Repository navigation
Home
🇬🇧 English first · 🇪🇸 Español más abajo
A zero-dependency Python library that computes the hash chain (huella) of
Spanish VERI*FACTU invoicing records, exactly as specified by the AEAT.
It does one thing. It is not an invoicing system, it does not talk to the AEAT, and it does not sign anything. What it does, it does against the Tax Agency's own published test vectors — all three of them, byte for byte.
| Page | What you will find |
|---|---|
| The VERIFACTU hash | Field order, the exact input string, and the three official AEAT vectors reproduced in full |
| Design decisions | Why there are no dependencies, why the input string is a public API, and why NIF appears twice |
For task-oriented documentation — installing, the CLI, chaining records,
integrating into an existing system — see the docs/
folder in the repository. This wiki covers the why; docs/ covers the how.
flowchart LR
A[Your invoicing system] -->|invoice fields| B[cadena_de_entrada]
B -->|"IDEmisorFactura=...&Huella=..."| C[SHA-256]
C -->|64 uppercase hex chars| D[huella]
D -->|becomes 'previous hash'| A
That is the whole scope. Everything to the left of your invoicing system and everything after huella is your problem, deliberately.
What it does
- Builds the input string for the three record types: alta (8 fields), anulación (5 fields) and evento (9 fields).
- Applies SHA-256 and returns 64 uppercase hexadecimal characters.
- Chains records together, refusing to chain one that does not follow from the previous hash.
- Reproduces the three official AEAT test vectors exactly — including the input strings, not just the resulting hashes.
What it does not do
- It does not build the XML of a registro de facturación.
- It does not sign anything (no XAdES, no certificates, no keys).
- It does not send anything to the AEAT, in VERI*FACTU mode or any other.
- It does not store records, and it has no notion of a ledger or an audit trail.
- It is not, by itself, a sistema informático de facturación (SIF) and it is published without a declaración responsable, because it is a component and not a system. The full legal notice is in the README and it should be read before you build anything on top of this.
Independence. This is not AEAT software, it is not endorsed by the AEAT, and the AEAT does not certify invoicing software at all — conformity is established by the producer's own responsible declaration (art. 13 RD 1007/2023, art. 15 Order HAC/1177/2024).
«Detalle de las especificaciones técnicas para generación de la huella o "hash" de los registros de facturación», AEAT, version 0.1.2 (27/08/2024), section 6, pages 10–12.
Every constant in the library traces back to that document, and the test suite (61 tests) fails if any of them drifts.
Biblioteca de Python sin dependencias que calcula la huella (el encadenado SHA-256) de los registros de facturación VERI*FACTU, exactamente como la especifica la AEAT.
Hace una sola cosa. No es un sistema de facturación, no habla con la AEAT y no firma nada. Lo que sí hace, lo hace contra los vectores de prueba publicados por la propia Agencia: los tres, carácter a carácter.
| Página | Qué encontrarás |
|---|---|
| The VERIFACTU hash | Orden de los campos, la cadena de entrada exacta y los tres vectores oficiales de la AEAT reproducidos enteros |
| Design decisions | Por qué no hay dependencias, por qué la cadena de entrada es API pública y por qué NIF aparece dos veces |
Para la documentación de uso —instalación, CLI, encadenado, integración— está la
carpeta docs/
del repositorio. Esta wiki cuenta el porqué; docs/ cuenta el cómo.
flowchart LR
A[Tu sistema de facturación] -->|campos de la factura| B[cadena_de_entrada]
B -->|"IDEmisorFactura=...&Huella=..."| C[SHA-256]
C -->|64 caracteres hex en mayúsculas| D[huella]
D -->|pasa a ser la 'huella anterior'| A
Ese es todo el alcance. Todo lo que hay a la izquierda de tu sistema de facturación y todo lo que viene después de huella es cosa tuya, a propósito.
Lo que hace
- Construye la cadena de entrada de los tres tipos de registro: alta (8 campos), anulación (5 campos) y evento (9 campos).
- Aplica SHA-256 y devuelve 64 caracteres hexadecimales en mayúsculas.
- Encadena registros y se niega a encadenar uno que no venga de la huella anterior.
- Reproduce los tres vectores de prueba oficiales de la AEAT de forma exacta, incluidas las cadenas de entrada y no solo las huellas resultantes.
Lo que no hace
- No construye el XML del registro de facturación.
- No firma nada (ni XAdES, ni certificados, ni claves).
- No envía nada a la AEAT, ni en modo VERI*FACTU ni de ninguna otra forma.
- No almacena registros: no tiene noción de libro registro ni de traza de auditoría.
- Por sí sola no es un sistema informático de facturación (SIF) y se publica sin declaración responsable, porque es un componente y no un sistema. El aviso legal completo está en el README y conviene leerlo antes de construir nada encima.
Independencia. No es software de la AEAT ni está respaldado por ella, y la AEAT no certifica software de facturación: la conformidad se establece mediante declaración responsable del propio productor (art. 13 RD 1007/2023 y art. 15 de la Orden HAC/1177/2024).
«Detalle de las especificaciones técnicas para generación de la huella o "hash" de los registros de facturación», AEAT, versión 0.1.2 (27/08/2024), apartado 6, páginas 10 a 12.
Cada constante de la biblioteca sale de ese documento, y la batería de pruebas (61 tests) falla si alguna se desvía.