for separating the two.
Building on Peppol?
GoRoute is a certified Peppol Access Point & SMP. Book a demo or read the docs to get started.