FBR Digital Invoicing · Guide

How to Get Your FBR Digital Invoicing Token (Sandbox & Production) in 2026

Every FBR digital invoice needs a security token. Here is how a Pakistani business gets its sandbox token, passes the test scenarios, and unlocks the production token — and how a ready platform removes the developer work entirely.


What the token is

FBR's Digital Invoicing API is reached with a security token — a Bearer token that must be included in the header of every request. There are two: a sandbox token for testing and a production token for live invoices. Each token is reported to be valid for five years, and the same token decides which environment your invoices go to, so sandbox and production tokens must be kept strictly separate.

You do not create the token in code; you request it from FBR/PRAL through the IRIS portal, then either wire it into your own integration or hand it to a ready platform that uses it for you.

Step 1 — Request the sandbox token

Log in to iris.fbr.gov.pk with your NTN/CNIC and password, open Digital Invoicing, choose API Integration and select 'Proceed with PRAL as Licensed Integrator' (PRAL provides licensed-integrator services, including sandbox testing, free of cost). Complete the technical details form and submit any IP addresses to be whitelisted.

PRAL reviews the request, provisions your sandbox token and whitelists your IP — reported to complete within about two working hours, with an email when it is ready. The token then appears in IRIS under the sandbox environment section.

Step 2 — Pass the sandbox test scenarios

With the sandbox token you post the FBR test scenarios (SN001–SN028) that match your business activity and sector. The scenarioId is required in every sandbox payload — and must be removed for production. FBR tracks which scenarios you have cleared.

This step is where most integration errors surface, so it is worth getting each required scenario to a clean 'Valid' response before moving on.

Step 3 — Unlock the production token and go live

Once every required sandbox scenario passes, FBR generates your production environment token. You switch to the production tab in IRIS, use the new token, drop the scenarioId from the payload, and start posting live invoices that return a real Invoice Reference Number (IRN) and QR code.

With Digi Invoice you skip the developer work at every step: you connect your FBR profile through a guided setup and the platform manages tokens, payloads, scenario testing and the sandbox-to-production switch for you.

Frequently asked questions

How do I get an FBR digital invoicing token?

Log in to iris.fbr.gov.pk, open Digital Invoicing, choose API Integration with PRAL as licensed integrator, submit the technical details and IP for whitelisting, and PRAL provisions your sandbox token (reported within about two working hours). After you pass the sandbox test scenarios, FBR issues your production token.

How long is the FBR token valid?

The FBR Digital Invoicing security token is reported to be valid for five years, after which it must be renewed. The same token also decides routing — a sandbox token posts to sandbox and a production token to production — so the two must be kept strictly separate.

Do I need a developer to use the token?

Not if you use a ready, licensed platform. Building your own integration means handling the token in API headers, scenario testing and the production switch yourself. Digi Invoice connects your FBR profile through a guided setup and manages the tokens and payloads for you, so no coding is required.

Start issuing FBR-compliant invoices today

Digi Invoice validates, posts and QR-stamps your sales tax invoices through FBR's Digital Invoicing API — no development required.