What is a Verkada access credential?
Verkada is a cloud-managed physical-security vendor, and a Verkada access credential is what a Verkada badge reader authenticates before it unlocks a door. In its most secure form, a Verkada credential is an AES-secured 13.56 MHz smart card carrying an encrypted access credential, managed from the same Verkada Command cloud console as the cameras and readers.
Verkada supports several credential carriers on top of that secure card: a legacy 125 kHz proximity layer for sites migrating from older systems, the Verkada Pass mobile app that unlocks over Bluetooth, and phone-based NFC via Apple Wallet or Android. The physical high-security credential itself is issued through Verkada rather than manufactured by third parties.
What frequency and encryption does a Verkada card use?
A secure Verkada card operates at 13.56 MHz over the ISO/IEC 14443-A air interface and is protected with 128-bit AES. Verkada's own credential documentation lists the encrypted smart card at 13.56 MHz with AES-128, in direct contrast to the 125 kHz proximity option, which Verkada lists with an encryption value of "none."
The AES-secured 13.56 MHz smart card Verkada uses adds anti-relay protection at the chip level on top of 128-bit AES. That is the technical reason Verkada treats the 13.56 MHz card as the secure credential and the 125 kHz prox layer purely as a migration convenience.
Can a Verkada access card be cloned?
A Verkada 125 kHz proximity card can be copied like any unencrypted low-frequency proximity credential — Verkada itself records that layer's encryption as "none." The AES-secured 13.56 MHz Verkada smart card is a different matter: its identity is released only after a 128-bit AES exchange, so it cannot be cloned by reading a serial number.
For sites that want to remove the weak layer entirely, Verkada documents a hardening step on its fourth-generation readers: disable the 125 kHz antenna and turn off "Prox Unlock," so the reader will only accept the AES-secured card. Once a site has re-badged everyone onto the encrypted card and disabled prox, the copyable layer is gone.
What are the Verkada credential options?
Verkada offers a spread of credential carriers so a site can trade off security, convenience, and migration needs. The options below map the main choices a Verkada administrator selects between.
| Credential | Carrier | Security | Third-party compatible? |
|---|---|---|---|
| Secure smart card | 13.56 MHz AES card/fob | 128-bit AES (encrypted smart card) | No — issued via Verkada |
| Multi-technology card | 13.56 MHz AES + 125 kHz 26-bit | AES on the smart side, none on prox | Prox layer only |
| Legacy prox | 125 kHz proximity | Encryption: none (copyable) | Yes — an open prox format |
| Verkada Pass | Phone over Bluetooth | Encrypted mobile credential, geofencing on-device | No — provisioned in-app |
| Mobile NFC | Apple Wallet / Android NFC | On-device, biometric/2FA, Express Mode | No — provisioned in-app |
How do I upgrade from 125 kHz prox without replacing everything?
Verkada's documented migration route is a multi-technology combo card that carries both a 125 kHz 26-bit (H10301) proximity credential and an AES-secured 13.56 MHz smart credential on the same card. Verkada notes this needs "no firmware updates or custom reader configuration" — the combo card is read by old and new readers alike during the transition.
A site therefore keeps its existing readers working, issues combo cards, and moves users over gradually. Once everyone is carrying the AES-secured credential, the site hardens the readers by disabling the 125 kHz antenna and Prox Unlock, ending on full AES-secured cards, Verkada Pass, or Mobile NFC. The 125 kHz half of that combo card is the layer a third party can supply.
Can I buy a compatible Verkada access card?
Not for the secure credential. Because a Verkada AES-secured 13.56 MHz smart card is cryptographically bound within Verkada's system, no independent manufacturer can produce a working compatible version, and Security ID Systems does not offer one. Additional secure Verkada credentials, and Verkada Pass or Mobile NFC provisioning, come through Verkada.
The part we can supply is the 125 kHz proximity layer many Verkada sites still run during migration — including the Verkada 40-bit format and the general HID, AWID, and Indala prox formats a mixed site carries. Those open low-frequency formats we encode as fully compatible credentials.
The 125 kHz layer we can supply during migration
If your Verkada site still runs 125 kHz proximity anywhere during the move to AES-secured cards, these open formats are ones we encode as fully compatible credentials that read on your existing readers.
Sources & references
Verkada and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.