1. Profil Zaufany has expired or is inactive
Profil Zaufany must be renewed every 3 years. If it has lapsed, login shows a message along the lines of „no active trusted profile, login process interrupted”. That message comes from the identity layer, not from KSeF itself.
Check the expiry date at pz.gov.pl under „My profile”. If it has expired, renew it through your online banking (fastest, a few minutes), through the mObywatel mobile app, or in person at a confirmation point. After renewing, wait a few minutes for the update to propagate and try again.
2. Your Profil Zaufany data does not match the CEIDG entry
At login, KSeF looks for a link between the PESEL (personal ID number) tied to your Profil Zaufany and your company NIP in the CEIDG and GUS registers. If your CEIDG entry (Poland's sole-trader business register) is out of date, that link fails and login is rejected, even when Profil Zaufany itself works fine.
This is a common trap after a change of personal details or address. Confirm that the PESEL behind your Profil Zaufany matches the details in CEIDG. If something is off, update the entry and allow a few hours for the registers to sync before retrying.
3. No permissions for that NIP (the classic error 403)
Logging in as a private person does not automatically grant access to a company's data. Access to a specific NIP requires assigned permissions. The usual symptom is error 403 when opening a session or attempting an action.
If you run a JDG (sole proprietorship), you hold owner permissions automatically through the NIP and PESEL link, with no extra steps. If you log in as an employee, an accountant, or on behalf of a company, the owner must first grant you permissions in the KSeF Taxpayer Application (the Permissions tab). After granting, wait 10 to 15 minutes, as changes need time to propagate.
4. Wrong login context (private person instead of company NIP)
During authentication, KSeF asks you to choose a context, meaning the identifier you want to act on behalf of. Choosing the „private person” context instead of the company NIP is one of the most frequent causes of error 403, even though the login technically succeeds.
The fix is simple: on the identity screen, select the correct context and enter the company NIP rather than your PESEL. If you log in but cannot see the right entity afterwards, that is also a sign you are in the wrong context.
5. Outage or overload at the Ministry or Profil Zaufany
Some problems are not yours to fix. The Ministry of Finance has published notices confirming that disruptions affected the Profil Zaufany login layer while KSeF itself kept working. During peak load you may also see a „request limit exceeded” message.
Before you change any settings, check the technical notices at ksef.podatki.gov.pl. Do not refresh the page repeatedly, as that can extend the block. Wait a while, try outside peak hours, or log in with another method (qualified electronic signature, mObywatel) if you have one.
6. Browser issues
Cache, cookies, extensions, and pop-up blockers can break the authentication session, especially during the redirect from online banking. KSeF login is most stable in Chrome and Firefox. Safari can be unreliable and sometimes returns a blank page.
Clear the KSeF site data or your full cache and cookies, disable pop-up blocking, and try again. A good test is logging in through an incognito window with no extensions. If that works, one of your extensions in the normal browser profile is the culprit.
7. You are logging in to the wrong environment
KSeF runs three separate environments, and credentials from one do not work in another. Production is ap.ksef.mf.gov.pl, Demo is ap-demo.ksef.mf.gov.pl, and the test environment lives under the api-test.ksef.mf.gov.pl family of addresses.
If you land on Demo or Test by accident, the login may „succeed”, but you will not see your real invoices or permissions, because these are sandboxes with no legal effect. Always confirm you are in Production before concluding that something is broken.
Quick checklist when login fails
Check the Profil Zaufany expiry date at pz.gov.pl (valid for 3 years).
Verify that your PESEL and NIP match in CEIDG; after any change, wait for the sync.
Make sure you have permissions for that NIP in the Taxpayer Application.
Pick the correct login context (company NIP, not private person).
Check the Ministry's technical notices before changing anything on your side.
Clear cache and cookies, or test the login in an incognito window.
Confirm you are in Production (ap.ksef.mf.gov.pl), not Demo or Test.
Summary
Most Profil Zaufany login problems come down to four areas: whether the profile is current, whether your data matches, whether you have permissions for the NIP, and the state of the Ministry's services. Working the checklist top to bottom usually surfaces the cause within minutes.
If you would rather not go through Profil Zaufany every time you issue an invoice, Biurko lets you connect a company once and keeps the KSeF session for you, and it translates raw KSeF error codes into concrete guidance instead of cryptic messages. See how it works at biurko.io.
FAQ
Why can't I log in to KSeF when Profil Zaufany itself works? Usually the issue sits outside the profile: missing permissions for the company NIP, the wrong context (private person instead of the company), or a PESEL and NIP mismatch in CEIDG. Check those three first.
How do I check whether my Profil Zaufany has expired? Log in at pz.gov.pl and open the „My profile” section. The profile is valid for 3 years. If it has lapsed, the quickest way to renew is through online banking or the mObywatel app.
What does error 403 mean when logging in to KSeF? Error 403 usually means you lack permission for the chosen NIP, or you logged in under the wrong context. After granting permissions in the Taxpayer Application, allow 10 to 15 minutes for them to propagate.
As a sole proprietor, do I need ZAW-FA to log in to KSeF? No. A JDG owner holds owner permissions automatically through the NIP and PESEL link, so you log in with Profil Zaufany without filing extra forms. ZAW-FA mainly applies to companies and delegated users.
Profil Zaufany is down and I need to issue an invoice. What now? Try another available login method (qualified electronic signature, mObywatel), or use software integrated with KSeF that keeps the connection open and does not require a manual login for every invoice.
