Access and identity APIs
These references cover identity, credential and event interfaces in access control platforms. Confirm access conditions and product support before implementing a client.
On this page
Overview#
Vendor APIs / Access and identity
Access control integrations cross multiple authorities: the identity source, PACS cardholder record, credential issuer, controller policy, reader transaction, lock/egress system, and audit trail. An API “success” proves only that the service accepted or completed its defined operation; it doesn't by itself prove a credential reached a handset, a controller received policy, a lock changed state, or a person passed through a door.
Pages#
- HID Origo and Mobile Access
- Gallagher Command Centre integrations
- LenelS2 OnGuard, OpenAccess, and Elements
- Johnson Controls C•CURE integrations
- SALTO APIs
- Brivo API
- Suprema BioStar 2 API
- Kisi API
Separate these capabilities#
| Capability | Required control |
|---|---|
| Identity/user synchronisation | Authoritative source rules, joiner/mover/leaver semantics, stable identifiers, conflict and deletion policy |
| Credential issue/revoke | Issuer authority, inventory/subscription, proof of possession, asynchronous delivery state, revocation recovery |
| Access assignment | Approval, effective interval, site/tenant scope, role separation, controller propagation and offline state |
| Events and occupancy | Duplicate/order/gap handling, privacy minimization, passage uncertainty, antipassback semantics |
| Door/output/lockdown commands | Explicit high impact privilege, preconditions, idempotency/uncertain outcome, local life safety authority, immutable audit |
| Biometrics and photos | Lawful basis, consent where required, template/image minimization, retention, export/deletion, vendor and jurisdiction constraints |
| Mobile SDK | App signing, device integrity, keychain/keystore protection, lifecycle, offline behaviour, reader proximity proof, accessibility |
Safety boundary#
Never exercise unlock, lockdown, elevator, output, alarm, antipassback, or credential operations on a live site as exploratory testing. Door hardware, emergency egress, fire interfaces, and accessibility remain under qualified design and the authority having jurisdiction. Use a documented test tenant and physically isolated lab only under written authority from the integration and site owners.
See PACS architecture, credential lifecycle, mobile access, identity and authorisation security, and privacy.