Dual-technology migration credential

Brivo Prox Cards Explained: The 125 kHz Layer & Migration Path

The Brivo prox layer is the 125 kHz proximity credential Brivo pairs with its AES-secured 13.56 MHz Unified Credential on a dual-technology card. The proximity half keeps legacy readers working during an upgrade, while the encrypted smart-card half provides the real security. The 125 kHz layer is an open format that can be supplied as a compatible card.

Last updated 2026-07-29

What is the Brivo prox card layer?

The Brivo prox layer is the 125 kHz low-frequency proximity credential that Brivo places on a dual-technology card next to its AES-secured 13.56 MHz Unified Credential. On the dual-technology card, the proximity side is typically a 37-bit (H10304-class) format, and it presents a readable number that older 125 kHz readers can accept.

This prox layer is not where a Brivo card's security lives. Its purpose is compatibility: it lets a building that still runs 125 kHz readers keep unlocking doors while the site rolls out encrypted Unified Credentials and upgrades its readers. The encrypted 13.56 MHz half is what makes the card secure.

Why does Brivo pair a prox layer with an encrypted smart card?

Brivo pairs a 125 kHz proximity layer with the AES-secured 13.56 MHz smart card so a site can migrate without a flag-day cutover. Brivo's dual-technology cards are described as being for "a gradual migration," and its Smart Readers "support legacy prox cards alongside higher-security encrypted cards and mobile credentials at the same door."

The result is one card that works everywhere during the transition: on old 125 kHz readers via the prox layer, and on new Brivo readers via the encrypted Unified Credential. As readers are upgraded, the same cardholders are already carrying the secure credential, so no second re-badging is needed when the proximity layer is finally switched off.

Can a Brivo prox card be cloned?

The 125 kHz proximity layer of a Brivo card can be copied, like any unencrypted low-frequency proximity credential — it presents a readable number rather than performing a cryptographic challenge. That is a property of 125 kHz proximity in general, not a Brivo-specific weakness.

The AES-secured 13.56 MHz Unified Credential on the same card cannot be cloned that way, because it releases its identity only after an AES exchange and the smart card generation is certified to Common Criteria EAL5+. This split is exactly why a site should treat the prox layer as temporary: keep it while legacy readers exist, then remove it so only the encrypted credential remains.

How does a Brivo dual-technology migration work?

A Brivo migration runs the proximity and encrypted layers in parallel, then retires the weaker one. The stages below show how the dual-technology card carries a site through the transition.

StageWhat the card presentsWhat the reader accepts
Start (legacy)125 kHz prox number onlyOld 125 kHz readers
Dual-technology rollout125 kHz prox + AES-secured 13.56 MHzBoth old readers and new Brivo Smart Readers
Reader upgrade125 kHz prox + AES-secured 13.56 MHzBrivo Smart Readers on OSDP secure channel
Hardened end stateAES-secured 13.56 MHz (or mobile) onlyEncrypted credential only; prox retired

How do I phase out the 125 kHz layer on Brivo?

Once every cardholder carries the AES-secured Unified Credential and readers have been upgraded to Brivo Smart Readers, a site can stop relying on the 125 kHz proximity layer. Moving reader wiring to OSDP with secure channel also closes the gap that legacy Wiegand leaves, since OSDP secure channel encrypts and authenticates the reader-to-controller link.

The end state is a Brivo deployment that accepts only encrypted credentials — the Unified Credential card or fob, or a Bluetooth mobile credential — with the copyable proximity layer removed. Until that point, the 125 kHz half of the dual-technology card is the part a third party can legitimately supply.

Can I buy a compatible Brivo prox card?

Yes — the 125 kHz proximity layer of a Brivo card is an open low-frequency format, so a compatible prox card can be encoded to match your site's format and read by your existing 125 kHz readers. This is different from the AES-secured Unified Credential, which is keyed within Brivo's system and can only come from Brivo or your integrator.

If your Brivo site still runs 125 kHz proximity anywhere, that layer is what we supply as compatible cards — the Brivo 37-bit prox format and the general HID, Indala, and AWID prox formats a mixed site carries. The encrypted Unified Credential itself should be sourced through Brivo.

Compatible prox formats we supply

The 125 kHz layer a Brivo site runs during migration, and adjacent open prox formats, can be encoded as fully compatible credentials that read on your existing readers.

Sources & references

Brivo and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

Brivo Unified Credential (prox layer) — common questions

What is a Brivo prox card?

A Brivo prox card is the 125 kHz proximity layer Brivo pairs with its AES-secured 13.56 MHz Unified Credential on a dual-technology card, usually as a 37-bit (H10304-class) format. It keeps legacy 125 kHz readers working during migration and is not where the card's security lives.

Why does Brivo put a prox layer on the same card as the smart credential?

So a site can migrate gradually. Brivo's dual-technology cards are for a gradual migration, and its Smart Readers accept legacy prox alongside encrypted cards at the same door. One card works on old 125 kHz readers and new Brivo readers, avoiding a second re-badging when prox is retired.

Can a Brivo prox card be cloned?

The 125 kHz proximity layer can be copied like any unencrypted low-frequency card, because it presents a readable number. The AES-secured 13.56 MHz Unified Credential on the same card cannot be cloned that way, since it authenticates with AES and the smart card is certified to Common Criteria EAL5+.

How do I remove the 125 kHz layer from my Brivo system?

Once all cardholders carry the AES-secured Unified Credential and readers are upgraded to Brivo Smart Readers, stop relying on the prox layer and move reader wiring to OSDP with secure channel. The end state accepts only encrypted credentials, with the copyable proximity layer removed.

Can I buy a compatible Brivo prox card?

Yes. The 125 kHz proximity layer is an open format, so a compatible prox card can be encoded to match your site and read by existing 125 kHz readers. The AES-secured Unified Credential is keyed within Brivo's system and must come from Brivo or your integrator.