How RFID Keyfobs Work For Access Control?

Dec 09, 2025

Leave a message

Ruby Chen
Ruby Chen
A product expert specializing in RFID solutions. Ruby focuses on customer service, matching suitable hardware to clients across various industries seeking RFID solutions, and has over 10 years of sales experience.

RFID key fobs for access control work only when the credential, reader, controller, and software agree on the same frequency, chip protocol, card format, and permission rules. The fob does not unlock the door by itself; it carries an ID or secure credential that the access system validates before releasing the lock.

 

For a door-access project, the most important question is not whether the key fob looks good on a keyring. The first question is whether it can communicate with the installed reader and whether the access controller can interpret the credential value correctly.

 

A fob may scan successfully and still fail to open the door if the facility code, card number range, Wiegand format, sector data, application key, or reader interface is wrong. That is why custom RFID key fobs for door access projects should be specified by system compatibility before color, logo, or housing material.

Custom RFID key fobs for access control reader compatibility and encoding selection

 

What Happens When an RFID Key Fob Opens a Door?

 

A passive access key fob has no battery in most door-entry applications. The door reader creates a short-range radio field, the antenna inside the fob harvests enough energy to wake the chip, and the chip responds with either a fixed identifier, formatted credential number, or encrypted application response.

 

  1. The reader at the door generates a low-frequency or high-frequency field around the presentation area.
  2. The fob enters that field and the internal antenna powers the RFID chip.
  3. The chip answers according to its protocol, such as EM4200, T5577, MIFARE Classic, MIFARE DESFire, NTAG, ICODE, or another supported option.
  4. The reader converts the response into the configured output format, commonly Wiegand, OSDP, RS485, TCP/IP, or a vendor-specific interface.
  5. The access controller or management software checks the credential against user permissions, time schedules, door groups, and status rules.
  6. If the credential is valid, the controller triggers the relay and the electric lock, gate, turnstile, elevator, or cabinet releases.

 

In normal door access use, this should feel almost instant to the user. If the fob must be tapped repeatedly, the root cause is usually not the plastic shell alone. Check reader output power, antenna tuning, metal keyrings, reader configuration, chip type, card number format, and software enrollment before blaming the fob body.

 

The Access System Chain: Which Part Decides What?

 

The key fob is only one part of the system. A practical compatibility check separates four decisions: radio communication, credential interpretation, access authorization, and physical unlocking.

 

System part Main responsibility What to confirm before ordering key fobs
RFID key fob credential Carries the chip, antenna, UID, memory, formatted number, or secure application data. Frequency, chip model, UID length, memory size, read/write status, encryption support, encoding data, printed number rule.
Door reader Powers the fob, reads the credential, and sends data to the controller. Supported RFID technology, reader firmware, read range, output interface, keypad or biometric combination, indoor/outdoor rating.
Access controller Receives credential data and decides whether the user has permission. Wiegand bit format, OSDP setting, facility code, card number range, user group, door schedule, anti-passback rules.
Access software or backend Stores users, logs events, revokes lost credentials, and manages permissions. Import file format, decimal/hex conversion, user enrollment method, audit log requirements, lost fob procedure.
Lock, relay, gate, or turnstile Physically releases or blocks the access point after authorization. Fail-safe/fail-secure behavior, power supply, relay wiring, fire safety connection, emergency release requirement.

 

If the project includes both credentials and door hardware, compare the fob specification with RFID access control readers and door controllers before approving production. A reader/controller mismatch can cause the same fob to work on one door and fail on another.

 

125 kHz, 13.56 MHz, DESFire, or Dual Frequency?

 

Frequency selection should follow the installed reader base and the security level required. For replacement projects, match the existing reader first. For new buildings, choose a credential technology that can support the expected security policy for the next several years.

 

125 kHz LF

 

Best for legacy proximity replacement when existing readers already support EM, TK, HID Prox-compatible, T5577, EM4305, or similar low-frequency credentials. It is usually cost-effective, but many common fixed-ID systems are weak for high-security doors.

13.56 MHz HF

 

Used for smart-card access systems such as MIFARE, DESFire, NTAG, ICODE, and ISO/IEC 14443 or ISO/IEC 15693 families. It can support read/write memory and stronger authentication, but the exact chip and reader application must match.

Dual Frequency

 

Useful when a site is migrating from old LF readers to newer HF readers. One fob can carry both technologies, but both sides must be encoded and tested against real door readers before mass production.

Credential choice Best fit Main advantage Main risk if specified poorly
125 kHz fixed-ID fob Existing apartment, gym, storage, or low-risk proximity systems Broad legacy compatibility and low unit cost Often static ID only; not suitable as the only control for sensitive areas
T5577 / EM4305 writable LF fob Replacement jobs requiring a specific low-frequency format Can be programmed for selected legacy formats Wrong format or facility code may scan but fail authorization
MIFARE Classic 1K / compatible HF fob Older HF access, membership, hotel, or campus systems Read/write memory and wide reader support Not the right choice for new high-security deployments where stronger cryptography is required
MIFARE DESFire EV2 / EV3 fob Enterprise access, higher-security buildings, multi-application credentials Supports stronger authentication, secure applications, and controlled file structure Requires application IDs, key settings, and reader-side support
Dual-frequency LF + HF fob Phased reader migration across buildings or campuses One user credential can work during mixed-reader transition Antenna layout and encoding must be validated for both technologies

 

Sites that keep 125 kHz readers on some doors while upgrading others can evaluate dual-frequency key fobs for phased reader migration. For a deeper security and migration discussion, review the guide to choosing the right RFID keyfob frequency.

Security: UID Is Not the Same as Authorization

 

A door system can be configured in several ways. The weakest systems treat a visible UID or fixed card number as the credential. Stronger systems use formatted numbers, protected memory sectors, mutual authentication, diversified keys, or secure applications. The plastic housing does not determine security; the chip, reader, controller, and key management do.

 

Security tier What the reader checks Typical use Procurement warning
UID-only or fixed ID Static identifier returned by the chip Low-risk legacy doors, basic attendance, simple membership Do not rely on this alone for server rooms, labs, finance offices, or restricted warehouses.
Formatted credential number Facility code, card number, bit length, and controller format Standard commercial door systems The fob may read correctly but fail if Wiegand format or number conversion is wrong.
Protected memory or sector data Configured blocks, sectors, passwords, or keys Membership, hotel, campus, and multi-use systems Default keys or unprotected memory weaken the system.
Encrypted application credential Mutual authentication and secure application data Enterprise access and higher-security sites Requires reader support, application file design, and controlled key management.

 

For HF smart-card projects, ISO/IEC 14443 defines proximity card communication behavior at the RF interface level, while specific chip families add their own security and application structure. MIFARE DESFire, for example, is positioned for secure contactless applications and supports cryptographic engines such as DES, 3DES, and AES. For reader-to-controller communication, OSDP is a separate access-control protocol and should not be confused with the RFID frequency inside the fob.

 

When cloning risk matters, compare UID-only credentials with authenticated chips in the RFID data security for access credentials guide.

 

Wiegand, OSDP, and Why Frequency Is Not the Whole Format

 

RFID frequency describes the wireless communication between the key fob and reader. Wiegand, OSDP, RS485, TCP/IP, or another interface describes how the reader sends data to the controller. These are different layers. A 125 kHz reader and a 13.56 MHz reader may both output a 26-bit Wiegand number, but they do not read the same credential technology.

 

If a buyer only says "make the same number," the factory may still lack the information needed to produce working fobs. The order should specify the chip, card number format, bit length, facility code, printed number rule, and whether the reader/controller expects raw UID, decimal conversion, sector data, or application data.

 

Ordering Checklist for Replacement Access Key Fobs

 

For replacement credentials, start from the installed access system rather than the fob appearance. The safest order file includes the current reader model, a working sample credential, the required chip type, the encoded number range, and the print/laser numbering rule.

 

  • Reader brand and model, or clear photos of reader labels and controller settings.
  • Existing fob or card sample, including printed number and scanned chip result if available.
  • Required chip family: EM4200, TK4100, T5577, EM4305, MIFARE Classic 1K, NTAG213, DESFire EV3, or project-specific option.
  • Frequency and protocol: 125 kHz LF, 13.56 MHz HF, ISO/IEC 14443A, ISO/IEC 15693, dual-frequency, or other requirement.
  • Facility code, site code, card number range, Wiegand bit format, or software import CSV.
  • Printed number rule: UID, decimal conversion, card number, barcode, QR code, employee ID, or hidden encoding only.
  • Security requirement: read-only UID, writable memory, password protection, locked memory, sector key, application file, or diversified key management.
  • Packaging rule: packed by department, building, floor, user group, or sequential number range.

 

For new branded batches, approve a pilot sample before mass production. A small pre-production test can catch the most expensive errors: correct logo but wrong chip, correct chip but wrong facility code, correct number printed but wrong value encoded, or correct encoding but poor read range at the actual door reader.

 

Common Reasons a New RFID Key Fob Does Not Open the Door

 

Wrong frequency: A 13.56 MHz fob will not work with a reader that only supports 125 kHz, even if both are called RFID access credentials.
Wrong chip family: MIFARE Classic, NTAG, DESFire, EM4200, T5577, and HID Prox-compatible credentials are not interchangeable.
Wrong output format: The reader may scan the fob, but the controller rejects the number because the bit format, facility code, or decimal conversion is different.
Reader-side application mismatch: Secure HF credentials need the reader to know the right keys, application IDs, or protected memory locations.
Physical interference: Metal keyrings, phones, thick decorative layers, and small antenna layouts can reduce read distance in compact fobs.

 

Customization Choices After Compatibility Is Confirmed

 

Once the chip, frequency, format, and security settings are fixed, the remaining decisions are mainly about daily handling, branding, and issuing workflow.

 

  • ABS housing for cost-effective apartment, office, gym, school, and staff access projects.
  • Epoxy logo surface when a full-color brand graphic needs better scratch protection.
  • Leather or wooden housing for hotel, club, resort, membership, or premium brand use.
  • Laser numbering for long-term wear resistance on daily keyrings.
  • Color-coded shells for tenants, staff, contractors, visitors, departments, or permission groups.
  • Pre-programmed number lists packed by building, floor, door group, or issuing sequence.

 

After the chip and encoding are fixed, use the ABS vs epoxy RFID keyfob material comparison to select the right housing for daily keyring wear.

 

FAQ

Q: Can RFID key fobs be copied?

A: Some can. Many legacy 125 kHz and UID-only credentials can be copied because they expose a fixed identifier. Encrypted HF credentials are harder to duplicate when the reader and fob use proper authentication, protected keys, and secure applications. Security depends on the full system design, not the plastic fob shape.

Q: What happens if an access control key fob is lost?

A: The administrator should deactivate the lost credential in the access software and issue a replacement with a new authorized number or application. The door lock usually does not need to be changed because permission is controlled by the database and controller, not by the physical fob alone.

Q: Is 13.56 MHz always better than 125 kHz for door access?

A: Not always. If a building already uses 125 kHz readers and the risk level is low, matching the existing system may be the practical replacement choice. For new or security-sensitive sites, 13.56 MHz smart credentials with stronger authentication are usually a better direction than fixed-ID legacy fobs.

Q: Can one key fob work with two different access systems?

A: Yes, if the fob is built as dual-frequency or multi-technology and both sides are encoded correctly. This is common during migration: old 125 kHz readers remain on some doors while upgraded 13.56 MHz readers are installed on main entrances or higher-security areas.

Q: Why does my RFID key fob scan but not open the door?

A: The reader may detect the chip but send data the controller does not accept. Check frequency, chip type, Wiegand or OSDP settings, facility code, card number range, decimal/hex conversion, and user permissions. A readable fob is not automatically an authorized credential.

Q: Can a phone read an access control key fob?

A: A phone with NFC can usually detect only compatible 13.56 MHz NFC/HF tags, and even then it may not read protected access data. It normally cannot read 125 kHz low-frequency fobs. Phone detection is not a reliable compatibility test for a door access credential.

 

A reliable access key fob order starts with the door system: reader model, controller format, chip protocol, facility code, security level, and software enrollment method. Once those details are confirmed, shell material, logo printing, numbering, and packaging can be customized without risking the most common failure: a credential that looks correct but does not work at the door.

Send Inquiry