How to Connect a Custom Web App to the PRAL Digital Invoice API

If you build your own shop or ERP software in Pakistan, you can send invoices to FBR through the PRAL digital invoicing API. This guide summarises, in plain words, what the PRAL papers say, in the order a developer needs it.

ApnaBill is not an API service, and it is not run by FBR or PRAL. This page is a reading aid, not the official document. Always check the current PRAL Technical Documentation (we summarised v1.12, July 2025) before you build, because fields and rules change.

اگر آپ اپنا سافٹ ویئر بنا رہے ہیں تو یہ گائیڈ پرال کے ڈیجیٹل انوائس API کا آسان خلاصہ ہے۔ یہ سرکاری دستاویز نہیں، بنانے سے پہلے پرال کی تازہ ٹیکنیکل دستاویز ضرور دیکھیں۔ تفصیل کے لیے پرال گائیڈ کھولیں۔

Updated

What you need first

  • A registered taxpayer account in FBR IRIS, with Digital Invoicing registration started.
  • A sandbox token from the IRIS Sandbox tab, and later the production token.
  • A server or PC you control to hold the token. Never put the token in website code that visitors can read.
  • The PRAL Technical Documentation for the DI API (v1.12 when we last checked).

From access to your first posted invoice

  1. Step 1

    Get access: IRIS, integrator and sandbox

    Register for Digital Invoicing in IRIS and pick the integrator. The PRAL papers say PRAL integration and sandbox are free. If you pick another integrator, that company reviews your application and handles IP whitelisting and sandbox. The sandbox opens after approval, and you copy its address, token and sample JSON from the Sandbox tab.

    IRIS registration and who must join →

  2. Step 2

    Know the two calls and the addresses

    There are two main calls: validate (checks the invoice without saving it) and post (sends it for real). Sandbox and production have separate addresses, and the sandbox ones end in _sb. Sandbox post: gw.fbr.gov.pk/di_data/v1/di/postinvoicedata_sb. Production post: gw.fbr.gov.pk/di_data/v1/di/postinvoicedata. Validate uses validateinvoicedata_sb or validateinvoicedata.

  3. Step 3

    Send the token in the header

    Every request carries your token in the Authorization header as a Bearer token. Use the sandbox token for the sandbox and the production token for production. The papers say a token is valid for 5 years. An HTTP 401 means a bad token or a token from the wrong environment.

    POST https://gw.fbr.gov.pk/di_data/v1/di/postinvoicedata_sb
    Authorization: Bearer <your-sandbox-token>
    Content-Type: application/json

    💡 Do not call the API from the visitor's browser with the token inside. Keep it on a server or a PC you control. ApnaBill does the same: the token stays in the FBR Sender on the shop PC.

  4. Step 4

    Build the invoice JSON

    The invoice is one JSON. The header goes once: invoiceType, invoiceDate, seller and buyer details, buyerRegistrationType and invoiceRefNo. Then comes an items list. The sandbox also needs a scenarioId. Each item needs: hsCode, productDescription, rate, uoM, quantity, totalValues, valueSalesExcludingST, fixedNotifiedValueOrRetailPrice, salesTaxApplicable, salesTaxWithheldAtSource and saleType. Optional: extraTax, furtherTax, sroScheduleNo, fedPayable, discount, sroItemSerialNo.

    {
      "invoiceType": "...",
      "invoiceDate": "YYYY-MM-DD",
      "buyerRegistrationType": "Registered | Unregistered",
      "invoiceRefNo": "...",
      "scenarioId": "SNxxx (sandbox only)",
      "items": [ { "hsCode": "0000.0000", "uoM": "...", "quantity": 1, "rate": "..." } ]
    }
    // Field names only. Take exact values and the full field list from the PRAL Technical Documentation.

    💡 The buyer NTN or CNIC may be left out only when the buyer is Unregistered.

  5. Step 5

    Write the fields the way FBR expects

    Date is YYYY-MM-DD and a future date is rejected. NTN and CNIC are digits only, with no dashes. The HS code is 4 digits, a dot, then 4 digits. Province is the province name, not a city. The buyer type is exactly Registered or Unregistered. The unit (UoM) is case-sensitive, so write KG, not kg. Numbers cannot be negative or empty, with up to 2 decimals and up to 4 for quantity. The tax amount must equal the sale value times the rate. If the rate is not 18%, give the SRO or schedule number and the SRO item serial number.

    Find the HS code for a product →

  6. Step 6

    Use the FBR reference lists instead of guessing

    FBR gives lists of the exact valid values, and they need your token. They cover provinces, document types, HS codes, SRO items, sale types, units (and the units allowed for an HS code) and the rates allowed for each sale type. There are also checks for whether a registration number is active and whether it is Registered or Unregistered.

    See the list paths in the PRAL guide →

  7. Step 7

    Read the reply, including each item line

    A good reply has statusCode 00 and an invoiceNumber made by FBR. A bad reply has statusCode 01 and an error code. Also look inside invoiceStatuses, because each item line can have its own error. HTTP replies are 200, 401 and 500 (server problem).

    Look up an error code →

  8. Step 8

    Plan for failures, then print the number and QR

    There is no bulk upload: send each invoice in real time when it is made. Nothing retries by itself, so your software must keep a queue and send again after an internet or system fault. After a successful post, print the FBR invoice number and the QR code on the bill. After sending, changes are made in the IRIS portal or with a debit note, not by editing in your own software.

    QR code and print size →

Make your first invoice free

Questions about this guide

Does ApnaBill have an API I can use?

No. ApnaBill is not an API service. It is a free tool for making and printing invoices. If you build your own software, you connect to PRAL directly with your own token.

Is the PRAL sandbox free?

The PRAL papers say PRAL integration and sandbox are free of cost. Other integrators may charge, so ask them.

What is the difference between validate and post?

Validate checks the invoice without saving it. Post sends it for real and returns the FBR invoice number. Use validate while you build, and post when you are ready.

Can I upload invoices in bulk at the end of the day?

No. The papers say bulk upload is not allowed and each invoice must be sent in real time when it is made.

What if my internet is down when I post?

Nothing retries by itself. Your software has to send the invoice again once the connection is back. The IRIS rules also mention marking such invoices as offline-mode invoices and uploading them within 24 hours (rule 150XC).

Is this the official PRAL documentation?

No. It is a plain-language summary by an independent tool that is not run by or connected to FBR or PRAL. Use the official PRAL documents for the real field list and rules.

Read the disclaimer →

Related guides and tools

All guides →

ApnaBill is an independent tool. It is not run by FBR or PRAL and it is not tax advice. Rules and menu names can change, so confirm with FBR or your tax consultant. See the disclaimer.