Download the PHP package thesmarter/zatca without Composer
On this page you can find all versions of the php package thesmarter/zatca. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download thesmarter/zatca
More information about thesmarter/zatca
Files in thesmarter/zatca
Package zatca
Short Description ZATCA E-Invoicing integration tools
License MIT
Homepage https://github.com/thesmarter/zatca
Informations about the package zatca
English | العربية
Table of Contents
- Features
- Requirements
- Installation
- Quick Start
- 1. Generate Certificate Signing Request (CSR)
- 2. Request Compliance Certificate
- 3. Hash Invoice XML
- 4. Sign Invoice
- 5. Check Compliance
- 6. Generate Production Certificate
- 7. Submit Invoice to ZATCA
- Environment Configuration
- Using the Facade
- Invoice Types
- API Reference
- Build UBL Invoices From Arrays
- Renew a Production Certificate
- Examples
- Testing
- Error Handling
- Best Practices
- ZATCA Integration Workflow
- Resources
- Contributing
- License
- Credits
- Support
Features
- Certificate Management: Generate CSR (Certificate Signing Request) and obtain compliance/production certificates, including production CSID renewal
- UBL Invoice Builder: Build standard/simplified invoices, credit and debit notes (388/383/381) from plain PHP arrays with automatic totals and VAT grouping
- Invoice Processing: Hash and sign XML invoices according to ZATCA specifications (namespace-aware DOM signing)
- QR Code Generation: Create compliant QR codes for both simplified and standard invoices
- Compliance Validation: Check invoice compliance before production submission
- Invoice Submission: Submit invoices to ZATCA via Reporting (simplified) or Clearance (standard) APIs
- Multi-Environment Support: Sandbox, Simulation, and Production environments
- Clean Architecture: Well-structured, maintainable, and testable code
Requirements
- PHP >= 8.1
- Required PHP extensions:
ext-opensslext-domext-xslext-jsonext-bcmathext-simplexml
- Composer for dependency management
Installation
Install the package via Composer:
Quick Start
1. Generate Certificate Signing Request (CSR)
First, generate a CSR and private key for your organization:
2. Request Compliance Certificate
Obtain a compliance certificate from ZATCA using your CSR and OTP:
3. Hash Invoice XML
Hash your unsigned invoice XML:
4. Sign Invoice
Sign the invoice with your private key and compliance certificate:
5. Check Compliance
Validate your signed invoice against ZATCA's compliance checks:
6. Generate Production Certificate
After successful compliance validation, request a production certificate:
7. Submit Invoice to ZATCA
Submit your signed invoice to ZATCA (Reporting for simplified, Clearance for standard):
Environment Configuration
The package supports three ZATCA environments:
Using the Facade (Alternative Approach)
The Zatca facade provides a cleaner, more convenient API for accessing all services. Instead of manually instantiating services and their dependencies, you can use the facade as a single entry point.
Benefits of Using the Facade
- Simplified API: Single entry point for all ZATCA operations
- Lazy Loading: Services are only instantiated when needed
- Dependency Management: Automatically handles service dependencies
- Cleaner Code: Less boilerplate, more readable
Facade Example: Complete Workflow
Facade API Methods
The Zatca facade provides the following methods:
Comparison: Traditional vs Facade
Traditional Approach:
Facade Approach:
The facade handles all dependency injection automatically, making your code cleaner and easier to maintain.
Invoice Types
When generating CSR, specify the invoice type using a 4-digit code:
1100- Standard & Simplified Invoices0100- Simplified Invoice Only (B2C)1000- Standard Invoice Only (B2B)
Each digit acts as a boolean flag: [Standard, Simplified, Future Use, Future Use]
API Reference
Core Services
CertificateSigningRequestBuilder
Generates CSR and private key for ZATCA onboarding.
Methods:
setCommonName(string $name)- Set common namesetSerialNumber(string $solutionProvider, string $solutionName, string $serialNumber)- Set device serial numbersetOrganizationIdentifier(string $id)- Set organization tax IDsetOrganizationalUnitName(string $name)- Set organizational unitsetOrganizationName(string $name)- Set organization namesetCountry(string $country)- Set country code (SA)setInvoiceType(string $type)- Set invoice type (e.g., '1100')setAddress(string $address)- Set business addresssetBusinessCategory(string $category)- Set business categorygenerate()- Generate CSR and private keygetCsr()- Get generated CSRgetPrivateKey()- Get generated private keysaveCsr(string $path)- Save CSR to filesavePrivateKey(string $path)- Save private key to file
ComplianceService
Handles compliance certificate requests and validation.
Methods:
requestComplianceCertificate(string $b64Csr, string $otp): CSIDcheckCompliance(string $binarySecurityToken, string $secret, string $invoiceHash, string $invoiceUuid, string $signedInvoice): ValidationResponse
InvoiceHashingService
Hashes invoice XML according to ZATCA specifications.
Methods:
hash(string $unsignedInvoiceXml): InvoiceHashingResult
InvoiceSigningService
Signs invoices with digital signature and generates QR codes.
Methods:
sign(CSID $csid, string $privateKeyContent, string $canonicalXml, string $invoiceHash): InvoiceSigningResult
QrCodeGeneratorService
Generates ZATCA-compliant QR codes.
Methods:
generate(CSID $csid, string $invoiceHash, string $canonicalXml, string $signatureValue): string
ProductionCsidGeneratorService
Requests production certificates after compliance validation, and renews them when needed.
Methods:
requestProductionCertificate(string $binarySecurityToken, string $secret, string $ccsidRequestId): CSIDrenewProductionCertificate(string $binarySecurityToken, string $secret, string $otp, string $b64Csr): CSID
InvoiceSubmissionService
Submits invoices to ZATCA via Reporting or Clearance APIs.
Methods:
submit(CSID $csid, bool $isSimplified, string $invoiceHash, string $invoiceUuid, string $invoiceXml): SubmissionResponse
InvoiceBuilder
Builds UBL 2.1 invoice XML (unsigned) from plain PHP arrays, with automatic totals and VAT grouping.
Methods:
InvoiceBuilder::simplified(array $data): string- Build a simplified (B2C) invoiceInvoiceBuilder::standard(array $data): string- Build a standard (B2B) invoiceInvoiceBuilder::build(array $data): string- Build any supported type (invoice388,credit383,debit381)
Entities
CSID
Represents a Certificate Signing ID (compliance or production certificate).
Properties:
string $certificate- Base64 encoded certificatestring $secret- Certificate secretstring $requestId- Request ID from ZATCA
Methods:
static loadFromJson(string $filepath): selfsaveAsJson(string $filepath): void
InvoiceHashingResult
Result of invoice hashing operation.
Properties:
string $invoiceHash- Base64 encoded SHA-256 hashstring $uuid- Invoice UUIDstring $b64Invoice- Base64 encoded invoicestring $b64CanonicalXml- Base64 encoded canonical XML
InvoiceSigningResult
Result of invoice signing operation.
Properties:
string $signature- Digital signaturestring $b64SignedInvoice- Base64 encoded signed invoicestring $b64QrCode- Base64 encoded QR code
SubmissionResponse
Response from invoice submission to ZATCA.
Properties:
ValidationResults $validationResults- Validation messagesstring $status- Submission status (REPORTED/CLEARED)bool $isSubmitted- Whether submission was successful
ValidationResponse
Response from compliance validation.
Properties:
ValidationResults $validationResults- Validation messagesstring|null $reportingStatus- Reporting statusstring|null $clearanceStatus- Clearance statusstring|null $qrSellerStatus- QR seller statusstring|null $qrBuyerStatus- QR buyer status
ValidationResults
Validation messages from ZATCA.
Properties:
array $infoMessages- Informational messagesarray $warningMessages- Warning messagesarray $errorMessages- Error messagesstring $status- Overall validation status
Build UBL Invoices From Arrays
Supports invoice (388), credit (383) and debit (381) via 'type' => ....
The builder emits the unsigned invoice (no UBLExtensions/QR/signature);
feed it to the hashing service, then InvoiceSigningService::sign(),
which inserts the fragments with namespace-aware DOM handling.
Renew a Production Certificate
Examples
Complete working examples are available in the examples/ directory:
0_using_facade.php- Using the Zatca Facade (Recommended)1_generate_csr.php- Generate CSR and private key2_generate_compliance_csid.php- Request compliance certificate3_hash_invoice_xml.php- Hash invoice XML4_generate_qr_code_xml.php- Generate QR code5_sign_invoice_xml.php- Sign invoice6_check_compliance.php- Validate compliance7_generate_production_csid.php- Request production certificate8_build_ubl_invoice.php- Build a UBL invoice from PHP arrays9_renew_production_csid.php- Renew a production certificate
Testing
Run the test suite:
Or use PHPUnit directly:
Error Handling
The package throws specific exceptions for different error scenarios:
Best Practices
- Store Certificates Securely: Keep your private keys and certificates in secure storage
- Use Environment Variables: Store sensitive data like OTPs and secrets in environment variables
- Validate Before Submission: Always check compliance before submitting to production
- Handle Errors Gracefully: Implement proper error handling and logging
- Test in Sandbox: Thoroughly test your integration in the sandbox environment
- Keep Certificates Updated: Monitor certificate expiration and renew as needed
ZATCA Integration Workflow
Resources
Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
License
This package is open-sourced software licensed under the MIT License.
Credits
Developed and maintained by Smart Team — eltayeb and CoderX249.
Support
For issues, questions, or contributions, please visit the GitHub repository.
Disclaimer: This is an unofficial package and is not affiliated with or endorsed by ZATCA. Use at your own risk and ensure compliance with all ZATCA regulations.
All versions of zatca with dependencies
ext-openssl Version *
guzzlehttp/guzzle Version ^7.2
ext-dom Version *
ext-xsl Version *
ext-json Version *
ext-bcmath Version *
ext-simplexml Version *