docs(skills): Sweden's Peppol Authority is Upphandlingsmyndigheten, not DIGG (#1736)

The e-handel and Peppol functions moved from DIGG to Upphandlingsmyndigheten
on 1 July 2026 (regeringsbeslut Fi2025/01826). The skill was written before the
handover and still told agents to sign with DIGG and mail peppol@digg.se.

Corrected across all eight files of the atom, repointed four digg.se URLs to
their verified redirect targets, and replaced the discontinued DIGG Peppol
testbadd (hard 404, no successor) with the SFTI Validex verification service.

Also refreshed the Service Provider path in peppol-network.md, which was thin
on what the process actually costs and requires:

- ISO/IEC 27001 mandatory for every Service Provider from 1 July 2027, with the
  1 Sept 2026 and 1 Oct 2026 interim milestones and the required SoA scope
- the SP Agreement clauses that drive product design: 9.2 end user
  identification, 9.7 authority-ordered blocking, 9.4.2 logging floor, 15
  subcontracting (the basis of the white-label market), 18 penalties, 19.3
  liability caps, 22 auto-termination on membership lapse
- the six Testbed cases and their prerequisites, including TLS grade A
- mandatory monthly TSR and EUSR reporting
- SMP-only fee row, and why AP-only is a trap for a SaaS vendor
- clause 14.3: a Peppol Authority may not charge for connecting

Regenerated the atom body migration (npm run skills:generate).

Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-08-26 09:50:25 +02:00
committed by GitHub
co-authored by Jakob Wennberg Claude Opus 5
parent c93a97bb4e
commit 3e4b5ddc80
11 changed files with 17833 additions and 50 deletions
+2 -2
View File
@@ -35,7 +35,7 @@ These are short enough to inline; the references expand each.
**Network:** Peppol four-corner (C1 sender → C2 sending AP → C3 receiving AP → C4 receiver). AS4 v2.0 over HTTPS. SMP discovery via NAPTR/SHA-256 (migrated from CNAME/MD5 in 2025). PKI: G3 only after end-2025. SMP servers must run on port 443 from **1 February 2026**.
**Authority:** DIGG is Sweden's Peppol Authority, regulator under Lag 2018:1277. **DIGG's Peppol-ID: `0007:2021006883`. Skatteverket: `0007:2021005448`.** Per regeringsbeslut Fi2025/01826, Peppol functions transfer to **Upphandlingsmyndigheten on 1 July 2026**; DIGG merges into PTS by 1 January 2027. SFTI ESAP 6 (EDIFACT) was removed 1 July 2025; Svefaktura is deprecated.
**Authority:** **Upphandlingsmyndigheten is Sweden's Peppol Authority since 1 July 2026** (regeringsbeslut Fi2025/01826 moved e-handel and Peppol out of DIGG; DIGG merges into PTS by 1 January 2027). Contact **peppol@uhmynd.se**; `digg.se/digitala-tjanster/peppol` now redirects. OpenPeppol's own Sweden country profile is stale and still names Digg. Lag 2018:1277 is the B2G mandate. **DIGG's Peppol-ID: `0007:2021006883`. Skatteverket: `0007:2021005448`.** SFTI ESAP 6 (EDIFACT) was removed 1 July 2025; Svefaktura is deprecated.
**Identifier formats:** Swedish orgnr → `schemeID="0007"`, 10 digits no dash. Swedish VAT ID → `SE` + 10 digits + `01` (e.g. `SE556732100001`), prefix mandatory (BR-CO-9). For sole proprietors **DIGG recommends GLN (`0088`) over personnummer (`0007`) for GDPR**.
@@ -53,4 +53,4 @@ When answering questions in this domain:
- For UBL fragments, output real, valid XML with full namespaces and example values, not pseudocode.
- For build-vs-buy or vendor selection, give numbers, €/SEK, monthly minimums, per-document costs, certification fee tiers, break-even volume, not adjectives.
- When a regulatory date is involved, distinguish (a) hard EU deadline, (b) currently-known Swedish proposal, (c) speculation. The user is technically sophisticated and is making product decisions; mistaking speculation for binding fact is the worst possible failure mode.
- Be willing to say "the spec is currently in flux", Peppol BIS 4.0 / PINT convergence, the DIGG → Upphandlingsmyndigheten / PTS reorganisation, the Dir. 2026:9 outcome, and the post-ViDA national mandate landscape are all moving targets in 2026-2027.
- Be willing to say "the spec is currently in flux", Peppol BIS 4.0 / PINT convergence, the completed DIGG → Upphandlingsmyndigheten handover and the pending DIGG → PTS merger, the Dir. 2026:9 outcome, and the post-ViDA national mandate landscape are all moving targets in 2026-2027.
@@ -88,7 +88,7 @@ This reference compares Sweden's likely trajectory to the mandates already enact
## Sweden's likely trajectory
Sweden has **20+ years of Peppol/SFTI infrastructure**, B2G mandatory since 2019, and DIGG already accredited as Peppol Authority. There is **zero political appetite** for an Italian-style centralised clearance hub, the existing decentralised infrastructure works, has proven low-friction, and aligns with EU peer countries (Belgium, Norway, Germany).
Sweden has **20+ years of Peppol/SFTI infrastructure**, B2G mandatory since 2019, and an accredited Peppol Authority (DIGG until 30 June 2026, Upphandlingsmyndigheten since 1 July 2026). There is **zero political appetite** for an Italian-style centralised clearance hub, the existing decentralised infrastructure works, has proven low-friction, and aligns with EU peer countries (Belgium, Norway, Germany).
**Realistic trajectory:**
@@ -88,7 +88,7 @@ Many AP rejections happen post-send when the receiver's MLR comes back hours lat
- **Storecove peppolvalidator.com**, error code lookup.
- **EC DG GROW eInvoicing validator**, https://itb.ec.europa.eu/invoice
- **Norwegian validator**, https://anskaffelser.no/verktoy/validator (also useful for Sweden).
- **DIGG testbädd**, https://www.digg.se/digitala-tjanster/peppol/peppol-testbadd
- **SFTI Validex**, https://sfti.validex.net/ (DIGG's Peppol testbädd was discontinued in the 2026 handover)
## Build vs buy, the economic break-even
@@ -157,7 +157,7 @@ This hybrid is the dominant strategy:
- Become Candidate Service Provider (AP-only) with OpenPeppol (~€4,400 one-off + €3,350/year ongoing).
- Pass Conformance Test Suite.
- Sign Service Provider Agreement with DIGG (free).
- Sign the Peppol Service Provider Agreement with Upphandlingsmyndigheten (free: SP Agreement clause 14.3 forbids a Peppol Authority from charging).
- Migrate to native Oxalis-NG receive.
- Marketing message: "your customers email PDFs, your suppliers send Peppol e-invoices, both arrive in your inbox."
@@ -200,6 +200,6 @@ The window to build with this advantage is the next **18-24 months** before incu
- Phive-rules: https://github.com/phax/phive-rules
- peppol-bis-invoice-3: https://github.com/OpenPEPPOL/peppol-bis-invoice-3
- Storecove docs: https://www.storecove.com/docs/
- DIGG Peppol testbädd: https://www.digg.se/digitala-tjanster/peppol/peppol-testbadd
- SFTI Validex verification service: https://sfti.validex.net/
- Peppol Testbed: https://peppol.org/tools-support/testbed/
- OpenPeppol membership: https://peppol.eu/who-is-who/openpeppol-membership/
@@ -10,14 +10,14 @@ The operative statute. SFS 2018:1277, in force **1 April 2019**, amended SFS 202
- **§2 Definition.** An e-invoice is an invoice issued, sent and received in a *structured electronic format that allows automatic and electronic processing*. **PDF and scanned paper are explicitly excluded.** Image-based formats fail the definition regardless of how they are transmitted.
- **§4 Standard.** EN 16931 conformance via Commission Implementing Decision (EU) 2017/1870. Parties may bilaterally agree on alternative standards.
- **§5 Reception duty.** Contracting authorities must receive and process EN 16931 invoices.
- **§7 Sanctions.** **DIGG can issue *vitesföreläggande* (penalty injunctions)** against non-compliant suppliers. The amount is set discretionarily.
- **§7 Sanctions.** **The supervising authority can issue *vitesföreläggande* (penalty injunctions)** against non-compliant suppliers (DIGG until 30 June 2026, Upphandlingsmyndigheten since 1 July 2026). The amount is set discretionarily.
- **§8 Appeals.** Appeals go to allmän förvaltningsdomstol; prövningstillstånd required for kammarrätten.
Source: https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-20181277-om-elektroniska-fakturor-till_sfs-2018-1277/
### Förordning (2018:1486)
Designates **DIGG (Myndigheten för digital förvaltning)** as supervising authority and Sweden's Peppol Authority. Source: https://www.digg.se/kunskap-och-stod/e-handel/lag-forordning-och-foreskrifter-for-e-handel
Designated **DIGG (Myndigheten för digital förvaltning)** as supervising authority and Sweden's Peppol Authority. **Since 1 July 2026 both functions sit with Upphandlingsmyndigheten** (regeringsbeslut Fi2025/01826). Source: https://www.upphandlingsmyndigheten.se/digitalisering-och-e-handel/e-handel/regler-for-e-handel-och-e-faktura/
### MDFFS 2019:1 (Föreskrift om registrering i PEPPOL)
@@ -90,13 +90,13 @@ Binding dates relevant for Sweden:
## Swedish authorities
### DIGG (Myndigheten för digital förvaltning)
### Peppol Authority: Upphandlingsmyndigheten (DIGG until 30 June 2026)
- Sweden's Peppol Authority.
- Regulator under §7 of Lag 2018:1277.
- Issues binding föreskrifter MDFFS 2019:1 and MDFFS 2021:1.
- DIGG's own Peppol-ID: `0007:2021006883`.
- **Reorganisation alert:** Per regeringsbeslut Fi2025/01826, DIGG's e-handel/Peppol functions transfer to **Upphandlingsmyndigheten on 1 July 2026**. DIGG itself is to be merged into PTS by 1 January 2027 forming a new digitalisation agency. Adjust regulatory monitoring accordingly.
- **Handover completed:** per regeringsbeslut Fi2025/01826, DIGG's e-handel and Peppol functions moved to **Upphandlingsmyndigheten on 1 July 2026**. Peppol contact is now **peppol@uhmynd.se**. DIGG itself is to be merged into PTS by 1 January 2027 forming a new digitalisation agency.
### Skatteverket
@@ -132,7 +132,7 @@ The inquiry will determine:
| Segment | Status (April 2026) | Format | Penalty |
|---|---|---|---|
| **B2G** (consequence of public procurement) | Mandatory since 1 April 2019 | EN 16931 / Peppol BIS Billing 3 | DIGG vitesföreläggande, discretionary fine; practical risk also: lost public-sector business |
| **B2G** (consequence of public procurement) | Mandatory since 1 April 2019 | EN 16931 / Peppol BIS Billing 3 | Vitesföreläggande from the supervising authority (Upphandlingsmyndigheten since 1 July 2026), discretionary fine; practical risk also: lost public-sector business |
| **B2G** (state-to-state, state-to-private with consent) | Mandatory | Peppol BIS Billing 3 | Internal compliance |
| **B2B** | **Voluntary** | Free choice (Peppol BIS dominant; legacy Svefaktura tolerated bilaterally) | None |
| **B2C** | Voluntary | Bank rails / Kivra (not Peppol) | None |
@@ -151,8 +151,8 @@ The inquiry will determine:
- Lag (2018:1277): https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-20181277-om-elektroniska-fakturor-till_sfs-2018-1277/
- Bokföringslag (1999:1078): https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/bokforingslag-19991078_sfs-1999-1078/
- DIGG e-handel laws and regs: https://www.digg.se/kunskap-och-stod/e-handel/lag-forordning-och-foreskrifter-for-e-handel
- DIGG Peppol statistics: https://www.digg.se/digitala-tjanster/peppol/statistik-fran-peppolnatverket-
- DIGG e-handel laws and regs: https://www.upphandlingsmyndigheten.se/digitalisering-och-e-handel/e-handel/regler-for-e-handel-och-e-faktura/
- Swedish Peppol statistics: https://www.upphandlingsmyndigheten.se/digitalisering-och-e-handel/peppol/statistik-fran-peppolnatverket/
- SFTI standards: https://sfti.se/sfti/standarder/peppolbisehandel/peppolbisbilling3.49021.html
- Skatteverket e-faktura: https://skatteverket.se/omoss/varverksamhet/forleverantorer/efakturortillskatteverket.4.b1014b415f3321c0de2680.html
- Skatteverket on transaction-based reporting: https://www.skatteverket.se/foretag/internationellt/transaktionsbaseradrapporteringochefakturering.4.386bd4b919276cc86c42b3f.html
@@ -122,7 +122,7 @@ For a new Swedish accounting/fintech product, the practical menu:
## Authoritative source list
- DIGG Peppol traffic stats: https://www.digg.se/digitala-tjanster/peppol/statistik-fran-peppolnatverket-
- Swedish Peppol traffic stats: https://www.upphandlingsmyndigheten.se/digitalisering-och-e-handel/peppol/statistik-fran-peppolnatverket/
- Visma Autoinvoice docs: https://documentation.autoinvoice.visma.com/
- Fortnox API: https://developer.fortnox.se/
- Pagero compliance pages: https://www.pagero.com/compliance/regulatory-updates/sweden
@@ -227,7 +227,7 @@ Validators to integrate:
- **Storecove peppolvalidator.com**, https://peppolvalidator.com, error code lookup.
- **EC DG GROW eInvoicing validator**, https://itb.ec.europa.eu/invoice, official EC validator.
- **Norwegian validator**, https://anskaffelser.no/verktoy/validator (also useful for Sweden).
- **DIGG testbädd**, https://www.digg.se/digitala-tjanster/peppol/peppol-testbadd
- **SFTI Validex**, https://sfti.validex.net/ (DIGG's Peppol testbädd was discontinued in the 2026 handover)
Validate at **three points** in your pipeline: (1) immediately after UBL generation locally; (2) before handoff to the Access Point; (3) on receive in your inbound flow before bookkeeping. Many AP rejections happen post-send when the receiver's MLR comes back hours later.
@@ -102,7 +102,22 @@ Authoritative live list: https://docs.peppol.eu/edelivery/codelists/ and https:/
GitHub: https://github.com/OpenPEPPOL/peppol-bis-invoice-3/blob/master/structure/codelist/eas.xml
## Becoming a Peppol Access Point, the operational path
## Becoming a Peppol Service Provider, the operational path
There is no Peppol licence to buy. Three things, in this order: OpenPeppol membership,
Testbed certification, then the **Peppol Service Provider Agreement** (v4.0.2, approved
28 May 2025) signed by the national Peppol Authority. The authority signs only after
certification passes.
### Sweden's Peppol Authority is Upphandlingsmyndigheten
**Since 1 July 2026, not DIGG.** Contact **peppol@uhmynd.se**. They book an introductory
digital meeting before anything is signed. OpenPeppol's own Sweden country profile page is
stale and still names Digg; do not route people there.
The authority charges nothing. SP Agreement clause 14.3: "The Peppol Authority cannot
charge the Peppol Service Providers or End Users for connecting to or using the Peppol
Network." Each party bears its own costs (14.1). All the money goes to OpenPeppol.
### OpenPeppol membership fees (effective 1 July 2025 for new members)
@@ -112,27 +127,123 @@ For a small Swedish fintech (S1 size, 1-10 employees):
|---|---|---|---|---|
| **AP + SMP S1** | €1,800 | €2,750 | €2,500 | **≈ €7,050** |
| **AP-only S1+S2** | €1,050 | €1,850 | €1,500 | **≈ €4,400** |
| **SMP-only S1+S2** | €1,050 | €5,000 | €1,000 | **≈ €7,050** |
| **End User S1+S2** | €650 | €1,250 | n/a | **≈ €1,900** |
Add infrastructure cost: 24/7 redundant AS4 hosting (€3-10k/yr), monitoring/on-call (€5-20k fully loaded), DigiCert G3 certs (bundled into OpenPeppol annual). DIGG charges no additional Peppol-Authority fee for Swedish service providers but requires signing the **Peppol Service Provider Agreement**.
The certification fee is charged once at first certification, then folds into the annual
fee. The annual fee is pro-rata for the remainder of the calendar year on joining.
**Realistic minimum to operate an own AP: €20-40k/year direct cost plus 0.5-1 FTE engineering and 3-6 months upfront build.** Twice-yearly spec updates with a 7-day implementation window and mandatory monthly volume reporting are non-trivial recurring costs.
**AP-only is a trap for a SaaS vendor.** A participant can be registered in exactly one SMP
at a time, so AP-only leaves every customer registration and every customer migration
dependent on another provider's SMP. Adding SMP later costs a second certification.
Add infrastructure cost: 24/7 redundant AS4 hosting (€3-10k/yr), monitoring/on-call
(€5-20k fully loaded), DigiCert G3 certs (bundled into OpenPeppol annual).
**Realistic minimum to operate an own AP: €20-40k/year direct cost plus 0.5-1 FTE
engineering and 3-6 months upfront build**, before ISO 27001. Twice-yearly spec updates
with a 7-day implementation window and mandatory monthly reporting are non-trivial
recurring costs.
### ISO/IEC 27001 is mandatory from 1 July 2027
Every Peppol Service Provider must hold a valid ISO/IEC 27001 certificate from **1 July
2027**. OpenPeppol milestones: 30 June 2026 equivalence requests for other certificates,
**1 September 2026** submit certificates already held, **1 October 2026** submit evidence
of an ongoing certification project, 1 February 2027 and 1 May 2027 progress reports,
1 July 2027 hard deadline.
The Statement of Applicability must explicitly cover Access Point, Service Metadata
Publisher, End User Identification, document management, integrity controls, logging and
audit trail, backup and business continuity. Scope that omits Peppol operations does not
count.
For a company of 1-10 people, budget 200-500 kSEK to first certificate plus recurring
surveillance audits. This, not AS4, is the real barrier to entry.
### Onboarding steps
1. Submit candidate application to `membership@peppol.eu`.
2. Sign the **Peppol Member Agreement** with OpenPeppol AISBL.
3. Sign the **Peppol Service Provider Agreement** (formerly Transport Infrastructure Agreement, TIA) with **DIGG** as Sweden's Peppol Authority.
4. Implement AS4 + SMP lookup + SBDH handling. Deploy in test environment.
5. Request DigiCert One G3 test certificate.
6. Pass the **Peppol Testbed conformance suite**, refactored 2025 with country-specific payload tests. https://peppol.org/tools-support/testbed/
7. Pay the Certification Fee.
8. Production certificate issued.
9. Register SMP in production SML via DIGG.
10. Commit to monthly volume reporting.
1. Mail the Peppol Authority (**peppol@uhmynd.se** in Sweden) and book the intro meeting.
2. Apply to `membership@peppol.eu` for **Candidate Service Provider** status in the chosen
category (AP+SMP, AP-only or SMP-only).
3. Return the signed **Peppol Member Agreement** plus company registration documents.
OpenPeppol runs due diligence: registration, solvency and criminal checks.
4. Pay sign-up plus pro-rata annual fee. Join the eDelivery Community and at least one
other Domain Community (Post-Award for invoicing).
5. Request **PKI test certificates** (DigiCert One G3) via the Peppol Service Desk. A
signed member form is sufficient; the SP Agreement is not required yet, so the build
can run fully in parallel with the authority track.
6. Implement AS4 + SMP + SBDH handling. Deploy to test, SML `acc.edelivery.tech.ec.europa.eu`.
7. Pass the eDelivery test suite at https://www.testbed.peppol.org (client-cert auth).
8. Download the test report, request the **production** PKI certificate. OpenPeppol's
Operating Office evaluates it; a positive result is required before production.
9. The Peppol Authority signs the Service Provider Agreement.
10. Register in the production SML, go live, begin monthly reporting.
**Total elapsed time: 3-6 months.**
### What the Testbed actually tests
Six AP test cases, run one at a time, re-runnable as often as needed:
1. **TLS grading verification**, must be Qualys SSL Labs **grade A or above**
2. AS4 message reception (static config, no SMP registration needed)
3. AS4 message submission (send a Testbed-supplied artifact unmodified)
4. Invalid certificate handling
5. Large AS4 message reception
6. Large AS4 message submission
Prerequisites: PKI v3 AP test certificate imported into the browser **and** configured on
the AP itself, HTTPS-only endpoint, a CA chain trusted by both Microsoft and Oracle trust
stores. Self-signed certificates are rejected outright.
The technical bar is modest. The organisational obligations below are where the cost is.
### What the SP Agreement binds you to (v4.0.2)
Clauses that change product design, not just paperwork:
- **9.2 End user identification.** A contract with every end user (directly, or indirectly
through an intermediary), identity verified at onboarding per the Entity Identification
rules, and the contract must state the user will be blocked on fraud, spam or criminal
acts. Upphandlingsmyndigheten lists a working *kundkännedomsprocess* as a standing
obligation. **For a self-serve SaaS this is the largest gap: instant signup is not
compatible with it.**
- **9.3** Membership must be maintained for the life of the agreement.
- **9.4.2** Log every send and receive, retain per law and never under 3 months,
disclosable on reasonable request.
- **9.4.5** Publish an incident contact (e-mail and phone) and respond to incidents.
- **9.4.9** Meet the domain minimum service levels and scale if capacity is short. The
exact figures live in the member-only Internal Regulations. The widely quoted "99.5%,
24/7, service windows under 2 hours announced 3 days ahead, retry 3 times within 2
hours" comes from the Norwegian enhanced-network AP requirements, not from OpenPeppol's
general post-award rules. Confirm the binding numbers before publishing an SLA.
- **9.7** The authority can order you to block an end user. That switch must exist.
- **15 Subcontracting is permitted**, and 9.2 allows the end user relationship to run
"indirectly through an intermediary". This is the clause the entire white-label and
reseller market rests on, and the fallback if the AP track stalls.
- **16** You may not collect or expose dataset content or metadata beyond what operating
the network requires or the end user instructs. Peppol traffic is not analytics or
training material.
- **18 Penalties** escalate: publication on the member site, publication on the public
site, temporary removal from the network, permanent removal. Five working days to supply
a remediation plan after a warning note.
- **19.3 Liability** capped at €500,000 per event and €1,000,000 per year, except wilful
acts or gross negligence.
- **22** Six months' notice to terminate; immediate on unremedied breach after 60 days,
insolvency or security failure; **automatic if OpenPeppol membership lapses**.
### Mandatory reporting
Monthly, both required of every Service Provider:
- **TSR** (Transaction Statistics Reporting): per document type, plus which other Access
Points you exchanged with. Raw data is derivable from the transport protocol and SBDH.
- **EUSR** (End User Statistics Reporting): number of end users served, per document type.
Specs: https://docs.peppol.eu/edelivery/specs/reporting/tsr/bis/ and
https://docs.peppol.eu/edelivery/specs/reporting/eusr/bis/
### Open-source AS4 / SMP stacks
- **Oxalis-NG** (https://github.com/OxalisCommunity/oxalis-ng), replaces Oxalis 6.x which is end-of-life Dec 2025. Java, Apache 2.0.
@@ -146,18 +257,18 @@ Add infrastructure cost: 24/7 redundant AS4 hosting (€3-10k/yr), monitoring/on
Trust stores updated to G3-only late 2025. Verify version when integrating.
## DIGG Peppol traffic statistics (Q4 2025)
## Swedish Peppol traffic statistics (Q4 2025, published by DIGG before the handover)
- October 2025: record **5,668,209 Peppol messages** to Sweden.
- November 2025: 4,810,015.
- December 2025: 5,190,513.
- Volume growth Sept 2024 → Sept 2025: **+30%**.
- **25,000+ Swedish Peppol receivers** registered.
- DIGG public sector survey (March 2025): 82% of public sector inbound invoices are e-invoices, 50% of outbound (up from 24%), 85% of public sector orgs use Peppol fully/largely for inbound.
- Public sector survey (DIGG, March 2025): 82% of public sector inbound invoices are e-invoices, 50% of outbound (up from 24%), 85% of public sector orgs use Peppol fully/largely for inbound.
- Bankföreningen reports 168.9M e-invoices to consumers in 2024.
- Total Swedish e-invoice volume estimate: **~250M/year** combining bank rails, Peppol B2G/B2B, and residual non-Peppol flows.
Live stats: https://www.digg.se/digitala-tjanster/peppol/statistik-fran-peppolnatverket-
Live stats: https://www.upphandlingsmyndigheten.se/digitalisering-och-e-handel/peppol/statistik-fran-peppolnatverket/
## Authoritative source list
@@ -167,6 +278,9 @@ Live stats: https://www.digg.se/digitala-tjanster/peppol/statistik-fran-peppolna
- Setup AP guide: https://peppol.helger.com/public/menuitem-docs-setup-ap
- Setup phoss SMP: https://peppol.helger.com/public/menuitem-docs-setup-smp-ph
- Peppol Testbed: https://peppol.org/tools-support/testbed/
- OpenPeppol membership: https://peppol.eu/who-is-who/openpeppol-membership/
- DIGG how Peppol works: https://www.digg.se/digitala-tjanster/peppol/sa-fungerar-peppol-
- OpenPeppol membership and fees: https://peppol.org/join/ and https://peppol.org/join/fees/
- Peppol SP Agreement v4.0.2: https://peppol.agid.gov.it/attachments/PeppolServiceProviderAgreement_v4.0.2_AGID_update_final.pdf
- Test and Onboarding guide v1.4: https://peppol.org/wp-content/uploads/2024/03/Peppol_TestbedAndOnboarding_v1.4.pdf
- Swedish Peppol Authority (blivande Service Provider): https://www.upphandlingsmyndigheten.se/digitalisering-och-e-handel/peppol/peppol-for-blivande-service-provider/
- How Peppol works (Upphandlingsmyndigheten): https://www.upphandlingsmyndigheten.se/digitalisering-och-e-handel/peppol/sa-fungerar-peppol/
- Identifier policy: https://docs.peppol.eu/edelivery/codelists/
@@ -309,7 +309,7 @@ Bookkeeping uses the **monthly average ECB rate** for the previous month (Skatte
- BAS-kontoplan: https://www.bas.se
- SFTI Peppol BIS Billing 3: https://sfti.se/sfti/standarder/peppolbisehandel/peppolbisbilling3.49021.html
- Swedish payment methods in BIS 3: https://support.inexchange.com/hc/en-us/articles/360001888178-Swedish-Payment-Methods-in-PEPPOL-BIS-3
- DIGG Peppol-ID instructions: https://www.digg.se/digitala-tjanster/peppol/instruktion-for-val-av-peppol-id-
- Peppol-ID instructions (Upphandlingsmyndigheten): https://www.upphandlingsmyndigheten.se/digitalisering-och-e-handel/peppol/instruktion-for-val-av-peppol-id/
- SE-R-005: https://docs.peppol.eu/poacc/billing/3.0/rules/ubl-peppol/SE-R-005/
- SE-R-011: https://docs.peppol.eu/poacc/billing/3.0/rules/ubl-peppol/SE-R-011/
- Skatteverket ROT/RUT XML: https://www.skatteverket.se/foretag/rotochrutarbete (HUSXML schema)
+1
View File
@@ -1246,3 +1246,4 @@ One line per decision: `[YYYY-MM-DD] <decision>: <why>`. Appended by agents and
[2026-08-25] ROT/RUT BegartBelopp truncates to whole kronor (truncateToWholeKronor), not half-up: the deduction is capped at 50%/30% of arbetskostnaden. At the RUT cap, half-up manufactured begart > betalt and blocked correct invoices; for ROT below the cap it over-requested past the cap and the 1513 fordran, so those files now ask 1 kr less (skeptic-verified on PR #1910).
[2026-08-25] Woo bulk revenue template = per-rate account choice, no hardcoded varor/tjanster preset: BAS 2026 has no standard 30xx goods/services subdivision (3040-series is company-specific), so presets would invent accounts; chosen accounts are validated against the company chart instead, and only diffs from the 3001-series default are sent.
[2026-08-26] RFC 9728 protected-resource metadata is served at THREE locations (root, path-based /.well-known/oauth-protected-resource/<mcp path>, and <mcp url>/.well-known/oauth-protected-resource): Claude.ai's connector setup derives the metadata URL from the server URL and fetches it before any 401, so the root document our WWW-Authenticate header points at was not enough ('Authorization with Accounted failed' with only 404s in the logs). One builder, three routes; the path-based route answers 404 for any path other than the MCP endpoint so no phantom resource is advertised.
[2026-08-20] The swedish-e-invoicing skill now names Upphandlingsmyndigheten as Sweden Peppol Authority across all eight files, not just the one that was flagged: the handover completed 1 July 2026 (regeringsbeslut Fi2025/01826) and the skill was written in future tense, so a partial fix would have left the atom internally contradictory and still pointed agents at peppol@digg.se. Four digg.se URLs were repointed to their verified 301 targets on upphandlingsmyndigheten.se; the fifth, DIGG Peppol testbadd, is a hard 404 with no redirect and no successor page at the new authority, so it was replaced with the SFTI Validex verification service (https://sfti.validex.net/) rather than left dead or guessed at. Historical attributions (Q4 2025 traffic statistics, the 0007:2021006883 Peppol-ID example) deliberately still say DIGG because they were accurate when published.
+16 -16
View File
@@ -40,40 +40,40 @@
"version": 2
},
"horizontal/swedish-e-invoicing": {
"hash": "287a9a7d4239de8db25b941345bb9b418e5fcf5b4dd65963c06b68215f54b2ce",
"version": 6
"hash": "59fb8f4ab9de7c907cf054f37ae6b651504987375f440831e199710b2a938223",
"version": 7
},
"horizontal/swedish-e-invoicing/consumer-and-b2c": {
"hash": "ebcb2c7e888497b61a5b25616314ae620f40d220c93c07a48aa4a49d00ac2068",
"version": 2
},
"horizontal/swedish-e-invoicing/european-mandates": {
"hash": "62e68fed6dff28d411b1fbe3ed60aeb25034bd7ff74e97c0ec16ac8c456076f7",
"version": 2
"hash": "cca73256fac8b3cd4ae614a2d512206ae30764676da88df3dc903e29a189a7d4",
"version": 3
},
"horizontal/swedish-e-invoicing/implementation-guide": {
"hash": "dd13aa80a8df4f5f44343133d5f885f1f7f1e914d73ffb5924f0296ead151439",
"version": 2
"hash": "a52c02278e98d7418b2866cf0dd2211629e4b1381d0c5d28ba3df4df83ee4415",
"version": 3
},
"horizontal/swedish-e-invoicing/legal-and-regulatory": {
"hash": "c1a2f945d60264d2b3e088c2d206be1048aa86688957f67c8047f653c8e48755",
"version": 2
"hash": "a5efa085631187766375a43b8a740497c4132466c0ec2873d798dcc823db8937",
"version": 3
},
"horizontal/swedish-e-invoicing/market-provider-pricing": {
"hash": "e9527da2e738cefc32990758f6cbfb5f90e12e911938836dea5a1f6a69e3609b",
"version": 2
"hash": "d99359e2b9b1455c6c2df20b266aca4d79b6585e3591125873751e947b5029f7",
"version": 3
},
"horizontal/swedish-e-invoicing/peppol-bis-billing": {
"hash": "71605dec0d6fe35175a2c40492fccdf04bf6dff9e1aa773e24fad449bdabd460",
"version": 1
"hash": "2407acacabb60836e1ebfff45f7d443dda92c3c432df83fd447cec6d5375c89f",
"version": 2
},
"horizontal/swedish-e-invoicing/peppol-network": {
"hash": "f751c3eac89dddac792e6f7993c2084300c0d70a3e6133cc309e49e9d818b829",
"version": 2
"hash": "efb8a84884c84a48bdc68049467d43f40503970bba7659231f7d964f51b5c2a1",
"version": 3
},
"horizontal/swedish-e-invoicing/swedish-cius-and-specifics": {
"hash": "538084e9f20585466adde5aafff03accaa3d7a24c11120014034706c2a01c60d",
"version": 2
"hash": "d3cadfe9c435013813edefdb435505f6df8f577352b929a24f156aeb0636ab5e",
"version": 3
},
"horizontal/swedish-financial-reporting": {
"hash": "4fc9d925de42b6a1c4658b960f269f97cf7035cd2041658d17e1883480d9be4b",
File diff suppressed because it is too large Load Diff