# Error 401 when requesting for compliance checks in Simulation Portal

**URL:** <https://zatca1.discourse.group/t/error-401-when-requesting-for-compliance-checks-in-simulation-portal/410>\
**Category:** Onboarding, renewal and revocation\
**Created:** [August 2, 2023, 10:21am UTC](https://zatca1.discourse.group/t/error-401-when-requesting-for-compliance-checks-in-simulation-portal/410 "2023-08-02T10:21:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vivek.kedia](https://avatars.discourse-cdn.com/v4/letter/v/6de8d8/32.png) [@vivek.kedia](https://zatca1.discourse.group/u/vivek.kedia)\
**Post date:** [August 2, 2023, 10:21am UTC](https://zatca1.discourse.group/t/error-401-when-requesting-for-compliance-checks-in-simulation-portal/410/1 "2023-08-02T10:21:23Z")

</div>

Hi,  
I am trying to onboard a client on the simulation portal. The CSR was successful and the certificate key was provided  
When I am sending the compliance xml with the key I am getting 401 error  
“You not authorized to use this api endpoint”

I have received the compliance request id also  
I have tried it twice on 30th and 31st but still getting the same error  
I can share the screen shot if required

What is the solution for this?

Regards  
Vivek Kedia

---

<div class="post-metadata">

**Author:** ![aelorr](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@aelorr](https://zatca1.discourse.group/u/aelorr)\
**Post date:** [August 3, 2023, 8:13am UTC](https://zatca1.discourse.group/t/error-401-when-requesting-for-compliance-checks-in-simulation-portal/410/2 "2023-08-03T08:13:32Z")

</div>

Hi Vivek,

When completing the CSR request you will receive 3 main outputs:

- The request id which will be used on the last step to request your production CSID
- The compliance certificate which should be used as a username for the basic auth on the onboarding APIs and for signing the simplified invoices on the invoice checks
- Finally, the secret which should be used as a password for the basic auth

We believe the issue you are facing is due to not including the certificate and secret on the basic auth. please check the API samples on the sandbox for more examples on the authorization (basic auth).

Thank you

---

<div class="post-metadata">

**Author:** ![MaShalaby](https://avatars.discourse-cdn.com/v4/letter/m/4491bb/32.png) [@MaShalaby](https://zatca1.discourse.group/u/MaShalaby)\
**Post date:** [August 4, 2023, 11:34am UTC](https://zatca1.discourse.group/t/error-401-when-requesting-for-compliance-checks-in-simulation-portal/410/3 "2023-08-04T11:34:39Z")

</div>

The error message you provided, “You are not authorized to use this API endpoint,” is a common explanation for a “401 Unauthorized” error. It’s a way for the server to inform the client that they need to provide valid credentials before they can access the requested API.

To resolve this issue, Please check:

**1- CSR Request** : Double-check that you’ve correctly configured the CSR (Certificate Signing Request) based on the environment you intend to use. Make sure the values you’re entering align with the intended environment as this [reference](https://zatca1.discourse.group/t/is-there-any-difference-between-simulation-portal-and-fatoora-portal-when-creating-csr/406)

**2- API Endpoint** : Ensure that you are using the correct APIs for the correct Environment you want to use.  
e.g :  
If using Simulation Env, use the Simulation portal to get the OTP and Simulation APIs to get the CCSID and PCCSID as this [reference](https://zatca1.discourse.group/t/what-are-the-integration-api-endpoints-for-production-and-simulation/350) and this [reference](https://zatca1.discourse.group/t/the-provided-otp-is-invalid-error-occurs-when-using-the-compliance-api/391/3)

**3 - Authentication Method** : Verify that you are using the correct authentication method (Basic Authentication).

**4- Check Credentials** : Ensure that you are providing the correct authentication credentials ( username = {binarySecurityToken} and password = {secret}) in the request Auth.

**5- Valid Credentials** : Ensure that you are using the correct credentials for the correct environment for example you should not use the Simulation Certificates on production and vice versa.

If you have verified all of the above and are still encountering the “401 Unauthorized” error, you may need to provide the support team with the **APIs collection** and **config file** used to generate the **CSR** and sample of submitted **invoices**.

---

<div class="post-metadata">

**Author:** ![vivek.kedia](https://avatars.discourse-cdn.com/v4/letter/v/6de8d8/32.png) [@vivek.kedia](https://zatca1.discourse.group/u/vivek.kedia)\
**Post date:** [August 16, 2023, 9:23pm UTC](https://zatca1.discourse.group/t/error-401-when-requesting-for-compliance-checks-in-simulation-portal/410/4 "2023-08-16T21:23:15Z")

</div>

Hi,  
After resolution by Zatca the compliance API have passed.in Simulation portal  
Now the error is for the CSID  
we are calling this Link - [https://gw-fatoora.zatca.gov.sa/e-invoicing/simulation/production/csids](https://gw-fatoora.zatca.gov.sa/e-invoicing/simulation/production/csids)  
The error returned is : The requested URL was rejected. Please consult with your administrator

We have got a support id number - how do we contact support for help?

What could be the error?  
Regards  
Vivek

---

<div class="post-metadata">

**Author:** ![jiri](https://avatars.discourse-cdn.com/v4/letter/j/53a042/32.png) [@jiri](https://zatca1.discourse.group/u/jiri)\
**Post date:** [August 20, 2023, 10:21am UTC](https://zatca1.discourse.group/t/error-401-when-requesting-for-compliance-checks-in-simulation-portal/410/5 "2023-08-20T10:21:42Z")

</div>

Please, try to repeat the action outside of your company network to potentially eliminate the probability of being blocked by your company’s firewall (e.g. as the message might be coming from your own network instead of ZATCA).

Secondly, try to perform the task via Postman collection. If the issue still persists, please, share the postman collection with ZATCA via the official channels or your RM for further investigation.
