AES-secured 13.56 MHz smart card

STid 8870 (2K AES Smart Card): What It Is & How to Reorder

The STid 8870 is a 2K AES-secured 13.56 MHz smart card and one of the most common STid card SKUs in the US. It is a blank platform until it is encoded: a live 8870 credential carries your site's own AES keys, written with the STid SECard kit, so blank stock can be reordered but a ready-to-use "compatible" 8870 cannot be bought pre-keyed from a third party.

Last updated 2026-07-29

What is the STid 8870 (2K) card?

The STid 8870 is STid's 2K-memory AES-secured 13.56 MHz smart card, referenced in STid's US catalogue among its Architect-compatible credentials. It operates over ISO/IEC 14443 Type A and is designed to be encoded with AES-128 keys through the STid SECard kit, then read by STid Architect readers.

"8870" is a card SKU, not a security level — the security is defined by how it is keyed. On its own, an 8870 is a blank AES smart card with 2K of memory. Once a site writes its private keys and application layout onto it with SECard, it becomes a working credential that authenticates by AES mutual authentication with a per-card diversified key. That is why two physically identical 8870 cards can be completely non-interchangeable between two different buildings.

What does "2K" mean, and do I need 2K, 4K or 8K?

"2K" refers to the card's on-chip memory — roughly two kilobytes — which is plenty for access control alone but limits how many separate applications the card can hold. STid and equivalent AES smart cards come in 2K, 4K, and 8K memory sizes, often referenced by their chip codes. Choose the size by how many applications the card must carry, not by how secure it is: all three sizes use the same AES cryptography.

Card memoryChip codeTypical use
2K8870 / D23-classAccess control only — the common US SKU
4KD43-classAccess plus a second application (payment, time & attendance)
8KD83-classMulti-application campus or enterprise cards

Why can't I just buy a "compatible" STid 8870 card?

You cannot buy a working "compatible" STid 8870 card because a live credential must contain your site's private AES keys, and those exist only inside your STid SECard kit. A card sold pre-encoded by a third party would either carry the wrong keys (and never open your doors) or would require someone to already possess your secret keys — which, in a correctly run STid deployment, no outside party does.

This is by design and is the whole point of STid's "create your own security keys" model, explained in full in the STid Architect & SECard guide. Security ID Systems does not sell a drop-in encoded 8870, and any supplier claiming to offer a ready-to-use "compatible" STid card for a keyed site should be treated with suspicion. The legitimate paths are blank stock encoded by your own integrator, or the open formats below.

Can I reorder blank STid 8870 cards, and what else can I get?

Blank STid 8870 stock can be reordered and then encoded by whoever holds your site keys — usually your integrator, using SECard. That is the correct route for topping up credentials on an existing STid Architect system without compromising your key policy.

What Security ID Systems supplies directly is the surrounding layer many STid sites still run: 125 kHz proximity cards on legacy doors, and card-serial-number (CSN) or generic Wiegand credentials where an Architect reader is set to read a plain identifier. Those open and UID-based formats we encode as fully compatible credentials that read identically on your existing readers, so you can standardise the low-security doors while the keyed 8870 credentials stay under your own control.

Compatible formats we do supply

A keyed STid 8870 must be encoded with your own keys via SECard. But where an STid site still runs 125 kHz proximity or reads a plain card serial number, these open formats are ones we supply as fully compatible, encoded credentials.

Sources & references

STID and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

STid 8870 — common questions

What is an STid 8870 card?

The STid 8870 is STid's 2K AES-secured 13.56 MHz smart card, one of the more common STid card SKUs in the US. It runs on ISO/IEC 14443 Type A and is encoded with AES-128 keys through the STid SECard kit before it works as an access credential.

What is the difference between STid 2K, 4K and 8K cards?

The number is the card's on-chip memory, not its security. 2K (the 8870) suits access control alone; 4K adds room for a second application such as payment or time-and-attendance; 8K supports multi-application campus and enterprise cards. All use the same AES cryptography.

Can I buy a pre-programmed compatible STid 8870 card?

No. A working 8870 must carry your site's private AES keys, which live only in your SECard kit, so no third party can supply a ready-to-use drop-in card. You can reorder blank 8870 stock and have your integrator encode it with your keys.

Why won't a blank STid 8870 open my door?

A blank 8870 has no site keys or application layout written to it. Until it is encoded with your AES keys in SECard, an STid Architect reader has nothing to authenticate against, so it will not grant access even though the card is physically identical to your working ones.

Where can I reorder STid 8870 credentials?

Blank 8870 stock can be reordered and encoded by your integrator using SECard. For the legacy 125 kHz proximity and card-serial-number credentials that many STid sites also run, Security ID Systems supplies fully compatible, encoded replacements.