ATCUD: How to Create a User at the Portuguese Tax Authority
Step by step: creating a sub-user on the Portal das Finanças with permission to file invoice series and obtain the ATCUD validation code.
Before any certified invoicing package can issue an invoice with a valid ATCUD, the series has to have been filed with the Portuguese tax authority (AT) and to have received its validation code. That is done on the Portal das Finanças, and the cleanest way, particularly if you work with an external accountant or with several people handling invoicing, is to create a dedicated sub-user carrying the WSE — Comunicação e Gestão de Séries por webservice operation and nothing beyond what you need.
This guide shows exactly how.
Why you want a sub-user
The obligation to carry an ATCUD on every relevant tax document comes from Portaria 195/2020, of 13 August, which regulates the QR Code and the unique document code. In force since 1 January 2023, it means every invoice series has to be filed with the tax authority beforehand. Only then can certified software include the ATCUD on the invoices it issues.
Creating a dedicated sub-user has three practical advantages:
- Credential separation: your accountant or employee files series without reaching the rest of the company's tax information.
- Audit trail: each series is associated with the sub-user that filed it.
- Quick reset: if the employee leaves, you revoke the sub-user without changing the company's main password.
Important: the sub-user is created by the company (its corporate VAT number) and does not replace the legal representative's password. It is a delegated account with limited permissions.
Step 1: reach the Portal das Finanças
- Open www.portaldasfinancas.gov.pt.
- Click Iniciar Sessão, top right.
- Sign in with the company VAT number and its password. Do not use the manager's personal number: it has to be the corporate one, because the obligation to file series belongs to the legal entity.
Step 2: open user management
Inside the company area:
- Go to Todos os Serviços in the side menu, or use the search bar at the top.
- Look for Gestão de Utilizadores, which also appears as Subutilizadores on some screens.
- Go into Gerir Utilizadores → Criar Utilizador.
The page lists the existing sub-users. The first time, it is empty.
Step 3: create the sub-user
In the Criar Utilizador form, fill in:
| Field | What to put |
|---|---|
| Name | Something readable, for example Comunicação Séries, or the employee's name |
| Email address | A valid address: the tax authority sends the sub-user and a provisional password here |
| Phone | Optional, but recommended for recovery |
| Authorised operations | See the table below. At minimum, WSE |
Which operations to tick
The form shows a list of operations with codes. Three matter to anyone invoicing:
| Code | Description, as it appears on the portal | Who needs it | |---|---|---| | WSE | Comunicação e Gestão de Séries por webservice | Everyone. This is the one that authorises series. Without it the sub-user exists with no access to series registration | | WFA | Webservice de comunicação de dados de facturas | Anyone filing invoice data by webservice rather than submitting the SAF-T file by hand | | WDT | Webservice de comunicação de documentos de transporte | Only those issuing delivery notes |
WSE is the minimum and the indispensable one. The other two depend on what your software does for you: most certified packages file invoices on their own (WFA), and anyone shipping goods with a delivery note needs WDT.
Do not tick what you do not need, but do not be stingy either: adding an operation later means going back to the portal, and the automatic filing that was failing in the meantime does not recover on its own.
Confirm and submit. The system generates:
- A sub-user in the form
NIF/N, for example500123456/1, whereNincrements with each sub-user created. - A provisional password, sent to the address you gave.
Write down the
NIF/Nimmediately. That is the credential you will use in the following steps, not the company's base VAT number.
The webservice is configured here, and only here. The operations you ticked on this form are what authorise automatic filing — WSE for series, WFA for invoices, WDT for delivery notes — and the webservice credential is this same NIF/N with this sub-user's password. There is no key to generate afterwards and no second password on the side: what you later enter into InvoiceXpress, Moloni or Vendus is exactly this pair.
That is why it is worth creating the sub-user even if you plan to file your series by hand the first time. The day you want the software to file on its own, everything is already in place.
Step 4: first sign-in and password change
The sub-user has to sign in once before it can operate:
- Sign out of the current session, where you are authenticated as the company.
- Sign in again, this time with the sub-user (
NIF/N) and the provisional password from the email. - The portal forces you to set a permanent password. Set it and store it somewhere safe, in a password manager.
Step 5: file your first series
Now signed in as the sub-user, you can finally file a series:
Todos os Serviços → Faturas e Outros Documentos Fiscais
→ Comunicar Séries Documentais
→ Registar Série
Fill in:
- Document type: FT, FS, FR, NC, ND, GT...
- Series identifier: the name exactly as it is in your software, for example
2026FR. - Starting sequence number: normally
1. - Expected start date.
- Processing method:
Programa informático de faturação, plus the software's certification number. Each package has its own: InvoiceXpress192, Moloni2860, Vendus2230. Always confirm in your software's About panel or in the footer of an issued document.
Submit. The tax authority returns an 8-character alphanumeric validation code, for example CSDF7T5H. That is your ATCUD code for that series, and it is what you enter into the invoicing software.
Step 6: maintenance
- One series, one code. Each
document type + identifierpair gets its own code. If you have FT and FR, those are two separate filings. - Do not reuse identifiers across years without filing a new series. If you want
2026FR, file it;2025FRstays closed. - The sub-user password expires. The portal forces periodic renewal. Put a reminder in your calendar.
- Revocation: if the employee leaves, go to Gestão de Utilizadores and remove or deactivate the sub-user. The series they filed remain valid.
How Rioko helps
Rioko does not need the AT sub-user credentials at all: that part stays on the Portal das Finanças, under your control. What Rioko does is use the series you have already filed, whose ATCUD is configured in your InvoiceXpress, Moloni or Vendus account. When you connect your Shopify store or Stripe account, you pick the default series in the dashboard and Rioko checks the ATCUD is present before any invoice is issued. To go deeper on the concept of a series, read Invoice series: what they are and how to file them.
Original source: talkguest.zendesk.com
Frequently asked questions
Can I file series with the company password, without creating a sub-user?
You can, but the software cannot. Automatic filing by webservice needs a sub-user carrying the WSE operation, because that is the credential you enter into the invoicing software. The legal representative's password should never be handed to a piece of software.
Which operations do I tick when creating the user?
WSE, for series, is mandatory. WFA if you want the software to file invoice data by webservice, and WDT if you issue delivery notes. The permissions are set when the user is created: there is no separate webservice key.
Does one sub-user work for every package I use?
It does. The same NIF/N and password can be entered into more than one certified package. If you prefer a separate audit trail per package, create one sub-user for each.
I lost the sub-user password. What now?
Go back to Gestão de Utilizadores with the company password and generate a new one for that sub-user. Series already filed are unaffected, but the software stops filing until you enter the new password.
What happens if the employee who created the user leaves?
You deactivate the sub-user in Gestão de Utilizadores. The series they filed stay valid: they belong to the company, not to them.
Still have questions
Write the question. It reaches a person, not a form.