CS ComplyStream
Toggle menu

Setup guide

Connect your Shopify store to FBR: the full setup

This is the sequence we use with Pakistani merchants. IRIS labels can move, but the responsibilities stay the same: your registration, your integrator selection, your token and a tested store mapping.

Before you start

Keep the IRIS credentials for the correct NTN, your Shopify owner access, your approved tax mappings and one example of each real order type nearby. Decide who can approve an IRIS request: the owner, accountant or authorised representative. Do not share an IRIS password over WhatsApp merely to finish quickly.

  • Confirm the registered business name, STRN/NTN and address.
  • Ask your adviser for HS codes, rates, sale types and buyer rules.
  • Choose a quiet test window; sandbox work does not require interrupting checkout.

Step 1: enable Digital Invoicing in IRIS

Sign in to IRIS from the official FBR website and open the registration or Digital Invoicing area for the registered person. The screen should identify the taxpayer at the top and present a Digital Invoicing registration, integration or onboarding action. Select the establishment or business activity that will issue invoices and submit the request.

If the menu is absent, stop and verify that you are in the right taxpayer profile and that the registration is active. Taking screenshots of the profile name, request reference and status makes later support much easier. Screenshots will be added to this guide; until then, match the screen by its taxpayer heading and Digital Invoicing wording, not by menu colour.

Step 2: select a licensed integrator

In the integrator-selection screen, you should see a list of FBR-licensed providers and an action to nominate one for your registration. PRAL appears as the FBR automation organisation and is commonly selected because Rule 150XF provides for free-of-cost integration services on demand. Other licensed integrators may offer broader implementation services.

ComplyStream will not appear in that list because it is Shopify software, not a licensed integrator. Read how the relationship works or the comparison of licensed integrators and software before making the selection.

Step 3: generate the sandbox token

Open the sandbox or test-environment credentials area after the integrator relationship is active. The screen should show an environment marked “Sandbox” or “Test” and an option to generate or reveal an authentication token. Copy it once into a password manager. Treat it as a secret even though it cannot create production invoices.

Record which NTN and environment issued it. A frequent failure is pasting a production token into sandbox settings, or using a token from another company managed by the same accountant.

Step 4: whitelist the submission IP

FBR accepts calls only from approved network addresses for the integration. In the IP whitelist area, add the exact server IP shown in ComplyStream's setup screen. The IRIS screen normally has an address field, environment selection and save or submit action. Copy the digits; do not whitelist your office Wi-Fi address unless that is genuinely the system sending invoices.

Wait for the whitelist status to become active before diagnosing invoice fields. An otherwise perfect invoice will still fail if the source IP is not allowed.

Step 5: install ComplyStream

Install the app from Shopify while signed in as the store owner or a staff account allowed to approve apps. Review the requested Shopify permissions, open setup, select Sandbox, enter the token and confirm the registered seller details. The app needs order and product data to construct invoices; it does not need your IRIS password.

Map default HS code, tax rate and sale type only when they genuinely apply across the catalogue. Use product-level mappings where clothing, cosmetics, electronics or zero-rated items differ.

Step 6: submit a sandbox invoice

Choose a representative Shopify test or real order and send it to sandbox from the order action. Review the preview before submission. Seller identity, buyer status, line values, discount, shipping and tax should reconcile to the expected treatment, even though sandbox does not create a live liability.

A successful response should show an FBR validation result or reference against the order. Then test the awkward cases: COD to Faisalabad, a registered buyer from Lahore, multiple rates, a voucher and a delivery charge. If FBR rejects one, use the field path and message rather than repeatedly pressing retry. Our FBR invoice-errors guide translates common responses.

Step 7: move to production

Complete the production activation requested in IRIS or by the selected integrator. Generate the production token, add the production whitelist entry where required, and switch the ComplyStream environment only after approval. Replace the sandbox token; never assume it works in both environments.

Send one controlled live invoice and confirm the FBR reference, amounts and Shopify status with your accountant. Agree who monitors failures and when COD orders are submitted. Production is an operating process, not merely a toggle.

If something goes wrong

Authentication or unauthorised response

Check environment, token, expiry or rotation, and the registered person it belongs to. Re-enter it rather than sending the token in a support screenshot.

IP or connection response

Compare the whitelist entry with the exact IP shown in app setup. Confirm sandbox and production separately and allow for IRIS activation.

Invoice validation response

Read the specific field and fix the source mapping—HS code, buyer registration, scenario, date, rate or value. Keep the Shopify order unchanged unless its commercial data is itself wrong.

No Digital Invoicing menu or approval

Confirm taxpayer profile and registration status with your authorised representative, then use official FBR/PRAL support channels. ComplyStream cannot activate an IRIS feature or approve your registration.

Last updated: 4 August 2026

Not tax advice. Confirm registration scope, rates, deadlines, and filing obligations with a Pakistani tax practitioner against current FBR SROs and the Sales Tax Act. ComplyStream is not affiliated with FBR or PRAL.

Start with sandbox, not guesswork

Install the app and follow the setup checklist with your own IRIS credentials.