Skip to content
eFacturaSPV

ANAF e-Factura · OAuth 2.0

Connect ANAF once over OAuth 2.0. Then it runs unattended.

Authorize ANAF a single time with your USB token. After that, eFacturaSPV runs on ANAF’s official OAuth 2.0 tokens — auto-renewed 90-day access and 365-day refresh — pulling your received invoices from SPV with no one watching.

  • The USB certificate is used once, at authorization
  • 90-day access / 365-day refresh tokens, renewed automatically
  • Direct to ANAF — no middleman, nothing to keep plugged in

Free to start · no card · ANAF connection over official OAuth 2.0

Imagine ilustrativă a aplicației. Facturile și denumirile firmelor sunt exemple, nu date reale.
ANAF OAuth 2.0, made self-serve

The connection model is the same for everyone. A tool you set up yourself was the missing piece.

Search for “ANAF e-Factura OAuth” and you mostly find tax advisories and enterprise EDI vendors quoting integration projects. The OAuth 2.0 mechanism itself is simple — authorize once, run on auto-renewing tokens. eFacturaSPV is the lightweight option you connect yourself in minutes, then leave running.

The connection model

How the ANAF OAuth 2.0 connection actually works

ANAF authorizes you once with your qualified certificate, then hands back tokens that do the day-to-day work. Here is what that means in practice.

The certificate is used once

Your qualified certificate — USB token or cloud certificate — only signs in at the ANAF authorization screen. From that moment the platform runs on tokens, not on the certificate, so nothing has to stay plugged in.

90-day access, 365-day refresh

ANAF’s OAuth 2.0 issues a short-lived access token (about 90 days) and a long-lived refresh token (about 365 days). The access token does the work; the refresh token mints the next one before it lapses.

Rotated and saved before they lapse

We rotate both tokens on every renewal and persist them immediately, so a renewal that arrives mid-sync never orphans the connection. This is exactly where most ANAF integrations quietly die — and where we don’t.

One grant → every CUI

A single authorization covers every CUI your certificate is enrolled for in SPV. One grant feeds multiple workspaces and bulk-imports the companies it can act for — built for groups and accountants.

Direct to ANAF, no middleman

We connect straight to ANAF’s OAuth endpoints and pull invoices from the source. We don’t resell someone else’s access and we don’t route your fiscal data through a third party.

Unattended, observable pulls

With the token chain healthy, pulls run on a schedule with no one watching. You still see exactly what was downloaded, skipped or failed — each failure shows the invoice and ANAF’s own message.

ANAF keeps a received invoice downloadable in SPV for roughly 60 days, then the API can no longer return it — to anyone. Yet you must retain each invoice for 5 years. An OAuth connection that lapses silently means missed pulls you only notice once the document is gone, which is exactly why auto-renewed tokens and unattended pulls are the whole point.

How it connects

One USB-token authorization, then everything on OAuth

The qualified certificate steps in a single time. The rest runs on ANAF’s official OAuth 2.0 mechanism.

01

Authorize once with your USB token

You tap your qualified certificate (USB token) a single time and approve access through ANAF’s official OAuth 2.0 flow. The certificate is only needed here, at authorization — then it goes back in the drawer.

02

We run on ANAF’s OAuth tokens

After you authorize, we hold ANAF’s official tokens — a 90-day access token and a 365-day refresh token — exactly the mechanism ANAF prescribes. No certificate has to stay plugged in.

03

Tokens auto-renew, unattended

Both the access and refresh tokens rotate on every renewal and are saved immediately, so the chain never breaks. The connection stays alive on its own — you never re-authorize by hand.

Why eFacturaSPV

A connection built to stay alive, not to be babysat

Four things that make the difference between a connection you set up once and one you keep nursing.

Official ANAF PDF

You get the same official PDF ANAF generates from the invoice — the one a tax inspector sees, not a third-party re-render.

One USB tap, then unattended

The USB certificate is used once, at authorization. After that it runs on its own, with the connection renewed automatically.

One certificate → every company

A single authorization covers every CUI your certificate is enrolled for. Company switching, bulk import, team invites — built for accountants.

Archive to your own Drive

Folders by year and month in your own Google Drive. Your data stays yours, and the 5-year retention duty is covered.

Auto-renewed tokens

Authorize once. The token chain renews itself.

The classic failure of any ANAF connection is a token that expires and stops the sync. We rotate the access and refresh tokens automatically and save them the instant they change, so you never end up with a dead connection you didn’t know about.

How the ANAF connection works
ANAF connection · OAuth 2.0
Authorize with USB token once
Access token 90 days
Refresh token 365 days
Auto-renewal active

One grant, every company

One authorization covers every CUI on your certificate

If your qualified certificate is enrolled in SPV for several CUIs — common for groups, holdings and the accountants who service them — a single OAuth grant imports them all. Switch between companies from one login and invite the people who handle them, with owner and member roles.

How automatic download works
One grant · multiple CUIs
RO 14820 — Holding SRL bound
RO 28315 — Trading SRL bound
RO 39044 — Logistics SRL bound

ANAF returns the list of CUIs the certificate can act for, so the right to a company is verified at the source — never assumed.

FAQ

Frequently asked questions

Do I need the USB token every time?
No. The USB certificate is used once, at authorization. After that the connection runs on ANAF’s official OAuth 2.0 tokens (90-day access / 365-day refresh), which we renew automatically — you never touch the token again.
What happens when the ANAF token expires?
We renew it before it becomes a problem. The refresh token mints a new access token, both are rotated and saved immediately, and the connection keeps running. This is exactly where most ANAF integrations fail silently — with us it is handled automatically.
Do I need a cloud certificate, or does a USB token work?
Either works. ANAF’s OAuth flow accepts a qualified certificate as a USB token or as a cloud certificate. You sign in once at ANAF’s login screen; afterwards everything runs on tokens, with nothing plugged in.
Are you a middleman between me and ANAF?
No. We connect directly to ANAF over its official OAuth 2.0 endpoints and download invoices from the source. We don’t resell anyone’s access and we don’t route your fiscal data through another service.
Can one certificate connect several companies?
Yes. A single authorization covers every CUI your certificate is enrolled for in SPV. One grant can feed multiple workspaces, and the authorized companies can be bulk-imported from a single sign-in — built for accounting firms.
Does the connection run without me?
Yes. Once authorized, pulls run on a schedule, unattended. You still get real-time progress and a clear record of what was downloaded, skipped or failed, with ANAF’s own message on each failure.
How far back can the connection pull invoices?
60 days — that is ANAF’s retention limit in SPV. Older than that, the API can no longer return the invoice to anyone, which is why we pull and archive to your own Google Drive automatically, before documents disappear.

Connect ANAF once. The token renewal is on us.

Official OAuth 2.0, tokens renewed automatically, direct to ANAF. Your first company is free, forever.

Free to start · no card · direct ANAF connection over OAuth 2.0

Start free

No card · your first company stays free

Start

Each option starts exactly what it says. Anything you leave unticked does not start. You can change your mind at any time.

Strictly necessary

They remember the choice you make here, so we stop asking, and keep you signed in to the app. The site does not work without them.

Cannot be turned off