Buying Guide

Access Credentials and Encoding, Explained

Facility codes, card formats, prox versus smart credentials, and magnetic stripe coercivity, explained plainly by an authorized HID dealer.

Nearly everyone who reads this page arrived with one of two questions. Either you need to order access cards and you are not sure what to order, or you have cards in your hand right now and they will not open the door. Both come back to the same fact: an access card is not really a card. It is a number, and that number has to be written to the card in exactly the form your readers and your access-control panel already expect. Print whatever you like on the front. The reader never looks at it.

This guide walks the whole picture in the order it actually matters: the difference between a credential category and a named technology, what a facility code and a card number really are, why formats like 26-bit H10301 and 37-bit H10304 come up in every conversation, where magnetic stripe still fits, and exactly what we need from you before we can program a card that works on the first tap. We have been doing this in Woodridge since 1984, and almost nothing we see is exotic. It is usually a missing facility code or a format mismatch.

One thing up front, because it saves everybody time: Card Imaging programs HID credentials only. HID Prox, iCLASS, iCLASS SE, iCLASS SR, and SEOS. We do not program generic MIFARE or other non-HID smart chips. We still explain them below, because you should know what is running in your building, but the programming we do is HID.

Category, technology, and format are three different questions

Ask ten facility managers what cards they use and eight will say "prox cards." That answer can mean any of three different things, and the confusion between them causes most bad card orders.

The category is how the card communicates with the reader. RFID is the umbrella term for anything read by radio without physical contact, and it covers two very different worlds. At 125 kHz you have the proximity card, which holds one fixed number and hands it to any reader that asks. At 13.56 MHz you have contactless smart cards, which are tapped rather than swiped and can hold real memory and run cryptography. A smart card is defined by having that chip, not by the frequency: a chip card can be contactless, or contact (the gold pads you insert), or both in one card.

The technology is the named product family the card belongs to. HID Prox, iCLASS, iCLASS SE, iCLASS SR, and SEOS are HID families. MIFARE and MIFARE DESFire are NXP families. Two cards can both be 13.56 MHz contactless smart cards and still be completely useless to each other's readers, because a reader has to speak that specific family.

The format is how the data is packed into bits once you are inside a family. 26-bit H10301 and 37-bit H10304 are formats, not technologies. One HID Prox card can be encoded in either, and your reader and panel will only accept the one they were set up for.

You need all three to order correctly. "125 kHz prox" is not enough. "HID Prox" is not enough. "HID Prox, 26-bit H10301, facility code 112, starting at card 4001, 250 cards" is an order we can fill today.

Not sure which printer or supply you need?
Tell us your use case and we'll point you to the exact gear, since 1984.

125 kHz proximity: what the reader actually receives

A 125 kHz prox card has no battery. Inside the plastic there is a coil of wire and a small chip. When you hold the card near the reader, the reader's field induces just enough current in that coil to wake the chip, and the chip broadcasts its stored number back. That is the whole transaction. It takes a fraction of a second, and it happens identically every single time, which is both the appeal and the weakness.

HID Prox is by far the most common 125 kHz credential in North American buildings. It is inexpensive, it is understood by essentially every access panel that has been installed in the last thirty years, and it does its one job reliably. If your building was wired for access control before roughly 2010 and nobody has touched it since, this is very likely what you have. If prox is what you run, our prox card guide goes further into formats, card bodies, and exactly what we need from you to program a batch.

Once the reader has the number, it has to hand it to the access-control panel, and the language it usually uses is Wiegand. Wiegand is two things at once, which trips people up. It is a wiring standard (two data lines, Data0 and Data1, plus power and ground) and it is also the way the bit structure of the credential data is described. That is why formats are named by bit count. When an integrator asks "what is your Wiegand format," they are asking about the bit structure of the number, not about the cable.

Security is where prox shows its age. The number is not encrypted, and the card does not check who is asking before it answers, so an inexpensive handheld cloner held near a card in a coat pocket can copy it in seconds. Prox is still perfectly reasonable for interior doors, supply rooms, and sites where the real risk is a lost card rather than a determined attacker. Where the risk profile is higher, the answer is a 13.56 MHz credential, covered further down and in our prox versus smart cards explainer.

The physical card body matters as much as the number in it. 1386 ISOProx II is standard ISO thickness and directly printable, which is what you want for a photo badge that also opens doors, and it is our standard prox card. 1586 composite ISOProx is a PVC and polyester blend that takes the heat of retransfer printing and stands up to heavy daily handling. The same credential also comes as key fobs and tags. You can see current stock on our blank and technology card pages, or narrow it down with the prox card finder.

You will also run into the 1326 ProxCard II, the thick clamshell card. We do not stock it, and if that is what your building buys today it is worth knowing what it costs you. A clamshell is around twice the thickness of a standard card, which puts it beyond what a card printer can print on, so it cannot carry the photo. Programs on clamshell almost always end up issuing two things, a clamshell for the door and a separate printed ID for the face, and neither one fits a normal slot punch or wallet. The credential inside is ordinary 125 kHz HID Prox, the same thing a 1386 carries. Encode a 1386 with your existing facility code and card number and the readers behave identically, with one printable card doing both jobs. If you want to check before committing, send us a working clamshell and we will read the format and facility code off it.

Facility code, card number, and card format

This is the section worth reading twice, because it explains nearly every "the cards arrived and they do not work" call we take.

The facility code

The facility code (also called a site code) is a number shared by every card issued to your organization. It is the reader's first filter. Before the system ever asks whether card number 4,012 belongs to somebody with permission to be here at 6am, it checks whether the card belongs to this site at all. Get the facility code wrong and the card number can be perfectly valid and the door still will not open.

Facility codes are not globally unique and nobody assigns them centrally. Whoever installed your access system picked one, or your original card vendor did. That is why we cannot look yours up for you. It lives in your panel and on your existing cards, not in any registry we can query.

The card number

The card number, sometimes called the internal number or the credential ID, is the part that changes from card to card. It is what your access software binds to a person, so that revoking one employee's badge does not affect anyone else's. Most organizations run it as a simple sequence, which is why we ask for a starting number and a quantity rather than a list.

Worth knowing: the number encoded inside the card is not automatically the number printed on the outside of it. They are two separate operations. If you want the encoded number to match a human-readable number, a barcode, or an asset tag on the face of the badge, say so when you order and we will print them in step. Plenty of programs skip this deliberately, so a card found in a parking lot gives away nothing.

The format ties the two together

The card format is the blueprint that says how many bits the whole credential is, which bits carry the facility code, which carry the card number, and which are parity bits used to check the read was clean. Your readers and panel are configured for one specific format. A card encoded in a different one does not read as "wrong," it usually does not read as anything at all, which is why the failure looks like a dead card rather than a rejected one.

26-bit H10301

26-bit H10301 is the open, non-proprietary format that almost every access system on the market understands. Its 26 bits break down as a leading parity bit, an 8-bit facility code, a 16-bit card number, and a trailing parity bit. That gives you facility codes 0 through 255 and card numbers up to 65,535. For a single site with a few hundred badges, it is plenty, and its universality is exactly why it has stayed dominant for decades.

The trade-off is that the address space is small and the format is open, so combinations repeat across the country. Two unrelated buildings can genuinely hold the same facility code and card number pair. For most organizations that is a theoretical concern. For a large employer, a hospital, or anywhere with a written security policy, it is a concrete reason to move up.

37-bit H10304

37-bit H10304 is the usual next step when 26-bit runs out of room. It carries a 16-bit facility code (0 to 65,535) and a 19-bit card number (up to 524,287), plus parity, which is far more unique credentials than H10301 can express. Multi-site employers and growing campuses land here most often.

Two practical differences. First, H10304 is an HID-controlled format rather than an open one, so the numbering tends to be managed rather than picked at random. Second, and this is the one that bites, your readers and panel have to be configured to accept 37-bit before the cards arrive. Confirm that first. A batch of correct 37-bit cards is still a batch of coasters against a reader expecting 26-bit.

Beyond these two there are proprietary and manufacturer-specific formats, some tied to a particular access-control brand and some issued to one customer. We program many of them. We simply have to be told which one you are on.

13.56 MHz HID credentials: iCLASS, iCLASS SE, iCLASS SR, and SEOS

Everything above still applies at 13.56 MHz. A smart credential normally carries the same facility code and card number, in a recognizable format. What changes is the wrapper around that data and how hard it is for someone to copy. If the chip itself is the part you want explained, our guide to what a smart card is covers contact versus contactless, what is actually stored on one, and why 13.56 MHz on its own does not make a credential secure. Here is how the HID families line up, oldest to newest.

  • iCLASS is HID's original 13.56 MHz smart-card platform, and it is common in corporate and institutional buildings installed in the mid-2000s onward. It was a real step up from prox at the time. Classic iCLASS has since had published security research against it, so new installations generally do not start here anymore, but there is a great deal of it still in service.
  • iCLASS SE is the current generation. It adds stronger cryptography and wraps the credential data in a secured object rather than handing over a plain number. Just as usefully, SE readers can be set up to accept more than one credential technology, which is what makes a phased migration possible instead of a single overnight cutover.
  • iCLASS SR sits between classic iCLASS and SEOS, and it comes up most often as a migration option: it is the choice for moving a large population off legacy iCLASS when you cannot change out every reader at once. Where it lands for your particular readers and your security requirement is a conversation worth having before you order, and we will have it with you.
  • SEOS is HID's flagship. It uses modern encryption and mutual authentication, meaning the card and the reader each prove themselves to the other before any data moves. It is also chip-independent: the credential is not welded to one piece of silicon. That is what allows one SEOS credential to carry several applications at once (door access, computer login, secure print release) and to live somewhere other than a plastic card.

We program all four in-house, matched to your system. On mobile access, one honest caveat: SEOS is the platform that phone-based credentials are built on, but whether a phone can open your specific door depends on your readers and your HID mobile program, not on the card order. Ask us before you plan around it.

If you are moving a whole population from prox to a smart credential, that is usually part of a rebadge or a full access system migration. Both can be phased so old and new credentials work side by side and nobody is stuck at a door during the switch.

MIFARE, DESFire, and NFC: what they are, and where our line is

MIFARE is NXP's 13.56 MHz contactless family, and it is genuinely everywhere: transit fare cards, campus cards, cashless vending, hotel locks, and plenty of access control. MIFARE Classic is the old workhorse. Its proprietary encryption was broken publicly years ago and is now treated as unsuitable for anything security-sensitive, though enormous numbers of those cards are still in circulation.

DESFire is the secure end of the same product line. MIFARE DESFire (you will see it as EV1, EV2, or EV3 depending on generation) uses standard, well-reviewed encryption and a file-based structure that lets several applications share one card with separate keys for each. If a security policy rules out classic MIFARE and legacy prox, DESFire is what a non-HID integrator will usually propose.

NFC is the odd one on this list, because it is not a credential family at all. It is a short-range communication standard running at the same 13.56 MHz, and it is what lets a phone behave like a card or a reader. Phone-based access exists because NFC (and Bluetooth) gave the phone a way to talk to the reader. The credential riding on top is still SEOS or an equivalent. "Our readers are NFC" tells you nothing about what card to buy.

Now the boundary, stated plainly: we program HID credentials only. We do not program generic MIFARE, MIFARE DESFire, or other non-HID smart chips. That is not a capability we quietly have and keep off the website. If your site runs on a MIFARE platform, the conversation worth having is what a move to a supported HID credential would actually involve. Encoding another vendor's platform is not work we take on.

Magnetic stripe, HiCo, LoCo, and coercivity

Radio credentials get the attention, but the magnetic stripe has not gone anywhere. Time clocks, cafeteria and point-of-sale systems, library and campus accounts, parking gates, and a fair number of older door systems still read a swipe, and a great many badges carry a stripe on the back purely so one card covers everything.

The stripe stores a small amount of data in up to three parallel tracks running its length. Track 1 and Track 3 hold more characters, and Track 2 is the short numeric track that most simple systems read. Whichever track your system uses, the data has to be written in the layout that system expects. It is the same principle as a Wiegand format on a prox card, just in a different medium.

Then the part that catches people out. Coercivity is how much magnetic force it takes to write to (and therefore to erase) a stripe, measured in Oersteds. HiCo and LoCo are the two grades. High-coercivity stripes, around 2750 Oe, are usually black, resist accidental erasure from magnets, phone cases, and bag clasps, and belong on any card meant to last years. Low-coercivity stripes, around 300 Oe, are usually brown, cost less, and are fine for visitor passes, event credentials, and anything reissued constantly.

The rule is simple and it is not optional: your encoder has to be set for the coercivity of the card in front of it. A printer set for LoCo cannot generate enough field to write a HiCo stripe, so the card comes out blank or reads intermittently. The mismatch matters in the other direction too, so the setting and the stock need to agree either way. If cards are swiping unreliably straight out of a fresh box, check this before you blame the printer, along with the other checks in our printer troubleshooting guide.

Cards very often carry more than one technology. A single badge can hold a prox antenna, a smart chip, and a magnetic stripe, so it opens the door, logs into a workstation, and swipes at the time clock. Plan that at order time, because none of it can be added later: the antenna, the chip, and the stripe are all built into the card body during manufacturing. Order the technology in the blank. We encode magnetic stripes as part of in-house card printing, and it is a routine add-on to an HID credential order.

What we need from you before we can program a card

Encoding is the step that turns a blank technology card into a working credential, and it is not something anyone can guess at. A card encoded with the wrong facility code is not close. It is a coaster, and reprinting a population of them is expensive. So we ask for a short, specific list before we cut a batch.

Four things are required:

  • Credential type or part number. HID Prox, iCLASS, iCLASS SE, iCLASS SR, or SEOS, and ideally the specific body (1386 ISOProx II, 1326 ProxCard II, 1586 composite, fob, or tag).
  • Wiegand format. Usually 26-bit H10301 or 37-bit H10304, sometimes a proprietary or manufacturer-specific format.
  • Facility (site) code. The number that identifies your building to the reader. Without it we cannot encode a working card, full stop.
  • Starting card number and quantity. Where the sequence begins and how many cards you need.

A few more details are optional, but they are the difference between a batch that arrives finished and a batch that needs handling twice: whether the numbering should be sequential or non-sequential, whether the encoded number should also be printed on the card and in what form (human-readable, barcode, or both), the artwork or photo layout, slot punch placement for lanyards and reels, any magnetic stripe track data, and your deadline.

Where to find your format and facility code

If nobody in the building knows these numbers, that is normal, and there are four reliable places to look.

  • Your access-control software. Most systems display the configured format and facility code somewhere in credential or cardholder settings.
  • Your last card order. The invoice or purchase order from whoever supplied the previous batch usually spells out credential, format, facility code, and number range.
  • A working card. Send us one. We can identify the credential and read the format and facility code from it, then match your new cards exactly. This is the fastest route when the paperwork is long gone.
  • Your integrator or locksmith. Whoever installed or maintains the panel set these values and will have them on file.

Two limits worth being straight about. We cannot read your facility code out of your panel remotely, and we have no back door into anyone's access system, so everything we program comes from what you tell us or from a sample card you send. And as above, we program HID credentials only.

From there, two paths. Standard combinations, HID Prox and iCLASS SE or SR in 26-bit or 37-bit, are programmed and shipped quickly and can be ordered online. Run the prox card finder if you want to confirm which one you need. SEOS, proprietary formats, unusual numbering, or anything you would rather talk through goes on an in-house programming quote, which we normally answer within one business day. Full service detail lives on our prox and access card programming page.

Common questions about access credentials and encoding

How do I find out what card format and facility code we use?

Check your access-control software first, since most systems show the configured format and facility code in credential settings. If that is a dead end, look at the invoice from your last card order, or ask whoever installed the system. If none of those work, mail us one working card. We can identify the credential type and read the format and facility code from it, then match your new cards exactly.

Will a 26-bit card work on a reader configured for 37-bit?

No. The reader and panel are looking for one specific bit structure, and a credential in a different format usually does not register at all rather than being rejected with a beep. It is the same in reverse: correct 37-bit cards will not work against a 26-bit configuration. Confirm what your system expects before ordering, not after.

What is the difference between a proximity card and a smart card?

A proximity card operates at 125 kHz and broadcasts one fixed, unencrypted number to any reader that asks. A smart card has a chip that can store data and perform cryptography, so it can prove itself to the reader instead of just announcing a number. Smart cards are typically 13.56 MHz contactless. Prox is cheaper and universally supported; smart is much harder to clone and can carry more than one application on a single card.

Do you program MIFARE or DESFire cards?

No. We program HID credentials only: HID Prox, iCLASS, iCLASS SE, iCLASS SR, and SEOS. If you are on a MIFARE or other non-HID platform, we can still talk through your options, including what a migration to a supported HID credential would involve.

Do you need access to our access-control system to program cards?

No, and we do not ask for it. Programming happens on our side from four pieces of information you supply: credential type, Wiegand format, facility code, and the starting number with quantity. Nothing connects to your network, and we never need panel or software credentials.

Can we keep our existing facility code and card numbering when we reorder?

Yes, and that is the normal case. As long as you are staying on the same access system, we encode new cards to your existing facility code and continue your number sequence from wherever you tell us to start, so the new cards behave exactly like the ones already in circulation.

Should we order HiCo or LoCo magnetic stripe cards?

HiCo (high coercivity, around 2750 Oe) for anything meant to last, because it resists accidental erasure from magnets and phone cases. LoCo (around 300 Oe) for short-term cards such as visitor and event passes, where the lower cost matters more than durability. Whichever you choose, your encoder has to be set to match the card, or the stripe will not write correctly.

Can one card have prox, a smart chip, and a magnetic stripe?

Yes, and multi-technology cards are common where one badge has to cover doors, computer login, and a time clock. The important part is ordering it that way from the start. The antenna, chip, and stripe are manufactured into the card body, so none of them can be added to a plain card afterward.

If you are still not certain what you need, that is the normal starting point, not a problem. Tell us what your readers are, or send us one working card, and we will identify the credential, the format, and the facility code and quote the batch from there. We have been programming access credentials for organizations across Illinois and nationwide since 1984, and the goal is always the same: cards that badge in the first time somebody taps them.

Keep reading

    Questions about your setup?

    Our team has spec'd card systems since 1984. Tell us what you're printing.