What is the QR code on a tax invoice?
Published
The QR code on a Saudi invoice is not a link and not decoration. It is a structured data container defined by the authority's specification: fixed fields encoded as TLV and then Base64, letting any reader verify the invoice data - and letting the authority verify its cryptographic integrity.
The fields
| Tag | Field | Since |
|---|---|---|
| 1 | Seller name | Phase 1 |
| 2 | Seller's VAT number (15 digits) | Phase 1 |
| 3 | Invoice timestamp (date and time) | Phase 1 |
| 4 | Invoice total including VAT | Phase 1 |
| 5 | Total VAT amount | Phase 1 |
| 6 | Hash of the XML invoice | Phase 2 |
| 7 | ECDSA cryptographic signature | Phase 2 |
| 8 | ECDSA public key | Phase 2 |
| 9 | The authority's signature over the public key (simplified invoices) | Phase 2 |
The original source of this table is the authority's QR code creation guide, which is the reference at implementation.
Worked on Al-Waha's invoice
The SAR 34,500 invoice carries a code whose core fields are:
Tag 1: Al-Waha Office SuppliesTag 2: 3XXXXXXXXXXXXX3 (the 15-digit VAT number)Tag 3: 2026-06-20T14:32:07 (ISO 8601 format)Tag 4: 34500.00Tag 5: 4500.00
Each field encodes as a triple: tag (field number) + length (value size in bytes) + value (UTF-8 text, which carries Arabic correctly). The triples concatenate into one byte array, which is Base64-encoded, which is rendered as the QR image.
Why this design
- UTF-8 means the Arabic seller name reads correctly in any scanner.
- TLV means a reader knows each field's boundaries without breakable delimiters.
- The Phase 2 cryptographic fields mean changing a single character in the invoice breaks the hash and signature - the code proves the invoice is untouched since clearance or stamping.
Common mistakes
| Mistake | Effect |
|---|---|
| A QR that carries the company website instead of TLV data | Entirely non-compliant, however much it looks like a QR code |
| Tag 4 populated with the pre-tax amount | A contradiction with the invoice, visible on any verification scan |
| A free-format timestamp | A specification breach; the format is defined |
| Hand-generating the code with a generic tool under Phase 2 | Tags 6-9 require signatures and certificates no generic tool produces |
Frequently asked questions
On which invoices is the code mandatory?
Mandatory on simplified tax invoices since Phase 1. Its application to standard invoices follows the requirements applicable in your phase, per the authority's specification.
What does a customer see when scanning?
The field data: seller name, VAT number, timestamp, and amounts - a fast check that the invoice really came from who it claims.
Does the code replace the printed fields?
No. It is an additional verification layer; the mandatory fields remain visible on the invoice itself.