KSeF Login in 2026: Trusted Profile, Signature or Certificate

The first login to KSeF (Poland's mandatory national e-invoicing system) trips up more people than issuing the actual invoice. The Taxpayer Application shows several authentication methods, and none of them explains which one is right for you. This is not a trivial choice. Since 1 February 2026, KSeF has been mandatory for the largest companies, and since 1 April 2026 for all other businesses (Ministry of Finance timeline). Without valid authentication you can neither issue nor receive a structured invoice.

7 min read 53 views
KSeF Login in 2026: Trusted Profile, Signature or Certificate

Three methods, three different jobs

The most common mistake is treating Trusted Profile, qualified signature and KSeF certificate as competing "either/or" options. In practice they answer different questions.

Trusted Profile (Profil Zaufany, Poland's free government eID) and a qualified signature are how a person logs in and confirms their identity. A KSeF certificate is how a system, your invoicing software, connects to KSeF in the background without a manual login each time.

That is why most companies end up using at least two: the owner signs in with a Trusted Profile in the Taxpayer Application, while the accounting software runs on a certificate. Login happens through the KSeF Taxpayer Application at ap.ksef.mf.gov.pl (production) and ap-demo.ksef.mf.gov.pl (the Demo environment).

Trusted Profile and mObywatel: the free start for sole proprietors

A Trusted Profile is a free digital identity issued by the Polish state, the same one you use to sign filings to the tax office or social security. In KSeF it is ideal for manual logins in the Taxpayer Application.

Who it fits: sole proprietors (JDG, single-owner businesses) and micro-companies issuing a handful of invoices a month, doing it themselves in the official Ministry app.

From 1 April 2026, citizen-identity login runs through the National Node (Węzeł Krajowy, login.gov), which offers the Trusted Profile, the mObywatel mobile app, online banking and the e-Dowód (electronic ID card) (KSeF 2.0 Manual, Part I).

Upside: zero cost, nothing to install, a path you already know from other government matters. Downside: it is a method for a human at a screen, so you cannot automate invoice sending from software with it.

Qualified signature and qualified seal

A qualified electronic signature is a paid, commercial e-signature (on a card or in the cloud) with the legal weight of a handwritten signature. In KSeF it authenticates both individuals and people representing a company.

The equivalent for non-natural persons, meaning companies, is the qualified seal (pieczęć kwalifikowana). A company authenticates with its seal, and only then can it grant permissions and generate certificates.

Who it fits: businesses that already hold a signature or seal for other purposes (SAF-T filings, contracts, tenders), and companies that need entity-level authentication.

It has one real advantage over a KSeF certificate: a qualified signature also signs documents outside KSeF. A KSeF certificate works only inside KSeF.

KSeF certificate: the target method for integrations

A KSeF certificate is a cryptographic tool issued free of charge by the Ministry of Finance Certification Centre. Certificate-based authentication has worked since 1 February 2026, and you request one in the KSeF 2.0 Taxpayer Application or via the API (KSeF Certificates, Ministry of Finance).

Key traits:

  • Authentication only. It carries no permissions; those are tied to a NIP (tax ID) or PESEL (personal ID number), not to the certificate file.

  • Two types. Type 1 for login and integration, type 2 for stamping invoices with a QR code in offline mode.

  • Valid for a maximum of 2 years from the requested start date or the date of issue.

  • Up to 100 active certificates per NIP, which helps teams and accounting offices.

  • A prerequisite: you can only generate a certificate after logging in with a Trusted Profile, qualified signature or seal.

Who it fits: anyone connecting KSeF to external software through the API, and businesses that want a durable, automatic method without manual logins.

A practical example: a sole proprietor issuing 60 invoices a month from their accounting software does not want to log in per transaction. They sign in once with a Trusted Profile, generate a KSeF certificate, load it into the software, and from then on invoices flow to KSeF in the background.

What about the token? The matter is not settled

A token is a string generated after you authenticate with one of the primary methods. Unlike a certificate, it carries assigned permissions.

Under the original timeline the token was a transitional option, available until 31 December 2026, after which, from 1 January 2027, the KSeF certificate was to become the only method for system integration.

That scenario is no longer certain. At consultations on 9 June 2026 the Ministry of Finance proposed keeping tokens in the system permanently, with new rules: a validity window of 1 to 365 days and automatic renewal with the owner's prior consent (consultation summary, Ministry of Finance; KIS communiqué).

Important: for now this is a consultation proposal, not enacted law. Until it takes effect, do not assume any hard token cut-off date. If you are building an integration, it is safer to base it on the KSeF certificate, which is the target method regardless of what happens to tokens.

Which method to pick in 2026: quick cheat sheet

Your profile Primary method For software integration Sole proprietor, a few invoices a month, manual in the Ministry app Trusted Profile / mObywatel not needed Sole proprietor or firm with accounting software Trusted Profile for login KSeF certificate Company (legal entity) Qualified seal KSeF certificate Already hold a qualified signature for SAF-T/contracts Qualified signature KSeF certificate Accounting office serving many clients Signature / seal + permissions KSeF certificates (up to 100 per NIP)

Checklist before your first login

  1. Decide whether you log in as a person (NIP/PESEL) or on behalf of a company; this determines the method.

  2. Confirm you have an active Trusted Profile or a valid qualified signature or seal.

  3. Log in to the Taxpayer Application (ap.ksef.mf.gov.pl) and confirm the context (the correct NIP).

  4. If you use invoicing software, generate a type 1 KSeF certificate.

  5. Need offline mode? Generate a type 2 certificate for QR codes as well.

  6. Note your certificate expiry dates; they lapse after 2 years at the latest.

  7. Do not plan an integration on tokens alone until their future is clear.

Conclusion

Choosing a KSeF login method in 2026 comes down to one question: who is logging in. A human doing manual work in the Ministry app picks a Trusted Profile or a qualified signature. A system connecting via API needs a KSeF certificate, the target method and a free one.

With Biurko you do not have to juggle this by hand. You authenticate once, through a Trusted Profile or your own KSeF certificate, and the platform manages the session and connection validity in the background. Create a free account at biurko.io and connect KSeF in minutes, without logging in for every invoice.

FAQ

Do I need a KSeF certificate to use KSeF? No. For login alone, a Trusted Profile or qualified signature is enough. A KSeF certificate is needed if you connect KSeF to invoicing software through the API, or if you want to issue offline invoices with a QR code.

How much does a KSeF certificate cost? Nothing. The KSeF certificate is issued free of charge by the Ministry of Finance Certification Centre. Only the commercial qualified signature, a separate authentication method, is paid.

Will the KSeF token stop working after 2026? Originally tokens were to be available until 31 December 2026. After the 9 June 2026 consultations, the Ministry of Finance proposed keeping them permanently with new validity rules. This is still a proposal, not enacted law, so watch the Ministry's communiqués.

How long is a KSeF certificate valid? A maximum of 2 years from the date of issue or the requested start date. Once it expires you request a new one and the system revokes the old one. A single NIP can hold up to 100 active certificates at once.

How does a company log in to KSeF? A non-natural person authenticates with a qualified seal. On that basis it can grant permissions to staff and generate KSeF certificates for software integration.

Tags

#KSeF
Share

Previous article

The inFakt Alternative Question: Where Biurko.io Actually Fits

Stay in the Loop

Get notified when we publish new articles — no newsletter, unsubscribe anytime.

We respect your privacy. Unsubscribe at any time.

Cookies

We use cookies to keep the service running and — with your consent — to improve it. You can accept all, reject the optional ones, or customize your choices. Cookie Policy