A credential can arrive blank or arrive ready to work. Those are different orders with different security implications, and confusing them is a common cause of delay.
- Two models, decided before production
- Security keys belong to the property
- Numbering is how an estate stays auditable
- Counted, range-labelled supply
- Where reorders go wrong
Two models, decided before production
In the first, the property encodes on site as part of its existing check-in process, and what it needs from a supplier is unencoded stock of exactly the right type. This is the most common arrangement and the simplest: nothing sensitive changes hands.
In the second, credentials are delivered pre-encoded to a defined range. That requires the encoding input to be agreed and transferred before production, and it makes the delivery itself more sensitive, because what arrives is closer to a working key than to a blank.

Security keys belong to the property
Where a system uses authenticated credentials, the keys that make authentication work are the property’s or its integrator’s. They are handled under that party’s process, not passed around casually to make an order easier.
A supplier who is relaxed about key handling is telling you something about how they handle everyone else’s. The right posture is that most orders do not need keys at all, and the ones that do are handled deliberately.
A system model and a non-sensitive description of the current credential are enough for a first technical review. Nothing about a quotation requires live encoding secrets.
Numbering is how an estate stays auditable
Numbering answers questions a property will eventually be asked: which range went to which property, which block was issued in which season, which credentials are unaccounted for. Without it, a box of credentials is anonymous and a security question has no answer.
New credentials either continue an existing convention or start a separate one, and that must be stated before production rather than discovered at goods-in. Continuing a range badly is worse than starting a new one cleanly.

Counted, range-labelled supply
Goods supplied in counted blocks with the range on the label let a property record what arrived without opening everything. It also lets a busy issue point reconcile by block rather than by scanning, which works when a network does not.
This is decided at order time and cannot be retrofitted, so it is worth asking for explicitly even though it costs nothing.
Where reorders go wrong
Almost always at the encoding input. A reorder that repeats the artwork but changes the credential type, the range or the encoding convention is not a repeat, and treating it as one produces a delivery that looks right and does not work.
That is why the confirmed credential input travels in the reorder record alongside the approved sample and artwork revision, and why any changed field triggers a fresh check.
Compatibility is confirmed against the property’s lock system, credential technology and encoding requirements before production. We do not claim universal compatibility.
Questions this raises
01Should we encode on site or have credentials delivered encoded?+
On site, if you already encode at check-in — it is simpler and nothing sensitive changes hands. Pre-encoded delivery suits properties without an encoding step, and it requires the input to be agreed in advance and the delivery treated as more sensitive than blank stock.
02Will you need our security keys?+
For most orders, no. Where authenticated credentials require them, they belong to you or your integrator and are handled under your process. Nothing about a quotation or a first technical review requires them.
03Can new credentials continue our existing numbering?+
Usually, provided the convention and the range in use are stated before production. Continuing a range badly is worse than starting a clean one, so it is worth being explicit about which you want.
