Fehlercodes · ksef · Polen

KSEF-21115Hier ergänzbar

KSeF error 21115 — invalid authentication certificate

So lautet die Ablehnung wörtlich: „[KSEF-21115] KSEF-21115 ("Nieprawidłowy certyfikat" / invalid certificate) is a gateway error returned during authentication, before any invoice is processed. The KSeF 2.0 API rejected the certificate presented to establish the session, so the connection is never authorised and no document reaches schema or business validation. It is an integration/credential problem, not a fault in the invoice XML — the same certificate fails for every document until it is corrected.“

On KSeF 2.0 the most common driver is presenting a certificate that is not a valid authentication certificate for the current platform. Causes: (1) a certificate generated in the old User Certificate Manager (MCU) — KSeF 2.0 consistently rejects MCU certificates with 21115; (2) a certificate from the previous KSeF 1.0 architecture, not supported in 2.0; (3) the wrong certificate type in the authorisation form, e.g. a KSeF offline-type certificate used for authentication instead of the dedicated authentication certificate; (4) an environment mismatch, where a Demo certificate is used against Production (or vice versa). The rejection happens at the authentication handshake, so it relates to the session, not a specific invoice.

Was Sie bereithaltenDen fehlenden Wert aus Ihrer Bestellung, Ihrem Vertrag oder Ihrer Buchhaltung.
Was wir tunTreat this as a credentials/configuration fix, not an invoice fix. Verify which certificate is loaded in the KSeF integration settings and confirm it is a current KSeF 2.0 authentication certificate — not MCU-generated, not KSeF 1.0, not an offline-type certificate. Confirm the environment matches (Demo cert → Demo endpoint, Production cert → Production). If the certificate is the wrong type or origin, generate a new authentication certificate and re-upload it. As an alternative you can authenticate with a qualified electronic signature or trusted profile (profil zaufany), or grant token-based permissions to the integrating service. This cannot be auto-fixed from invoice data, so Invoice Navigator surfaces 21115 to the integrator with the likely cause.
Wenn Sie es selbst im Rechnungssystem eintragen
Vorher
Authentication request signed with an MCU / KSeF 1.0 certificate
→ KSeF 2.0 responds: 21115 "Nieprawidłowy certyfikat"
Nachher
Authentication request signed with a current KSeF 2.0 authentication certificate
(correct environment: Demo cert → Demo, Prod cert → Prod)
→ session authorised, invoices proceed to validation
So sieht der Befund ausBeispiel
BefundAngabe fehlt · KSEF-21115
Von IhnenDer fehlende Wert
DanachBestanden
NachweisSHA-256 und /verify-Link nach der Prüfung