A manifest signature isn't like clicking "I agree" on a website — it's a legally binding electronic signature that has to hold up the same way a wet-ink signature would, under a federal regulation called CROMERR (Cross-Media Electronic Reporting Regulation, 40 CFR Part 3). CROMERR is why the registration process feels heavier than a typical account signup: EPA has to be genuinely sure of your identity before it lets you sign anything, not just that you have a working email address.
1. Your EPA ID number
Every generator needs an EPA ID before anything else — it's how EPA and your state track a specific site, independent of who owns or operates it. You get one by filing the Site Identification Form (EPA Form 8700-12), either through your state hazardous waste agency or electronically via RCRAInfo's myRCRAid module, where available.
2. A CDX / RCRAInfo account
RCRAInfo — the system e-Manifest actually runs on — sits behind EPA's Central Data Exchange (CDX), the shared login EPA uses across several of its reporting systems. As of August 5, 2024, every CDX Industry account has to be configured with multi-factor authentication through Login.gov — a real, recent change worth knowing about if you set up an account before then and haven't logged in since.
Permission tiers matter
Not every RCRAInfo user at a site can do the same things. There are real tiers — Viewer, Preparer, Certifier, and Site Manager — and only a Site Manager can issue API credentials or grant other people permission for the site. EPA specifically recommends every site register at least two Site Managers, so one person leaving or losing access doesn't lock the whole site out.
3. The Electronic Signature Agreement (ESA)
This is the actual CROMERR identity-proofing step, and it's where the "real person, verified" requirement gets satisfied. RCRAInfo offers two paths:
- Online identity proofing (via LexisNexis) — your information is checked and scored immediately. This is the one worth choosing if it's offered.
- Paper, notarized form — mailed in, and RCRAInfo's own documentation says this can take two weeks or longer before you can sign anything.
4. Generating your API credentials
Once you're a Site Manager with a completed ESA, RCRAInfo lets you generate an API ID and Key under Tools → API. This is the credential pair that lets a third-party tool act on your behalf through EPA's actual e-Manifest API — treat it like a password, since anyone holding it can sign on your site's behalf.
This article covers the why. For the actual click-by-click checklist — tracked, so you can pick up where you left off, with a short video for each step — see Get set up with EPA.
Sign in