Cloud access credential on an open standard

Brivo Cards & Fobs Explained: The Unified Credential, LEAF & Security

A Brivo card or fob is most often the Brivo Unified Credential, built on an AES-secured 13.56 MHz smart card that uses the open LEAF file structure. Brivo also offers dual-technology cards that carry a 125 kHz proximity layer for gradual migration, plus Bluetooth mobile credentials, all managed from the Brivo Access cloud platform.

Last updated 2026-07-29

What is a Brivo access credential?

Brivo is a cloud access-control provider, and its flagship credential is the Brivo Unified Credential. Brivo builds the Unified Credential on an AES-secured 13.56 MHz smart card using the LEAF file structure, an open and interoperable credential standard, and manages it through the Brivo Access cloud platform.

Alongside the secure smart card, Brivo supplies dual-technology cards that add a 125 kHz proximity layer for sites migrating from older readers, and Bluetooth mobile credentials for phone-based unlock. The secure Unified Credential is provisioned through Brivo and its integrators rather than manufactured by third parties.

What is the LEAF standard behind the Brivo Unified Credential?

LEAF is an open, interoperable credential data structure that runs on AES-secured 13.56 MHz smart cards, and Brivo is a member of the LEAF community. Rather than a proprietary format locked to one vendor, LEAF is designed so a credential works across any LEAF-compatible reader, which is why Brivo describes its Unified Credential as built on the LEAF file structure.

For a buyer, the practical effect is that a Brivo Unified Credential is both encrypted and portable across the LEAF ecosystem, while still being provisioned and keyed through Brivo. The openness is about interoperability between manufacturers, not about the credential being copyable — the underlying smart card still authenticates with AES before releasing any data.

How secure is a Brivo card, and can it be cloned?

A Brivo Unified Credential is an AES-secured 13.56 MHz smart card, and the current generation of that smart card is independently certified to Common Criteria EAL5+. Brivo's own credential material cites the EAL5+ rating and offers optional card-plus-PIN two-factor authentication for higher-assurance doors.

Because the credential releases its identity only after an AES exchange, a Brivo Unified Credential cannot be cloned by copying a serial number the way a 125 kHz proximity card can. The weaker element is only the optional 125 kHz layer on a dual-technology card, which exists purely so legacy readers keep working during a migration.

What are the Brivo credential options?

Brivo lets a site choose among secure smart cards and fobs, dual-technology cards for migration, and mobile credentials. The options below summarise the main choices, from most secure to most migration-oriented.

CredentialCarrierSecurityThird-party compatible?
Brivo Unified Credential13.56 MHz AES card/fob (LEAF)AES, EAL5+ smart card, optional card+PINNo — via Brivo
Dual-technology card13.56 MHz AES + 125 kHz proxAES on the smart side, none on proxProx layer only
Legacy prox card125 kHz proximityUnencrypted, copyableYes — an open prox format
Brivo mobile credentialPhone over BluetoothEncrypted mobile credentialNo — provisioned in-app

What readers does Brivo use, and do they read old cards?

Brivo Smart Readers read 125 kHz proximity, 13.56 MHz smart cards, and Bluetooth mobile credentials, and they output over both OSDP and Wiegand. Brivo describes them as supporting "legacy prox cards alongside higher-security encrypted cards and mobile credentials at the same door."

That multi-technology capability is what makes a phased upgrade practical: a Brivo site can accept its existing 125 kHz cards while it issues AES-secured Unified Credentials, then retire the proximity layer once everyone has moved. Using OSDP with secure channel also encrypts the reader-to-controller link, closing a gap that legacy Wiegand wiring leaves open.

Can I buy a compatible Brivo card or fob?

Not for the secure Unified Credential. Because a Brivo Unified Credential is an AES-secured, LEAF-structured smart card keyed within Brivo's system, no third party can produce a working compatible version, and Security ID Systems does not offer one. Additional secure cards, fobs, and mobile credentials come from Brivo or your integrator.

What we can supply is the 125 kHz proximity layer a Brivo site runs during migration — including the Brivo 37-bit prox format and the general HID, Indala, and AWID prox formats a mixed site carries. Those open low-frequency formats we encode as fully compatible credentials.

The 125 kHz layer we can supply during migration

While a Brivo site still runs 125 kHz proximity alongside its AES-secured Unified Credentials, these open formats are ones we encode as fully compatible credentials that read on your existing readers.

Sources & references

Brivo and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

Brivo Unified Credential (LEAF) — common questions

What is the Brivo Unified Credential?

The Brivo Unified Credential is Brivo's flagship access credential, built on an AES-secured 13.56 MHz smart card using the open LEAF file structure. It is encrypted, portable across the LEAF ecosystem, and provisioned through Brivo, and it can be issued as a card or a fob.

Does Brivo use the LEAF standard?

Yes. Brivo is a member of the LEAF community, and the Brivo Unified Credential is built on the LEAF file structure. LEAF is an open, interoperable credential data structure on AES-secured 13.56 MHz smart cards, designed to work across any LEAF-compatible reader rather than being locked to one vendor.

Can a Brivo card be cloned?

A Brivo Unified Credential is an AES-secured 13.56 MHz smart card certified to Common Criteria EAL5+, so it cannot be cloned by copying a serial number. Only the optional 125 kHz proximity layer on a dual-technology card is copyable, and it exists solely to keep legacy readers working during migration.

Do Brivo readers still read my old prox cards?

Yes. Brivo Smart Readers read 125 kHz proximity, 13.56 MHz smart cards, and Bluetooth, and output over OSDP and Wiegand. They accept legacy prox cards alongside encrypted cards and mobile credentials at the same door, so a site can upgrade gradually.

Can I buy a compatible Brivo card?

No for the secure Unified Credential — it is an AES-secured, LEAF-structured smart card keyed within Brivo's system and comes only through Brivo or your integrator. The 125 kHz proximity layer, including the Brivo 37-bit format, can be supplied as a compatible card during migration.