Back to Knowledge Base

Connecting to KSeF

The two ways to authenticate, and what Biurko does with your credentials

Connecting to KSeF

Overview

Connecting to KSeF (Krajowy System e-Faktur, Poland's National e-Invoice System) requires authentication. Biurko supports two methods — and only these two — and keeps your credentials encrypted.

The two authentication methods

  • Profil Zaufany (Trusted Profile) — Poland's trusted identity for signing in through government e-services. This is the default path and the cheapest one, because it requires buying nothing. It has one cost: you sign the authorisation XML by hand on gov.pl, so renewing the connection always needs you in person.
  • The files of a qualified electronic signature you bought — you upload the certificate and the private key once, with the passphrase if the key is protected, and the connection is then kept up without you. Biurko issues nothing here: you bring the files you already hold.

The token you see on a connection is a session token issued by the KSeF gateway itself, after authentication. It is not a third way of signing in, and you do not generate it in the KSeF portal. A KSeF certificate generated in the KSeF Taxpayer Application, and signing in with a token, are the next step — neither is something you can use today.

Managing credentials in Biurko

  • Credentials are stored encrypted and are used only to sign requests sent to KSeF on your behalf.
  • You can renew or revoke the connection at any time from its settings.
  • Biurko monitors certificate expiry and warns you in advance, so you can renew or replace credentials before access is interrupted.

Cookies

Essential ones keep the service running. The rest only with your consent. Cookie Policy