Set up credentials
The Inland Revenue Board of Malaysia (IRBM) credentials, digital certificate, and API access you need to configure before submitting invoices through MyInvois.
Unlike Pan-European Public Procurement On-Line (PEPPOL) network countries where integration uses participant identifiers, Malaysia requires an IRBM client ID and client secret for API authentication, plus a digital certificate issued by a Malaysian Certification Authority (CA).Sovos uses this certificate to sign invoices before submitting them for clearance. You must obtain and configure credentials before you can submit any documents.
Before you begin
Before starting credential setup, make sure you:
-
Create your organization and companies in Compliance Network.
-
Verify your Tax Identification Number (TIN) is active and verified with IRBM.
-
Verify your Business Registration Number (BRN) is registered with Companies Commission of Malaysia (SSM).
-
You have access to the MyInvois portal.
About credential contexts
Each credential upload includes a Context value that tells Sovos how to use the credential.
- Transmission
- Use Transmission to send documents to IRBM.
- Polling
- Use Polling to fetch documents from IRBM.
- Signing
- Use Signing to sign documents before transmission.
Set up sequence
Complete the following steps to configure your credentials for Malaysia e-invoicing.
-
Register your business with IRBM and obtain your TIN.
-
Enroll in MyInvois.
-
Get a digital certificate.
-
Request sandbox access.
-
Upload transmission or polling credentials.
-
Upload signing credentials.
Register your business with IRBM
Register your business with IRBM at https://www.hasil.gov.my to obtain your TIN and BRN.
- TIN
- An alphanumeric string assigned by IRBM.
- BRN
- Issued by SSM to Identify your business entity, with a format that varies by entity type (company, sole proprietor, partnership).
Both identifiers are required before you can configure credentials and submit invoices.
Obtain a digital certificate
Document signing is optional in Malaysia. If you have a certificate, obtain it from a Malaysian Certification Authority (CA) or through the MyInvois portal.
- Certificate type
- X.509
- Issued by
- Malaysian Certification Authority (CA) or MyInvois portal
- Format
- PFX (PKCS#12) with private key included
If you don't have a certificate configured, set listVersionID="1.0" on InvoiceTypeCode. If you do, set listVersionID="1.1".
Request sandbox access
Malaysia's sandbox environment uses the MyInvois pre-production portal, a mock tax authority service that simulates IRBM responses without sending data to the live system.
Test environment considerations:
-
Do not submit real taxpayer information or real invoice data.
-
Use credentials generated from the MyInvois sandbox portal, not production credentials.
-
Respect the batch size limit in UAT, which is 10 documents per API call.
-
Obtain production credentials separately and update all endpoint URLs.
Upload transmission or polling credentials
Get your Client ID and Client Secret from the Inland Revenue Board of Malaysia (IRBM)' MyInvois portal.
SETTING-ID for when you need to update your credentials.
Upload signing credentials
Get a signing certificate from a Malaysian CA and convert it to Base64 format.
Update credentials
You need the SETTING-ID returned from when you upload your credentials.
