Skip to content
Start free
Getting started

TRIBU-CR: getting your signing certificate and API credentials

The old ATV portal stopped existing in October 2025. Where the two things any invoicing software needs are obtained now — and the button that can stop you invoicing without anyone warning you.

8 min readTicuenta
In one sentence: the signing certificate and the API credentials are generated at ovitribucr.hacienda.go.cr, inside the Tico Factura module. The ATV portal was replaced by TRIBU-CR in October 2025, so any instructions referring to ATV as a live portal are out of date.

The two things you need

  • The signing certificate

    A .p12 file containing your certificate and private key, plus a four-digit PIN you choose. That is what digitally signs your documents. Without a signature, an XML is not an electronic document.

  • The API credentials

    A username and password your software identifies itself to the tax authority with. They are not the same as your login to the virtual office: they are exclusive to the API.

Before you start

  • An active user at ovitribucr.hacienda.go.cr.
  • The right profile: individual, or legal representative if it is a company.
  • Access to the email and phone registered in the taxpayer register: that is where the login code arrives, and where the credentials are sent.

The steps

  • Sign in to the virtual office

    Go to ovitribucr.hacienda.go.cr, enter your identification and password, and type the validation code that arrives by email or SMS. If you manage several companies, select the right taxpayer.

  • Open Tico Factura

    In the left-hand menu, under Información, choose Tico Factura. The name is misleading: Tico Factura is both the tax authority's free invoicing tool and the module where credentials for using other software are managed. It is the second use you want.

  • Check whose credentials these are before pressing anything

    The screen greets you with the name of the person signed in, not necessarily the taxpayer selected. If the active taxpayer is the individual, the credentials come out in their name and will not work for invoicing on behalf of the company.

  • Generate the API credentials

    For the test environment, use the “I need a test user” link. If it asks whether you will use Tico Factura or your own system, answer that you will use other software. The system gives you a username and password, and also sends them to the registered email.

  • Generate and download the signing certificate

    Press Generar Llave Criptográfica, enter a four-digit PIN twice, save and download. You get the .p12 file. The test environment has its own certificate: you have to do it again there.

You choose the PIN and it cannot be recovered. Write it down at the time. If you lose it, a new certificate has to be generated — with everything that implies, which is what comes next.

The button that can stop you invoicing

If you are already invoicing with a system in production, be careful here. Generating a production certificate makes the platform revoke the previous one: two certificates cannot be live at once for the same taxpayer in the same environment. The one your current system is using stops signing, and it issues nothing until you load the new one.

The same goes for the API password: regenerating it invalidates the previous one.

The good news is that generating test certificates and credentials does not affect production. The two environments are separate end to end. The danger is not testing: it is picking the wrong option and pressing the production one thinking it was the test one.

How to check you got the right ones

With the credentials in hand, the username itself tells you whether you got it right. It is the fastest check there is:

If the username…It means
starts with cpj-Correct: a company
starts with cpf-Wrong taxpayer: these belong to the individual
ends in @stag.…Correct: test environment
ends in @prod.…Production environment

What you hand your software

Four items per company and per environment, and the test set and the production set are four different items each. They do not mix and they do not substitute for one another:

  • The .p12 file.
  • The four-digit PIN.
  • The API username.
  • The API password.
And a security warning worth taking seriously. The .p12 file and its PIN are, together, the ability to sign documents in your company's name. Do not send them over WhatsApp and do not leave them in a shared folder.

The expiry date, which gets forgotten

The signing certificate expires. And since it does not warn you, the normal way to find out is the day it stops signing. It is worth having your software warn you in advance — or, failing that, writing the date down somewhere.

If you are a foreign owner

The process is the same, but you cannot reach it without a Costa Rican tax identification number first. That is what the NITE is for. And one practical note: the validation code arrives at the phone and email registered with the tax authority — make sure those are ones you can actually reach from abroad.

From Ticuenta

Test or production, visible on every screen

The environment shows in the bar at all times. Ticuenta checks that the certificate matches the environment, and warns you when fewer than 60 days of validity are left.

See how it works

About this article. The steps follow the current TRIBU-CR portal, which replaced ATV in October 2025. The revocation behaviour when generating a new production certificate, and the username prefixes, are what the platform does today — the portal has changed more than once, so confirm before acting on a screen that looks different.

Verified as of 24 September 2026. Tax rules change. This is information, not tax advice.

Sources: Ministry of Finance Current legal texts (Sinalevi)

Also in English