
Kenya Revenue Authority's (KRA) electronic Tax Invoice Management System (eTIMS API 3.0) mandates real-time electronic invoice signing, itemized VAT 16% calculation, and cryptographic Control Code (eTIMS-CC) verification for all VAT-registered businesses, corporate vendors, and financial institutions in Kenya.
This guide provides developer specifications for integrating KRA eTIMS API 3.0, generating SHA-256 control signatures, handling Withholding VAT (WHVAT 2%), and auto-linking Safaricom M-Pesa transaction callbacks with eTIMS QR receipts.
---
🏛️ Key Capabilities of eTIMS API 3.0
eTIMS-CC): Every tax invoice requires a unique cryptographic signature derived from the seller's PIN, invoice date, total amount, and KRA device serial number.---
💻 SHA-256 Control Code Generation Example
import { crypto } from "node:crypto";
export function generateEtimsControlCode(
kraPin: string,
invoiceNum: string,
totalAmountKes: number,
timestamp: string
): string {
const rawPayload = `${kraPin}|${invoiceNum}|${totalAmountKes.toFixed(2)}|${timestamp}`;
return crypto.createHash("sha256").update(rawPayload).digest("hex").toUpperCase();
}
---
📋 Developer & Business Integration Checklist
Test live invoice signing and QR verification on the [KRA eTIMS Signer Cockpit](https://ramongitau.uk/tools/pdf-inspector) on [ramongitau.uk](https://ramongitau.uk).