The KSeF certificate: type 1 and type 2, how to get one and when you need it
Type 1 signs you in, type 2 marks offline invoices — one certificate will not do both. How to obtain one, whose data it carries, and when it is genuinely required.
A KSeF certificate is one of the methods of authenticating to the system. It is also required to mark an invoice with the code that confirms the issuer's identity when issuing in the special modes.
There are two types and they are not interchangeable. Type 1 signs you in, type 2 marks offline invoices — and one certificate will not serve both purposes.
This guide covers both types, the path to obtaining one, the decision about whose data it carries, and the difference between a certificate and a token.
What a KSeF certificate is for
It has two uses, and they are what define the two types. The first is authentication: the certificate is one of the permitted ways of signing in to KSeF.
The second is marking invoices. A certificate is required to give an invoice the code that allows the issuer's identity to be confirmed, in the offline24, offline-for-unavailability and failure modes.

The scope is set out on the Ministry's KSeF certificates page. Authenticating with a certificate and using one in the special modes have been possible since 1 February 2026.
When type 2 is genuinely needed
When you hand the invoice to the buyer outside KSeF before transmitting it to the system. Such a document needs two QR codes: one marked OFFLINE and one marked CERTYFIKAT.
The second of those is generated from a type 2 certificate. Once the invoice has been transmitted and numbered, the visualisation carries one code.
We cover the whole mechanism in the piece on the offline24 mode. If you send invoices online only, you will not need this type.
Why this type exists at all
The Ministry explains it in terms of continuity. Certificates are meant to ensure the invoicing process carries on regardless of external circumstances.
Without the issuer-confirming code, an invoice given to a customer before transmission would leave them no way to check who actually issued it.
Which is why type 2 belongs to the offline modes rather than to everyday sending. It answers the situation where KSeF cannot confirm the document straight away.
How to tell which certificate you have
Both types are generated separately, through separate requests. There is no way to generate a single certificate covering both uses at once.
To make them easier to tell apart, the Ministry appends the purpose to the CN attribute.

That is a technical tell, not a filename. Whatever you name the certificate when you save it to disk does not change its type.
How to obtain a KSeF certificate
Since February 2026, requesting and downloading a certificate has worked through the KSeF 2.0 API and the KSeF 2.0 taxpayer application.
Before that, from November 2025 to the end of January 2026, generation happened in the Certificates and Permissions Module. Permissions granted in that module were carried over to KSeF 2.0.

To request a certificate you must authenticate to KSeF as the taxpayer or as an authorised person. A trusted signature, a qualified electronic signature or a qualified seal will do it.
The request carries the data of the person or entity matching the identity authenticated at the moment it is submitted. An entity authenticated with a KSeF certificate may also request another.
How long issuance takes
The Ministry publishes no guaranteed processing time for a request. The certificate becomes available to download once the request has been processed correctly.
The practical conclusion is simple: do not leave this to the day you need the certificate. Submit the request as soon as you know type 2 applies to you.
Only the person who requested a certificate can download it. The Certificates and Permissions Module page covers context and permissions.
Is a certificate mandatory
It is not the only authentication method, and not every seller will need one. What decides it is how you issue and deliver your invoices.
If you issue invoices in the offline modes and hand them to buyers before transmission, a type 2 certificate is essential.
If your integration authenticates with a token and sends invoices online, no certificate is required. We come back to that distinction below.
Whose certificate to issue
A certificate can be issued to a natural person identified by a NIP, as with a sole trader, or by a PESEL number, provided they hold some permission to use KSeF.
It can also be issued to a non-natural entity that has a NIP — a limited company, say — after authenticating with a qualified seal.

This decision has a visible consequence. When an invoice is issued by a person using a certificate carrying the company's data, only the company's data is visible in KSeF.
When certificates are issued to employees, KSeF shows the data of the individual who issued the document while acting for the company.
A personal certificate can only be downloaded by that person
Certificates carrying personal data are a form of identity credential. Only that person may request such a certificate, and only they may download it.
Certificates issued on an entity's data work differently — they are not tied to specific individuals. Responsibility for passing them on and using them then sits with the company.
So with company certificates, keep a register from day one: who downloaded them, who they were given to, and when they were revoked.
A certificate and a token are not the same
Tokens remain a permitted authentication method. They are not, however, functionally equivalent to certificates.

A token contains the taxpayer's permissions, declared at the moment it is generated. A KSeF certificate is purely a means of authentication — much like a qualified signature.
Once signed in with a certificate, the permissions taken into account are those tied to the tax identifier recorded on it. The system also honours the link between a NIP and a PESEL.
Tokens will be kept indefinitely
Under the original plan, tokens were to be available as an authentication method only to the end of 2026.
The Ministry decided instead to keep them indefinitely, taking account of what businesses and software vendors need. It announced that the regulation will be amended accordingly.
For a seller that means one thing: if your integration runs on a token, there is no deadline by which you must move to a certificate.
How long a certificate stays valid
A KSeF certificate is valid for no longer than 2 years from the date it was created, or from a start date the taxpayer specifies.

Changes to the holder's permissions have no bearing on the certificate's validity. One certificate can be used to work in different contexts, that is on behalf of different entities.
For offline invoices, having no valid type 2 certificate does not stop you issuing the document. It does stop you marking it with the issuer-confirming code.
Do you need a certificate to send invoices from easySales
No. Our integration authenticates to KSeF with a token and transmits invoices in the online mode.

We record the submission status on the order, the KSeF number and the UPO, and show rejection messages against the document. The verification link that goes into the QR code on the PDF is built too.
What we do not do is issue invoices in the offline modes or generate the CERTYFIKAT code. Those modes are handled by the software the invoice is created in.
What software needs to be able to do to use a certificate
To use a KSeF certificate, a commercial system has to implement XAdES-BES signing for the purpose of authenticating to the API.
Issuing offline invoices additionally needs a mechanism for generating the link that verifies the invoice issuer. Those are requirements on the software, not on you.
Worth knowing too that a certificate will not authenticate you in the KSeF taxpayer application. That route stays with the other methods.
The integration page covers the scope of our KSeF handling, and numbers and receipts sit in the piece on the KSeF number and the UPO.
A checklist before you start
Settle these seven things before generating any certificates
- Whether you issue invoices in the offline modes at all — if not, type 2 is not needed.
- Which type matches your use, and for both, two separate requests.
- Whether the certificate should carry the company's data or specific individuals'.
- Who in the business is accountable for downloading, handing over and revoking.
- The start date of validity, and a reminder set well before expiry.
- Whether your software supports XAdES-BES signing and the issuer-verification link.
- What each integration that sends your invoices authenticates with.
Start with the first point, because it settles the rest. A seller who sends invoices online only answers "no" and closes the topic.
Whether a given obligation and mode apply to your sales is a question for your accountant. What we describe is what a certificate does technically and what an integration needs.