Kit
Start free

How to register your Kit EFRIS certificate with URA

Register a Kit POS CA-issued EFRIS certificate and Virtual Device in the URA portal, from device application to the public .cer upload.

Kit issues and keeps the signing certificate for a Kit-managed EFRIS integration, so you never handle a private key. What URA still needs from you is a Virtual Device, the certificate's compact SHA-1 thumbprint and the public .cer file, registered in the EFRIS portal in the right order. This guide walks through the seven steps, from the files you download in Kit to the final check that the connection works. It takes about eight minutes to read and the URA review steps can take longer, so do not generate a second certificate while you wait.

What you need before you start

  • A saved EFRIS integration in Kit with the Kit-managed certificate option selected.
  • The Virtual Device number used by your Kit EFRIS integration.
  • The Kit-generated EF-1001 PDF, completed and signed by the taxpayer or authorised representative.
  • The public X.509 certificate downloaded from Kit as a DER .cer file.

Step 1: Download the public certificate and EF-1001 from Kit

Where: Kit POS > Integrations > EFRIS > Signing certificate

Copy the 40-character URA portal thumbprint, download the public .cer certificate and download the generated EF-1001 PDF. Complete and sign the form before uploading it to URA.

  • Copy "URA portal thumbprint (SHA-1)": exactly 40 hexadecimal characters with no spaces or colons.
  • Download the public DER X.509 certificate ending in .cer; it contains no private key.
  • Check the pre-filled EF-1001 business details, complete the declaration and sign it.
  • Never look for or upload a private key. Kit keeps it encrypted and uses it only to sign EFRIS requests.

Step 2: Create the Virtual Device application

Where: EFRIS portal > Device Management > Device Application

Create the application in the portal, add an order under Section B and choose Virtual Device. Nothing needs to be downloaded or installed as an Offline Enabler.

  • Click Add on the Device Application page and choose the branch that will use Kit.
  • Under Section B: Order Details, click Add and select Virtual Device as the Device Type.
  • Use the Virtual Device number shown by EFRIS as the device number in Kit, with no leading or trailing spaces.
  • Select Self for the solution provider and submit the application.

Step 3: Wait until the device is Distributed

Where: EFRIS portal > Device Application > Application status

Do not continue while the application is pending. Continue only after the portal shows the device status as Distributed.

  • Refresh the application status in the EFRIS portal.
  • Confirm the selected device number matches the one configured in Kit.
  • Continue when the status reads Distributed.

Step 4: Register the compact SHA-1 thumbprint

Where: EFRIS portal > Thumbprint Configure List > Add

Choose Certificate Authority Signed, enter Kit POS as the Certificate Authority Name, and paste the URA portal thumbprint copied from Kit. It must be 40 hexadecimal characters with no separators.

  • Click Add under Thumbprint Configure List.
  • Choose Certificate Authority Signed for a Kit-managed certificate.
  • Enter Kit POS as the Certificate Authority Name.
  • Paste the compact SHA-1 value with no spaces and no colons.
  • Do not paste the longer SHA-256 fingerprint; Kit shows that separately for integrity checks.

Step 5: Upload the signed EF-1001 and wait for Enable

Where: EFRIS portal > Thumbprint Configure List

Attach the completed and signed EF-1001 PDF to the thumbprint request. Submit it and wait until URA changes the thumbprint status to Enable.

  • Upload the signed taxpayer copy of EF-1001 generated by Kit.
  • Submit the thumbprint request.
  • Wait for URA review and continue only when the status reads Enable.

Step 6: Upload the Kit public .cer file

Where: EFRIS portal > Device Public Key List

Select the Distributed device and upload the public DER X.509 certificate downloaded from Kit. This is the .cer file, not a PKCS#12 bundle and never a private key.

  • Open Device Public Key List and select the same device number.
  • Upload the public certificate file downloaded from Kit; its filename ends in .cer.
  • Confirm the portal accepted the public key for that device.

Step 7: Verify the connection in Kit

Where: Kit POS > Integrations > EFRIS

Return to Kit, confirm the device number and certificate details, then enable or test the integration. If URA approval is pending, wait instead of generating another certificate.

  • Check that the device number in Kit matches the device registered with URA.
  • Keep the current certificate during review; replacing it creates a new thumbprint and public key.
  • Contact Kit support if URA shows Enable but the connection still cannot be verified.

If something does not match

The two values that cause most rejections are the thumbprint and the device number. The thumbprint must be the 40-character SHA-1 shown in Kit, with no spaces or colons, not the longer SHA-256 fingerprint. The device number in Kit must be exactly the Virtual Device number EFRIS issued, with no leading or trailing spaces. If URA shows the thumbprint as Enable and the public key as accepted but Kit still cannot verify the connection, contact Kit support with your business name and the device number rather than regenerating the certificate.

Sources

  1. https://pos.kit.africa/blog/how-to-register-kit-efris-certificate-with-ura

Run the whole business from one login.

Point of sale, stock, CRM, accounting free in every plan, payroll and Kit AI. Start on the web today and add the till, the phone app and the desktop app as you grow.

No card needed · 14-day trial