Certificate and device problems¶
What each device status means¶
| Status | Meaning | What to do |
|---|---|---|
| Active | Connected to ZATCA and ready to issue compliant invoices | Nothing |
| Pending Activation | Waiting for ZATCA approval to start issuing invoices | Wait — "Usually takes 1–2 hours — check back shortly." |
| Setup in Progress | Completing security setup with ZATCA | Wait — "Automatic process, usually completes within minutes." |
| Action Required | The connection setup hit a problem | "Click 'More Details' to see what went wrong." |
| Unknown Status | The page lost track of the registration | Reload the page first. Right after Connect, the page can stop watching the certificate chain too early and show "Connection failed" with this status although the connection completed; after a reload it reads Active (seen on the sandbox 2026-09-27). If it is still Unknown after a reload, contact support |
Pending Activation and Setup in Progress are normal parts of registration. Do not delete the device and start again because it has not gone Active in a minute — you will need a fresh OTP and be no further forward.
stateDiagram-v2
[*] --> SetupInProgress: Connect with a Fatoora code
SetupInProgress --> PendingActivation: security setup done
PendingActivation --> Active: ZATCA approves
SetupInProgress --> ActionRequired: setup hit a problem
SetupInProgress --> UnknownStatus: page stopped watching
UnknownStatus --> Active: reload the page
ActionRequired --> SetupInProgress: fresh code, connect again
OTP problems¶
The Fatoora code is six digits and expires one hour after you generate it.
| Problem | Cause | Fix |
|---|---|---|
| Rejected immediately | Fewer or more than six digits | "The code must be exactly 6 digits" — re-copy it |
| Rejected after a delay | Expired | Generate a fresh code in Fatoora and use it straight away |
| Rejected but looks right | Already used, or from a different taxpayer account | Generate a new one from the correct account |
An OTP is single-use. If a registration attempt fails for any reason, generate a new code rather than reusing the one you have.
Get the OTP immediately before you need it
The common failure is generating a batch of codes in Fatoora, then registering devices over the following hours. Open Fatoora, generate, paste, submit.
Certificate expiry¶
Certificates expire. Clix emails reminders before they do, and the device screen shows the state.
What an expired certificate breaks: that device can no longer sign, so no new invoices from it. Invoices already issued stay cleared and are unaffected.
Renew from the device's entry under ZATCA Connections. If reminder emails keep arriving after you have renewed, check you renewed the device the email names — an organisation with several devices gets a reminder per device.
"I cannot issue an invoice"¶
Work down this list:
- Is there a device at all? No device means nothing can be signed. The dashboard checklist keeps "Connect to ZATCA" as step 1.
- Is it Active? Pending or Setup in Progress means wait.
- Is its certificate current? An expired certificate stops invoicing.
- Is it registered for the right invoice type? A device set to simplified only cannot issue a standard invoice. You may need a second device.
- Is it on the right branch? The branch decides the address on the invoice.
When to contact support¶
- A device has been in Setup in Progress for more than a few hours.
- Action Required, and More Details does not tell you what to change.
- Registration fails repeatedly with fresh OTPs from the correct account.
Include the connection name and what the More Details panel says. Write to support@goclix.ai.