e-invoicing

Compliance Network Implementation Guide

Set up credentials

The Inland Revenue Board of Malaysia (IRBM) credentials, digital certificate, and API access you need to configure before submitting invoices through MyInvois.

Unlike Pan-European Public Procurement On-Line (PEPPOL) network countries where integration uses participant identifiers, Malaysia requires an IRBM client ID and client secret for API authentication, plus a digital certificate issued by a Malaysian Certification Authority (CA).Sovos uses this certificate to sign invoices before submitting them for clearance. You must obtain and configure credentials before you can submit any documents.

Before you begin

Before starting credential setup, make sure you:

  • Create your organization and companies in Compliance Network.

  • Verify your Tax Identification Number (TIN) is active and verified with IRBM.

  • Verify your Business Registration Number (BRN) is registered with Companies Commission of Malaysia (SSM).

  • You have access to the MyInvois portal.

About credential contexts

Each credential upload includes a Context value that tells Sovos how to use the credential.

Transmission
Use Transmission to send documents to IRBM.
Polling
Use Polling to fetch documents from IRBM.
Signing
Use Signing to sign documents before transmission.

Set up sequence

Complete the following steps to configure your credentials for Malaysia e-invoicing.

  1. Register your business with IRBM and obtain your TIN.

  2. Enroll in MyInvois.

  3. Get a digital certificate.

  4. Request sandbox access.

  5. Upload transmission or polling credentials.

  6. Upload signing credentials.

Register your business with IRBM

Register your business with IRBM at https://www.hasil.gov.my to obtain your TIN and BRN.

TIN
An alphanumeric string assigned by IRBM.
BRN
Issued by SSM to Identify your business entity, with a format that varies by entity type (company, sole proprietor, partnership).
Note:

Both identifiers are required before you can configure credentials and submit invoices.

Obtain a digital certificate

Document signing is optional in Malaysia. If you have a certificate, obtain it from a Malaysian Certification Authority (CA) or through the MyInvois portal.

Certificate type
X.509
Issued by
Malaysian Certification Authority (CA) or MyInvois portal
Format
PFX (PKCS#12) with private key included
CAUTION: Set a renewal reminder well before the certificate expiration date. An expired certificate causes all invoice submissions to fail until a new certificate is uploaded.
Note:

If you don't have a certificate configured, set listVersionID="1.0" on InvoiceTypeCode. If you do, set listVersionID="1.1".

Request sandbox access

Malaysia's sandbox environment uses the MyInvois pre-production portal, a mock tax authority service that simulates IRBM responses without sending data to the live system.

Test environment considerations:

  • Do not submit real taxpayer information or real invoice data.

  • Use credentials generated from the MyInvois sandbox portal, not production credentials.

  • Respect the batch size limit in UAT, which is 10 documents per API call.

  • Obtain production credentials separately and update all endpoint URLs.

Upload transmission or polling credentials

Get your Client ID and Client Secret from the Inland Revenue Board of Malaysia (IRBM)' MyInvois portal.

  1. Send a POST request to https://api-test.sovos.com/v2/configurations/organizations/{orgId}/settings with the following request headers.
    • Content-Type: application/json

    • Authorization: Bearer {accessToken}

    • x-correlationId: {uniqueValue}

  2. Include the following JSON body:
    JSON
    [
      {
        "context": "transmission",
        "configurations": [
          {
            "name": "partner_credentials_irbm",
            "value": {
              "client_id": "INSERT-CLIENTID-HERE",
              "client_secret": "INSERT-SECRET-HERE"
            },
            "scope": {
              "category": "MY_INV",
              "productId": "my_UBLInvoice__1.0",
              "orgId": "YOUR-ORG-ID",
              "taxId": "YOUR-COMPANY-TAXID"
            }
          }
        ]
      }
    ]
    Note:

    For polling, use polling for the context and my_UBLInvoice_Polling_1.0 for the productId.

  3. Verify that the response returns HTTP 201.
    JSON
    {
      "status": 201,
      "message": "Created",
      "success": true,
      "timestamp": 1664826411521,
      "data": [
        {
          "message": "Configurations are created",
          "statusCode": 201,
          "configurationContextResponse": {
            "context": "Transmission",
            "configurations": [
              {
                "id": "SETTING-ID",
                "name": "partner_credentials_irbm",
                "value": {
                  "client_id": "INSERT-CLIENTID-HERE",
                  "client_secret": "INSERT-SECRET-HERE"
                },
                "scope": {
                  "category": "MY_INV",
                  "productId": "my_UBLInvoice__1.0",
                  "orgId": "YOUR-ORG-ID",
                  "taxId": "YOUR-COMPANY-TAXID"
                }
              }
            ]
          }
        }
      ]
    }
Save the SETTING-ID for when you need to update your credentials.

Upload signing credentials

Get a signing certificate from a Malaysian CA and convert it to Base64 format.

  1. Send a POST request to https://api-test.sovos.com/v2/configurations/organizations/{orgId}/settings with the following request headers.
    • Content-Type: application/json

    • Authorization: Bearer {accessToken}

    • x-correlationId: {uniqueValue}

  2. Include the following JSON body:
    JSON
    [
      {
        "context": "signing",
        "configurations": [
          {
            "name": "credentials",
            "value": {
              "certificateFileData": "INSERT-BASE64-CERT-HERE",
              "password": "INSERT-PASSWORD-HERE"
            },
            "scope": {
              "category": "MY_INV",
              "productId": "my_UBLInvoice__1.0",
              "orgId": "YOUR-ORG-ID",
              "taxId": "YOUR-COMPANY-TAXID"
            }
          }
        ]
      }
    ]
  3. Verify that the response returns HTTP 201.
    JSON
    {
      "status": 201,
      "message": "Created",
      "success": true,
      "timestamp": 1667465886908,
      "data": [
        {
          "message": "Configurations are created",
          "statusCode": 201,
          "configurationContextResponse": {
            "context": "Signing",
            "configurations": [
              {
                "id": "SETTING-ID",
                "name": "credentials",
                "value": {
                  "certificateFileData": "*****",
                  "password": "*****"
                },
                "scope": {
                  "category": "MY_INV",
                  "productId": "my_UBLInvoice__1.0",
                  "orgId": "YOUR-ORG-ID",
                  "taxId": "YOUR-COMPANY-TAXID"
                }
              }
            ]
          }
        }
      ]
    }
    Note:

    The response redacts the certificateFileData and the password.

Update credentials

You need the SETTING-ID returned from when you upload your credentials.

Update credentials when, for example, IRBM issues new API credentials or a certificate is renewed.
  1. Send a PUT request to https://api-test.sovos.com/v2/configurations/organizations/{orgId}/settings/{settingId} with the following request headers.
    • Content-Type: application/json

    • Authorization: Bearer {accessToken}

    • x-correlationId: {uniqueValue}

  2. Optional: For transmission or polling credentials, include the following body:
    JSON
    {
      "value": {
        "client_id": "NEW-CLIENTID-HERE",
        "client_secret": "NEW-SECRET-HERE"
      }
    }
  3. Optional: For signing credentials, include the following body:
    JSON
    {
      "value": {
        "certificateFileData": "NEW-CERT-HERE",
        "password": "NEW-PASSWORD-HERE"
      }
    }
  4. Verify that the response returns HTTP 200.
    JSON
    {
      "status": 200,
      "message": "OK",
      "success": true,
      "data": {
        "id": "SETTING-ID",
        "value": {
          "client_id": "NEW-CLIENTID-HERE",
          "client_secret": "NEW-SECRET-HERE"
        }
      }
    }