Peppol access points explained: do you have to choose one?
What a Peppol access point is, why you can't reach the network without one, and what changes when a service handles the access point for you.
The phrase that trips people up when they first read about Peppol is "access point". It sounds like something you have to buy, configure, and maintain, a box in a rack somewhere. It is simpler than that.
An access point is your on-ramp
Peppol is a network with agreed rules for how documents are formatted, addressed, and transported. To put a document onto that network, or to receive one from it, you connect through an access point: a certified provider that speaks the Peppol transport protocol and is authorised to exchange documents with every other access point.
Access points play the role a mail provider plays for email, with one difference: they are certified. A provider has to be accredited by a Peppol authority to operate one, which is what lets any two access points trust each other's documents without a prior relationship.
The four-corner model
Peppol describes delivery with a four-corner model, which is why an access point is not optional.
- Corner one is you, the sender, with your billing system.
- Corner two is your access point, which takes your document onto the network.
- Corner three is the recipient's access point.
- Corner four is the recipient, with their accounting or ERP system.
A document travels one → two → three → four. The two providers do the routing, the format checks, and the delivery receipts between them. This is why the network can span countries and software you have never heard of: everyone agrees on the rules at corners two and three, so corners one and four do not need to match.
Before any of that can happen, the sending access point has to know which access point serves the recipient. It finds corner three by looking up the recipient's SMP record, which what is a Peppol ID covers, and what is Peppol gives the fuller picture of the network itself.
Why you can't just send it yourself
There are two reasons you cannot post a document to the network directly. First, the network only accepts documents from accredited access points, and that accreditation is what the trust model rests on. Second, operating one means implementing the Peppol transport protocol, holding the certificates, staying current as the specifications change, and maintaining the connection reliably. That is real infrastructure work to take on for a handful of invoices a month.
So everyone uses a certified provider. The question is whether you deal with that provider directly or through a service that wraps it.
What it means when a service handles it for you
For most small and mid-size senders, you choose a service and the access point comes with it.
That is how Peppost works. It sits at corner one alongside your Stripe billing and dispatches through a certified access point on your behalf. You never select a provider, hold a certificate, or configure a transport connection. You connect Stripe once, and when you send, Peppost generates the structured document, resolves the recipient's directory record to find their access point, and hands the document off. The sending guide shows the flow from your side, and the FAQ covers the questions that come up most.
One thing worth being precise about: Peppost is send-only. Handling the sending access point for you is not the same as making you a receiving participant on the network. If you also need to receive Peppol documents, that is a separate registration, and a send-only service does not provide it.
If you bill through Stripe, how to send a Stripe invoice over Peppol picks up where this leaves off.