Actions and results

What each E-invoicing button and automatic behaviour does, with worked numbers and what the system refuses.

On this page (21)

Dashboard

ActionWhenWhat you doWhat happens
Start with the sandboxCompany with e-invoicing off (banner 'E-invoicing is switched off for this company.' visible); user has configure + secretOpen Dashboard; press 'Start with the sandbox'; then open Configuration > Onboarding and Credentials; press the button again from the API or reopenE-invoicing flips on, banner disappears; an Active Test onboarding with SANDBOX exists with two credentials (callback secret and signing key, both Active, signing certificate self-signed); the four profiles (AE B2B, AE B2C, SA standard, SA simplified) are Active in Test; pressing again creates no second onboarding or duplicate credentials
Dashboard tiles agree with the listA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; a mix of pending, queued, submitted, accepted, rejected, unknown, blocked submissionsCompare each tile with the Submissions tab counts; click a recent rowWaiting to send = Pending + Queued; Awaiting answer = Submitted; Status unknown; Accepted; Rejected with open issues count; Pending clearance (legal state, not superseded); at risk; credentials expiring within the alert days; 'Accepted - last 14 days' bars sum to accepted in the window; superseded is not charted

Settings

ActionWhenWhat you doWhat happens
Save settings and detect an edit conflictSettings open in two browser tabs (same revision)Tab 1: change 'Warn before a credential expires' from 30 to 45, Save. Tab 2 (stale): change Submit automatically, SaveTab 1 shows 'Saved.'. Tab 2 is refused with 'This record changed since you opened it. Reload it and try again.' (409) and nothing of tab 2 is stored
Master switch off stops hand-overA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; one draft invoice readyTurn 'E-invoicing is on' off and Save; post the invoice; check Submissions; turn it on again and post anotherWhile off: no submission is created for the posted invoice, smart button absent, scheduler ignores the company. After switching on the next posted invoice gets a submission (the first one does NOT appear retroactively)

Onboarding

ActionWhenWhat you doWhat happens
Test onboarding: draft to active in two clicksActive SANDBOX provider; user with configureNew onboarding: provider SANDBOX, environment Test, registration = company TRN; Save; open it; press Start testing; press Request activationState goes Draft > Testing > Active with no second person (a test onboarding cannot send a legal document). Actions: Edit is no longer offered once Active; audit lines 'einvoicing.onboarding.start_testing' and '.request_activation'
Edit is refused while activeAn Active onboardingOpen it; look for Edit; try PUT through the APINo Edit button; API: 'An active onboarding is not edited; suspend it first.' After Suspend the Edit button returns
Production onboarding needs another person and every gateA production provider (kind ZATCA or UAE ASP) Active, a production profile, onboarding created by user A in Production and requested for activationAs user B (approver, not A) press Approve with: no evidence; evidence but no certified profile; a certified profile that never ran conformance; no auth credential; a self-signed signing key. Fix one gate at a timeEach refusal names its gate: 'Blocked pending the authority's or provider's acceptance evidence.', 'Blocked pending a certified production profile that passed its conformance run.', 'Bind an active production authentication credential.', 'Bind an active production signing key.', 'A production signing key needs the authority's certificate, not a self-signed one.'. As user A pressing Approve: 'Somebody other than the person who prepared this onboarding must approve it.' Only when every gate passes does it become Active
Sandbox provider can never go to productionOnboarding in Production environment pointing at the SANDBOX provider is attemptedCreate onboarding with provider SANDBOX, environment Production; separately make a provider of kind Sandbox with environment ProductionOnboarding: 'The onboarding's environment is the provider's.'. Provider: 'The sandbox provider is only ever a test environment.'. A worker never sends to production through the sandbox: 'The sandbox provider is never used for production.'
Suspend, reinstate and retireAn Active test onboarding; approver user other than the requesterSuspend with reason 'Provider maintenance'; look at the banner; as approver (not the requester) Reinstate; then RetireSuspended shows the reason in a banner and sending stops ('The company has no active test onboarding with SANDBOX.' alert 'not_ready'). Reinstate refused for the requester, allowed for another approver. Retire is final (no actions left except none)
Bind a test credential (auto-active)Active test onboarding; user with secretBind credential: Purpose Authentication, secret 'test-token-0001', Valid to 2027-03-31; then Purpose Signing key with Generate on; then Purpose Callback secret with Generate onEach credential shows Active at once (test environment), reference 'vault:xxxxxx…', no secret anywhere in the screen, the signing one has a thumbprint and a certificate valid for 365 days; second credential of the same purpose marks the older one 'Rotated'
Production credential needs a second personProduction onboarding; user A (secret) and user B (activate)As A bind an auth credential on the production onboarding; look at its state; as A press Approve; as B press ApproveCredential starts 'Awaiting approval'; A is refused with 'Somebody other than the person who prepared this credential must approve it.'; B approves (needs einvoicing.activate) and it becomes Active; an old credential of the same purpose becomes Rotated
Credential health checkActive credentials of a test onboardingIn the onboarding dialog press Check on the signing credential; on an expired one; on a rotated oneActive sandbox credential: health 'ok - The sandbox answers.'. Expired: 'expired - The credential has expired.'. Not active: 'inactive - The credential is rotated.' Last health time is stamped
Report a credential compromisedActive signing credential; one submission Submitted or Status unknownPress Compromised and type 'Laptop stolen'Credential state Compromised and its vault secret destroyed (unreadable); the onboarding is Suspended with reason 'Credential <thumbprint> reported compromised: Laptop stolen'; unsent signed documents will be re-signed after a new key; uncertain sends are queried first; red alert 'A signing credential was reported compromised; sending is suspended and N documents will be reconciled.'
Rotate a signing key (T013)KSA company on the sandbox with: one invoice accepted, one pending unsent (auto submit off), one Status unknownBind a new signing key (Generate on) to the same onboarding; check the old key; open the unsent and unknown submissionsNew key Active, old key Rotated. The Status-unknown invoice is queried FIRST (questions before sends); the unsent invoice is re-signed with the new key keeping the same counter (ICV) and previous hash, so its invoice hash is unchanged; nothing is sent twice
ZATCA compliance CSID by API [Blocked if no sandbox]Blocked if no sandbox: needs a real authority / provider sandbox account and credentials. ZATCA developer-portal provider (https, allowlisted host), KSA onboarding with the 15-digit VAT, OTP from the Fatoora portalAs custodian call POST onboarding/<id>/request_compliance_csid with {otp: '123456'}; read the onboardingA new signing key and CSR are made, ZATCA answers a compliance CSID: signing and auth credentials bound, solution unit serial and request id stored, evidence line 'Compliance CSID <id> issued <time> UTC.' appended. Without OTP: 'Enter the one-time password from the Fatoora portal.'; VAT not 15 digits: 'The VAT number must be the 15 digits ZATCA registered.'; non-ZATCA provider: 'Only a ZATCA onboarding asks ZATCA for a CSID.'
ZATCA production CSID [Blocked if no sandbox]Blocked if no sandbox: needs a real authority / provider sandbox account and credentials. Compliance CSID obtained and compliance invoices passedCall request_production_csidWithout a compliance CSID: 'Request the compliance CSID first.'. With it: production certificate must belong to the same key ('ZATCA's production certificate is not for this unit's key.' otherwise); new signing and auth credentials bound; production evidence line 'Production CSID <id> issued...'

Alerts

ActionWhenWhat you doWhat happens
Credential expiry scanCredential with Valid to 20 days from today (alert window 30); another with Valid to yesterdayWait for the daily scan (or run the scheduler tick); open Alerts and Credential health20-day credential: alert 'A <purpose> credential expires on <date>; rotate it before then.'; yesterday's: state Expired and red alert 'A <purpose> credential expired on <date>; nothing is sent with it.'. Credential health report shows Days left (20) and counts it in 'expiring_30_days'
Escalation and deadline arithmeticA test company whose country is Saudi Arabia (SA) with a 15-digit VAT number starting and ending with 3 (e.g. 300000000000003), seller CRN 1010000001, building 1234, district Al Olaya, postal 12211, e-invoicing on via the sandbox; simplified (B2C) invoice with policy deadline 24 h and escalation 6 h; a standard invoice stuck Pending clearance with escalation 2 hCreate the simplified invoice with the provider unavailable; read Deadline; wait or use a back-dated test company clock; read Alerts, the Unknown and deadline queue and the dashboard tile 'Deadline at risk'Deadline = creation + 24 h. Dashboard 'at risk' counts items whose deadline is within 6 hours. The alert 'must reach the authority by <date time> UTC' is raised once when deadline - 6 h (18 h after creation) has passed, and 'is past its deadline' after 24 h; the standard invoice raises 'is still not cleared, so it has not been issued' after 2 h; a Status-unknown item raises 'has had no confirmed status for too long' after the policy hours (UAE 4 h). Each only once per submission (escalated_at); alert times are shown in UTC in the text
Acknowledge and one alert per subject per daySeveral alerts; user with operateAcknowledge one; switch tab to All; cause the same rejection kind twice on the same submission on one dayAcknowledged alerts leave 'To acknowledge' and show 'Acknowledged' in All; the dashboard list excludes them; a second alert of the same kind for the same submission on the same company day is not created

Providers

ActionWhenWhat you doWhat happens
Create, review and activate a provider with two peopleUsers A (configure) and B (activate)A: New provider code 'ASP1', kind UAE accredited service provider, Production, base URL https://api.asp.example.ae, allowed host api.asp.example.ae, Authentication Bearer; Save. A: look for Review. B: Review, then ActivateStarts Draft. A is not offered Review/Activate (author). B reviews (Reviewed) then activates (Active). B cannot activate a record B edited last. Any edit by A sends it back to Draft. A production provider needs a base URL and allowlist: sandbox kind refused ('The sandbox provider is never used for production.')
Provider address safetyNew provider formTry base URLs: http://api.x.ae; https://localhost/a; https://10.0.0.5/a; https://api.x.ae:8443; https://user:pw@api.x.ae; a host not in the allowlist; allowed host entries 'localhost', 'https://x.com', '192.168.1.5'Refused with: 'A provider address must use HTTPS.'; 'That address points at this machine or an internal network.' (x2); 'Providers are reached on the standard HTTPS port.'; 'Credentials do not belong in the address; add them as a credential.'; 'The provider's address must be on its reviewed allowlist.'; allowlist entries 'localhost cannot be a provider host.', 'https://x.com cannot be a provider host.', '192.168.1.5 is not a public address.'
Sandbox behaviour switchActive SANDBOX provider; user with configureOpen SANDBOX; press Sandbox behaviour; type 'reject'; post an invoice; repeat with 'timeout_after_accept', 'unavailable', 'async', then 'accept'; try 'foo'Next sends follow the chosen mode (rejected with SIM-ADDR-001; accepted then timeout; unavailable; submitted/pending; accepted). 'foo' -> 'Choose one of: accept, reject, timeout_after_accept, unavailable, async.' Behaviour changes do not need review or a second person

Country profiles

ActionWhenWhat you doWhat happens
New version of a used profileAE-PINT-B2B v1 Active and used by at least one submission; users A (configure) and B (activate)Try Edit on v1; press New version as A; change Priority nothing else; B: Review and Activate v2v1 has no Edit ('Submissions use this profile version; make a new version instead.' via API). v2 is a Draft copy (version 2, certified off, evidence cleared). Activating v2 archives v1; later invoices use v2, earlier submissions keep showing v1
Two profiles cannot overlapAE-PINT-B2B v1 Active (priority 10)Create a new profile code AE-PINT-X: UAE, Business, Invoice + Credit note, same dates, priority 10; review (B) and activate (B)Activation refused: 'AE-PINT-B2B v1 already covers these documents and dates at the same priority.' With priority 5 or non-overlapping dates it activates
Run conformance (local fixtures)Any profile; user with configureOpen SA-ZATCA-STD v1; press Run conformance; open the Conformance card; repeat for AE-PINT-B2BCard shows 'passed' with one line per check and per fixture (invoice and credit note): profile rules, payload builds, required elements, totals carried exactly (payable 115.00 KSA / 105.00 UAE), and for ZATCA invoice hash recomputes, signature verifies, QR carries hash and signature. Result is stored against that exact version
Production profile activation gateProduction profile (Draft->Reviewed), production provider Active; approver BB presses Activate with: certified off; certified with evidence 'ok'; evidence ok but no conformance run; conformance failedRefused each time with: 'A production profile needs the authority's or provider's acceptance evidence.' or 'Run the conformance fixtures for this version first.'; passes only with Certified + evidence of 10+ characters + a passed conformance run for this version

Retry and outage policies

ActionWhenWhat you doWhat happens
Offline issue needs an official ruleUser with configureNew policy: tick 'May issue while the provider is down' with contingency text 'later'; then with a 10+ character rule reference; review and activate with approverFirst save: 'Name the official rule that allows issuing while the provider is down.'. Second saves as Draft and needs an approver who is not the author to Review and Activate. 'Between 1 and 20 attempts.', 'Jitter between 0 and 50%.', 'The longest wait is shorter than the first.' for bad numbers

Code mappings

ActionWhenWhat you doWhat happens
A code mapping changes the XMLA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; invoice with a product whose unit is 'carton'; user with configureNew mapping: List Unit of measure, Our code carton, Their code CT; Activate (no second person); post a UAE invoice with that product; download the request payloadThe line carries unitCode='CT' instead of the default C62 (unit lookup is lower-case; unknown units fall back to C62). A draft mapping is NOT used until Activate

Partner endpoints

ActionWhenWhat you doWhat happens
Endpoint format checks and verificationA business partner; sandbox provider activeNew endpoint: scheme 0235, identifier 12345; then 100000000000011; save; press Verify endpoint; then another endpoint with scheme 9957 and identifier UNKNOWN-PARTICIPANT, Verify; GLN 4006381333931 (valid) and 4006381333932 (bad check digit) with scheme 0088'12345' -> 'A 0235 endpoint is the 15-digit UAE TIN/TRN.'. Valid: verification 'format valid'; Verify with the sandbox: 'verified - The sandbox directory lists 0235:100000000000011.'; UNKNOWN-PARTICIPANT: 'failed - The sandbox directory has no such participant.'. GLN with a wrong check digit: 'A 0088 endpoint is a 13-digit GLN with a valid check digit.' Real directory lookup is not built (ASP: 'Directory lookup goes through the provider's own portal; the format was checked.')
Endpoint address feeds a KSA buyerA test company whose country is Saudi Arabia (SA) with a 15-digit VAT number starting and ending with 3 (e.g. 300000000000003), seller CRN 1010000001, building 1234, district Al Olaya, postal 12211, e-invoicing on via the sandbox; business customer partner with a Saudi VAT 310000000000003 but no address detailPost an invoice to that customer (blocked); add an endpoint with building 4321, street, district, postal 23434, city, country SA; then use Rebuild after repair / Validate againThe submission lists the missing buyer fields by path (building_number, street, district, postal, city); after the endpoint exists a rebuilt submission carries them.

Retention policies

ActionWhenWhat you doWhat happens
Retention policy reviewSeeded Draft rows AE 5 years and SA 6 years; users A and BAs B Review and Activate the AE row; try Years 0 and 31 on a draftNeeds a reviewer who did not author/last edit the draft; 'Between 1 and 30 years.' for bad values; the Archive integrity report lists country, years, legal hold and status. No deletion job exists, the policy is a record only

Submissions

ActionWhenWhat you doWhat happens
Posting hands an invoice over (UAE business)A test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; auto-submit on; business customer partner with a TRN, an endpoint 0235 and an address; a product at 50.00 AEDCreate a customer invoice: 2 x 50.00 at 5% VAT; confirm and post; open the invoice smart button; open the submissionWithin a minute (or press Process queue now) the submission is Accepted with legal state Issued; profile AE-PINT-B2B v1; totals Net 100.00, Tax 5.00, Payable 105.00; canonical lines equal the invoice; snapshot hash and payload hash shown; UUID shown; one attempt; sandbox reference starts 'SIM-'
Customer type picks the profileA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; one business partner (market 'business') and one consumer partnerPost an invoice to each; compare the Profile columnBusiness customer -> AE-PINT-B2B; consumer -> AE-PINT-B2C. If no active profile covers country, customer type, document type and date the invoice posts anyway and no submission is created (via manual hand-over: 'No active e-invoicing profile matches this invoice's country, customer type and date.')
Auto-submit off: Pending until Submit; Process queue nowA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; 'Submit automatically' offPost two invoices; open the first: press Submit; on the dashboard press Process queue nowBoth start Pending (nothing sent, 0 attempts). Submit on the first queues it and sends it at once (Accepted). Process queue now works the outbox (up to 50 items) and the second is only sent if it was queued; a Pending one is not sent by Process queue
Blocked by validation and Validate againA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; a business customer WITHOUT an endpoint 0235Post an invoice to that customer; open the submission; read Issues; press Validate again; try Submit via APISubmission Pending and Blocked (tab Blocked, tile 'n blocked by validation'); Issue 'Buyer electronic address (endpoint) is required by UAE PINT AE - business.' with field path buyer.endpoint.id, owner master data; Validate again re-checks the SAME stored snapshot; Submit is not offered; API: 'Fix the validation issues first; nothing is sent while the submission is blocked.'
Validation messages by field path (UAE)A test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; invoices with: seller TRN 12345; buyer UAE with no TRN; a zero-rated line with no exemption reasonPost each; read the Issues tab'Seller registration '12345' is not a 15-digit UAE TRN starting with 1.'; 'Buyer TRN is required by UAE PINT AE - business.'; 'Line 1 is zero without an exemption reason.' (owner tax). One message per field; codes like EIN-FMT-AE_TRN, EIN-REQ-BUYER-REGISTRATION-ID, EIN-TAX-REASON
Accept then time out: ask first, never send twice (EIN-A1, T005)A test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; sandbox set to 'timeout_after_accept'Post an invoice; wait/Process queue; open the submission (Attempts tab); then set the sandbox back to accept and wait for the first back-off (60 s) or press Ask the providerAttempt 1 outcome 'timeout'; state Status unknown with yellow banner 'No confirmed answer.'; alert 'no answer from SANDBOX; it will be asked before anything is sent again.'; the next action is a QUERY attempt that finds the stored acceptance, so the state becomes Accepted with NO second send (attempt list: submit timeout, query accepted)
Confirmed absence resends the identical payloadA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; sandbox set to 'unavailable' for the first send onlySet sandbox to unavailable; post an invoice (send fails); set it back to accept; press Retry; compare payload hashes of both attemptsThe second send reuses the SAME payload bytes and UUID (request hash equal on both attempts); the invoice ends Accepted; only one request payload is stored
Back-off arithmetic and attempts exhaustedA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; sandbox unavailable; default policy (6 attempts, 60 s first retry, 3600 s cap, 20% jitter)Post an invoice; watch Next attempt after each failure (use the submission record and Attempts tab); stop the sandbox failure only after 6 attemptsWaits are about 60 s (48-72), 120 s (96-144), 240 s, 480 s, 960 s ... never above 3600 s (+-20%). After attempt 6 the outbox row is Dead and a red alert says '<EIN-no> (<invoice>) could not be delivered after 6 attempts.'; Retry puts it back in the queue
Rejection is recorded with its reasonsA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; sandbox set to 'reject'; seeded rejection code SIM-ADDR-001Post an invoice; open the submission: Overview, Issues, Attempts & answers, Payloads; Alerts; Event logState Rejected (red), legal state stays Issued for the UAE profile; issue row origin 'provider' code SIM-ADDR-001, field path buyer.address.building_number, owner master data, remediation text; response payload kept; acknowledgement applied; alert 'was rejected: ...'; event einvoice.rejected.v1; rejected bytes are never deleted
Rebuild after repair: KSA clearance rejection (EIN-A2)A test company whose country is Saudi Arabia (SA) with a 15-digit VAT number starting and ending with 3 (e.g. 300000000000003), seller CRN 1010000001, building 1234, district Al Olaya, postal 12211, e-invoicing on via the sandbox; sandbox once ['reject']; a KSA business customer with incomplete addressPost the invoice (sandbox rejects); add the endpoint address on Partner endpoints; open the Rejected submission; press Rebuild after repair; type 'Address fixed'The old submission shows legal state 'Not cleared' and becomes Superseded; a NEW submission in its lineage is Accepted with legal state Cleared; old issues become Resolved pointing at the new submission; both payload sets are kept; if amounts or lines changed meanwhile: 'The invoice's amounts or lines differ from what was submitted; that is a correction for Billing.'
Correct an issued rejected invoice by credit noteA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; a UAE invoice Rejected (sandbox reject)Open the submission; press Correct by credit note; reason 'Wrong address'; open the credit note from the 'Credit note' smart button; confirm and post it; check SubmissionsRebuild is NOT offered (legally issued). A DRAFT credit note is created linking the invoice (same lines, quantities, prices, taxes; note = the reason); open issues get remediation 'Corrected by credit note <no>; post it to e-invoice the correction.'; after posting, the credit note gets its own submission, type 381 with a BillingReference to the original number; the original submission stays Rejected; Correct is not offered again and not offered on a credit note
Debit note carries its originalA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; a posted UAE invoice INV-A; a second invoice with meta debit_of = INV-A and correction_reasonPost the second invoice; download its payload; remove the correction_reason on another debit invoice and postCanonical type is 'debit_note', XML type code 383 with BillingReference to INV-A (ZATCA: reason in the payment means note). A debit note without the original or reason is blocked: 'The invoice this debit note corrects is required by ...' / 'The reason for the debit note is required by ...' (reason rule applies to ZATCA profiles)
Asynchronous provider answer by signed callbackA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; sandbox 'async'; a callback secret YOU entered (Bind credential: Callback secret, secret 'cb-secret-123', not generated)Post an invoice (state Submitted, provider says 'Received; validation in progress.'); compute HMAC-SHA256 of the exact JSON body {ack_id:'A1', document_uuid:'<uuid>', status:'accepted', code:'OK'} with cb-secret-123; POST to /api/v1/einvoicing/callbacks/<company>/<provider> with header X-Ein-SignatureReply {ok:true, duplicate:false, applied:true, state:'accepted'}; submission becomes Accepted; the body is stored as a 'callback' payload; delivery receipts ({type:'delivery'}) are stored on their own track and never change the state
Duplicate, late and refused callbacksSubmission accepted by the callback aboveSend the same callback again; send a pending callback with an older authority_timestamp; send with bad signature, empty signature, invalid JSON, a list body, unknown document_uuid, no ack_id; send for an inactive providerRepeat: {duplicate:true} nothing changes (T007). Late pending: kept as evidence, applied false, note 'Accepted is final; this acknowledgement is kept as evidence and not applied.' (T018). Errors: 403 'Signature check failed.', 400 'Not JSON.', 400 'Not an acknowledgement.', 404 'No such document.', 400 'An acknowledgement needs its id.', 404 'Not found.' for unknown/inactive provider or other company, 413 'Too large.' over 1 MB
Idempotency key on commands (T006)A Pending submission; browser developer tools or an API clientPOST .../submit with header Idempotency-Key 'abcd1234' twice with the same body; again with a different body; and with no keySecond identical call answers the first result with repeated:true and sends nothing more; different body -> 409 'This idempotency key was already used for a different request.'; no key -> 'Send an idempotency key with the command.'; the screen buttons send a fresh key each click (a double click is one command)
Payload download with hash check (T004)An accepted submission; user with operate or auditPayloads tab: download each row; compute SHA-256 of the file and compare with the screen; open the XMLDownload is named '<kind>-<id8>.xml'; its SHA-256 equals the stored value and header X-Content-SHA256; an altered database row (not testable by UI) would answer 409 'The stored payload no longer matches its hash.'; a view-only user sees the table but no Download button and the API says 'Downloading e-invoice evidence needs the auditor or operator role.'
Issued rendering and PDF/A-3An Accepted/Issued submission; and a Pending-clearance KSA onePayloads tab: press 'Issued rendering with QR'; call .../pdf for the same submission; try both on the pending-clearance oneRendering is an HTML page with the seller, buyer, lines, totals, a QR picture, e-invoice number, legal state, UUID and payload hash, made once and reused (same hash next time). PDF is an A-3 PDF with the e-invoice XML inside (open the attachments panel of a PDF reader). Pending clearance: 'Only an invoice that has been legally issued has an issued rendering.'
Manual hand-over of an older invoice (API only)A test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; an invoice posted BEFORE e-invoicing was switched on; user with operatePOST /einvoicing/submissions {document_id:<id>} with an Idempotency-Key; repeat; try a draft invoice; try a vendor bill idCreates one submission (source manual) and sends it at once; a repeat with the same key returns the same result; the same invoice again returns the existing submission, not a second; draft: 'An invoice is e-invoiced once it is posted.'; bill: 'Only customer invoices, credit notes and self-billing sales are e-invoiced.'; no matching profile: 'No active e-invoicing profile matches this invoice's country, customer type and date.'
ZATCA invoice: counter, hash chain, signature and QR (local)A test company whose country is Saudi Arabia (SA) with a 15-digit VAT number starting and ending with 3 (e.g. 300000000000003), seller CRN 1010000001, building 1234, district Al Olaya, postal 12211, e-invoicing on via the sandbox; sandbox; three KSA standard invoices posted in orderOpen each submission Overview (Counter / previous hash); download request payloads; compareInvoices carry ICV 1, 2, 3; the first PIH is the fixed seed (base64 of the SHA-256 of '0': NWZlY2Vi...); each later PIH equals the previous invoice's hash; XML has InvoiceTypeCode 388 with name 0100000 (standard) or 0200000 (simplified), ICV, PIH, QR and signature blocks; the QR is Base64 TLV tags 1-9 (seller name, VAT number, date-time, total with VAT, VAT amount, hash, signature, public key, certificate signature); the counter never repeats or skips even when two invoices are processed together
KSA standard invoice: clearance legal statesA test company whose country is Saudi Arabia (SA) with a 15-digit VAT number starting and ending with 3 (e.g. 300000000000003), seller CRN 1010000001, building 1234, district Al Olaya, postal 12211, e-invoicing on via the sandbox; business customer with full Saudi address and VAT 310000000000003Post an invoice with the sandbox unavailable; then let it be accepted; open the submissionWhile unsent: legal state 'Pending clearance' (not issued), dashboard 'Pending clearance' counts it, issued rendering refused; after acceptance: legal state 'Cleared'; the printed invoice (PDF) now carries the statutory QR; sandbox rejection: legal state 'Not cleared'
KSA simplified invoice: issued at once, reported within 24 hoursA test company whose country is Saudi Arabia (SA) with a 15-digit VAT number starting and ending with 3 (e.g. 300000000000003), seller CRN 1010000001, building 1234, district Al Olaya, postal 12211, e-invoicing on via the sandbox; consumer (B2C) customer; policy deadline 24 hPost an invoice with the sandbox accepting; repeat with the sandbox unavailable; compare legal state and deadlineLegal state 'Issued' immediately and 'Reported' after acceptance; deadline = creation + 24 h; while unavailable it stays queued and escalates (see deadline arithmetic); offline-allowed policy is on by default for this profile (contingency note shown)
KSA validation messagesA test company whose country is Saudi Arabia (SA) with a 15-digit VAT number starting and ending with 3 (e.g. 300000000000003), seller CRN 1010000001, building 1234, district Al Olaya, postal 12211, e-invoicing on via the sandbox; invoices with: seller CRN 'AB123'; seller building '12'; buyer VAT 300000000000001 (does not end in 3); missing buyer postal codePost each; read the Issues tab'Seller CRN 'AB123' is not a 10-digit commercial registration number.'; 'Seller building number '12' is not a 4-digit building number.'; 'Buyer VAT number '300000000000001' is not a 15-digit Saudi VAT number that starts and ends with 3.'; 'Buyer postal code is required by KSA ZATCA standard tax invoice (clearance).'; credit notes also need 'The reason for the credit note is required by ...'
POS till receipt as a simplified invoiceA test company whose country is Saudi Arabia (SA) with a 15-digit VAT number starting and ending with 3 (e.g. 300000000000003), seller CRN 1010000001, building 1234, district Al Olaya, postal 12211, e-invoicing on via the sandbox; POS configured with fiscal adapter a2n-einvoicing; B2C profile activeSell and pay a ticket at the till; refund part of it; open SubmissionsEach sale becomes a simplified invoice (document kind pos_receipt) signed and numbered at once so the receipt prints the QR; the refund is a simplified credit note naming the sold ticket; reporting runs from the queue; the same ticket twice returns the first submission; with e-invoicing off the till gets 'E-invoicing is switched off.'; with no B2C profile 'No active B2C e-invoicing profile covers this receipt.'
ZATCA clearance against the real portal [Blocked if no sandbox]Blocked if no sandbox: needs a real authority / provider sandbox account and credentials. KSA company on the ZATCA developer portal, compliance + production-test CSID boundPost a standard invoice; Process queue now; open the submissionZATCA answers CLEARED with a stamped invoice (QR replaced by ZATCA's); legal state Cleared; warnings listed on the record; a NOT_CLEARED answer gives Rejected with the portal's codes and messages in Issues
ZATCA reporting of a simplified invoice [Blocked if no sandbox]Blocked if no sandbox: needs a real authority / provider sandbox account and credentials. As above; B2C profile on the ZATCA providerPost a consumer invoice; Process queue nowZATCA answers REPORTED; legal state Reported. After a timeout the 'Ask the provider' step finds no status query ('ZATCA does not publish a status query; reconcile by resending the identical signed invoice.') so the identical signed bytes are resent and ZATCA must treat them as the same invoice
UAE accredited service provider exchange [Blocked if no sandbox]Blocked if no sandbox: needs a real authority / provider sandbox account and credentials. A UAE ASP test tenant with its API contract, provider and bearer token entered; allowlisted hostPost a business invoice; Process queue; check Attempts; query the documentThe PINT AE XML is accepted (or rejected with the ASP's errors); delivery receipts appear under 'Delivered to the buyer'; status query by UUID works; the generic REST adapter paths may need fitting to the chosen ASP

Provider outages

ActionWhenWhat you doWhat happens
Three failures open an outage case; first answer closes itA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; sandbox unavailablePost three invoices (or let one fail three times) so three submit attempts in a row are 'unavailable'; open Provider outages and Dashboard; set sandbox to accept and let the queue runA case with origin 'detected' opens once (not again while open) and a red alert 'SANDBOX is not answering; an outage case was opened.' appears; Dashboard 'Provider outages' card lists it; waiting documents count = queued + unknown items; the first accepted submission closes a detected outage by itself (manual ones need Close)
Report an outage, approve a contingency, close itTwo users: operator A (operate) and approver B (activate)A: Report an outage on SANDBOX; A tries Approve contingency; B approves with text 'Hold clearance invoices pending; report within 24 h'; B closes it; report a second while one is openCase origin 'manual', red alert; A is refused (needs activate and another person); B's text is stored with approver and time; contingency changes NO document's legal state; Close sets Closed with an end time; second open case: 'An outage is already open for this provider.'; 'The outage is already closed.' on a second close

Invoices

ActionWhenWhat you doWhat happens
A sent invoice cannot be reversed; an unsent one is closedA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; 'Refuse to reverse' on; one invoice sent (attempts > 0), one with auto-submit offReverse/cancel the sent invoice; reverse the unsent one; switch 'Refuse to reverse' off and retry the firstSent: refused with '<no> was sent for e-invoicing as EIN-0000xx; it cannot be reversed. Issue a credit note to correct it.'. Unsent: reverses and its Pending submission becomes Superseded with 'The invoice was reversed before it was sent.'. Switch off: the reversal is allowed

E-invoice smart button

ActionWhenWhat you doWhat happens
Smart button on invoice and credit noteA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; posted invoices in states Accepted, Rejected, Blocked, Status unknown; one draft invoiceOpen each posted invoice in Sales > Invoices; click the chip; open a draft invoiceChip shows the state (green accepted, amber rejected/blocked/unknown; 'Pending clearance' for KSA standard waiting); click opens the submission; the draft shows no chip; with e-invoicing off or no permission it shows nothing

Received e-invoices

ActionWhenWhat you doWhat happens
Upload a valid supplier e-invoiceA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; a supplier partner with tax id equal to the invoice's supplier TRN; a UBL file addressed to the company TRN with one line (qty 2, price 50.00, tax 5%)Received e-invoices > Upload e-invoice; open the new rowRow INB-000001 State Valid; supplier matched; Total 105.00 AED, tax 5.00; lines listed; event einvoice.inbound_validated.v1; the file can be downloaded back with the same SHA-256
Duplicates: same bytes and same number with other contentThe valid document received aboveUpload the identical file; then edit one amount (same invoice number) and uploadIdentical: State Duplicate 'Already received as INB-000001.' no second bill possible. Changed content: State Needs review (invalid) '...has the same invoice number with different content; review both before any bill is made.'; neither is merged
Safety checks before parsing (T017)User with inboundUpload: a file with <!DOCTYPE ...>; a file with <!ENTITY ...>; a file over 5 MB; a text file; XML nested more than 40 levelsEach is stored as evidence and shown Rejected with 'The document declares a DOCTYPE or entities, which is never accepted.', 'The document is larger than 5 MB.', 'The document is not well-formed XML: ...', 'The document is nested too deeply or is too large.'; nothing is parsed or billed
Content checksUser with inboundUpload files: addressed to another TRN; lines adding to 100.00 but line total 90.00; net 100 + tax 5 but total 104.50; no invoice number; an Order (not UBL invoice)Needs review with: 'The document is not addressed to this company's tax number.'; 'The lines do not add up to the document's line total.'; 'Net plus tax is not the document's total.' (tolerance 0.01); 'The invoice number is missing.'; 'Not a UBL invoice or credit note.'
Draft the billA Valid received invoice; supplier matched; one line whose seller item id equals a product code, one that matches nothingPress Draft the bill without a fallback product; set 'Product for unmatched received lines' in Settings; press again; open the billFirst: 'Choose a product for line(s) 2, or set the fallback product in settings.' After the fallback: State Bill drafted; Billing gets a DRAFT supplier bill (never posted) dated with the e-invoice's issue date, reference = supplier's invoice number, quantities/prices/tax rates from the file; unmatched supplier -> pick one in the Supplier selector first ('Choose the supplier this document is from.')
Reject a received document; received credit notesA Valid invoice and a Valid credit notePress Reject with reason 'Not our order'; open the credit note and look for Draft the billState Rejected with 'Rejected: Not our order'; Reject refused for settled ones ('This document is already settled.'); credit note shows no Draft the bill; via API 'A received credit note is matched to its bill by hand.' (not built: no automatic credit)

Submission monitor (R040)

ActionWhenWhat you doWhat happens
Monitor totals reconcileA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; submissions created this month, one supersededOpen the monitor for this month; change From/To; compare with the Submissions list; Export CSVOne row per submission with its latest state; totals: semantic documents (superseded excluded), attempts, and one count per state label; period defaults to the 1st of the month to today; CSV has the same rows and column headings

Reject analysis

ActionWhenWhat you doWhat happens
Rejections grouped by code and fieldAt least two rejections of SIM-ADDR-001 and one validation block this monthOpen Reject analysis; read Count, Open, Oldest open (h); repair one and rebuild; reopenRows grouped by origin, code, field and profile version; open ones first; Open falls and Resolved ones stop counting as open after the rebuild; totals issues/open agree

Invoice-to-provider bridge

ActionWhenWhat you doWhat happens
One invoice, one semantic submissionA test company whose country is UAE (AE) with a 15-digit TRN starting with 1 (e.g. 100000000000003), e-invoicing on via the sandbox; invoices accepted on the first try, one with three attempts, one reversed before sending, one posted before e-invoicing was onOpen the bridge for the monthEach posted/reversed invoice and credit note appears once with Total and attempts; 'Submissions' = live ones (superseded counted apart); flag 'missing' for the posted invoice with no submission; 'duplicate identity' only if two live submissions share an invoice and profile (should be zero); totals invoice value equals the sum of Totals

Archive integrity

ActionWhenWhat you doWhat happens
Every payload hash verifiesSeveral submissions and a received documentOpen Archive integrity; read totals by kind; open a row with a submission; read the retention cardEvery row Hash verified; totals payloads, mismatched 0 and a count per kind (request, response, callback, inbound, rendering); any mismatch would turn red (cannot be produced from the UI)

Event log

ActionWhenWhat you doWhat happens
Events are written with the change and published afterAn accepted and a rejected submission; user with auditOpen Event log; compare the Occurred and Published columns; open a submission's Lineage & events tabeinvoice.accepted.v1 / rejected.v1 / status_unknown.v1 / inbound_validated.v1 with the submission and revision; Published shows a time within about a minute of Occurred; events carry hashes and ids, never a payload or secret; user without audit does not see the menu item

Feature switches

ActionWhenWhat you doWhat happens
Turn off 'Received supplier e-invoices'Company admin able to open Applications > E-invoicing > FeaturesSwitch off 'Received supplier e-invoices'; open Received e-invoices; try to upload and to draft/reject; switch on againMenu entry disappears; changes through its routes are refused (capability_disabled) while already recorded rows stay readable; 'Submission, status and repair' is always on and has no switch; Settings fields 'Provider account', 'Solution unit serial (EGS)', 'Seller commercial registration' and 'Seller additional address number' can be made Required or Hidden under field settings, and a hidden one makes an input refused