Back to case studies // authentication

Smart-Lock Access Tokens

A coworking operator replaced shared keycards with short-lived, identity-bound access tokens, so every smart-lock entry was scoped, time-boxed, and revocable without re-keying a single door.

October 14, 2024 · Veripass
Smart-Lock Access Tokens

A coworking operator ran dozens of locations where members, day-pass visitors, and staff all needed door access on different terms. The legacy answer was plastic keycards cloned per person and never reliably collected. Lost cards stayed valid for weeks, contractors kept access long after a job ended, and the only way to truly cut someone off was to re-key the lock.

The operator wanted access to be a token, not a card: issued against a verified identity, scoped to specific doors, valid only for a defined window, and revocable instantly.

The challenge

Smart locks trusted whatever credential they were presented. There was no link between the credential and the person, no expiry that the door enforced, and no central place to say “this access ends now.” Membership tiers, hot-desk bookings, and one-off visitor passes all collapsed into the same flat keycard model, so the access system could not express the business rules the company actually ran on.

They needed entitlements derived from identity and presented to the lock as a verifiable, short-lived token the door could trust.

What Veripass deployed

Veripass issued access as short-lived tokens minted against a verified identity. A member authenticated through their organization tenant — federated over OIDC where the customer used an external directory — and Veripass evaluated their access profile to determine which doors, on which floors, during which hours they were entitled to enter. From that decision it issued a time-boxed token the lock could validate, rather than a standing credential.

Entitlements were expressed through claims, capabilities, roles, and access profiles, so a day-pass visitor received a token scoped to common areas for a single day while a resident member’s token covered their floor during business hours. Every token issuance and every door event landed in an immutable audit trail.

  • Short-lived, identity-bound access tokens replacing standing keycards
  • OIDC federation to the member’s home directory
  • RBAC from claims, capabilities, roles, and access profiles driving token scope
  • Context-aware policy: door set, floor, and time window per token
  • Adaptive, step-up MFA over phone TOTP for after-hours or restricted areas
  • Instant revocation by disabling the identity — no door re-keying
  • Immutable audit trail of every token issued and every entry

After-hours access and restricted labs demanded a step-up: before Veripass would mint a token for those doors, the member completed adaptive MFA over phone TOTP. The elevated token carried a tighter window, and the step-up was recorded next to the entry it authorized.

Outcome

Lost-card panic disappeared, because there were no standing cards to lose. Access expired on its own when the token’s window closed, and revoking a member took effect on the next door tap — no locksmith, no re-keying. Visitor passes, hot-desk bookings, and membership tiers finally mapped cleanly onto distinct token scopes instead of one undifferentiated card.

The operator gained a complete, immutable record of who entered which door, under which entitlement, and whether they had to step up to do it — across every location from one control plane.

More deployments

Campus-Wide Student SSO

Campus-Wide Student SSO

A university gave every student one login for the entire campus stack by federating Google Workspace and the student directory through Veripass, ending the credential sprawl across portals and services.

Clinician EHR Single Sign-On

Clinician EHR Single Sign-On

A hospital network gave clinicians one federated sign-on across the EHR and clinical applications, cutting repeated logins at the bedside while keeping every access policy-governed and audited.

Fingerprint Turnstile Entry

Fingerprint Turnstile Entry

A manufacturing site replaced badge tailgating at its turnstiles with fingerprint biometric verification bound to identity, so every entry proved the person was physically present and authorized.