انتقل إلى المحتوى

لم تُترجم هذه الصفحة بعد

تعرض هذه الصفحة النص الإنجليزي حتى تصدر ترجمتها.

Devices, certificates and branches

ZATCA does not register a company to issue e-invoices. It registers a device, and it is the device that signs.

That one fact explains most of the setup: why you cannot invoice before connecting to ZATCA, why a certificate expiring stops invoicing, and why a second shop needs its own registration rather than a setting.

How they fit together

flowchart TD
    O["Organisation<br/><small>your VAT registration and Company Profile address</small>"] --> D0["Business-level connection<br/><small>uses the Company Profile address</small>"]
    O --> B1["Branch<br/><small>a location with its own address</small>"]
    B1 --> D1["Branch connection<br/><small>uses the branch address</small>"]
    B1 --> D2["Branch connection"]
    D0 --> C0["Certificate<br/><small>issued by ZATCA, expires</small>"]
    D1 --> C1["Certificate"]
    D2 --> C2["Certificate"]
  • An organisation is your business and its VAT registration. Its address is on the Company Profile.
  • A branch is an optional location with its own address and business ID. Branches are a Pro and Business feature.
  • A device, called a ZATCA connection in Clix, is a registration with ZATCA. It is either linked to one branch or is a business-level connection with no branch. It issues Businesses (B2B), Consumers (B2C) or Both invoice types.
  • A certificate is what ZATCA issues to that connection. The connection signs with it.

The address on an invoice comes from the connection: the branch address for a branch connection, the Company Profile address for a business-level one.

Why registration is per device

ZATCA's Phase 2 model assumes invoices are produced by identifiable points of sale or billing systems, each with its own cryptographic identity. The signature on an invoice is supposed to answer "which system produced this", not merely "which company".

Practical consequences:

  • You cannot issue an invoice before a device exists. There is nothing to sign with.
  • A connection is set to an invoice type: Businesses (standard, B2B), Consumers (simplified, B2C) or Both. Choose Both when one till issues both kinds.
  • Certificates expire. Renewal is routine maintenance, not an exception.

What CSID means

During registration Clix generates a certificate signing request, sends it to ZATCA with your six-digit code from the Fatoora portal, and receives a CSID: the cryptographic identity for that connection. Clix stores it and signs every invoice from that connection with it.

You never handle the key material. The Fatoora code you paste is the only part that passes through your hands, and it expires one hour after you generate it.

When you need a branch

Most small businesses invoice from one place and need no branch at all: a business-level connection uses the Company Profile address. Add a branch when a location issues its own invoices with its own address: a second shop, a regional office, a warehouse.

Adding a branch for an internal team or a cost centre is a misuse: the branch address goes on the invoice.

What breaks, and what does not

Event Effect
Certificate expires That connection cannot sign. Existing invoices stay cleared or reported.
Branch edited or archived Not possible while a connection is linked to it.
Company Profile address corrected Applies to invoices issued afterwards only.
Organisation VAT number corrected Possible only until ZATCA has seen it. Earlier invoices keep what they carried.

The pattern is consistent: issued documents never change retroactively. A cleared invoice is a tax record, and corrections are made with credit and debit notes, never by editing history.