Skip to content

KSeF configuration

Connecting the clinic to the National e-Invoice System: a token from the KSeF portal, the choice of test or production environment, a connection test and a view of submission status.

Required permissions:
Clinic Admin
Reviewed: 2026-08-24

The KSeF Configuration screen does one thing: "Connect to the National e-Invoice System (KSeF) to submit invoices electronically". You do not generate the token here but in the KSeF portal — Heltio stores it and uses it on every submission.

At the top of the screen stands a reminder: "KSeF is mandatory for B2B VAT transactions from 1 February 2026. Medical services exempt from VAT (zw.) are still submitted to KSeF but with BrakID flag for anonymous patients".

Open the KSeF configuration

How to do it

01

Generate a token in the KSeF portal

The token is created on the Ministry of Finance's side. The field in Heltio says it outright: "Generate this token in the KSeF portal under API Keys". Generate it for the same NIP you issue invoices under.

02

Choose an environment

The API Access section offers two options:

  • Sandbox (Test) — "Test environment. Safe to use with real credentials".
  • Production — "Live KSeF. Invoices submitted here are legally binding".

Once production is picked, the screen shows a warning: "Production mode: invoices submitted here create legal obligations". A test token will not work in production or the other way round — they are two separate tokens.

The screen sits in the clinic settings and has a fixed layout: (1) the list of entries on the left — KSeF Configuration sits in the Billing & Fiscal Setup group, (2) the API Access section with the environment choice, (3) the token field, (4) saving the change.

Konto demonstracyjne — dane przykładowe, nie są to dane rzeczywistePayment ProvidersInsurersBank PayoutsKSeF ConfigurationP1 integrationSubscription & BillingKSeF ConfigurationZapiszSekcja ANazwa gabinetunp. Gabinet Rehabilitacji...NIP000-000-00-00Adresul. Przykładowa 1, 00-001 WarszawaSekcja BTelefon kontaktowy+48 000 000 000E-mail gabinetugabinet@przykład.pl1The list of entries2API Access3Token4Save
The environment and the token are one pair — a sandbox token will not work in a production configuration, so changing the environment always means swapping the token.
03

Paste the token and save

The KSeF API Token field accepts a pasted value and never shows it again. After saving, the same place reads Token is set, with a Replace token button next to it for rotation.

04

Test the connection

Test Connection opens and closes a session in KSeF. Success is acknowledged with Connection successful. KSeF is reachable. Do this before you issue the first invoice — otherwise you find out about a bad token only on a document that has already gone into circulation.

05

Watch the System Status

The System Status panel shows four things:

  • Last successful session — or Never, if there has not been one yet.
  • Token healthValid, Expiring soon or Expired or invalid.
  • Offline queue — how many invoices are waiting to be resubmitted.
  • EnvironmentSandbox or Production.

The Retry failed submissions button goes back to invoices that were rejected or held in offline mode; it is confirmed by Failed submissions queued for retry.

When something does not work

Error

KSeF token not configured

What this means: **Test Connection** was clicked before any token was saved. This message comes straight from the server and is not translated.

What to do: Paste the token into the **KSeF API Token** field, click **Save**, and only then test.
Error

Expired or invalid

What this means: The token health in the **System Status** panel. The token has expired, was revoked in the KSeF portal, or belongs to the other environment.

What to do: Generate a new token in the KSeF portal, click **Replace token**, save and test the connection. While you are there, check that the selected environment matches the token.
Warning

KSeF rejected this invoice. Issue a correction to fix and resubmit.

What this means: The document reached KSeF and was rejected — most often over the buyer's details or a mismatched NIP.

What to do: An invoice, accepted or rejected, is never edited in place. Issue a correcting invoice; **Retry failed submissions** will send it again.
Warning

Offline mode

What this means: An invoice status on the list. The hint above it explains: KSeF was unavailable at the moment of issuing, the document is waiting in the queue, and the grace period is 7 days.

What to do: Nothing has to be done right away — Heltio retries by itself. Do watch the **Offline queue** counter, though: after seven days the invoice needs a correction, not another attempt.
Error

Could not load KSeF settings.

What this means: The screen received no answer from the server.

What to do: Click the retry link under the message. If the error returns, check whether your plan covers KSeF submission — below the **Gabinet** plan this entry is not available.

Who has access

Clinic Admin

"KSeF configuration is restricted to Clinic Admins". Other roles see a padlock on the screen and are sent to an administrator. Saving the token is recorded in the audit log.

Invoices arriving from suppliers land separately, in the KSeF Inbox.

Open the KSeF Inbox

Was this article helpful?

Didn't find an answer? Write to us.

Open the contact form