Fehlercodes · ksef · Polen
KSeF error 21115 — invalid authentication certificate
So lautet die Ablehnung wörtlich: „[KSEF-21115] KSEF-21115 ("Nieprawidłowy certyfikat" / invalid certificate) is a gateway error returned during authentication, before any invoice is processed. The KSeF 2.0 API rejected the certificate presented to establish the session, so the connection is never authorised and no document reaches schema or business validation. It is an integration/credential problem, not a fault in the invoice XML — the same certificate fails for every document until it is corrected.“
On KSeF 2.0 the most common driver is presenting a certificate that is not a valid authentication certificate for the current platform. Causes: (1) a certificate generated in the old User Certificate Manager (MCU) — KSeF 2.0 consistently rejects MCU certificates with 21115; (2) a certificate from the previous KSeF 1.0 architecture, not supported in 2.0; (3) the wrong certificate type in the authorisation form, e.g. a KSeF offline-type certificate used for authentication instead of the dedicated authentication certificate; (4) an environment mismatch, where a Demo certificate is used against Production (or vice versa). The rejection happens at the authentication handshake, so it relates to the session, not a specific invoice.
Authentication request signed with an MCU / KSeF 1.0 certificate → KSeF 2.0 responds: 21115 "Nieprawidłowy certyfikat"
Authentication request signed with a current KSeF 2.0 authentication certificate (correct environment: Demo cert → Demo, Prod cert → Prod) → session authorised, invoices proceed to validation