Free tool for developers

Verifactu Hash and QR Code Calculator

Compute the SHA-256 hash (huella) of an issuance, cancellation or event record exactly as the Spanish Tax Agency (AEAT) defines it, chain it to the next record and generate the invoice’s URL and QR code with its validations. Load the official examples and check that your code returns the same result.

  • Reproduces the 3 official examples
  • Runs in your browser
  • No sign-up

Testing tool based on the technical documents published by the AEAT (hash v0.1.2 and QR v0.5.0). It sends nothing to the Spanish Tax Agency and does not replace its validations.

Invoicing Record Hash

Choose the record type, fill in the fields exactly as they appear in your XML and compute. Leave the previous hash empty if this is the system’s first record.

Record type
Official AEAT examples:

Exactly as on the invoice, up to 60 characters.

DD-MM-YYYY format, with hyphens.

Use a decimal point. The AEAT treats 123.1 and 123.10 as equal, but the hash is computed on exactly what you type.

64 uppercase hexadecimal characters. Left empty (field “Huella=”) for the first record.

ISO 8601 with seconds and time zone offset.

Everything is computed in your browser with the Web Crypto API. We do not store or send the data you type.

Invoice URL and QR Code

Generate the verification URL with the correct encoding, validate it against the AEAT rules and download a print-ready QR code.

System mode
Environment

Up to 60 printable ASCII characters. “&”, “/” and spaces are encoded automatically.

Decimal point, up to 12 integer digits and 2 decimals.

Validate a QR URL You Already Have

Paste the URL your software prints (or the one a QR reader returns) and we will tell you whether the AEAT will accept it.

How the Verifactu Hash Works

What the AEAT technical document says, explained for whoever has to program it.

Which fields go in, and in what order

The hash of an issuance record is computed over eight XML fields, in this order: IDEmisorFactura, NumSerieFactura, FechaExpedicionFactura, TipoFactura, CuotaTotal, ImporteTotal, Huella (the previous record’s hash) and FechaHoraHusoGenRegistro.

The cancellation record uses five: IDEmisorFacturaAnulada, NumSerieFacturaAnulada, FechaExpedicionFacturaAnulada, Huella and FechaHoraHusoGenRegistro. The event record, which only exists in NO VERI*FACTU mode, uses nine, starting with the computer system’s details.

How the string is built

Each field is written as name=value and joined with &. Leading and trailing spaces are stripped from the values. If a field has no value, only the name and the equals sign are written: in the system’s first record the previous hash goes as Huella=. The string is encoded in UTF-8 and hashed with SHA-256; the result is uppercase hexadecimal, 64 characters.

IDEmisorFactura=89890001K&NumSerieFactura=12345678/G33&FechaExpedicionFactura=01-01-2024&TipoFactura=F1&CuotaTotal=12.35&ImporteTotal=123.45&Huella=&FechaHoraHusoGenRegistro=2024-01-01T19:20:30+01:00
→ 3C464DAF61ACB827C65FDA19F352A4E3BDC2C640E9E9FC4CC058073F38F12F60

Why it is chained

Each record carries the previous one’s hash, so changing an old invoice breaks every later hash. That is why the chain runs per system and installation, and why two processes invoicing at the same time must serialise the calculation: if two records take the same previous hash, the chain forks.

In VERI*FACTU mode the AEAT recalculates the hash of every record it receives. If it does not match yours, the record is left “Aceptado con errores” (accepted with errors).

And the QR code

The invoice QR code contains a URL of the AEAT verification service with four parameters: nif, numserie, fecha (DD-MM-YYYY) and importe (with a decimal point). The values are URL-encoded in UTF-8: a series number such as 12345678&G33 must travel as 12345678%26G33.

The path depends on the mode: ValidarQR for VERI*FACTU and ValidarQRNoVerifactu for NO VERI*FACTU, on www2.agenciatributaria.gob.es (production) or prewww2.aeat.es (test). The optional formato=json parameter is meant for integrations, but it must never appear in the printed QR code.

We checked it on 7 October 2026 against the verification service in the AEAT test environment: the URL this tool generates with 12345678&G33 is accepted and the Agency reads the series number correctly, and an amount with a comma returns the same error 2005 that this tool flags.

The Mistakes We See Most Often

And that this calculator helps you catch before the AEAT does.

  1. Lowercase hash

    Most libraries return lowercase hexadecimal. The AEAT wants it in uppercase.

  2. Issue date in ISO format

    In the hash and the QR code, the issue date goes as DD-MM-YYYY, not YYYY-MM-DD. The record’s date and time, on the other hand, does use ISO 8601 with a time zone offset.

  3. Date and time without a time zone

    2024-01-01T19:20:30 is not valid: the offset is required, +01:00 or +02:00 depending on the time of year, and +00:00 or +01:00 in the Canary Islands.

  4. Decimal comma in amounts

    Neither in the hash nor in the QR code: always a point. In the QR code, a comma returns error 2005.

  5. Forgetting “Huella=” in the first record

    The field is included even when empty. Removing it from the string changes the hash of the first record and, with it, the whole chain.

  6. Unencoded “&” in the series number

    It splits the QR URL into two parameters and the verification service cannot find the invoice. Always encode the values.

  7. Two processes with the same previous hash

    When two tills or two workers invoice at the same time without a lock, the chain forks. Serialise the calculation per system and installation.

  8. Recalculating on “normalised” data

    The hash is computed on the value in the XML. If your XML has 123.10 and the hash is computed with 123.1, they will not match.

What This Calculator Does Not Do

It computes the hash and the QR URL so you can test your implementation. It does not generate the full XML record, sign it (XAdES) or send it to the AEAT, which is what turns software into a Verifactu system: submission queue, flow control, retries, corrective invoices and the responsible declaration (declaración responsable).

That is what we do at Kiwop: we adapt your in-house software, your ERP or your online store to Verifactu, or build your invoicing from scratch, and we deliver the responsible declaration.

See the Verifactu service

FAQ

Frequently Asked Questions

About the hash, the QR code and the calculator.

Which algorithm does the Verifactu hash use?

SHA-256, the only one the AEAT accepts today (list L12 in the annex to Order HAC/1177/2024, the technical specifications). The result is expressed in uppercase hexadecimal, 64 characters long.

How is the hash of the first record computed?

Like all the others, but with the previous-hash field empty: the string carries Huella= with nothing after it. The record also sets PrimerRegistro to “S” and has no previous-record block. Case 1 of the official examples is exactly that.

Do the amounts 123.1 and 123.10 give the same hash?

No: the hash is a SHA-256 of the string, so changing one character changes it. What the AEAT says is that it accepts both formats (one or two decimals) as valid; what matters is that the hash is computed with the same value that goes in your XML.

Does the calculator send my data anywhere?

No. The hash is computed in your browser with the Web Crypto API and the QR code is also drawn locally. There is no server behind the tool and we do not store what you type.

What size must the Verifactu QR code be?

Between 30×30 and 40×40 mm, according to ISO/IEC 18004 and with error-correction level M. It must have at least 2 mm of white margin (6 are recommended) and go at the top of the invoice, on the first page, with “QR tributario:” (tax QR) above it. The SVG the calculator downloads measures 35 mm.

What does “Aceptado con errores” mean?

It is the status the AEAT gives a VERI*FACTU record that it has received but in which it found something wrong, for example a hash that does not match its own calculation (“accepted with errors”). The record exists, but you have to correct it with an amendment. That is why it pays to test the hash before going to production.

Can I use the test URL on real invoices?

No. prewww2.aeat.es is the external test environment and only works with records sent to that environment. Real invoices carry the production URL, www2.agenciatributaria.gob.es.

Sources

Sources

Official AEAT technical documents the tool is based on, read on 7 October 2026.

  1. Detalle de las especificaciones técnicas para generación de la huella o hash (v0.1.2), the hash specifications Fields, order, format and the three examples the calculator reproduces.
  2. Detalle de las especificaciones técnicas del código QR (v0.5.0), the QR code specifications URL, parameters, encoding, size and error codes 1001 to 3002.
  3. Order HAC/1177/2024, technical specifications Articles 13 (hash), 20 and 21 (graphic representation and QR code).
  4. Verifactu technical information on the AEAT e-office Schemas, WSDL, validations and test environment.
  5. QR Code generator library, by Project Nayuki MIT licence. Generates the QR code in your browser.

Next step

Your Hash Matches? The Hard Part Comes Next

Submission, retries, corrective invoices, concurrency and the responsible declaration. We get it running in your system.

  • No commitment
  • Response in 24h
  • Custom proposal