Peppol four-corner model showing Access Points, SMP and SML lookup
    E-Invoicing

    What Is a Peppol Access Point? Certified APs, Four-Corner Model, AS4

    11 min read

    Global E-Invoicing Platform Series

    This guide is part of a comprehensive series. Explore all 36 topics:

    A Peppol Access Point (AP) is a certified service provider that sends and receives structured business documents on the Peppol network on behalf of a participant. APs sit at corners 2 and 3 of the four-corner model: they resolve the receiver's endpoint via the Peppol SML/SMP, transmit documents over AS4 with signed non-repudiation receipts, and validate against Peppol BIS Schematron. You almost never run your own AP — you use the one operated by your invoicing platform.

    At a glance

    • Role: Corner 2 (sender's AP) and Corner 3 (receiver's AP) in the four-corner model
    • Transport: AS4 per Peppol AS4 Profile v2.0.3
    • Lookup: SML (DNS) → SMP (per-participant metadata)
    • Certification: OpenPeppol AP certification, renewed annually
    • Used for: invoices, credit notes, orders, despatch advices, catalogues, MLR
    • Last reviewed: 23 June 2026

    Why this term keeps appearing

    If you read about Peppol in the EU, B2G procurement in the United States, or the upcoming Australian Peppol mandate, the term Peppol Access Point is everywhere. It is the operational unit of the Peppol network — every document on Peppol touches at least two APs.

    If you read about Peppol in the EU, B2G procurement in the United States, or the upcoming Australian Peppol mandate, the term Peppol Access Point is everywhere. It is the operational unit of the Peppol network — every document on Peppol touches at least two APs.

    The four-corner model

    Peppol is a four-corner network:

    Peppol is a four-corner network:

    • Corner 1 (C1) — the sender (the invoicing application).
    • Corner 2 (C2) — the sender's Access Point.
    • Corner 3 (C3) — the receiver's Access Point.
    • Corner 4 (C4) — the receiver (the buyer's AP/ERP system).

    C1 and C4 never connect directly. C2 looks up C3 via SMP/SML, transmits over AS4, and the document lands at C4 via C3. Both APs sign non-repudiation receipts to prove delivery.

    What an Access Point actually does

    Identifies the receiver via SML + SMP — endpoint URL, certificate, supported document types from the receiver's Peppol Participant Identifier. Transports the document over AS4 with signed receipts that prove delivery.

    • Identifies the receiver via SML + SMP — endpoint URL, certificate, supported document types from the receiver's Peppol Participant Identifier.
    • Transports the document over AS4 with signed receipts that prove delivery.
    • Validates outgoing documents against the Peppol BIS Billing 3.0 Schematron and incoming documents against the same rules.
    • Acknowledges receipt and returns Message Level Responses (MLR) when the receiver business-rejects a document.
    • Reports traffic to OpenPeppol and the national Peppol Authority for monitoring.

    SMP and SML — how lookup works

    The SML (Service Metadata Locator) is the DNS-backed root directory of all SMPs on the network, operated by the European Commission's DIGIT under the eDelivery building block. The SMP (Service Metadata Publisher) is per-participant metadata: endpoint URL, public-key certificate, and accepted document types.

    The SML (Service Metadata Locator) is the DNS-backed root directory of all SMPs on the network, operated by the European Commission's DIGIT under the eDelivery building block. The SMP (Service Metadata Publisher) is per-participant metadata: endpoint URL, public-key certificate, and accepted document types.

    Step-by-step lookup

    1. Sender's AP hashes the buyer's Participant Identifier and queries the SML via DNS.
    2. The SML returns the SMP URL for that participant.
    3. The sender's AP queries the SMP for the buyer's endpoint, certificate, and accepted document types.
    4. The sender's AP transmits over AS4 to the buyer's AP endpoint.

    AS4 transport — what's on the wire

    AS4 is the OASIS ebMS3 v3. 0 web-services profile, further restricted by the CEF eDelivery AS4 Profile v1.

    AS4 is the OASIS ebMS3 v3.0 web-services profile, further restricted by the CEF eDelivery AS4 Profile v1.14 and then by the Peppol AS4 Profile v2.0.3. Each AS4 message includes a SOAP envelope with WS-Security headers, the UBL payload as a MIME attachment, and is signed using the AP's Peppol certificate. The receiver returns a non-repudiation receipt signed with its own certificate.

    How to choose an Access Point

    Confirm active OpenPeppol certification (renewed annually). Check supported document types — at minimum BIS Billing 3.

    1. Confirm active OpenPeppol certification (renewed annually).
    2. Check supported document types — at minimum BIS Billing 3.0 Invoice and Credit Note; ideally also order and despatch advice.
    3. Confirm jurisdictional coverage — most APs are cross-border, some restrict to specific Peppol Authorities.
    4. Confirm SLA — AP availability, support hours, escalation paths.
    5. Confirm ancillary services — Schematron validation, MLR handling, archiving, ERP connectors.
    6. Confirm pricing model — per-document, per-participant, or bundled with the invoicing platform.

    Should I run my own Access Point?

    Almost certainly not.

    Almost certainly not. Running an AP requires:

    • OpenPeppol AP certification, including security and conformance audits.
    • Production AS4 infrastructure with HSM-backed signing keys.
    • Continuous tracking of OpenPeppol eDEC policy changes (revised most months).
    • Renewal of the Peppol PKI certificate annually.

    Only large multinationals at very high volume or service providers reselling Peppol connectivity run their own AP. Everyone else uses the AP bundled with their invoicing platform — Invoicemonk operates as an AP for customers in scope.

    What fails in production

    SMP lookup miss: receiver not registered, or the wrong Participant scheme. Verify via the Peppol Directory.

    • SMP lookup miss: receiver not registered, or the wrong Participant scheme. Verify via the Peppol Directory.
    • Document type not declared: receiver's SMP does not advertise the type you sent. Coordinate with the buyer to add it.
    • Certificate chain failure: AP's Peppol certificate has expired or the trust anchor is stale.
    • Schematron failure on send: validation should be upstream of AS4 — otherwise the AP returns a hard reject.
    • MLR ignored: receiver business-rejects the document; if you do not process MLR, you do not know the invoice was rejected.
    • AS4 receipt loss: non-repudiation receipts must be archived alongside the signed UBL — otherwise you cannot prove delivery in a dispute.

    Key takeaways

    Key takeaways includes: An Access Point is the operational unit of Peppol — every document touches two. Lookup is SML → SMP; transport is AS4; the AP also validates and handles MLR.

    • An Access Point is the operational unit of Peppol — every document touches two.
    • Lookup is SML → SMP; transport is AS4; the AP also validates and handles MLR.
    • Use the AP bundled with your invoicing platform — running your own is rarely worth it.
    • The most common failure modes are SMP misses and declared-document-type mismatches, both fixed by coordination with the buyer.

    Related reading

    Pillar: e-invoicing. Mandate: Peppol EU.

    Pillar: e-invoicing. Mandate: Peppol EU. Siblings: Peppol EU explained, how to comply with Peppol in the EU, Peppol vs national portals, UBL 2.1 explained.

    What "certified access point" means

    A certified Peppol access point is a provider that has passed OpenPeppol conformance and security testing, signed the Peppol Transport Infrastructure Agreement with a national Peppol Authority, and holds a valid Peppol PKI certificate. Certification is renewed annually, so a provider listed as certified two years ago may not be certified today.

    Check any provider against the OpenPeppol member directory before you sign, and confirm it is covered by the Peppol Authority for the country you invoice into.

    Access points by country

    Requirements differ by Peppol Authority. Country guides: Belgium access points, Belgium mandate, Bulgaria, Nigeria (FIRS) — plus every deadline in the e-invoicing mandate tracker.

    Requirements differ by Peppol Authority. Country guides: Belgium access points, Belgium mandate, Bulgaria, Nigeria (FIRS) — plus every deadline in the e-invoicing mandate tracker.

    Sources

    Tags:
    Peppol
    Access Point
    e-invoicing
    explainer
    AS4
    SMP
    More in this series (36 articles)
    OO
    Olayinka Olayokun

    Digital Marketing, SEO Specialist, Content Creator & Product Professional

    CIM Certified
    MBA in Digital Marketing and Business Transformation

    Olayinka is a digital marketer, content creator, growth and SEO specialist with 10+ years helping businesses in Nigeria, the UK, the US, Australia, and Dubai achieve their goals online.

    More from Global E-Invoicing Platform