The ZATCA QR code on an invoice: what is inside it and how to check it

The QR on a Saudi tax invoice is not a link. It is five invoice facts packed into one code, so anyone can confirm who issued the invoice and how much VAT it charges without opening a system.

By Naeem AhmedReviewed 6 October 20266 min read

What the ZATCA QR code is

The ZATCA QR code is a QR printed on a Saudi tax invoice that carries five facts about it — the seller's name, the seller's VAT registration number, when it was issued, the total including VAT, and the VAT amount — so the invoice can be checked by scanning it. ZATCA (the Zakat, Tax and Customs Authority) introduced it with e-invoicing, known as FATOORA.

A phone camera that scans one usually shows a long string of letters rather than a web page. That is expected: the five values are packed into a compact binary format and then written as text. The sections below show exactly how, so you can check one yourself.

The five fields

The fields in a Phase 1 ZATCA QR code, in order
TagFieldExample valueFormat
1Seller nameAl Noor TradingText, as registered
2Seller VAT registration number30000000000000315 digits
3Time stamp of the invoice2026-10-07T00:00:00.000ZISO 8601 date and time
4Invoice total including VAT1150.00Number, two decimals
5VAT total150.00Number, two decimals

How the code is built

  1. Each field becomes a TLV record

    TLV means tag, length, value: one byte for the tag (1 to 5), one byte for the length of the value in bytes, then the value itself as UTF-8 text. "Al Noor Trading" is 15 bytes, so its record starts 01 0F.

  2. The five records are joined

    They are written one after another in tag order, making a single run of bytes.

  3. The bytes are base64-encoded

    Base64 turns the bytes into plain letters, digits, + and /, which is what the QR stores.

  4. The text is drawn as a QR code

    Any standard QR library can render it. Scanning gives the base64 text back; decoding the base64 and reading the TLV records gives the five values.

The example above, encoded
First bytes (hex)
01 0F 41 6C 20 4E 6F 6F 72 …
Base64 stored in the QR
AQ9BbCBOb29yIFRyYWRpbmcCDzMwMDAwMDAwMDAwMDAwMwMYMjAyNi0xMC0wN1QwMDowMDowMC4wMDBaBAcxMTUwLjAwBQYxNTAuMDA=

01 is tag 1 (seller name), 0F is its length (15), and 41 6C 20… is "Al ". The same pattern repeats for tags 2 to 5.

Phase 1 and Phase 2: what changes

ZATCA brought e-invoicing in two phases. Phase 1, which began on 4 December 2021, required invoices to be generated electronically and introduced the five-field QR described above. Phase 2, rolled out to groups of taxpayers in waves from 1 January 2023, requires invoices to be produced by compliant software that is integrated with ZATCA's FATOORA platform, and adds cryptographic data — a hash of the invoice and a cryptographic stamp — to what the QR carries.

Checking a QR code before you send the invoice

Scan it and confirm

  • It decodes to exactly five values, in tag order 1 to 5.
  • The seller name and VAT number match your VAT registration certificate character for character.
  • The total and VAT amounts match the printed totals to the halala — 1150.00, not 1150.
  • The VAT amount is consistent with the rate you charged: at 15%, a net 1,000 gives 150 VAT and a 1,150 total.
  • The code is printed large and sharp enough to scan from the paper or the PDF you actually send.

If the VAT figure looks wrong, check the arithmetic first with the VAT calculator, and see how to calculate VAT for the rounding rule that keeps net, VAT and total reconciling.

The QR code in BuzPulse

The Invoice Generator adds this five-field QR automatically once the seller name and a VAT number are filled in, using the invoice's own totals. With no VAT number there is no QR, because the code would claim a registration that does not exist. The same builder runs on the free page and in the workspace, so the code is identical in both.

  • The time stamp is the invoice's issue date, encoded at 00:00 UTC; the builder records a date, not a time of day.
  • Seller names longer than the 255-byte limit are shortened to fit rather than producing a broken code.
  • It is a Phase 1 style QR. BuzPulse is not integrated with ZATCA's FATOORA platform and does not add the Phase 2 cryptographic stamp, so it is not a substitute for a Phase 2 compliant solution once your wave has started.

For everything else a Saudi tax invoice needs — the supply date, the buyer's VAT number when the buyer is registered, the commercial registration — see what to put on an invoice.

Frequently asked questions

Why does scanning the QR show random letters instead of a link?
The QR holds the five invoice values packed into binary TLV records and written as base64 text. Decoding the base64 and reading the records gives the seller name, VAT number, time stamp, total and VAT.
Why is there no QR code on my BuzPulse invoice?
The code is added only when both the seller name and the seller VAT number are filled in. Without a VAT number it would encode a registration that does not exist.
Is the BuzPulse QR code Phase 2 compliant?
No. It carries the five Phase 1 fields. Phase 2 requires invoices from a compliant solution integrated with ZATCA's FATOORA platform, with a cryptographic stamp that BuzPulse does not produce.
What is the maximum length of the seller name?
Each value can be up to 255 bytes. English letters take one byte each and Arabic letters usually two, so an Arabic name reaches the limit at about 127 letters.
Do amounts in the QR need two decimal places?
Write them with two decimals, as the invoice does — 1150.00 and 150.00 — so the values in the code match the printed totals exactly.

The tools behind this

Was this guide helpful?

About the author

Naeem Ahmed builds and runs BuzPulse. These guides describe tools he has built, and they describe how those tools actually behave — including where they stop.

Corrections and questions: nsglobal6@gmail.com

Read next

All business guides