Blog · Updated for 2026

How to Get FBR Digital Invoicing Credentials (Token, Sandbox → Production)

Service hub: our main 2026 guide for the same topic is FBR digital invoicing in Pakistan (full pillar page)—this article is a focused read; the pillar is the one URL we want to rank for head terms.

What an FBR access token is, how businesses usually obtain sandbox then production credentials, how to avoid mixing environments, and how to paste the token into Wise Digital Invoice for validate and submit.

Before you can validate or post a single digital invoice to the Federal Board of Revenue, you need FBR digital invoicing credentials—typically a bearer access token for the sandbox environment first, then a separate production token when you go live. This guide explains what those credentials are, how teams usually obtain them, how sandbox differs from production, and how to store and use the token safely inside invoicing software. Pair it with how to integrate the FBR API step by step and our FBR API integration page once the token is in hand.

What “credentials” means for FBR digital invoicing

In the Digital Invoicing (DI) API model, your software calls FBR gateways (commonly under the FBR / PRAL gateway host) with an authorization token. That token identifies your registered business for:

  • Invoice operations — validate and submit (post) sales invoices and related documents such as debit notes
  • Reference lookups — HS/UoM lists, registration-type checks, tax rates, and SRO schedules (depending on the endpoint set enabled for your token)

A PDF logo and an Excel total are not credentials. Without a valid token bound to the correct environment (sandbox vs production), the API will reject authentication before it ever inspects your buyer NTN or HS code.

Sandbox vs production (do not mix them)

FBR runs parallel environments. Treat them as two different systems that happen to share a similar payload shape:

Topic Sandbox Production
Purpose Learn payloads, fix master data, train staff safely Live statutory posting for real sales
Token Sandbox access token only Production access token only
Invoice effect Test responses; not your live return trail Real FBR invoice references / QR-linked posts
When to use Until validate/submit is clean on your real customers and products After go-live approval and environment switch in software

Pasting a production token into a sandbox-configured app (or the reverse) is one of the most common “authentication failed” causes. Always match token + environment URL + software mode as a set.

How to get FBR digital invoicing credentials (typical path)

Exact screens and form names change as FBR updates IRIS / DI portals. The operational sequence most Pakistani businesses follow is:

  1. Confirm you need DI — Check whether your sector or tier is notified (see who must use FBR digital invoicing in Pakistan). Credentials without a compliance deadline still help if buyers already demand DI-ready invoices.
  2. Use your registered NTN / business profile — Digital invoicing registration is tied to the taxpayer identity already known to FBR. Keep company name, address, and contact data consistent with IRIS.
  3. Apply or register for Digital Invoicing / API access via FBR’s official channels — Follow the current process on fbr.gov.pk and the IRIS / DI documentation FBR publishes for your program. Your tax consultant or licensed integrator often submits or tracks this on your behalf.
  4. Receive sandbox credentials first — FBR (or the integration path they specify) issues a sandbox access token. Store it in a password manager or your invoicing app’s encrypted credentials screen—not in a shared WhatsApp chat or an unprotected spreadsheet.
  5. Prove the pipeline — Create one real-shaped customer and product, validate an invoice, then submit in sandbox. Fix buyer, HS, UoM, and tax errors until the pass rate is stable.
  6. Request or activate production credentials — After sandbox success (and any FBR approval step your circular requires), obtain the production token, switch the software environment, and post a controlled first live invoice during business hours with an owner on standby.

Wise Digital Invoice stores FBR connection settings per company under FBR Credentials: you paste the access token for the active environment and run validate/submit from the invoice screen (or in bulk from the invoices list). You do not need a static IP for cloud SaaS posting.

What to prepare before you request a token

  • NTN / CNIC and registered business name matching FBR records
  • Province and address consistent with how you will appear on invoices
  • Primary technical contact who can rotate the token if it expires or leaks
  • Sample catalog — a few products with correct HS codes and units of measure
  • Sample buyers — registered and, if you sell to them, unregistered patterns with the right registration type

Teams that skip master-data prep often “get the token” on Monday and spend the rest of the week failing validation. Importing the official FBR Sales_Invoice_Template (.xlsm) can accelerate the first clean batch once credentials work.

Using your token in Wise Digital Invoice

After signup (trial or paid):

  1. Open FBR Credentials in the app menu.
  2. Select the correct environment (sandbox for trials and pre-go-live; production only when live).
  3. Paste your FBR access token and save.
  4. Create or import a customer and product, draft an invoice, then run Validate.
  5. On success, Submit and confirm the FBR response fields appear on the invoice record.

On the 7-day free trial, production posting stays disabled by design: you exercise sandbox validate/submit with your token. Reference-data lookups may fall back to a platform token when yours is blank, but invoice validate/submit always use the credentials you entered—so the sandbox identity FBR sees is yours.

Security and rotation habits that prevent outages

  • Never share tokens in email threads or chat groups without encryption and an expiry plan.
  • One owner, one backup — finance and IT should both know how to rotate credentials if the holder leaves.
  • Rotate after any suspected leak — treat a leaked bearer token like a leaked password.
  • Separate sandbox and production secrets — different vault entries; different software modes.
  • Log failures — authentication errors usually mean wrong environment, expired token, or clock/network issues—not a bad HS code. See the patterns table on FBR API integration.

Sandbox → production cutover checklist

  1. Sandbox pass rate is stable on your real catalog (not only demo SKUs).
  2. Staff know how to read and fix common validation messages.
  3. Production token is stored in the app; sandbox token retained for future regression tests.
  4. Software environment switched to production; first live invoice posted with a named owner watching the response.
  5. Print / share path checked so buyers still receive a readable PDF (optionally via email & WhatsApp share) while FBR holds the structured post.

Ready to paste a sandbox token and prove one invoice end to end? Start the 7-day trial or request a free demo on Wise Digital Invoice.

Credential issuance, portal names, and gateway URLs are controlled by FBR and can change. Always follow the latest official Digital Invoicing / API documentation and confirm registration steps with a qualified tax adviser or FBR helpdesk. This article describes the practical sandbox → production pattern used with Wise Digital Invoice; it is not a substitute for FBR’s own registration instructions.

Get a free demo

See Wise Digital Invoice on your use case: customers, products, and FBR validation in one walkthrough.

Request free demo