Knowledge · E-invoicing
The four-corner model in e-invoice exchange, explained technically
What is the four-corner model?
The four-corner model is the architecture the Peppol network uses to exchange electronic documents. It involves four parties, referred to in Peppol terminology as the four corners.
The core of the model is that the first and the fourth corner never communicate directly. Thanks to the network’s interoperability, all participating access points can communicate with one another, and no dedicated coordination is required. Once connected, a participant reaches every other participant in the network without building a separate interface for each counterparty.
-
Sender
The company issuing an invoice. In a vendor's software, this is the end customer creating an outgoing invoice.
-
The sender's Access Point
It accepts invoices and other business documents, checks them and transports them into the network.
-
The recipient's Access Point
It receives the document from the network and hands it over to the recipient.
-
Recipient
The company that receives the invoice and processes it further. The receiving system is usually the recipient's accounting or DMS software.
The benefits of Access Points
The Access Point provides software vendors with several functions that would otherwise have to be built and maintained in-house.
Standardised access to the network: The Access Point connects your software to the Peppol network once and speaks a single protocol and a single set of formats to the outside, regardless of which software sits behind it.
Validation before sending: The Access Point checks outgoing documents against the relevant rules, such as EN 16931 and format specifications. That lowers the risk of invoices being rejected by the recipient.
Interoperability through the common standard: Sender and receiver exchange a document in a format that both sides can process. In Europe this is usually based on EN 16931, while other regions follow their own standards.
Secure transmission with proof of delivery: The Access Point handles the encrypted and signed transmission in full, including the receipt confirming delivery to the receiving Access Point. Via the Message Level Status (MLS), it additionally confirms that the document has reached the recipient’s receiving system, not just the Access Point.
Whether a vendor provides these functions through a certified Access Point of its own or sources them from an existing provider is one of the central decisions in any implementation.
AS4, the protocol for transmission between Access Points
AS4 handles the transmission between the sender’s Access Point and the recipient’s Access Point. AS4 is a messaging protocol based on the ebMS 3.0 standard and specified in a dedicated Peppol profile.
AS4 provides three properties that matter in invoice exchange.
Encrypted transmission: The message is transmitted in encrypted form, so the content is protected in transit.
Signed message: The message is signed, so its origin and integrity can be verified.
Delivery acknowledgement: Delivery is acknowledged with a signed receipt, which gives the sender proof that the message reached the recipient’s Access Point. Note: this receipt does not confirm that the end recipient accepts the invoice — that runs through a separate response message where required.
For software vendors, AS4 runs entirely inside the Access Point. If you source the connection from a provider, you never touch the protocol itself and work against a higher-level interface instead.
SML and SMP, how a recipient is found
Before an Access Point can deliver an invoice, it needs to know where to send it. Two lookup services handle that: the Service Metadata Locator (SML) and the Service Metadata Publisher (SMP).
Every participant in the network has a unique Peppol participant identifier. It consists of a scheme and a value, for example a VAT identification number or another registered identifier.
The SML is a central service built on DNS. It answers the question of which SMP is responsible for a given participant identifier, and in that sense functions as an address book of the network.
The SMP holds the participant’s metadata. It states whether the participant can be reached, which document types and processes it supports, and which Access Point it is connected through.
In combination, the process runs in three steps. The sender’s Access Point queries the SML for the SMP responsible for the recipient. From the SMP it receives the supported formats and the technical address of the receiving Access Point. Only then does it send the document over AS4 to that address.
Software vendors can also put this lookup to active use, checking before sending whether a recipient can be reached over Peppol and which formats it accepts. Without a connection of your own, you can try this out directly with the Peppol ID lookup, which runs the query without an account.
Certificates and the trust model
So that Access Points in the network can trust one another, Peppol operates a certificate infrastructure of its own, a public key infrastructure (PKI).
Every Access Point receives a certificate that marks it as an approved participant in the network. This certificate is used for transmission over AS4 and for the entries in the SMP.
The certificate allows a receiving Access Point to tell whether an incoming message genuinely comes from an approved participant. The result is a closed network of trust in which only certified Access Points exchange documents.
Non-compliant Service Providers can be excluded from the network. This results in their certificate being revoked, and transmission is no longer possible.
A certified Access Point with its own certificate requires OpenPeppol membership and proof of conformance. In that case, the operator takes on the role of Service Provider — the certified OpenPeppol role — including the ongoing maintenance of certificates and technical conformance.
What the four-corner model means for software vendors
For software vendors adding e-invoicing to their product, the model results in a clear division of tasks. Your own product creates and processes e-invoices and makes them available to the end customer; the Access Point takes care of the network side. A vendor can operate that side itself or source it from an existing Access Point.
On the network side, the four-corner model brings the individual building blocks together into one continuous process. Sender and recipient connect only to their Access Point, AS4 transfers the document between the two, SML and SMP establish where it goes and in which format, and the certificates ensure that both sides can trust an approved participant.
A single connection is therefore enough to reach every other participant in the network. Knowing how this runs makes it easier to plan your own implementation and to make sense of exchange errors more quickly.