Authentication & Conventions

Every request to the EFRIS API is authenticated with your business's API key, sent as a Bearer token. You can generate and rotate the key from your EFRIS Simplified dashboard under Security.

Authorization: Bearer YOUR_API_KEY
Content-Type: application/json
Environment Base URL Use for
Production https://app.efrissimplified.com/api/efris/{tin} Live traffic - every request fiscalises against URA for real
Sandbox https://sandbox.efrissimplified.com/api/efris/{tin} Building & testing your integration - reaches URA's sandbox, not their live system
Start in sandbox. Requests to the production host submit real invoices, credit notes, and stock movements to URA's live system. Build and test your integration against sandbox.efrissimplified.com first, which talks to URA's separate testing environment, then switch only the hostname when you're ready to go live.

{tin} is the TIN of the business registered on EFRIS Simplified. All endpoints are POST and accept/return JSON.

Pricing rule: amounts are tax-inclusive

All invoice amounts are gross (tax-inclusive). If an item's net price is 10,000 UGX and VAT is 18%, you send a unit price of 11,800 UGX. The VAT portion is then reported per line and per tax category - see Fiscal Invoices for worked examples.

Security recommendations

  • Store the API key server-side. Never embed it in mobile apps, browser JavaScript, or public repositories.
  • Rotate the key from your dashboard if you suspect it has leaked - the old key stops working immediately.
  • Always call the API over HTTPS; plain HTTP requests are not served.
Looking for the complete reference? Field definitions, code lists, validation rules, error handling, and ready-to-run examples for every endpoint are available inside your EFRIS Simplified dashboard once your business is registered on the platform.
Sign in to the dashboard · Get started

Stuck on an integration step? Our engineers reply fast.