Error codes · ksef · Poland

KSEF-21116Partly

KSeF authentication token is invalid

This is the rejection, word for word: „[KSEF-21116] KSeF error 21116 ("Nieprawidłowy token") is returned when the AuthorisationToken supplied to /online/Session/InitToken does not match a valid, active token issued for the target NIP context. Unlike 21170 (session expired) or 21302 (token inactive), 21116 means KSeF cannot recognise the token at all — wrong value, wrong environment, or wrong context.“

KSeF supports two authentication paths: signed challenge (qualified electronic signature or personal seal) and token-based (a token issued via /online/Credentials/GenerateToken). Tokens are context-bound: a token generated for NIP A cannot authenticate for NIP B, and a token generated in the test environment cannot authenticate against production. The AuthorisationToken is included in the signed InitToken payload as base64-encoded plaintext.

What to have readyThe correct figures from your bookkeeping; we show you which field is affected.
What we doVerify the token value character-for-character, confirm you are calling the correct environment (test vs production), and confirm the token was generated for the exact NIP context you are authenticating against.
What the finding looks likeExample
FindingNeeds your check · KSEF-21116
From youThe correct figures
ThenChecked again
ProofSHA-256 and /verify link after the check