How to Generate a KSeF Certificate? Step-by-Step Guide
The KSeF certificate is an electronic proof of identity issued free of charge by Poland's National e-Invoicing System (KSeF). It is required for issuing invoices in offline modes (offline24, system outage) — it is used to generate the second "CERTYFIKAT" QR code on the invoice. Importantly, from 1 January 2027 certificates will fully replace authorisation tokens, so every business integrated with KSeF should generate a certificate before the end of 2026.
This guide walks you through the whole process step by step, using screenshots from the official KSeF 2.0 Taxpayer Application user manual published by the Ministry of Finance.
Before you start — key facts
- The certificate is free and valid for 2 years from its start date.
- There are two certificate purposes, requested separately:
- Issuer verification link signature — for marking invoices with QR codes in offline modes,
- Authentication in the KSeF system — for logging in and system integrations (the successor of tokens).
- A certificate does not carry permissions — it is purely a means of authentication. KSeF permissions must be granted separately.
- The authentication method used at login (and the NIP or PESEL it contains) determines which identifier the certificate is issued for.
Step 1. Log in to the KSeF 2.0 Taxpayer Application
Open the KSeF 2.0 Taxpayer Application (available from podatki.gov.pl) and authenticate — with a Trusted Profile (the simplest method for sole traders), a qualified electronic signature or a qualified seal. Then select the working context, i.e. the NIP of the company you want the certificate for.
On the application's main screen, click the "Wnioskuj o certyfikat" (Request a certificate) tile to begin.
Step 2. Generate the key and the certificate request
In the first step, the application generates a key pair: a public key (attached to the request) and a private key (which stays only with you).

Fill in the fields:
- Certificate name — 5 to 100 characters; the private key and the certificate will be saved under this name.
- Password — protects the private key. It must be 15 to 32 characters long and contain an upper- and lower-case letter (no Polish diacritics), a digit and one of the special characters
!@#$%^&*()-_=+. - Repeat the password and click Generuj (Generate).
Note: the password cannot be reset — store it in a safe place (e.g. a password manager). The private key is automatically saved on your device as a .key file (e.g. moj_certyfikat.key).
Step 3. Submit the certificate request
In the second step, choose the certificate purpose and the validity start date.

- Certificate purpose — "Podpis linku weryfikacyjnego wystawcy" (issuer verification link signature, i.e. offline QR codes) or "Uwierzytelnienie w systemie KSeF" (authentication). If you need both, go through the process twice.
- Valid from — defaults to the current date; the certificate is valid for 2 years from that date. When renewing, it is best to set the day after your current certificate expires.
Click Wyślij wniosek o wydanie certyfikatu (Submit the certificate request).
Step 4. Wait for issuance and download the certificate
The request is usually processed within a few minutes. Click Odśwież (Refresh) to check the status.

Once completed successfully, you will see a confirmation. Click Pobierz certyfikat (Download certificate) to save it to your device (PEM format, a .crt file).

Important: only the certificate with the public key can be downloaded from KSeF. If you lose the private key (the .key file) or its password, they cannot be recovered from the system — you will have to generate a new certificate.
Managing certificates — list, download, revocation
All issued certificates are shown on the Lista certyfikatów (Certificate list) screen. There you can check the serial number, purpose, status and validity dates, re-download the certificate (PEM) or revoke it.

If the private key may have been compromised, revoke the certificate immediately: select it on the list, click Unieważnij (Revoke), choose the reason and confirm. This operation cannot be undone.

Frequently asked questions
How much does a KSeF certificate cost? Nothing — it is issued free of charge by the KSeF system.
How long is it valid? Up to 2 years from the start date; after that a new one must be generated.
Can I generate a certificate through my accounting software? Yes — the request can also be submitted via the KSeF 2.0 API; most accounting software providers and integrators offer this feature.
What about tokens? Authorisation tokens work only until 31 December 2026. From 1 January 2027, KSeF certificates will be the only method of automated authentication.
Summary
Generating a KSeF certificate takes about fifteen minutes: log in to the KSeF 2.0 Taxpayer Application, set a name and password, choose the purpose, submit the request and download the file. The crucial part is keeping the private key and password safe — without them the certificate is useless, and the system cannot recover them for you.
The basics of the system are explained in What is KSeF?, and invoicing is covered in How to issue an invoice?. If you would rather have someone handle certificates, permissions and KSeF invoicing for you — contact the LinTax accounting office.
Screenshots come from the official KSeF 2.0 Taxpayer Application user manual (Ministry of Finance, version 2.4, June 2026).