Access Map
Choose the Account, Credential, and Portal That Fit the Service
Separate the identity proof from the account, application portal, electronic mailbox, and authority deciding the case.
Treat digital government as five connected layers: the authority that owns the service, its application portal, the account used to enter, the credential proving identity, and the evidence created after submission. Confusing any two can leave a reader logged in but unable to complete the actual task.
BundID is the private-person account
BundID is the federal user account offered by a growing range of public services. Its account creation page shows four routes: online ID, qualifying non-German EU identity, personal ELSTER certificate, and username with password. These routes do not provide equal access. Username and password is basic registration, personal ELSTER is substantial assurance, and an eligible online ID provides high assurance. The connected service selects the assurance level needed.
A basic account can manage the profile and read basic-level messages, but it may not submit a sensitive application or open a message requiring stronger identification. Upgrade the credential in the same account where supported rather than creating several BundID accounts with inconsistent personal data.
Online ID is a credential, not another portal
The Online-Ausweisfunktion is the chip-based identity function of an eligible German identity card, electronic residence permit, or eID card for EU and EEA citizens. AusweisApp creates the encrypted connection between the card and online service. A person still needs the portal or BundID flow that requested this credential.
The card's identity function does not store a government inbox or show application status. It proves selected personal data during a transaction after the person enters the PIN.
ELSTER has personal and organisational roles
Mein ELSTER is the tax administrations' service for returns, forms, authorisations, messages, and notices. A personal certificate can also create a substantial-level BundID account. It does not become an organisation certificate simply because the user owns a business.
Mein Unternehmenskonto is the nationwide organisation account based on ELSTER organisation certificates. It lets an organisation authenticate to participating business-facing services. Staff permissions and certificate custody matter because submissions can bind the organisation.
Local and specialist portals still matter
Germany's Länder, municipalities, insurers, courts, universities, and specialist authorities may provide their own portal or connect only part of a service to BundID. Start from the official service description and confirm jurisdiction, required assurance, permitted representative, accepted file type, payment, and final submission step. The login operator handles access; the authority named on the application handles eligibility, evidence, decisions, and remedies.
Access Rules
Check Document, Assurance Level, Age, Device, and Acting Role
The correct route depends on who is acting, which document they hold, and how strongly the service must verify identity.
Read the service's access requirement before creating an account. The strongest credential is useful only if the service accepts it, and a working login does not prove that the user is legally entitled to apply.
Match the document to the online ID route
German identity cards issued to people aged at least 16 have normally had the eID function activated by default since July 2017. The holder must still set and know a personal six-digit PIN. Eligible third-country residents use the eID function on their electronic residence permit when activated. Non-German EU and EEA citizens aged at least 16 can apply for a separate eID card; it is an electronic identity document, not a residence permit or travel document.
Other foreign identity schemes can work where BundID lists that country's EU identity at the assurance required by the connected service. Do not assume every national card with a chip is supported.
Assurance determines capability
BundID basic registration with username and password is available from age 13, but sensitive processes can demand substantial or high assurance. A personal ELSTER certificate supplies substantial assurance. Online ID normally supplies high assurance. The credential can also control which inbox messages the user can read. If a shield or access message requests a stronger level, log in again with the qualifying credential rather than repeatedly submitting the password.
Separate identity from entitlement and representation
A portal can verify who is present without deciding that the person meets the service's residence, income, employment, family, study, or legal-status rules. Those conditions belong to the underlying application.
A parent, guardian, tax adviser, lawyer, employee, or other representative may need a power of attorney, custody evidence, professional authorisation, organisation role, or service-specific delegation. Do not log in as the represented person or share that person's PIN or certificate file. Use the portal's representation route and preserve the authority document.
Organisations need managed credentials
Mein Unternehmenskonto normally relies on a German Steuernummer and ELSTER organisation certificate. A personal ELSTER certificate may work for a sole trader only where the specific service accepts it. Staff should receive separate organisation certificates with permissions matching their work. The official business-account help warns that certificates can carry broad authority unless access is restricted.
Finally check device compatibility, supported browser, accessibility needs, language, payment method, file limits, and whether the service has a postal or in-person route. Eligibility to use a portal is not meaningful if the reader cannot complete its technical steps.
Setup Records
Prepare the Card, PIN, Account Data, Certificates, and Authority
Create a secure access pack that can survive a lost device without turning credentials into shared office files.
Prepare access before opening a time-limited application. A portal session can expire while the reader searches for a PIN letter, activation code, certificate, or power of attorney.
Build the online ID setup
You need an eligible valid identity document, activated eID function, self-chosen six-digit PIN, AusweisApp, and a compatible NFC smartphone or USB reader. The official AusweisApp checklist explains direct phone use, pairing a phone with a computer, and USB readers. Use the app's device-and-card check before the deadline.
A five-digit one-time or transport PIN is used to set the personal six-digit PIN. Keep the blocking password or loss instructions separately from the card. If the eID is inactive or the PIN is forgotten or blocked, take the valid card to the competent authority. The checked PIN service confirms that activation and a new PIN are free. Local appointment access varies.
Create accounts with consistent personal data
Use an email address you control long term and a unique password. Enter names, birth details, and address exactly as the identity credential and service require. If BundID already exists, add or use the stronger credential in that account instead of creating a duplicate profile. Save recovery information in a password manager or another protected location.
ELSTER registration can use online identity verification or split activation. The official ELSTER registration help states that postal registration sends the activation ID by email and activation code by post, while online identity verification can create access the same day. Secure post therefore depends on a deliverable address.
Protect certificate files and organisational authority
A downloaded .pfx file and its password together can authenticate filings. Back up the certificate in an encrypted location, but do not send it through chat or keep the password beside it. Copies are equivalent, so copying one to several colleagues removes accountability. Issue separate organisation certificates and revoke access when a role ends.
Prepare a written power of attorney, custody or guardianship proof, professional credentials, register extract, or internal authorisation when the service asks for it. Also retain the service description, required attachments, payment evidence, and deadline.
Keep a separate case folder for the actual submission: final form, uploaded files, electronic signature result, payment receipt, transfer protocol, Aktenzeichen, messages, and decision. Credentials prove access; these case records prove action.
Submit Safely
Move from Official Service Page to Verified Submission
Confirm jurisdiction, test the credential, inspect every attachment, and save evidence after the portal accepts the filing.
The reliable route begins with the responsible service, not with BundID, ELSTER, or AusweisApp in isolation. Search the official federal, Land, municipal, tax, or specialist authority and open its service description. Confirm location, audience, deadline, fee, accepted channel, and whether representatives are permitted.
Test the route before building the application
Follow the official login link and note the assurance level requested. If online ID is required, run AusweisApp's device check, confirm the PIN, and test card reading. If ELSTER is required, confirm the certificate and password. For an organisation, select the correct certificate and staff role. Do this before preparing a long form or waiting until the final evening.
Check supported file types, maximum size, language, signature, photo, scanning, and payment rules. Scan legibly in colour where relevant, include every page, orient the file correctly, and use descriptive filenames. Preserve the originals because an upload does not guarantee that the authority will accept the evidence.
Read the final declaration as a legal filing
Before sending, verify the applicant, represented person or organisation, recipient, service, address, dates, bank details, attachments, declarations, and payment. A prefilled field can still be wrong. Download a preview when available. If the service asks to sign or authenticate again at the end, complete that step. Logging in at the start is not necessarily the submission signature.
After sending, look for a clear success screen, transfer protocol, downloadable copy, timestamp, payment receipt, and Aktenzeichen. Save them outside the portal. An email stating that activity occurred may be useful, but it is weaker than the official receipt and final submitted file. A draft, upload queue, or browser confirmation before the final send action does not protect a deadline.
Monitor the case in the right place
Check the account inbox and service-specific status, but do not assume BundID displays every message from every connected authority. Some decisions appear in the specialist portal or ELSTER. Record when an authority requests missing evidence and the exact response deadline. Submit the response through the stated channel and save a second receipt.
For questions about login, use the account or app's technical support. For eligibility, missing documents, fees, processing, or the decision, contact the authority shown on the case. If the portal returns an error after payment or submission, do not blindly resend several times. Check receipts and bank status, then ask the authority whether a case was created.
Digital Costs
Distinguish Free Access from Card, Hardware, and Advice Costs
Core government accounts and identity software are free, while obtaining a document or buying optional equipment can cost money.
As checked on 25 August 2026, creating and using BundID, personal ELSTER, Mein Unternehmenskonto, and AusweisApp carries no official account or software charge. Activating the online ID function and setting a new PIN through the competent identity-card authority also costs EUR 0. A search result charging for access is selling private assistance, not the government account.
Use existing hardware before buying anything
Many current smartphones can read the card directly through NFC. AusweisApp publishes compatibility information and a device check, but the list is not a purchase guarantee because firmware and operating systems change. Test the phone first. A phone can also act as the reader for a computer. Buy a USB reader only if this setup is unsuitable, and compare the device price, driver support, operating system, return policy, and security features. There is no single official market price.
The credential document can create a real cost
A person who already holds an activated German identity card or eligible electronic residence permit does not pay a separate eID usage fee. A non-German EU or EEA citizen aged at least 16 may choose the separate eID card. The checked Bundesportal eID-card service charges EUR 37 with no fee waiver and estimates three to four weeks for production. The displayed appointment route is Berlin-specific, so use the responsible local authority.
An expired, lost, or damaged identity card or residence permit may require a paid replacement under that document's own rules. Do not attribute that fee to BundID or AusweisApp. Photographs, travel, postal delivery, and urgent or out-of-area issuance can add costs. Check the live service for the exact document and case.
Separate access fees from application fees
The underlying service can charge even when authentication is free. A residence permit, register extract, licence, court filing, certification, or professional signature may have its own tariff, payment deadline, exemption, and refund rule. The portal should identify the payee and case. Save the official fee page and receipt.
Tax advisers, lawyers, relocation providers, interpreters, and accessibility assistance are private services unless an authority provides or funds them. Obtain a written scope and VAT-inclusive price. No adviser can buy a higher assurance level or guarantee a decision.
The safest cost plan has four lines: account and software at EUR 0, identity document if needed, optional hardware, and the substantive service fee. This prevents a free login from being mistaken for a free application and prevents unnecessary purchases before the device is tested.
Keep Access Current
Manage Expiry, Moves, New Devices, Roles, and Electronic Notices
Update credentials before a deadline and treat every legally delivered notice according to the rules of its own service.
Maintain access as part of every move, document renewal, name change, job or staff change, and device replacement. Updating one portal does not automatically update the population register, tax office, immigration authority, insurer, or every connected service.
Renew certificates while the old access works
ELSTER certificate files are valid for three years. ELSTER sends advance email reminders and offers renewal during login. Renew before expiry, download the new .pfx file, test it, replace protected backups, and remove obsolete copies. Once the renewed certificate is activated, old copies no longer work. If a certificate has already expired, access recovery requires new activation data even though the user account is not automatically deleted.
For Mein Unternehmenskonto, review each organisation certificate, named custodian, role, and mailbox before a staff member leaves or changes duties. Do not delete a certificate until relevant messages and records are secured because associated mailbox content can be lost.
Update facts in the system that owns them
After moving, correct the official address through the required registration and then update BundID, ELSTER, specialist portals, and secure-delivery settings where necessary. After a name change, update the identity or residence document and underlying authority records, then check that the online account imports the correct data. Creating a second account to work around a mismatch can split cases.
A new phone does not change the identity stored on the card. Install AusweisApp from the official source, test NFC, and pair it again if used as a computer reader. A lost card is different: report it through the document's loss and blocking route, then replace it. A stolen certificate file or exposed password requires account recovery or certificate change, not merely deletion from one device.
Read electronic notices on their legal timetable
An email alert is usually not the official decision. The governing service determines when a notice is legally available or served. For electronic tax notifications under the current consent process, ELSTER's official notice guidance states that the notice is deemed served on the fourth day after it is made available, even if it is not retrieved. The email announces availability; the official PDF is obtained through Mein ELSTER or the filing software.
Do not generalise that four-day rule to BundID, a court mailbox, or another portal. Read the notice, service terms, and legal-remedy instructions. Save the notice, availability date, download evidence, and deadline calculation. Questions about login belong to technical support; questions about the notice's content or appeal belong to the issuing authority. Electronic tax-notice rules change from 2027, so recheck them for later cases.
Fix Access
Recover Access, Avoid Phishing, and Protect a Deadline
Diagnose the credential, portal, submission, or decision separately and use a recognised fallback before time runs out.
Identify the broken layer before seeking help. A card-reading failure belongs to the document, PIN, reader, or AusweisApp route. A BundID authentication error belongs to the account or assurance level. A rejected form or missing case belongs to the service portal and substantive authority. An adverse decision belongs to the remedy stated in that decision.
Preserve useful technical evidence
Record the official service URL, authority, date and time, browser and operating system, credential type, error code, step reached, and deadline. Save screenshots that exclude PINs, passwords, certificate files, QR recovery secrets, and unnecessary identity data. Keep payment evidence and any transfer protocol. Try an official supported browser or device and the service's documented fallback, but do not repeatedly pay or create duplicate applications without checking whether the first one arrived.
For online ID, use AusweisApp's card-and-device test. Confirm NFC, supported software, card position, PIN state, and whether another device can act as reader. A forgotten or blocked PIN can be reset free at the competent authority. A lost card should be blocked and reported through its official route.
For ELSTER, distinguish a forgotten password, missing certificate, expired certificate, and suspected copied certificate. Each has a separate change or recovery process. If the .pfx file may have been copied, secure the account and replace the credential rather than changing only a local filename.
Protect the legal action separately
Technical support can restore access but usually cannot extend a tax, immigration, benefit, licensing, court, or application deadline. Notify the issuing or receiving authority before expiry through a channel it recognises. State the case, deadline, failed portal, attempts, and requested safe method to submit. Attach the technical evidence and keep delivery proof. Do not assume a social-media message or ordinary email counts when the service specifies another channel.
If a submission lacks a receipt, ask the authority whether it created an Aktenzeichen before sending again. If the authority confirms no filing, use the instructed fallback promptly. If it confirms receipt, save that response with the case.
Separate complaints from appeals
A service complaint addresses access, conduct, or delay. It may improve handling but does not necessarily change a decision or suspend an appeal period. A correction request fixes factual data. An objection, review, or court action challenges the substance under the notice's instructions and deadline. Use the correct route and seek qualified advice for high-stakes cases.
Phishing pages often imitate appointment booking, BundID, ELSTER, or document recovery. Enter credentials only after following an official service link and checking the domain. Never approve an unexpected identity transaction, disclose the PIN, or upload a certificate to a reseller. Report suspected compromise to the account operator and the affected authority, then review recent messages and submissions.