Skip to content
UITDesk — Generate. Comply. Move Forward.
Guide

ANAF Digital Certificate e-Transport: SPV Access and Tokens

ANAF digital certificate for e-Transport: the qualified certificate, SPV enrolment, power of attorney, and the OAuth token that lets software send declarations.

8 min readPublished 10 September 2026

An ANAF digital certificate for e-Transport is a qualified certificate, held on a physical device by a named person, that proves who that person is to ANAF. It does two jobs. It enrols the person in the Virtual Private Space (SPV) for a company, which is what creates the right to declare for that tax number. And it is presented once at ANAF’s login page to obtain an OAuth token, which is what an application uses afterwards to send declarations. The certificate identifies the person; the token carries the session; the right belongs to the pairing of person and company, and ANAF re-checks it on every call.

ANAF digital certificate for e-Transport: what do you need first?

Three things, in this order. Skipping one is the usual reason a first declaration never leaves.

Step What it is Who holds it
Qualified digital certificate A certificate on a physical device from an accredited Romanian provider A named person
SPV enrolment That person registered in the Virtual Private Space for the company’s tax number Person + company
Sending channel The SPV form filled by hand, or an application holding an OAuth token The company

The system this feeds into, and what it asks for, is set out in the RO e-Transport overview. The certificate part is the same one used for every other ANAF filing, so many companies already have it and do not realise it also covers e-Transport.

How do you get a qualified certificate and enrol in SPV?

Buy the certificate from an accredited provider in Romania. It arrives as a device you plug into a computer, plus middleware that asks for a PIN whenever the certificate is used. The private key stays on the device and cannot be copied off it — that is the point of a qualified certificate, and it is also why the certificate exists for your computer only while the device is plugged in.

Enrolment in SPV is a form filed with ANAF, naming the person, the certificate and the company. If the person is the legal representative, that is the whole story. If not — an accountant, a logistics manager, an external adviser — a power of attorney has to be registered with ANAF as well, and that document is what a control officer will look for if the right is ever questioned. ANAF’s enrolment pages list the current forms; they change more often than the underlying rule does.

What is the OAuth token, and who does it belong to?

The OAuth token is what an application shows ANAF instead of a certificate. You obtain it once, in a browser, at ANAF’s own login page, by presenting the qualified certificate. ANAF hands back an access token with a short life and a refresh token with a longer one. The application keeps them and renews on its own.

This is the single most misunderstood part of the whole setup, and it produces a specific failure. Someone authorises a company for which they are not enrolled in SPV. The authorisation succeeds, because the certificate is valid. The declaration is then rejected, sometimes days later, because the right on that tax number was never there. The token was never the problem.

How authorisation works in UITDesk

The application’s company record has an Authorise with ANAF button. Pressing it opens ANAF’s login page at logincert.anaf.ro in a new window. The browser asks which certificate to present, the device middleware asks for the PIN, and ANAF sends the browser back to the application with a code that is exchanged for the token. The whole thing takes under a minute when the device is plugged in.

What happens next is worth stating plainly, because it is where a web application and a desktop one differ. The declarations are sent by the server, not by your browser. Your certificate never reaches the server and never needs to: after the authorisation step, the token is what signs the calls to ANAF. There is no point in leaving the device plugged in for sending, and no way to make a server use a certificate sitting on your desk.

Two environments exist at ANAF, test and production, and both are ANAF’s. There is no simulator anywhere in the chain — a code that looks like a UIT code is either from ANAF or it is not a code at all.

Why authorisation fails, and the browser trap

ANAF answers a failed authorisation with access_denied. That is a code, not a diagnosis. It comes from logincert.anaf.ro whenever no acceptable certificate reached it, and the three causes look identical from the outside:

  • the certificate device is not plugged in, or the middleware is not running;
  • the certificate selection window was closed, dismissed or timed out;
  • the certificate is valid but has no rights in SPV for that company.

That behaviour costs more time than any other single point in the setup, because it turns a one-off mistake into a permanent-looking failure. If the first attempt of the day went wrong and every attempt since has failed in under a second, it is the browser answering, not ANAF.

Renewing, revoking and the multi-company case

Renewal happens by itself as long as the refresh token is there. An application that stores it obtains new access tokens without asking for the certificate again. What ends this is deleting the authorisation, or the certificate expiring — qualified certificates are issued for a fixed term and have to be replaced.

Deleting the authorisation is deliberate. It removes the refresh token, so automatic renewal stops and the next declaration needs a fresh authorisation. Do it when the person leaves, when the certificate is replaced, or when a company moves to a different declarant.

One certificate can serve many companies, which is the normal arrangement for accounting firms and for groups. The person is enrolled in SPV for each tax number, with a power of attorney where they are not the legal representative, and authorises each company in turn. The rights are still checked per company at every call, so an added company is not an authorised company.

Where the standard advice fails

“Install the certificate on the server.” Common advice, and it does not work for a web application. The private key of a qualified certificate cannot be exported from its device, so it cannot be copied anywhere. The OAuth token exists precisely to solve this.

“The token expired, so the declaration failed.” Sometimes. But ANAF answers HTTP 200 to most errors, and a rights problem reads very differently from an expiry. An expired token gives 401; a missing right on the tax number gives a refusal in the body. Applications that read only the status code miss the second one entirely.

“We authorised it once, so we are set.” The right in SPV can be withdrawn, the power of attorney can lapse, and the certificate expires. None of these produce a warning in advance. The cheapest check is a call ANAF answers for free — the message list for the company — run when something changes on your side.

“Any employee can authorise.” The person who authorises is the person whose rights are used. If that employee leaves and the certificate goes with them, the declarations stop. Decide who holds the certificate before you need it, and give a second person their own enrolment.

Once authorisation is in place, the next question is how the declaration itself is built: see how to get a UIT code in Romania, or declaring in SPV by hand if you want to see what the manual route involves before choosing.

Sources: OUG 41/2022 on legislatie.just.ro; ANAF’s RO e-Transport guide (2025); technical information on mfinante.gov.ro.

Frequently asked questions

What do I need to send e-Transport declarations to ANAF?

Three things, in order: a qualified digital certificate issued to a named person, that person enrolled in ANAF's Virtual Private Space (SPV) for your company, and a way to send the declaration — the SPV form by hand, or an application authorised with an OAuth token. Without the certificate there is no SPV enrolment, and without SPV enrolment there is no right to declare for that tax number.

Does the OAuth token belong to the company or to the person?

To the person. ANAF issues the token to whoever presented the qualified digital certificate, and it says nothing about which companies that person may act for. The right on each tax number is checked separately, at every single call. This is why a token can work perfectly for one company and be refused for another one in the same account, with no change on your side.

Why does ANAF answer access_denied when I try to authorise?

access_denied is a code, not an explanation. It comes from logincert.anaf.ro when no acceptable certificate reached it: the device is not plugged in, the certificate selection window was closed or dismissed, or the certificate has no rights in the Virtual Private Space for that company. Check all three before assuming the application is broken — the message is identical in every case.

The certificate dialog never appears again. What happened?

Chrome and Edge remember a refusal. Once you close the certificate selection window without choosing, the browser records "no certificate" for logincert.anaf.ro and keeps that answer for as long as the browser is running. Every later attempt then fails instantly, for any company, even with the device plugged in. Close every window of that browser and start it again.

How long does an ANAF OAuth token last, and does it renew?

An access token has a short life, and a longer-lived refresh token is issued alongside it so the application can obtain new access tokens without asking you for the certificate again. An application that keeps the refresh token renews on its own. If you delete the authorisation, the refresh token goes with it and the next declaration needs a fresh trip through logincert.anaf.ro.

Can one certificate serve several companies?

Yes, if the person holding it is enrolled in SPV for each of them, with a power of attorney where they are not the legal representative. An accounting firm typically holds one certificate and a power of attorney for each client. The rights are still checked per tax number at each call, so adding a company in your software does not by itself grant the right to declare for it.

Can I use my own certificate from my own computer with a web application?

No. A web application sends declarations from its server, and the server cannot reach the certificate device plugged into your desk. The browser is used only for the authorisation step, at ANAF's own login page, where your certificate proves who you are and ANAF returns an OAuth token. From then on the token, not the certificate, signs the calls.

Read next

Your first UIT code in 5 minutes

Account, company, ANAF authorisation with your digital certificate, first declaration. 14 days free, no card.