Mobile credentials are access badges stored on a smartphone or smartwatch. Instead of tapping a plastic card, a person holds or taps their phone at a compatible card reader, which reads the credential over Bluetooth Low Energy (BLE) or NFC and passes it to the access control system. Credentials live either in a provider’s app or, with some providers and supported readers, in Apple Wallet or Google Wallet. They can be issued and revoked remotely, which is why they are common in cloud-managed access control.
At a glance
- A phone or watch replaces or supplements the plastic badge, communicating with the reader over BLE, NFC or both.
- Credentials are issued and revoked from the access control platform, so no card has to be printed or collected.
- Some providers support badges in Apple Wallet and Google Wallet on supported devices and readers.
- Readers must support the mobile technology and the provider’s credential; older readers often need replacing.
- A physical card or fallback process is still needed for people without a suitable phone or with a dead battery.
What problem it solves
Plastic badges cost time and money: printing, mailing to remote hires, replacing lost cards, and collecting them when people leave. Cards are also easy to forget at home and, in older formats such as proximity cards, widely reported to be easy to copy.
Mobile credentials turn issuing a badge into sending an invitation. A new hire or contractor can have door access on day one without visiting a badge station, and access can be removed instantly from the same console. Because the phone is usually locked with a PIN or biometric, a credential can also carry more assurance than a card that works for whoever holds it, depending on how it is configured. When the access platform is linked to identity and access management (IAM) or an identity provider (IdP), door access can follow the same joiner and leaver process as other accounts.
How it works
Provisioning. An administrator assigns a credential in the access control platform. The user receives an invitation, signs in to the provider’s app and the credential is loaded onto the phone through the provider’s provisioning process. For wallet badges, the provider’s system pushes the badge into Apple Wallet or Google Wallet after the user links their account.
At the door. With BLE, the reader detects the phone at short range; depending on settings, the user may need to unlock the phone, tap a button in the app, or simply approach and touch the reader. With NFC, the user holds the phone or watch to the reader, much like a contactless payment. The phone and reader exchange credential data using the provider’s protocol, which may support mutual authentication and encryption; verify the protocol, key management, replay protection and reader configuration for the product you buy. The controller then decides whether to unlock, just as it would for a smart card.
Fallbacks. Batteries die and phones get lost. Some wallet badges on some devices can keep working briefly in a power-reserve mode after the phone shuts down; app-based credentials usually can’t. Most deployments keep physical cards available and a front-desk process for exceptions.
Visitors and contractors. Many platforms can send time-limited mobile credentials, often through a visitor management system, that expire automatically.
When it matters for buyers
- When moving to cloud access control. Mobile credentials are a common feature of access control as a service (ACaaS) platforms.
- When replacing old cards and readers. Upgrading readers is the moment to add mobile support.
- When you hire remotely or use many contractors. Remote issuing removes the badge-printing step.
- When employees resist work apps on personal phones. Plan a card alternative and a clear policy about what the app can see.
- When budgeting. Per-user licensing can add up; compare it with the full cost of printing and replacing cards.
Questions to ask vendors
- Which readers support your mobile credentials, over BLE, NFC or both?
- Do you support Apple Wallet and Google Wallet badges, and on which devices and readers?
- How is a credential provisioned, revoked and transferred to a new phone?
- What happens when the phone is locked, offline or out of battery?
- What data does the app collect from the phone, and is location tracked?
- How are mobile credentials licensed, and what happens to them if we change platforms?
- Can we issue time-limited credentials to visitors and contractors?
How it differs from smart cards
A smart card is a physical badge with a chip that authenticates with the reader. A mobile credential does a similar job from a phone or watch, using BLE or NFC and the phone’s own security, such as its screen lock. Mobile credentials can be issued and revoked remotely without printing anything; smart cards work without a charged phone and suit people who can’t or won’t use one. Many organizations run both, with readers that accept either. See our door access controls overview for help planning a rollout.
