🇵🇱 KSEF-21115: KSeF error 21115 — invalid authentication certificate in Poland
KSEF-21115 ("Nieprawidłowy certyfikat" / invalid certificate) is a gateway error returned during authentication, before any invoice is processed. The KSeF 2.0 API rejected the certificate presented to establish the session, so the connection is never authorised and no document reaches schema or business validation. It is an integration/credential problem, not a fault in the invoice XML — the same certificate fails for every document until it is corrected.
Why This Matters in Poland
Poland requires e-invoicing using KSeF XML format. Invoices with this error will be rejected. They cannot be processed for Poland compliance.
How to Fix KSEF-21115
Treat this as a credentials/configuration fix, not an invoice fix. Verify which certificate is loaded in the KSeF integration settings and confirm it is a current KSeF 2.0 authentication certificate — not MCU-generated, not KSeF 1.0, not an offline-type certificate. Confirm the environment matches (Demo cert → Demo endpoint, Production cert → Production). If the certificate is the wrong type or origin, generate a new authentication certificate and re-upload it. As an alternative you can authenticate with a qualified electronic signature or trusted profile (profil zaufany), or grant token-based permissions to the integrating service. This cannot be auto-fixed from invoice data, so Invoice Navigator surfaces 21115 to the integrator with the likely cause.
Example: Before & After
Authentication request signed with an MCU / KSeF 1.0 certificate → KSeF 2.0 responds: 21115 "Nieprawidłowy certyfikat"
Authentication request signed with a current KSeF 2.0 authentication certificate (correct environment: Demo cert → Demo, Prod cert → Prod) → session authorised, invoices proceed to validation
Poland E-Invoicing Requirements
Common Causes
- •An MCU or KSeF 1.0 certificate, an offline-type certificate used for authentication, or a Demo/Production environment mismatch.
Fix KSEF-21115 automatically
Upload your invoice and let Invoice Navigator auto-remediate this error.