Free decoder · nothing leaves your browser
ZATCA QR code decoder
A ZATCA e-invoice QR code is a base64 string of TLV records: seller name, VAT number, timestamp, total and VAT in Phase 1, plus the XML hash, ECDSA signature and public key in Phase 2. Paste the scanned text or upload a photo to see every tag — no upload, no sign-up, no data stored. You can also build a Phase 1 QR from five fields and receive the scannable code on WhatsApp.
Scan the QR with any phone scanner app and copy the text it shows. It normally starts with AQ.
Decoded tags
Paste a QR string or upload an image to decode it.
Reference
The nine ZATCA QR tags
Each record is one byte of tag, one byte of length, then the value. The length byte is why a seller name cannot exceed 255 bytes.
| Tag | Field | Introduced | Format |
|---|---|---|---|
| 1 | Seller name | Phase 1 | Registered business name, UTF-8 (Arabic is fine) |
| 2 | VAT registration number | Phase 1 | 15 digits, starts and ends with 3 |
| 3 | Timestamp | Phase 1 | Invoice date and time in ISO-8601, e.g. 2026-09-10T14:30:00Z |
| 4 | Invoice total (with VAT) | Phase 1 | Decimal, two places, no currency symbol |
| 5 | VAT total | Phase 1 | Decimal, two places |
| 6 | XML invoice hash | Phase 2 | SHA-256 of the signed invoice XML, base64 |
| 7 | ECDSA signature | Phase 2 | Signature over the hash with the system's private key (secp256k1) |
| 8 | ECDSA public key | Phase 2 | Public key of the invoicing system, from its CSID certificate |
| 9 | ZATCA stamp of the public key | Phase 2 | Simplified invoices only — ZATCA's signature over the public key |
Phase 1 QR (tags 1–5)
Required on simplified tax invoices since 4 December 2021. Any scanner can read it, and the five values must match what is printed on the invoice. Read the full requirements on the Phase 1 page.
Phase 2 QR (tags 1–9)
Adds the invoice hash, the cryptographic stamp and the public key so the QR is tied to one signed XML document. Only a system onboarded with Fatoora can produce tags 6–9. See the Phase 2 page and wave table.
FAQ
ZATCA QR code questions
What is inside a ZATCA e-invoice QR code?
A base64 string that wraps a list of TLV (tag-length-value) records. Phase 1 QR codes carry five tags: seller name (1), VAT registration number (2), invoice timestamp (3), invoice total with VAT (4) and VAT total (5). Phase 2 adds the SHA-256 hash of the invoice XML (6), the ECDSA signature (7), the ECDSA public key of the invoicing system (8) and, on simplified invoices, ZATCA's signature of that public key (9).
How do I read a ZATCA QR code from an invoice?
Scan it with any phone QR scanner. You will see a block of text that usually starts with 'AQ' — that is the base64 TLV payload, not a web link. Paste it into the decoder above and it will show each tag. You can also upload a photo of the QR and the tool reads it in your browser.
Is the QR code mandatory on every Saudi invoice?
The QR code has been mandatory on simplified tax invoices (B2C) since Phase 1 began on 4 December 2021. In Phase 2 it is required on both invoice types: the invoicing system generates it for simplified invoices, while for standard (B2B) invoices the QR is produced after ZATCA clears the invoice and must appear on the human-readable copy.
Why does my QR only show tags 1 to 5?
Because it was produced by a Phase 1 system. That was compliant before your integration wave, but once your wave's deadline has passed a simplified invoice QR must also carry tags 6, 7, 8 and 9 — which can only be produced by a system that has onboarded with the Fatoora portal and holds a cryptographic stamp identifier (CSID).
Can this tool verify that ZATCA actually cleared or reported an invoice?
No. It decodes the structure and checks the format of each field, which is what you need to debug a layout or a developer build. Whether the signature is genuine and whether the invoice was cleared or reported can only be confirmed against ZATCA's systems — and ZATCA's own app can verify a QR against the platform.
What format must the VAT number and timestamp be in?
A Saudi VAT registration number is 15 digits and starts and ends with 3. The timestamp is written in ISO-8601, for example 2026-09-10T14:30:00Z, and should match the invoice issue date and time. Totals are plain decimals with two places and no currency symbol.
Does the tool send my invoice data anywhere?
The decoder does not. Decoding, checking and image reading all run in your browser with JavaScript on this page; nothing is uploaded, stored or logged. The only time data leaves the page is if you ask for a scannable Phase 1 QR: the five fields you typed are placed in a WhatsApp message that you send to us yourself, and nowhere else.
This tool is a drafting and debugging aid, not tax advice and not a substitute for ZATCA's own validation. Confirm the current technical specification on zatca.gov.sa before relying on any output.
Need invoicing software for Saudi Arabia?
AmalERP issues ZATCA-compliant bilingual invoices with the Phase 1 QR code, and integrates with the Fatoora platform for Phase 2 clearance and reporting. 7-day free trial, no credit card required.
No credit card required · 200+ businesses across the Gulf and beyond.