ANAF e-Factura · OAuth 2.0
Connect ANAF once over OAuth 2.0. Then it runs unattended.
Authorize ANAF a single time with your USB token. After that, eFacturaSPV runs on ANAF’s official OAuth 2.0 tokens — auto-renewed 90-day access and 365-day refresh — pulling your received invoices from SPV with no one watching.
- The USB certificate is used once, at authorization
- 90-day access / 365-day refresh tokens, renewed automatically
- Direct to ANAF — no middleman, nothing to keep plugged in
Free to start · no card · ANAF connection over official OAuth 2.0
The connection model is the same for everyone. A tool you set up yourself was the missing piece.
Search for “ANAF e-Factura OAuth” and you mostly find tax advisories and enterprise EDI vendors quoting integration projects. The OAuth 2.0 mechanism itself is simple — authorize once, run on auto-renewing tokens. eFacturaSPV is the lightweight option you connect yourself in minutes, then leave running.
The connection model
How the ANAF OAuth 2.0 connection actually works
ANAF authorizes you once with your qualified certificate, then hands back tokens that do the day-to-day work. Here is what that means in practice.
The certificate is used once
Your qualified certificate — USB token or cloud certificate — only signs in at the ANAF authorization screen. From that moment the platform runs on tokens, not on the certificate, so nothing has to stay plugged in.
90-day access, 365-day refresh
ANAF’s OAuth 2.0 issues a short-lived access token (about 90 days) and a long-lived refresh token (about 365 days). The access token does the work; the refresh token mints the next one before it lapses.
Rotated and saved before they lapse
We rotate both tokens on every renewal and persist them immediately, so a renewal that arrives mid-sync never orphans the connection. This is exactly where most ANAF integrations quietly die — and where we don’t.
One grant → every CUI
A single authorization covers every CUI your certificate is enrolled for in SPV. One grant feeds multiple workspaces and bulk-imports the companies it can act for — built for groups and accountants.
Direct to ANAF, no middleman
We connect straight to ANAF’s OAuth endpoints and pull invoices from the source. We don’t resell someone else’s access and we don’t route your fiscal data through a third party.
Unattended, observable pulls
With the token chain healthy, pulls run on a schedule with no one watching. You still see exactly what was downloaded, skipped or failed — each failure shows the invoice and ANAF’s own message.
ANAF keeps a received invoice downloadable in SPV for roughly 60 days, then the API can no longer return it — to anyone. Yet you must retain each invoice for 5 years. An OAuth connection that lapses silently means missed pulls you only notice once the document is gone, which is exactly why auto-renewed tokens and unattended pulls are the whole point.
How it connects
One USB-token authorization, then everything on OAuth
The qualified certificate steps in a single time. The rest runs on ANAF’s official OAuth 2.0 mechanism.
Authorize once with your USB token
You tap your qualified certificate (USB token) a single time and approve access through ANAF’s official OAuth 2.0 flow. The certificate is only needed here, at authorization — then it goes back in the drawer.
We run on ANAF’s OAuth tokens
After you authorize, we hold ANAF’s official tokens — a 90-day access token and a 365-day refresh token — exactly the mechanism ANAF prescribes. No certificate has to stay plugged in.
Tokens auto-renew, unattended
Both the access and refresh tokens rotate on every renewal and are saved immediately, so the chain never breaks. The connection stays alive on its own — you never re-authorize by hand.
Why eFacturaSPV
A connection built to stay alive, not to be babysat
Four things that make the difference between a connection you set up once and one you keep nursing.
Official ANAF PDF
You get the same official PDF ANAF generates from the invoice — the one a tax inspector sees, not a third-party re-render.
One USB tap, then unattended
The USB certificate is used once, at authorization. After that it runs on its own, with the connection renewed automatically.
One certificate → every company
A single authorization covers every CUI your certificate is enrolled for. Company switching, bulk import, team invites — built for accountants.
Archive to your own Drive
Folders by year and month in your own Google Drive. Your data stays yours, and the 5-year retention duty is covered.
Auto-renewed tokens
Authorize once. The token chain renews itself.
The classic failure of any ANAF connection is a token that expires and stops the sync. We rotate the access and refresh tokens automatically and save them the instant they change, so you never end up with a dead connection you didn’t know about.
How the ANAF connection worksOne grant, every company
One authorization covers every CUI on your certificate
If your qualified certificate is enrolled in SPV for several CUIs — common for groups, holdings and the accountants who service them — a single OAuth grant imports them all. Switch between companies from one login and invite the people who handle them, with owner and member roles.
How automatic download worksANAF returns the list of CUIs the certificate can act for, so the right to a company is verified at the source — never assumed.
FAQ
Frequently asked questions
Do I need the USB token every time?
What happens when the ANAF token expires?
Do I need a cloud certificate, or does a USB token work?
Are you a middleman between me and ANAF?
Can one certificate connect several companies?
Does the connection run without me?
How far back can the connection pull invoices?
Connect ANAF once. The token renewal is on us.
Official OAuth 2.0, tokens renewed automatically, direct to ANAF. Your first company is free, forever.
Free to start · no card · direct ANAF connection over OAuth 2.0