KSeF Tokens: How Long Are They Valid, and What Just Changed

Until spring 2026 the answer was simple. A KSeF token (an authentication key for Poland's national e-invoicing system) worked through 31 December 2026, and from 1 January 2027 only certificates would remain. That certainty no longer holds. On 9 June 2026 Poland's Ministry of Finance (MF) announced that tokens will stay in the system permanently. That changes the practical answer to "how long," but not one detail: it is still a proposal, not a rule. If your accounting software logs into KSeF with a token, you need to know what is already settled and what is not yet in law.

6 min read 43 views
KSeF Tokens: How Long Are They Valid, and What Just Changed

KSeF token validity: the short answer

The formal position today: the ability to generate and use tokens was scheduled to expire at the end of 2026. This follows from the KSeF 2.0 Handbook (Part I) and the Ministry of Finance regulation of 12 December 2025 on the use of KSeF. That deadline is still formally in force.

The practical position today: MF has announced that the token will remain a permanent login method beyond 31 December 2026. That announcement has not yet been turned into a legal provision. Until an amendment passes, the letter of the existing schedule applies, not a statement from a conference.

The token itself has no "expiry date" in the classic sense. KSeF does not define how long a token stays active. It remains valid until the user revokes it. So "how long" is a question about the whole mechanism, not about a single token.

What MF actually announced in June 2026

At the first consultations after the partial rollout of KSeF on 9 June 2026, the ministry proposed that tokens remain available after 31 December 2026. The proposal also floated a token validity window of 1 to 365 days with a renewal mechanism, plus new token-linked permissions.

The reasoning is straightforward: roughly one in three taxpayers still logs in with a token. Forcing everyone to migrate within a few weeks would create risk the ministry would rather avoid.

Three things to keep in mind:

  1. This is a consultation proposal, not a finished implementation instruction.

  2. Concrete measures were due to be presented around the turn of June and July 2026.

  3. Until the act and the regulation are amended, the legal state has not changed.

In short, the direction is clear, but the dates in the proposal (the 1 to 365 days) are not yet law. In client-facing content and in system configuration, "MF has announced" is safer than "from 2027 a token is valid for X days."

KSeF token vs certificate: the real difference

Even if the token stays, it is not the same tool as a certificate. The difference is practical, not cosmetic.

Feature KSeF token KSeF certificate Purpose authenticate an app on the taxpayer's behalf authenticate the identity of an entity/person Permissions baked into the token at generation derived from permissions granted in the system Validity until revoked (mechanism was set to end in 2026) up to 2 years from issuance Offline24 / emergency mode not supported type 2 certificate supports it Permission change must regenerate the token no new certificate needed Requesting a KSeF certificate not possible while logged in with a token possible after authenticating with a certificate/signature Cost free free

Certificates come in two types. Type 1 is for login (interactive and batch sessions). Type 2 is required to mark invoices in special modes: offline24, system unavailability, and emergency mode. A token cannot do this at all.

What a token cannot do

This is the heart of the matter for companies that issue invoices at volume.

A token works online only. If the KSeF API stops responding, you cannot mark an invoice offline with a token. A type 2 certificate can.

After every change to the permission scope, a token has to be regenerated and re-entered into the software. With a certificate, changing permissions in the system does not mean replacing the certificate itself.

Logging in with a token does not let you request a KSeF certificate. If a company built its integration purely on tokens, moving "toward a certificate" requires first authenticating by another method (signature, seal, or Profil Zaufany, Poland's Trusted Profile).

A real-world accounting-office example

An office serves 40 clients. Some of them handed the office a token for sending invoices. On a Friday afternoon KSeF has an outage. Clients call, because they need invoices dated today.

On tokens the office is stuck: a token works online only. On type 2 certificates the invoices can be marked in offline24 mode and submitted once the system returns, keeping the original date. That is not a theoretical gap. It is the difference between "sorry, we'll call you back" and "already done."

What to do now: a decision independent of the token's fate

Even assuming the token stays for good, it is worth holding certificates. The reason is simple: offline24 and emergency modes only work with a type 2 certificate. A company without one is defenceless on the day KSeF goes down.

The good news for peace of mind: you do not need to migrate off tokens in a panic before the end of 2026. But it is worth issuing certificates at your own pace, before the December rush of applications.

Checklist: KSeF tokens in your company

  1. Identify which integrations (software, accounting office, ERP) log into KSeF with a token.

  2. Record who generated each token, its permission scope, and when it was created.

  3. Track MF communications from the turn of June and July 2026, since they will settle the token validity mechanics.

  4. Issue a KSeF certificate, type 1 (login) and type 2 (offline/emergency), even if you stay on a token.

  5. Do not build a multi-year procedure around tokens alone; keep the token for convenience and the certificate as the foundation.

  6. Limit token permissions to the minimum needed (for example, issuing and accessing invoices), not "everything."

Summary

The answer to "how long are KSeF tokens valid" has two layers today. Formally: end of 2026. In practice: MF has announced tokens will stay for good, but that is not yet a rule. The safe approach is to hard-code neither, and to hold certificates regardless of the decision.

Biurko is built around KSeF certificates from day one, so offline24 and emergency modes are there immediately, not bolted on later. Start on the FREE plan at biurko.io, or book a short demo to see the certificate setup on your own NIP (Polish tax ID).

FAQ

How long are KSeF tokens valid? Formally, the ability to generate and use tokens was set to expire at the end of 2026. In June 2026 MF announced that the token will stay in the system permanently. That announcement is not yet law, so the existing deadline applies until an amendment passes.

Does a KSeF token have an expiry date? The token itself has no predefined lifetime. KSeF does not set how long a token is valid; it stays active until the user revokes it. MF's June proposal floated a 1 to 365 day validity window, but that is only a proposal for now.

Do I have to switch from a token to a certificate? If MF's proposal becomes law, you will not have to drop the token. A certificate is still worth having, because only a type 2 certificate supports offline24 and emergency modes, which a token cannot handle.

What is the difference between a token and a KSeF certificate? A token carries baked-in permissions and handles automatic app login. A certificate proves identity, lasts up to two years, supports offline modes, and does not need regenerating when permissions change.

Does a KSeF 1.0 token work in KSeF 2.0? No. Tokens generated in KSeF 1.0 are not valid in KSeF 2.0 and must be generated again. Token generation for KSeF 2.0 opened on 8 December 2025.


This article is informational and is not tax or legal advice. Confirm deadlines and the scope of changes against current MF communications at ksef.podatki.gov.pl.

Tags

#KSeF
Share

Previous article

KSeF Login via mObywatel: Can You Log In From Your Phone?

Stay in the Loop

Get notified when we publish new articles — no newsletter, unsubscribe anytime.

We respect your privacy. Unsubscribe at any time.

Cookies

We use cookies to keep the service running and — with your consent — to improve it. You can accept all, reject the optional ones, or customize your choices. Cookie Policy