Published 6 min read

Published by the Taxora.pk product team

FBR DI Sandbox & IP Whitelisting: What PRAL Actually Requires

Illustration for: FBR DI Sandbox & IP Whitelisting: What PRAL Actually Requires

Before you can post live electronic invoices, FBR/PRAL expect a controlled onboarding path: IRIS Digital Invoicing registration, choice of licensed integrator (PRAL can provide this free of cost), IP whitelisting, sandbox tokens, and scenario testing. This article summarises what FBR's Digital Invoicing User Manual describes — use the PDF for the full screens and field lists.

1. Register on IRIS and open Digital Invoicing

Log in to IRIS with your taxpayer credentials and complete the Digital Invoicing registration flow. You will provide technical contact details, ERP / invoicing system information, software type (cloud or on-premises), and business nature / sector. FBR FAQs confirm there is no downloadable “FBR invoicing app” — you integrate using published technical documentation.

2. Choose PRAL or another licensed integrator

Under the Sales Tax Rules, notified registered persons integrate through a licensed integrator. Rule guidance (and FBR FAQs) state that PRAL shall act as licensed integrator and can provide free integration services including sandbox testing; other licensed integrators may charge for configuration. The current list is published on FBR's site.

3. IP whitelisting (mandatory for PRAL)

IP whitelisting restricts which servers may call PRAL. Per the user manual you typically provide hosting details and up to three IP addresses (or upload a file for more). Without an approved whitelist, sandbox and production API calls will fail even if your JSON payload is perfect.

4. Sandbox token and scenario testing

After whitelist approval, open the Sandbox Environment tab to get Web API details and a sandbox security token. Complete the scenarios assigned for your business nature / activity. Only after successful sandbox work do you move to a production token. Skipping scenarios is a common reason go-live stalls.

5. What “done” looks like in production

Production posting uses validate and post methods against FBR/PRAL endpoints. Accepted invoices return an FBR invoice number; customer copies must carry the Digital Invoicing logo and QR code to FBR's printing specifications (see the technical documentation for QR version and size).

Taxora.pk's role

Taxora.pk is the day-to-day invoicing workspace that talks to PRAL once your registration and tokens are in place. The team helps you exercise real validate/post steps during trial — it does not replace IRIS forms or IP whitelist approval. Continue with the full connect guide or the DI API overview.