
What Is a Peppol Access Point? Certified APs, Four-Corner Model, AS4
Global E-Invoicing Platform Series
This guide is part of a comprehensive series. Explore all 36 topics:
A Peppol Access Point (AP) is a certified service provider that sends and receives structured business documents on the Peppol network on behalf of a participant. APs sit at corners 2 and 3 of the four-corner model: they resolve the receiver's endpoint via the Peppol SML/SMP, transmit documents over AS4 with signed non-repudiation receipts, and validate against Peppol BIS Schematron. You almost never run your own AP — you use the one operated by your invoicing platform.
At a glance
- Role: Corner 2 (sender's AP) and Corner 3 (receiver's AP) in the four-corner model
- Transport: AS4 per Peppol AS4 Profile v2.0.3
- Lookup: SML (DNS) → SMP (per-participant metadata)
- Certification: OpenPeppol AP certification, renewed annually
- Used for: invoices, credit notes, orders, despatch advices, catalogues, MLR
- Last reviewed: 23 June 2026
Why this term keeps appearing
If you read about Peppol in the EU, B2G procurement in the United States, or the upcoming Australian Peppol mandate, the term Peppol Access Point is everywhere. It is the operational unit of the Peppol network — every document on Peppol touches at least two APs.
If you read about Peppol in the EU, B2G procurement in the United States, or the upcoming Australian Peppol mandate, the term Peppol Access Point is everywhere. It is the operational unit of the Peppol network — every document on Peppol touches at least two APs.
The four-corner model
Peppol is a four-corner network:
Peppol is a four-corner network:
- Corner 1 (C1) — the sender (the invoicing application).
- Corner 2 (C2) — the sender's Access Point.
- Corner 3 (C3) — the receiver's Access Point.
- Corner 4 (C4) — the receiver (the buyer's AP/ERP system).
C1 and C4 never connect directly. C2 looks up C3 via SMP/SML, transmits over AS4, and the document lands at C4 via C3. Both APs sign non-repudiation receipts to prove delivery.
What an Access Point actually does
Identifies the receiver via SML + SMP — endpoint URL, certificate, supported document types from the receiver's Peppol Participant Identifier. Transports the document over AS4 with signed receipts that prove delivery.
- Identifies the receiver via SML + SMP — endpoint URL, certificate, supported document types from the receiver's Peppol Participant Identifier.
- Transports the document over AS4 with signed receipts that prove delivery.
- Validates outgoing documents against the Peppol BIS Billing 3.0 Schematron and incoming documents against the same rules.
- Acknowledges receipt and returns Message Level Responses (MLR) when the receiver business-rejects a document.
- Reports traffic to OpenPeppol and the national Peppol Authority for monitoring.
SMP and SML — how lookup works
The SML (Service Metadata Locator) is the DNS-backed root directory of all SMPs on the network, operated by the European Commission's DIGIT under the eDelivery building block. The SMP (Service Metadata Publisher) is per-participant metadata: endpoint URL, public-key certificate, and accepted document types.
The SML (Service Metadata Locator) is the DNS-backed root directory of all SMPs on the network, operated by the European Commission's DIGIT under the eDelivery building block. The SMP (Service Metadata Publisher) is per-participant metadata: endpoint URL, public-key certificate, and accepted document types.
Step-by-step lookup
- Sender's AP hashes the buyer's Participant Identifier and queries the SML via DNS.
- The SML returns the SMP URL for that participant.
- The sender's AP queries the SMP for the buyer's endpoint, certificate, and accepted document types.
- The sender's AP transmits over AS4 to the buyer's AP endpoint.
AS4 transport — what's on the wire
AS4 is the OASIS ebMS3 v3. 0 web-services profile, further restricted by the CEF eDelivery AS4 Profile v1.
AS4 is the OASIS ebMS3 v3.0 web-services profile, further restricted by the CEF eDelivery AS4 Profile v1.14 and then by the Peppol AS4 Profile v2.0.3. Each AS4 message includes a SOAP envelope with WS-Security headers, the UBL payload as a MIME attachment, and is signed using the AP's Peppol certificate. The receiver returns a non-repudiation receipt signed with its own certificate.
How to choose an Access Point
Confirm active OpenPeppol certification (renewed annually). Check supported document types — at minimum BIS Billing 3.
- Confirm active OpenPeppol certification (renewed annually).
- Check supported document types — at minimum BIS Billing 3.0 Invoice and Credit Note; ideally also order and despatch advice.
- Confirm jurisdictional coverage — most APs are cross-border, some restrict to specific Peppol Authorities.
- Confirm SLA — AP availability, support hours, escalation paths.
- Confirm ancillary services — Schematron validation, MLR handling, archiving, ERP connectors.
- Confirm pricing model — per-document, per-participant, or bundled with the invoicing platform.
Should I run my own Access Point?
Almost certainly not.
Almost certainly not. Running an AP requires:
- OpenPeppol AP certification, including security and conformance audits.
- Production AS4 infrastructure with HSM-backed signing keys.
- Continuous tracking of OpenPeppol eDEC policy changes (revised most months).
- Renewal of the Peppol PKI certificate annually.
Only large multinationals at very high volume or service providers reselling Peppol connectivity run their own AP. Everyone else uses the AP bundled with their invoicing platform — Invoicemonk operates as an AP for customers in scope.
What fails in production
SMP lookup miss: receiver not registered, or the wrong Participant scheme. Verify via the Peppol Directory.
- SMP lookup miss: receiver not registered, or the wrong Participant scheme. Verify via the Peppol Directory.
- Document type not declared: receiver's SMP does not advertise the type you sent. Coordinate with the buyer to add it.
- Certificate chain failure: AP's Peppol certificate has expired or the trust anchor is stale.
- Schematron failure on send: validation should be upstream of AS4 — otherwise the AP returns a hard reject.
- MLR ignored: receiver business-rejects the document; if you do not process MLR, you do not know the invoice was rejected.
- AS4 receipt loss: non-repudiation receipts must be archived alongside the signed UBL — otherwise you cannot prove delivery in a dispute.
Key takeaways
Key takeaways includes: An Access Point is the operational unit of Peppol — every document touches two. Lookup is SML → SMP; transport is AS4; the AP also validates and handles MLR.
- An Access Point is the operational unit of Peppol — every document touches two.
- Lookup is SML → SMP; transport is AS4; the AP also validates and handles MLR.
- Use the AP bundled with your invoicing platform — running your own is rarely worth it.
- The most common failure modes are SMP misses and declared-document-type mismatches, both fixed by coordination with the buyer.
Related reading
Pillar: e-invoicing. Mandate: Peppol EU.
Pillar: e-invoicing. Mandate: Peppol EU. Siblings: Peppol EU explained, how to comply with Peppol in the EU, Peppol vs national portals, UBL 2.1 explained.
What "certified access point" means
A certified Peppol access point is a provider that has passed OpenPeppol conformance and security testing, signed the Peppol Transport Infrastructure Agreement with a national Peppol Authority, and holds a valid Peppol PKI certificate. Certification is renewed annually, so a provider listed as certified two years ago may not be certified today.
Check any provider against the OpenPeppol member directory before you sign, and confirm it is covered by the Peppol Authority for the country you invoice into.
Access points by country
Requirements differ by Peppol Authority. Country guides: Belgium access points, Belgium mandate, Bulgaria, Nigeria (FIRS) — plus every deadline in the e-invoicing mandate tracker.
Requirements differ by Peppol Authority. Country guides: Belgium access points, Belgium mandate, Bulgaria, Nigeria (FIRS) — plus every deadline in the e-invoicing mandate tracker.
Sources
More in this series (36 articles)
From this series
Mandate-compliant e-invoicing in 17 jurisdictions, with the local artefact (CSID, IRN, UUID, QR, digital signature) issued automatically.
Digital Marketing, SEO Specialist, Content Creator & Product Professional
Olayinka is a digital marketer, content creator, growth and SEO specialist with 10+ years helping businesses in Nigeria, the UK, the US, Australia, and Dubai achieve their goals online.




