Error codes · ksef · Poland

KSEF-21170Partly

KSeF interactive session has expired

This is the rejection, word for word: „[KSEF-21170] KSeF error 21170 ("Sesja interaktywna wygasła") is returned when the caller uses a session token whose validity window has elapsed. Interactive sessions have a bounded lifetime set by the Ministry of Finance (currently 2 hours from InitSession, refreshed by activity), and once expired the session cannot be resumed — a fresh authentication challenge is required.“

KSeF sessions come in two shapes: interactive (/online/Session/InitSigned or InitToken) and batch (/batch/Session/*). Interactive sessions carry a session token in the SessionToken header and are subject to both an absolute lifetime and an idle timeout. When either boundary is crossed, subsequent calls with that token return HTTP 401 and exceptionCode 21170. The session cannot be extended after expiry — the client must run AuthorisationChallenge → InitSigned/InitToken again.

What to have readyThe correct figures from your bookkeeping; we show you which field is affected.
What we doDetect 21170, discard the expired session token, run a fresh authentication challenge, and replay the failed request under the new session. Add proactive session refresh before the documented lifetime elapses.
What the finding looks likeExample
FindingNeeds your check · KSEF-21170
From youThe correct figures
ThenChecked again
ProofSHA-256 and /verify link after the check