Blog/July 21, 2026·4 min
How to onboard onto the Fatoora platform, step by step: a business owner's guide
From logging in with your ERAD credentials to receiving the production certificate — the full Fatoora onboarding journey in business-owner language, not developer language: OTP generation, solution unit onboarding, compliance checks and the two cryptographic stamp certificates.
The Fatoora platform is the official portal of the Zakat, Tax and Customs Authority (ZATCA) that connects businesses' invoicing systems to the authority — it is where the "onboarding and integration" required by Phase 2 of e-invoicing actually happens. The good news for business owners: the heavy technical lifting sits with your invoicing software vendor; your own part is a short, well-defined sequence of steps on the Fatoora portal. This guide walks through them in order, without programming jargon.
What do you need before you start?
You need exactly three things: an active VAT registration, your ERAD login credentials for ZATCA's services — your tax identification number (TIN) or registered email, plus your password — and a Phase 2-compliant invoicing system from a vendor that supports integration. If you are unsure about your system, ask your vendor one question: "Do you support Phase 2 integration with the Fatoora platform?"
For clarity: what ZATCA calls a "solution unit" or "device" simply means the invoicing system you use — whether cloud software, a POS system, or a device in your shop.
How do you log in to the Fatoora portal?
Go to the official address fatoora.zatca.gov.sa and sign in with the same ERAD credentials you use for ZATCA's tax services — there is no new account and no separate registration. Once in, you will see a dashboard listing your organisation's onboarded solution units (empty the first time) and the option to "onboard a new solution unit/device".
How do you generate the OTP, and how long is it valid?
From the portal, choose to onboard a new unit, then specify how many one-time passwords (OTPs) you need — one per solution unit you want to connect. Up to 100 OTPs can be generated in a single batch for businesses with many branches and devices. The portal displays the codes as soon as they are generated.
The critical point: each OTP is valid for one hour only. So do not generate a code until you are ready to enter it immediately into your invoicing system — usually in a setup screen or dedicated field your vendor provides, or by handing it to your vendor's support team if they run the onboarding for you.
What happens after you enter the OTP? (The two cryptographic stamp certificates)
Once the OTP is entered, your system talks to the platform automatically through three stages, all behind the scenes:
- Certificate request: your system sends a cryptographic request to the platform and receives a temporary compliance certificate (Compliance CSID).
- Compliance checks: the platform tests that your system can produce valid invoices — XML structure, QR code, hash and signature — for the invoice types it will issue.
- Production certificate: when the checks pass, your system receives its production certificate (Production CSID) — the "official stamp" it uses to sign your real invoices from that moment on.
From the Fatoora dashboard you can later review your onboarded units, renew an existing unit's certificate, or revoke a unit you no longer use — a step worth not neglecting when you switch vendors.
Can you try it out before going live?
Yes. ZATCA provides a simulation environment of the Fatoora portal that lets you run the entire onboarding journey — generating OTPs, obtaining certificates, submitting test invoices — with no legal effect. Ask your vendor to complete onboarding in simulation first; it is the best way to surface compliance issues before the real go-live. Ready-made cloud solutions — Efatora among them — typically reduce your journey to two steps: generate the OTP on the Fatoora portal, and paste it into the setup screen.
What are the common onboarding mistakes?
- Generating the OTP too early, letting the hour lapse and having to generate a new one — harmless, but a waste of time;
- Mixing up simulation and production: simulation certificates are not valid for real invoices;
- Forgetting branches: every independent solution unit (branch, POS device) needs its own OTP and certificate;
- Neglecting certificate renewals, or leaving retired units un-revoked on the dashboard.
The bottom line
From the business owner's seat, onboarding is four steps: log in to fatoora.zatca.gov.sa with ERAD, generate an OTP, enter it into your system within the hour, then let the compliance checks run and the production certificate arrive. Everything else is technical work your invoicing system does on your behalf.
