ZATCA FATOORA
Saudi Arabia’s e-invoicing system using UBL-based XML, security features, cryptographic stamping, hash chains and QR data during Phase Two integration.
Current version and implementation status
How to recognize the profile
Do not rely on the file extension alone. Inspect the root namespace, customization/profile identifiers, version values and authority-specific envelope.
- ZATCA UBL extensions
- Invoice hash
- Cryptographic stamp
- TLV QR payload
- ICV and PIH
Production validation stack
- 1UBL and ZATCA rules
Confirm that the document is well formed and structurally compatible with the intended FATOORA syntax.
- 2Security features
Apply semantic and business-rule checks rather than accepting a file merely because it parses.
- 3QR tags
Validate currencies, countries, tax categories, units, payment means and other controlled values against the correct release.
- 4Clearance/reporting API response
Apply the national, network or authority restrictions that narrow the base syntax.
Common errors and corrective action
Locate the relevant field and rule, correct the source mapping, rerun every validation layer, then preserve the final response.
Locate the relevant field and rule, correct the source mapping, rerun every validation layer, then preserve the final response.
Locate the relevant field and rule, correct the source mapping, rerun every validation layer, then preserve the final response.
Locate the relevant field and rule, correct the source mapping, rerun every validation layer, then preserve the final response.
Countries using or referencing this profile
Questions people ask
What is FATOORA?
Saudi Arabia’s e-invoicing system using UBL-based XML, security features, cryptographic stamping, hash chains and QR data during Phase Two integration.
How is FATOORA validated?
A production check normally applies UBL and ZATCA rules, Security features, QR tags, Clearance/reporting API response. Local browser preflight cannot replace the official validation artefacts or authority outcome.
Which version should I use?
The current research note is: XML Implementation Standard 1.2 and associated security artefacts; verify current waves. Confirm release notes at the official source before production deployment.
Inspect and prepare FATOORA files
Invoice QR reader
Read QR codes from invoice images in supported browsers.
Signature metadata inspector
Locate XML signature, certificate and digest metadata without claiming cryptographic validity.
Invoice SHA-256 hash calculator
Create a local SHA-256 fingerprint for invoice evidence, duplicate control and integration correlation.
Authority and network response decoder
Extract status, identifiers, error codes and messages from common JSON or XML invoice responses.