Authentication & Conventions
Every request to the EFRIS API is authenticated with your business's API key, sent as a Bearer token. You can generate and rotate the key from your EFRIS Simplified dashboard under Security.
Authorization: Bearer YOUR_API_KEY
Content-Type: application/json
| Environment | Base URL | Use for |
|---|---|---|
| Production | https://app.efrissimplified.com/api/efris/{tin} |
Live traffic - every request fiscalises against URA for real |
| Sandbox | https://sandbox.efrissimplified.com/api/efris/{tin} |
Building & testing your integration - reaches URA's sandbox, not their live system |
Start in sandbox. Requests to the production host submit real invoices, credit notes, and
stock movements to URA's live system. Build and test
your integration against
sandbox.efrissimplified.com first, which talks to URA's separate testing
environment, then switch only the hostname when you're ready to go live.
{tin} is the TIN of the business registered on EFRIS Simplified. All endpoints are
POST and accept/return JSON.
Pricing rule: amounts are tax-inclusive
All invoice amounts are gross (tax-inclusive). If an item's net price is 10,000 UGX and VAT is 18%, you send a unit price of 11,800 UGX. The VAT portion is then reported per line and per tax category - see Fiscal Invoices for worked examples.
Security recommendations
- Store the API key server-side. Never embed it in mobile apps, browser JavaScript, or public repositories.
- Rotate the key from your dashboard if you suspect it has leaked - the old key stops working immediately.
- Always call the API over HTTPS; plain HTTP requests are not served.
Looking for the complete reference? Field definitions, code lists, validation rules, error
handling, and ready-to-run examples for every endpoint are available inside your EFRIS Simplified dashboard
once your business is registered on the platform.
Sign in to the dashboard · Get started
Sign in to the dashboard · Get started