Free tool · no sign-up
ZATCA rejected the invoice. What does it say, and whose job is the fix?
Paste the validationResults response from the Fatoora platform, or the error text your software showed. You get the layer that failed, what it means, what to fix, and whether it is yours, your vendor’s or the certificate’s.
Runs in your browser. Nothing you paste is sent anywhere; our analytics records only which layer failed, never the text.
Rules read from ZATCA’s XML Implementation Standard v1.2 · Detailed Guidelines (responses table) · Technical Guideline (CSR and CSID) · Fatoora Portal manual (OTP validity) · read on 2026-09-17 · Decode the QR instead
Questions
Questions this tool gets asked
- Why does ZATCA reject an e-invoice?
- Four layers, in the order Fatoora checks them. Schema: the XML is not a valid UBL 2.1 document. Business rules: a value is missing, wrong or does not add up (the BR- and BR-KSA- codes). Signature and hash chain: the cryptographic stamp, the previous-invoice hash or the QR is wrong. Channel and certificate: the request itself was refused — an expired CSID, the wrong OTP, clearance switched off. This tool names the layer, so you know who to call.
- Is this ZATCA’s own list?
- No. The codes are ZATCA’s; the explanations are ours, dated, and each links to the validation rule it comes from in the XML Implementation Standard, the Detailed Guidelines or the Technical Guideline. When ZATCA revises a rule, the row shows the date we last read it.
- Why does the same invoice pass one day and fail the next?
- Usually the hash chain or the certificate. A CSID expired or was revoked, so every request now returns 401; or an earlier invoice was resubmitted, so the previous-invoice hash no longer matches and BR-KSA-26 fires on everything after it. Both show up here as their own layer.
- What is “clearance versus reporting”?
- Standard tax invoices (B2B) are cleared: sent to ZATCA first, stamped by ZATCA, then issued to the buyer; a rejection means the invoice must not be issued. Simplified invoices (B2C) are issued to the customer first and reported within 24 hours; a NOT_REPORTED verdict means the document is invalid and is corrected with a credit note and a new invoice. HTTP 303 means clearance is switched off and the invoice goes through reporting instead.
- What is the penalty for not complying with e-invoicing?
- ZATCA publishes the classification of VAT and e-invoicing violations, with the amounts, in its simplified guide to the classification of violations (linked below the questions). The tiers depend on the violation and on repetition, so we do not repeat figures here; read the guide, and ask a tax adviser about your case.
- My code is not here.
- Send it with the message text and we add it with its source within a week. Unknown codes still get a best guess of the layer from their prefix, and the result says it is a guess.
- Can you fix it for me?
- That is the assessment. Bring the rejection; we look at your invoicing setup, the integration and the certificate lifecycle, and you leave with a plan that says what changes and who does it.
A developer aid, not tax advice. Rule texts are read from ZATCA’s published documents on the date shown beside each row; ZATCA can revise them. Fines are set by ZATCA’s violations classification; read it at the source.
Sources: ZATCA’s simplified guide to the classification of VAT violations (PDF, Arabic) · ZATCA e-invoicing guidelines library
Next