/members/access-cards) even though it covers more than physical cards. The same registry is reachable from the Members overflow menu and from a member’s profile.
Overview
From Access cards you can:- See every credential ever enrolled in the org, with its assigned contact, type, number, status, and dates.
- Enroll (add) a new QR code, access card, or PIN and optionally assign it to a member in one step.
- Assign an unassigned credential to a contact and mark it their primary credential.
- Revoke an active credential (keeps it as an audit record) or delete an unassigned/revoked one outright.
- Jump to Access control settings, where check-in mode and identification methods are configured.
Credential types
There are three credential types, matching the three identification methods configured under Access control:- QR Code - a code scannable at a reader, kiosk, or in the member portal.
- Access Card - a physical card with a number printed or encoded on it (for example an NFC UID).
- PIN Code - a numeric or short alphanumeric code the member enters on a keypad.
Opening the page
Go to Members > Access cards, or open the overflow menu next to Add Member on the member list and pick Access Cards. The page shows every credential ever enrolled in the org, newest first. The Settings button in the top right jumps to Access control settings, where check-in mode and identification methods are configured.Grid columns
- Assigned to - the contact the credential belongs to, with avatar. A
+N morechip appears when a credential has more than one active assignment (rare; allowed for household-style sharing). Unassigned credentials show an Unassigned chip. - Type - QR Code, Access Card, or PIN Code.
- Number - the credential’s identifier.
- Status - active, suspended, revoked, or expired.
- Issued date - when the credential was enrolled.
- Expiry date - optional expiry, or
-if open-ended.
Adding a credential
Click Add Credential in the top right:- Pick the Type (QR Code, Access Card, or PIN Code). Only the types enabled for the club are listed.
- Enter the Credential identifier (or PIN Code if you chose PIN).
- Optionally pre-assign it to a contact.
Self-enrollment at a kiosk
If credential enrollment is enabled for a club in access control settings, a member can enroll a physical card themselves at a kiosk: they identify with their QR code and then tap the new card on the reader. The kiosk auto-detects the credential type from the scan and enrolls it as that member’s primary credential. Cards enrolled this way appear in the grid alongside admin-enrolled ones.Auto-provisioned credentials
When a member needs an access grant (for example, when their membership or booking becomes active) and they have no primary credential yet, the system provisions one automatically from the club’s enabled methods: it prefers a PIN if PIN is enabled, otherwise a QR code derived from the member’s check-in code. This is why a member can appear in the grid with a credential nobody manually created. Auto-provisioning only happens when access control is configured for the club or org; it never invents a PIN for an org that never enabled access control.Assigning to a member
Unassigned credentials show an Assign action in the row menu. Pick a contact and use the Set as primary credential for this contact checkbox to decide whether this becomes their primary. A contact can have at most one primary credential; assigning a new primary automatically demotes the previous one. From a member’s profile, the Assign button in the credentials block lets you pick from the pool of unassigned credentials, and the Add button enrolls a brand-new credential and assigns it in one step. A credential is always assigned to exactly one target - normally a contact, though the platform also assigns credentials to a membership or booking behind the scenes.Revoking and deleting
The row menu adapts to the credential’s current state:- Unassigned and active - can be assigned or deleted outright. Deletion is only allowed when there are no assignments on record.
- Assigned and active - can be revoked. The credential is marked revoked and rejected at the reader from then on; the row stays in the grid for audit.
- Revoked - can be deleted if you want to clear it from the grid. Otherwise it stays as a historical record.
Statuses
- Active - in use, accepted by readers.
- Suspended - temporarily disabled.
- Revoked - permanently disabled. The record is kept for the audit trail.
- Expired - past the optional expiry date.
How credentials interact with check-in
How strict the door is, and what happens when a credential is presented, depends on your check-in mode. See Check-in models for the full matrix. Quick summary:- Strict mode requires a credential to match an active booking or membership.
- Flexible mode allows walk-ins and anonymous check-ins.
- A scanned credential is matched to its primary contact, and the rest of the check-in flow proceeds as if you had selected that contact manually.
Worked examples
Issuing physical cards for a gym
A 24/7 strength-and-conditioning gym wants a fob-style card for every member so the front door works unattended.- In Access control, enable Access Card as an identification method and set the check-in mode to Strict so only members with an active membership get in.
- For each new member, click Add Credential, choose Access Card, scan or type the card’s NFC UID into the identifier field, and pre-assign it to the contact.
- Hand over the card. When a member cancels, revoke their card so it is rejected at the door immediately, and delete it later if you want it out of the grid.
QR check-in for a Pilates or yoga studio
A reformer Pilates studio runs class-based check-in and does not want to distribute hardware.- Enable QR Code as the identification method.
- Leave enrollment to the platform: each member gets an auto-provisioned QR credential tied to their check-in code, which they show from the member portal.
- At the desk or kiosk, scan the member’s QR at the start of class. In Strict mode the scan is accepted only if they have a spot in that class.
PIN keypad for a climbing gym
A bouldering gym has a keypad at the entrance and wants no phones or cards involved.- Enable PIN Code as the identification method.
- New members are auto-provisioned a PIN (PIN is preferred when enabled), or you can set a specific one via Add Credential > PIN Code using 4-10 alphanumeric characters.
- If a member forgets or shares their PIN, revoke it and enroll a new one.
Household sharing at a racket-sports club
A padel and tennis club lets a family share one access card. Enroll one Access Card and assign it to each family member, marking one person as primary. The grid shows the primary contact plus a+N more chip. Any household member can enter, and the check-in flow resolves the tap to the primary contact.
Tips & best practices
- Enable only the identification methods you actually use. The Add Credential type list and the auto-provisioning logic both follow the club’s enabled methods.
- Prefer revoke over delete for anything a member has actually used. Revoking keeps the audit trail; deleting is best reserved for unassigned mistakes or clearing already-revoked records.
- Keep one primary per member. If you assign a second primary, the old one is demoted automatically, but it is worth confirming who the primary contact is before a busy check-in period.
- For lost cards, revoke first, then enroll the replacement, so there is never a live duplicate.
- Use a consistent identifier convention (for example the number printed on the card) so the Number column is easy to scan when troubleshooting at the desk.
Troubleshooting
Related
- Access control - check-in mode, identification methods, organization-level credential settings
- Check-in models - how credentials are honored at the reader
- Member profile - per-contact credentials block
- Attendance - the check-in log