Settings

How to replace an expiring KSeF certificate in KSeFGPT

Add the new PEM key and certificate, verify the subject and expiry date of the new record, and only then remove the old credential.

Go to the procedureWatch the video
Module
Settings
Reading time
5 min
Difficulty
Intermediate

Follow the instructions carefully and you will succeed

Published
August 29, 2026
Author
Rafał Zeidler
Format
Written guide and video

Written procedure

What you will do

You will add a new certificate credential for the same company, verify its identifier, Subject and Valid until values, and then remove only the old record.

Two certificates will be active in the list for a short time. Do not perform KSeF operations during this period. Remove the old record immediately after confirming the new one because credential selection can be nondeterministic when more than one is active.

Requirements

Before you start

Generate a new certificate for the correct entity in KSeF beforehand. Prepare the matching private key and certificate. Keep the old credential active until the new record is visible with the correct metadata.

ItemRequirement
AccessThe company owner or a user with the credentials:manage scope who can manage this company's KSeF credentials.
FilesA private key in a .key or .pem file and its matching certificate in a .crt, .cer or .pem file. Each file can be up to 1 MB.
PasswordThe key password if the private key is encrypted.
Details to compareThe old record's identifier prefix, Subject, Valid until date and Created date.
Starting pointAfter signing in, open Settings, then KSeF Connection.
Time requiredAbout 3 minutes.
Important effectSelecting the trash icon deletes the credential immediately. The interface does not ask for confirmation and does not provide an undo action.

Process recording

PT24.76S

The recording shows how to add a new PEM certificate, verify its subject and expiry date, and safely remove the old record.

How to replace an expiring KSeF certificate in KSeFGPT - video guide
01Step

Identify the old certificate

In Settings, open KSeF Connection and find the correct company card by its name and TIN. In the certificate row, note the first eight characters of the identifier shown above Created.

Check Subject and Valid until. The yellow Certificate expiring soon warning appears when the expiry date is within 30 days or has already passed.

Step 1
KSeF Connection with an expiring certificate, its subject, expiry date and identifier prefix
02Step

Open the new credential form

On the same company card, select Add credential. Under Authentication method, select Certificate if it is not already selected.

The Private key (.key), Certificate and Key password (optional) fields appear. Do not remove the old record yet.

Step 2
New credential form with Certificate selected as the authentication method
03Step

Select the new key and certificate

Under Private key (.key), select the new key file. Under Certificate, select the matching certificate file. If the key is encrypted, enter its password under Key password (optional).

Selected file and the file name appear below each input. Save PEM certificate becomes available only after both files have been loaded.

Step 3
KSeF certificate form with the private key and PEM certificate files selected
04Step

Save the new certificate

Select Save PEM certificate. The application checks the file pair and certificate subject, saves the credential, closes the form and fetches the list again.

After a successful save, two certificate rows are visible. This screen does not display a separate success message. If the new row does not appear, leave the old certificate unchanged.

Step 4
Company card in KSeFGPT showing both the old and new certificates
05Step

Compare both records

Distinguish the rows by the identifier prefix and Created date. In the new row, check Subject and Valid until. The subject should match the correct company, and the new certificate should have a later expiry date than the old one.

Do not remove the old record if the new one has no Subject or Valid until value, identifies another entity, or shows an unexpected date. Do not perform KSeF operations while both records remain active.

Step 5
Comparison of two KSeF certificates by identifier, subject and expiry date
06Step

Remove the old certificate

Compare the identifier prefix, Created date and Valid until one more time. Select the trash icon only in the old certificate row.

Deletion happens immediately, without a confirmation dialog or success message. Wait for the old row to disappear. Only the new certificate with the later expiry date should remain on the company card.

Step 6
Company card after the old certificate was removed with one new KSeF credential remaining

Final state

Check the result

The correct company card contains one row with the Certificate method. Its identifier prefix matches the new record, Subject identifies the correct company, and Valid until shows the new expiry date.

The old identifier prefix is no longer present in the list. Return to operations that require the KSeF connection only after this check.

Diagnostics

If something does not work

Compare the visible symptom with the table below.

SymptomLikely causeWhat to do
Save PEM certificate is disabledBoth files have not been loaded.Select the private key and its matching certificate separately. A password is required only for an encrypted key.
An invalid PEM format or size error appearsA file lacks BEGIN and END headers, has an unsupported extension, or exceeds 1 MB.Select the original .key or .pem key file and .crt, .cer or .pem certificate file. Do not edit the file contents manually.
The application rejects the password or file pairThe password is incorrect or the private key does not match the certificate.Use the password set during export and select files from the same pair.
The application says the TIN in the certificate does not match the companyThe certificate was issued for another entity.Do not remove the old record. Generate a certificate for the company shown on the card and add the correct file pair.
The form closed, but only the old record is visibleThe new certificate was not saved or the list did not refresh.Do not remove the old certificate. Refresh the page and add the new one again only after checking the files and your access.
The new record has no Subject or Valid until valueThe response lacks the metadata required to distinguish the certificates safely.Do not remove the old record or perform KSeF operations. Contact support and provide the new identifier prefix.
The old row remains after selecting the trash iconDeletion was not accepted or the list refresh did not finish.Do not select the trash icon in the other row. Refresh the page and try again only after identifying the old prefix.

What next

Perform a safe read operation to verify the company's KSeF connection. If authorization fails, do not remove the new record before finding the cause.

Record the new certificate expiry date in your calendar and plan the next replacement before the warning appears.

If you are setting up the connection for the first time, see How to configure a KSeF connection in KSeFGPT.

Replace the certificate without interrupting access

Sign in, add the new certificate and remove the old one only after checking its metadata.

Sign in to KSeFGPT

Related instructions

How to set AI permissions for KSeF data and operations

Select a company and decide which read and write tools AI can use. Start with Read only, then enable only the features required by your workflow.

Open instruction

How to add a company to KSeFGPT

Add a company under Settings, fetch its details from GUS using its NIP, and check the new entry under Your companies. The company name and NIP are enough to create it.

Open instruction

How to configure a KSeF connection in KSeFGPT

Connect a company to KSeF using a token or certificate. You can upload an existing certificate or configure one by signing a downloaded request with Trusted Profile.

Open instruction