KSEF-21115
Error Guide

🇵🇱 KSEF-21115: KSeF error 21115 — invalid authentication certificate in Poland

ErrorMandatoryNeeds Input

KSEF-21115 ("Nieprawidłowy certyfikat" / invalid certificate) is a gateway error returned during authentication, before any invoice is processed. The KSeF 2.0 API rejected the certificate presented to establish the session, so the connection is never authorised and no document reaches schema or business validation. It is an integration/credential problem, not a fault in the invoice XML — the same certificate fails for every document until it is corrected.

Quick Facts
Severity
Error (rejection)
Ruleset
ksef
Fix Confidence
30%
Mandate
B2B Mandatory
Fix Type
Needs input

Why This Matters in Poland

Poland requires e-invoicing using KSeF XML format. Invoices with this error will be rejected. They cannot be processed for Poland compliance.

Invoice Navigator covers 134 KSeF FA(3) rules for Poland.

How to Fix KSEF-21115

Treat this as a credentials/configuration fix, not an invoice fix. Verify which certificate is loaded in the KSeF integration settings and confirm it is a current KSeF 2.0 authentication certificate — not MCU-generated, not KSeF 1.0, not an offline-type certificate. Confirm the environment matches (Demo cert → Demo endpoint, Production cert → Production). If the certificate is the wrong type or origin, generate a new authentication certificate and re-upload it. As an alternative you can authenticate with a qualified electronic signature or trusted profile (profil zaufany), or grant token-based permissions to the integrating service. This cannot be auto-fixed from invoice data, so Invoice Navigator surfaces 21115 to the integrator with the likely cause.

Example: Before & After

Before (invalid)
Authentication request signed with an MCU / KSeF 1.0 certificate
→ KSeF 2.0 responds: 21115 "Nieprawidłowy certyfikat"
After (fixed)
Authentication request signed with a current KSeF 2.0 authentication certificate
(correct environment: Demo cert → Demo, Prod cert → Prod)
→ session authorised, invoices proceed to validation

Poland E-Invoicing Requirements

Phase
Status
Scope
KSeF voluntary
Live (Jan 2022)
All VAT payers (opt-in)
B2B mandatory — Phase 1
Live (Feb 1, 2026)
Large taxpayers (>200M PLN turnover)
B2B mandatory — Phase 2
Live (Apr 1, 2026)
All remaining VAT-registered entities (SMEs, sole proprietors, VAT-exempt businesses)
B2G
Live (Feb 1, 2026)
Included in general KSeF mandate
Financial penalties
Jan 1, 2027
Up to 100% of VAT amount on non-compliant invoices

Common Causes

  • An MCU or KSeF 1.0 certificate, an offline-type certificate used for authentication, or a Demo/Production environment mismatch.

Fix KSEF-21115 automatically

Upload your invoice and let Invoice Navigator auto-remediate this error.