5 KSeF 2.0 Authentication Methods: Which One Is Right for You?

Before you issue your first invoice through KSeF (Krajowy System e-Faktur, Poland's national e-invoicing system), you have to prove who you are. That sounds trivial, but it's where most people get stuck. KSeF 2.0 offers five different authentication methods, each works differently, and each suits a different type of user. This matters now because KSeF is already mandatory. It applied to the largest taxpayers from 1 February 2026 and to all active VAT payers from 1 April 2026 (ksef.podatki.gov.pl). 2026 was a penalty-free grace period, but from 1 January 2027 the tax office can impose sanctions. Choosing a login method isn't paperwork. It's the precondition for issuing invoices at all.

7 min read 31 views
5 KSeF 2.0 Authentication Methods: Which One Is Right for You?

First, one distinction that decides everything

KSeF has two access modes, and they determine which method makes sense for you.

Manual mode means logging in through a browser to the Aplikacja Podatnika (the taxpayer web app) and issuing invoices yourself. For this, a Profil Zaufany (trusted identity profile) or a qualified signature is enough.

Automatic mode is when your invoicing software sends the invoice by connecting to KSeF through the API. Here the Trusted Profile won't work, because it's a way to log in a person, not a system. The software needs a KSeF token or a KSeF certificate instead.

If you issue a handful of invoices a month by hand, look at the first group. If you use accounting software or integrate KSeF with an ERP, look at the second.

Method 1: Profil Zaufany (Trusted Profile)

The most popular option and it's free. You set it up once, for example through online banking, and use it the same way you handle other government matters. For a JDG (jednoosobowa działalność gospodarcza, sole proprietorship) issuing invoices on its own, it's entirely sufficient.

One important change: from 1 April 2026 the Trusted Profile operates within the so-called Węzeł krajowy (National Node, an SSO gateway), alongside the mObywatel app, the e-ID card (e-dowód), and bank login. This follows directly from the KSeF regulation (legal basis).

There's one limit that matters: the Trusted Profile is for manual login. Your invoicing software can't use it.

Method 2: Qualified electronic signature

This is the digital equivalent of a handwritten signature, valid across the EU under the eIDAS standard. You buy it from commercial providers (Certum, Sigillum, EuroCert) on an annual or multi-year subscription. It costs money.

For KSeF, it gives the same access as the Trusted Profile: manual login to the taxpayer app. It makes sense mainly if you already hold a signature for other purposes, such as court-register (e-KRS) filings, public procurement, or signing contracts. If you don't have one and don't need it elsewhere, the Trusted Profile is cheaper and just as effective.

A qualified signature is a permanent method. It doesn't expire with the transition period.

Method 3: Qualified electronic seal

This is the equivalent of a signature, but for non-natural persons (limited companies, joint-stock companies). The seal is tied to the company's NIP (tax identification number) rather than to an individual, so documents are signed on behalf of the organisation. It costs on the order of 1,500 PLN.

A real advantage: with a seal, a company can operate KSeF without filing the ZAW-FA form (the KSeF authorisation notice). For smaller entities a seal is usually unnecessary, but in a larger organisation it can be convenient.

Method 4: KSeF certificate (the target method)

This is a cryptographic tool issued free of charge by the Ministry of Finance Certification Centre. Unlike a token, a certificate is purely a means of authentication and carries no permissions of its own. It works much like a qualified signature, but purpose-built for KSeF (ksef.podatki.gov.pl).

A few concrete points worth knowing:

  • Applications have been open since 1 November 2025, and authentication with a certificate has been possible since 1 February 2026.

  • A certificate is valid for no more than 2 years.

  • There are two types. Type 1 is for login (including via API), and Type 2 is for signing invoices in offline mode with a QR code when KSeF is unavailable.

  • Limits: a natural person by PESEL or "certificate fingerprint" gets up to 2 active certificates, while an entity with a NIP (a company, or a sole trader with a NIP) can hold up to 100.

The certificate is the most sensible long-term choice, especially when integrating invoicing software with KSeF. The software does need to produce a XAdES-BES signature, so in practice your software handles that for you.

Method 5: KSeF token (and what just changed)

A token is a 40-character string generated by KSeF after you log in. Unlike a certificate, a token carries the taxpayer's permissions inside it, which is what made it convenient for integrations: once generated, it lets software act on your behalf.

Pay attention here, because most guides online are already out of date. The original plan was for tokens to disappear on 31 December 2026, leaving certificates as the only systemic method from 1 January 2027. After the consultations on 9 June 2026, however, the Ministry of Finance announced that tokens are staying, permanently (KSeF consultations, MoF).

What changes is how they work. The announced approach sets token validity anywhere from 1 to 365 days, plus automatic renewal with the owner's consent. The changes are slated to take effect on 1 January 2027. Until the rules are formally enacted, it's worth following MoF communications, because details may still be refined.

The practical takeaway: if you log in with a token today, there's no need to rush onto a certificate. But the certificate remains the target method and the safer long-term bet.

Which should you pick? A quick cheat sheet

Your situation Method Paid? Mode Sole trader, a few invoices a month, manual Trusted Profile No Manual You already hold a signature for e-KRS / tenders Qualified signature Yes Manual Company avoiding ZAW-FA Qualified seal Yes Manual / API Invoicing software or ERP integration KSeF certificate No API Existing token-based integration Token (staying) No API

Simple rule: the more invoices you handle and the more you want to automate, the further you move toward a certificate. Logging in manually for hundreds of invoices a month gets old fast.

Checklist before your first invoice

  1. Decide whether you issue manually or through software. That settles the method.

  2. For manual mode, check that you have an active Trusted Profile.

  3. For software integration, apply for a KSeF certificate (Type 1 for login, Type 2 for offline mode).

  4. Confirm your software supports KSeF 2.0 and the FA(3) invoice schema.

  5. Grant permissions to the people who will issue invoices.

  6. Test the full cycle in the sandbox before going live.

Summary

Five methods sounds intimidating, but the choice usually comes down to one question: manual or through software. A solo sole trader is fine with a Trusted Profile. A business that wants to automate invoicing should head toward a KSeF certificate, and the token remains a convenient alternative even beyond 2026.

Biurko authenticates to KSeF using a certificate, so you don't log in manually for every invoice or refresh access by hand. You configure it once. Create an account at biurko.io and test e-invoicing without fighting the login screen.

FAQ

What authentication methods are available in KSeF 2.0? Five: Profil Zaufany (from 1 April 2026 within the National Node), qualified electronic signature, qualified electronic seal, KSeF certificate, and token. The first four confirm identity; the token additionally carries permissions.

Will KSeF tokens disappear after 2026? They were originally meant to end on 31 December 2026. After the 9 June 2026 consultations, the Ministry of Finance announced tokens will stay permanently, with new mechanics: validity from 1 to 365 days and automatic renewal. Keep an eye on MoF communications.

How does a KSeF certificate differ from a token? A certificate is purely a means of authentication, carries no permissions, and is valid for up to 2 years. A token carries the taxpayer's permissions. You can use either to integrate software with KSeF, but the certificate is the target method.

Is Profil Zaufany enough for KSeF? For issuing a few invoices a month yourself in the browser, yes. It won't work in invoicing software that connects to KSeF via the API, though. There you need a token or a certificate.

How much does KSeF authentication cost? The Trusted Profile, KSeF certificate, and token are free. The qualified electronic signature (annual subscription) and the qualified electronic seal (around 1,500 PLN, mainly for companies) are paid.

Tags

#KSeF
Share

Previous article

KSeF 10,000 PLN Limit: Do B2C Sales Count Toward It?

Stay in the Loop

Get notified when we publish new articles — no newsletter, unsubscribe anytime.

We respect your privacy. Unsubscribe at any time.

Cookies

We use cookies to keep the service running and — with your consent — to improve it. You can accept all, reject the optional ones, or customize your choices. Cookie Policy