In Poland every invoice to a business customer goes through the KSeF (Krajowy System e-Faktur), the state system for e-invoices. Zirko sends it there itself when you issue it. You upload nothing and copy no number — in return you store your own KSeF access once.
That is why the KSeF is preselected on the customer: the Invoice format field shows “KSeF FA(3)” with the badge “Required”. If you choose No e-invoice (PDF only) there, no invoice to this customer goes to the KSeF, and only the PDF is produced. A banner tells you on the customer and in the finalize dialog that the responsibility for that is yours.

What happens when you issue an invoice
- You issue the invoice. Zirko sends the FA(3) file to the KSeF.
- The KSeF assigns the KSeF number. It appears on the document in the KSeF field, usually within a few seconds — you can close the dialog, the transmission carries on.
- Only then is the PDF created, with the QR code KOD I and the KSeF number. Until then there is no download and no sending.
If the KSeF cannot be reached at the moment, the invoice waits, and Zirko keeps trying on its own. The document says why it is waiting.
Beforehand: the NIP
The connection is made for your business's NIP. If it is missing, enter it under Settings → Company → Business details — as the VAT identification number with the country code PL or as the tax number.
Creating the access in the KSeF
You create the access in the Aplikacja Podatnika KSeF of the Ministry of Finance, not in Zirko. There are two kinds:
- KSeF certificate (recommended). Under “Certyfikaty” you create a certificate of the type “Uwierzytelnienie”. You get a certificate file (.crt) and a private key (.key) with a password.
- KSeF token — only until 31 December 2026. Under “Tokeny” you create a token with the permissions “Wystawianie faktur” and “Przeglądanie faktur”. It is shown only once, so copy it straight away. From 1 January 2027 signing in with a token is no longer possible; store a certificate before then.
Storing it in Zirko
Under Settings → Company → Integrations you find the card KSeF (Krajowy System e-Faktur). There:
- Choose Connect KSeF.
- Choose the Access type and upload the certificate, private key and password — or paste the token.
- Check and save.
Zirko checks the access with the KSeF before it is saved. It is stored encrypted; only the e-invoice service can open it, and it never appears in any log. Afterwards the card shows Connected, with the access type and “Valid until”. Only Office – Admin can set this up.
Private customers: your choice
For private customers the KSeF is not mandatory. Whether their invoices go there anyway, you decide in three places. The choice on the invoice takes precedence over the one on the customer, and the one on the customer over the default:
| Where | What you set |
|---|---|
| KSeF card | Send invoices to private customers via the KSeF — the default, initially off |
| Customer | Send invoices via the KSeF: Business default, Yes or No |
| Invoice | Send via the KSeF when issuing |
If an invoice to a private customer does not go through the KSeF, the PDF is the invoice. Invoices to business customers go to the KSeF, unless No e-invoice (PDF only) is chosen on the customer.
If the KSeF goes down: issuing offline
For the statutory offline mode (offline24) you additionally store an offline certificate — in the Aplikacja Podatnika a KSeF certificate of the type “Offline”, in Zirko on the Offline certificate card. If an invoice is then waiting for the KSeF, you can issue it offline on the document: it immediately gets a PDF with KOD I “OFFLINE” and KOD II and can be handed over. Zirko sends it on by the next working day. This cannot be undone.
If the KSeF rejects the invoice
The document then shows Rejected by the KSeF, with the reason. In Poland a rejected invoice counts as not issued. It stays with its number as a record, and you do not cancel it. With Issue again in the KSeF field, Zirko creates a copy as a draft — correct it, issue it again, done.
Invoices from before the connection
Documents you issued before the KSeF was connected carry No KSeF number. They do not go to the KSeF on their own; with Send to the KSeF on the document you send them one by one. If one is already there, Zirko takes over the existing number.
Removing and revoking the access
Remove on the card deletes the access in Zirko. In the KSeF it stays valid until you revoke it there. For a token, tick Also revoke the token in the KSeF; a certificate you revoke in the Aplikacja Podatnika. Without access, invoices to business customers cannot be issued — except to customers for whom No e-invoice (PDF only) is chosen.
Zirko also collects your incoming invoices from the KSeF, as long as Collect incoming invoices from the KSeF is switched on — see Recording incoming invoices.