Error codes · ksef · Poland

KSEF-21301Partly

Missing authorization for this KSeF operation

This is the rejection, word for word: „[KSEF-21301] KSeF error 21301 ("Brak autoryzacji") is returned when the authenticated token has no permission to perform the requested action in the current NIP context. The most common trigger is attempting to issue a self-billing invoice (samofakturowanie) without an active samofakturowanie authorization on the seller's NIP, but any missing permission — invoice-write, credentials-manage, tax-representative — surfaces the same code.“

KSeF enforces a role-based permission model per NIP context. Each authorization is a signed grant recorded in KSeF that maps (grantor NIP → grantee identifier → role → validity window). Roles include invoice_read, invoice_write, credentials_read, credentials_manage, subunit_manage, and role-specific ones like samofakturowanie (self-billing) and tax_representative. 21301 fires when the caller's session has no matching active grant for the operation.

What to have readyThe correct figures from your bookkeeping; we show you which field is affected.
What we doVerify that the required KSeF authorization (invoice_write, samofakturowanie, or the specific role the endpoint requires) has been granted on the target NIP context and that the grant is still within its validity window. Grants take up to 15 minutes to propagate after issuance.
What the finding looks likeExample
FindingNeeds your check · KSEF-21301
From youThe correct figures
ThenChecked again
ProofSHA-256 and /verify link after the check