Error codes · ksef · Poland
KSeF authentication token is invalid
This is the rejection, word for word: „[KSEF-21116] KSeF error 21116 ("Nieprawidłowy token") is returned when the AuthorisationToken supplied to /online/Session/InitToken does not match a valid, active token issued for the target NIP context. Unlike 21170 (session expired) or 21302 (token inactive), 21116 means KSeF cannot recognise the token at all — wrong value, wrong environment, or wrong context.“
KSeF supports two authentication paths: signed challenge (qualified electronic signature or personal seal) and token-based (a token issued via /online/Credentials/GenerateToken). Tokens are context-bound: a token generated for NIP A cannot authenticate for NIP B, and a token generated in the test environment cannot authenticate against production. The AuthorisationToken is included in the signed InitToken payload as base64-encoded plaintext.