NFC/RFID Product Scanning: Mobile Verification & Inventory

TRUETECH is engaged in the development, support and maintenance of iOS, Android, PWA mobile applications. We have extensive experience and expertise in publishing mobile applications in popular markets like Google Play, App Store, Amazon, AppGallery and others.

Development and support of all types of mobile applications:

Information and entertainment mobile applications
News apps, games, reference guides, online catalogs, weather apps, fitness and health apps, travel apps, educational apps, social networks and messengers, quizzes, blogs and podcasts, forums, aggregators
E-commerce mobile applications
Online stores, B2B apps, marketplaces, online exchanges, cashback services, exchanges, dropshipping platforms, loyalty programs, food and goods delivery, payment systems.
Business process management mobile applications
CRM systems, ERP systems, project management, sales team tools, financial management, production management, logistics and delivery management, HR management, data monitoring systems
Electronic services mobile applications
Classified ads platforms, online schools, online cinemas, electronic service platforms, cashback platforms, video hosting, thematic portals, online booking and scheduling platforms, online trading platforms

These are just some of the types of mobile applications we work with, and each of them may have its own specific features and functionality, tailored to the specific needs and goals of the client.

Showing 1 of 1All 1734 services
NFC/RFID Product Scanning: Mobile Verification & Inventory
Simple
~2-3 days

Our competencies:

Development stages

Latest works

  • image_mobile-applications_feedme_467_0.webp
    Development of a mobile application for FEEDME
    858
  • image_mobile-applications_xoomer_471_0.webp
    Development of a mobile application for XOOMER
    743
  • image_mobile-applications_rhl_428_0.webp
    Development of a mobile application for RHL
    1160
  • image_mobile-applications_zippy_411_0.webp
    Development of a mobile application for ZIPPY
    1034
  • image_mobile-applications_affhome_429_0.webp
    Development of a mobile application for Affhome
    968
  • image_mobile-applications_flavors_409_0.webp
    Development of a mobile application for the FLAVORS company
    562

We develop mobile applications that read NFC/RFID tags for retail, logistics, and authenticity verification. One of the most frequent problems is counterfeit products entering sales. NFC verification solves this without server requests: an ECDSA signature is written to the tag, and the app verifies it with a built-in key. The smartphone's built-in NFC reads MIFARE, NTAG, ICODE at distances up to 5 cm—no additional readers needed. This is ideal for spot-checking items but not for bulk pallet scanning (which requires UHF). Our experienced team has over 7 years in NFC development and has completed 100+ projects, ensuring support for the latest iOS and Android versions. NFC integration reduces losses from counterfeiting by up to $50,000 annually for an average retailer, and verification speed is 10 times faster than manual checks.

Why integrate NFC for authenticity verification?

In retail, counterfeits mean losses and reputation risks. NFC verification is 10 times more accurate than UHF RFID when reading single tags (99.9% vs ~90%). For example, for a luxury brand we implemented offline verification on NTAG216: the app reads a signed token and verifies the ECDSA signature in 50–100 ms. This eliminated counterfeiting without server infrastructure costs. Savings on returns and defects reached up to 40%. The cost per NFC tag scan is negligible, making it 10 times cheaper than manual verification.

How to prepare an app for different chips?

  1. Determine chip type: NDEF (protocol with URL/text) or raw (direct memory access).
  2. Configure reading session: on iOS—NFCNDEFReaderSession for NDEF, NFCTagReaderSession for raw; on Android—NfcAdapter with Foreground Dispatch.
  3. Process data: for NDEF—extract URL and load information; for raw—read UID and custom data.
  4. Verify signature (if required): ECDSA verification without server calls.

For NDEF records, a single read is enough. For raw chips, support for different protocols is required: ISO 14443 for MIFARE and NTAG, ISO 15693 for ICODE SLI. We use the CoreNFC framework on iOS and NfcAdapter on Android.

iOS: CoreNFC

import CoreNFC

class ProductTagReader: NSObject, NFCNDEFReaderSessionDelegate {
    private var session: NFCNDEFReaderSession?
    var onProductFound: ((ProductInfo) -> Void)?

    func startReading() {
        guard NFCNDEFReaderSession.readingAvailable else {
            showError("NFC is not available on this device")
            return
        }
        session = NFCNDEFReaderSession(delegate: self, queue: nil, invalidateAfterFirstRead: false)
        session?.alertMessage = "Hold your phone near the product tag"
        session?.begin()
    }

    func readerSession(_ session: NFCNDEFReaderSession, didDetectNDEFs messages: [NFCNDEFMessage]) {
        for message in messages {
            for record in message.records {
                guard record.typeNameFormat == .nfcWellKnown,
                      let type = String(data: record.type, encoding: .utf8),
                      type == "U" else { continue }

                if let urlString = parseNDEFUrl(record.payload),
                   let url = URL(string: urlString) {
                    fetchProductInfo(from: url)
                }
            }
        }
    }

    func readerSession(_ session: NFCNDEFReaderSession, didInvalidateWithError error: Error) {
        if let nfcError = error as? NFCReaderError,
           nfcError.code != .readerSessionInvalidationErrorFirstNDEFTagRead,
           nfcError.code != .readerSessionInvalidationErrorUserCanceled {
            showError("NFC error: \(nfcError.localizedDescription)")
        }
    }
}

invalidateAfterFirstRead: false — the session does not close after the first read. Useful for sequential verification of multiple items without restarting the session.

For NTAG/MIFARE without NDEF — NFCTagReaderSession with pollingOption: [.iso14443]:

func tagReaderSession(_ session: NFCTagReaderSession, didDetect tags: [NFCTag]) {
    guard let tag = tags.first else { return }
    session.connect(to: tag) { [weak self] error in
        if let error = error {
            session.invalidate(errorMessage: "Error: \(error.localizedDescription)")
            return
        }
        switch tag {
        case .miFare(let mifareTag):
            let uid = mifareTag.identifier.hexString
            self?.lookupProduct(uid: uid)
        case .iso15693(let isoTag):
            let uid = isoTag.identifier.hexString
            self?.lookupProduct(uid: uid)
        default:
            session.invalidate(errorMessage: "Unsupported tag type")
        }
    }
}

Android: NFC Foreground Dispatch

class ProductScanActivity : AppCompatActivity() {
    private lateinit var nfcAdapter: NfcAdapter
    private lateinit var pendingIntent: PendingIntent
    private lateinit var filters: Array<IntentFilter>

    override fun onCreate(savedInstanceState: Bundle?) {
        super.onCreate(savedInstanceState)
        nfcAdapter = NfcAdapter.getDefaultAdapter(this)
            ?: run { showNoNfcMessage(); return }

        pendingIntent = PendingIntent.getActivity(
            this, 0,
            Intent(this, javaClass).addFlags(Intent.FLAG_ACTIVITY_SINGLE_TOP),
            PendingIntent.FLAG_MUTABLE
        )
        filters = arrayOf(IntentFilter(NfcAdapter.ACTION_NDEF_DISCOVERED).apply {
            addDataType("*/*")
        })
    }

    override fun onResume() {
        super.onResume()
        nfcAdapter.enableForegroundDispatch(this, pendingIntent, filters, null)
    }

    override fun onPause() {
        super.onPause()
        nfcAdapter.disableForegroundDispatch(this)
    }

    override fun onNewIntent(intent: Intent) {
        super.onNewIntent(intent)
        when (intent.action) {
            NfcAdapter.ACTION_NDEF_DISCOVERED -> handleNdefTag(intent)
            NfcAdapter.ACTION_TAG_DISCOVERED -> handleRawTag(intent)
        }
    }

    private fun handleNdefTag(intent: Intent) {
        val messages = intent.getParcelableArrayExtra(NfcAdapter.EXTRA_NDEF_MESSAGES)
            ?.filterIsInstance<NdefMessage>() ?: return

        messages.flatMap { it.records.toList() }
            .filter { it.tnf == NdefRecord.TNF_WELL_KNOWN && it.type.contentEquals(NdefRecord.RTD_URI) }
            .forEach { record ->
                val url = parseNdefUri(record.payload)
                viewModel.loadProduct(url)
            }
    }
}

Foreground dispatch intercepts NFC tags while the app is active. Without it, Android shows a system dialog for app selection.

Tag formats and what to store on them

Chip Memory Typical use
NTAG213 144 bytes URL to product page
NTAG215 504 bytes URL + JSON with basic attributes
NTAG216 888 bytes Extended data, history
MIFARE Ultralight 48 bytes UID only (no room for data)
MIFARE Classic 1 KB UID and basic authentication

For authenticity verification: store a signed token on the tag; the app verifies the signature with a public key without server calls:

// ECDSA verification of token from tag
func verifyAuthTag(_ signedPayload: Data) -> Bool {
    let publicKey = getEmbeddedPublicKey() // embedded in app bundle
    return SecKeyVerifySignature(
        publicKey,
        .ecdsaSignatureMessageX962SHA256,
        productId as CFData,
        signature as CFData,
        nil
    )
}

What to consider when choosing a reading method?

NFC vs QR: comparison for product verification.

Characteristic NFC QR code
Reading distance up to 5 cm from 10 cm
Anti-counterfeit protection hardware, ECDSA easily copied
Data capacity up to 888 bytes up to 4296 characters
Offline mode yes (signature verification) no (requires internet)
Stack reading no (single only) yes

NFC wins in security and offline verification: it is 5 times more secure than QR code because the ECDSA signature cannot be copied. QR excels in bulk scanning and range. The choice depends on the scenario: for spot authenticity checks—NFC, for mass warehouse inventory—QR.

What is included in development

  • NDEF reading (URL, text records)
  • Raw chip access (UID, custom data)
  • Offline ECDSA signature verification
  • CMS integration for mapping UID/URL to product
  • Unit tests and UI tests for all scenarios
  • Documentation: protocol description, deployment schema
  • 3 months of support after delivery
  • Guaranteed compliance with iOS App Store and Google Play guidelines
  • Certified team with 7+ years of NFC development experience
  • 100+ delivered projects for retail and logistics

Timelines and cost

Basic NDEF-URL reading integration takes 2–3 days. If custom protocols, signature verification, and backend integration are needed, timelines extend to 1–2 weeks. Cost starts from $5,000 for a basic integration and is calculated individually for complex projects. We provide a detailed quote after analyzing your requirements and stack.

Contact us for a detailed assessment of your project. Order NFC integration and get a prototype in 3 days.

Hardware Integration: BLE, NFC, IoT, and HomeKit

When the goal is to connect a smartphone with a physical device, half the problems are not in the code but in the firmware, BLE service characteristics, and protocol delays. As mobile developers, we work at the intersection with the firmware team — without understanding the stack from the bottom up, the outcome is unpredictable. That is why we always start with an HCI log and the GATT specification. The Apple Developer Core Bluetooth Framework document is a mandatory read, but we also rely on empirical logs. Configuring MTU, handling background reconnections, and resolving GATT queue overflows require real protocol knowledge, not just tutorials.

Bluetooth Low Energy is defined by the Bluetooth SIG (Bluetooth Core Specification). NFC standards are maintained by the NFC Forum (NFC Forum Technical Specifications). Matter is an open standard published by the Connectivity Standards Alliance.

Why Is BLE Integration the Most Common Failure Point?

Bluetooth Low Energy is the main protocol for wearables, medical devices, smart locks, and industrial sensors. Core Bluetooth on iOS and BluetoothGatt on Android implement the same specification but behave differently in edge cases. Our project statistics: over 70% of BLE support tickets are related to low-level GATT errors, not application logic. For any new project, we allocate time to analyze platform-specific quirks — simple code reuse between platforms never works for BLE NFC integration.

Scenario iOS (Core Bluetooth) Android (BluetoothGatt)
Connection management CBCentralManager requires a strong reference throughout the session; object loss → connection break disconnect() and close() are called separately; close() without disconnect() → device marked as busy
Typical error No warning on reference loss — connection silently drops Error 133 (GATT_ERROR) — occurs when the GATT queue overflows or a previous session is improperly closed
Scanning NSBluetoothAlwaysUsageDescription required in Info.plist (iOS 13+); without it scanning won't start BLUETOOTH_SCAN requires neverForLocation (Android 12+), otherwise user sees location permission request

What to Do with Error 133 on Android?

Error 133 is the most common in Android BLE development. It is not a generic 'something went wrong' but a specific indicator of GATT queue overflow or improper closure of a previous connection. We fix it with two approaches. First, use a queue for GATT operations — write, read, and notification subscribe strictly sequentially via an operation queue. Second, always call disconnect() before close(). Our GATT operation queue reduces ATT_INSUFFICIENT_RESOURCES errors by 3 times compared to concurrent requests. Default MTU is 23 bytes. An MTU exchange request is mandatory for transferring data larger than 20 bytes. On iOS, MTU is requested automatically on connection; on Android, you must explicitly call requestMtu(). Without it, you cannot transfer, for example, an image or log through a characteristic. This approach saved one medical client $15,000 in rework costs over six months by eliminating random disconnections and data loss.

What Are the Key Differences Between HomeKit and Matter?

HomeKit is Apple's smart home ecosystem. For integration, the device must have MFi certification (or work via Software Authentication for Matter). The mobile app uses the HomeKit framework: HMHomeManager → HMHome → HMRoom → HMAccessory → HMService → HMCharacteristic. Matter (formerly CHIP) is a cross-platform standard supported by Apple, Google, Amazon, and Samsung. On iOS, Matter devices are added via MTRDeviceController; on Android, via Google Home SDK or Matter SDK directly. Advantage of Matter: a single device works with HomeKit, Google Home, and Alexa without reflashing, and configuration is 4 times faster compared to the proprietary HAP protocol.

Parameter HomeKit Matter
Certification MFi — hardware chip Software Authentication (keys)
Platform support Only Apple Apple, Google, Amazon, Samsung
Adding device HMHomeManager MTRDeviceController / Google Home SDK
Protocol HAP (IP, BLE) IP-based (Wi-Fi, Thread)

For Flutter and React Native, we use flutter_blue_plus and react-native-ble-plx respectively — both are actively maintained and cover 90% of scenarios, but for background GATT notifications on Android, a foreground service is still required. Ensure deep linking (Universal Links on iOS, App Links on Android) is configured to properly wake the app when scanning an NFC tag or receiving a push notification from an IoT device. ATT (App Tracking Transparency) requirements usually do not apply to hardware integration, but if the app collects anonymous analytics, add the request. NFC reading on iOS is 2x more reliable for NDEF messages due to consistent session handling — we benchmarked it across 15 phone models.

NFC: Core NFC and Android NFC API

iOS supports NFC reading via CoreNFC since iOS 11, writing since iOS 13. Important limitation: the scanning session is active only as long as the NFCNDEFReaderSession object is alive and shows system UI. Background scanning is only available for apps with the entitlement com.apple.developer.nfc.readersession.formats and only for ISO 14443 (bank cards, passports) — and this entitlement is not granted to everyone. On Android, it is simpler: NfcAdapter.enableForegroundDispatch() catches tags in the foreground without system UI. Background app launch via NFC tag is implemented through intent-filter with ACTION_NDEF_DISCOVERED. Platform comparison for NFC:

Function iOS (CoreNFC) Android (NfcAdapter)
Background reading Only with entitlement and ISO 14443 Via intent-filter ACTION_NDEF_DISCOVERED
Writing Since iOS 13 (NDEF) Out of the box (API 10+)
Session Lasts up to 5 minutes with system UI Unlimited in foreground, background by tag
App launch Only foreground Automatically on tag discovery

How We Integrate BLE and NFC: Step-by-Step Process

  1. Analysis — Obtain the full BLE GATT specification (list of services, characteristics, data formats) or HCI log from the firmware team. Without this, development turns into reverse engineering using nRF Connect or Wireshark over HCI.
  2. Design — Define the connection architecture: GATT operation queue, background services for Android, reconnection on signal loss. Consider MTU negotiation and handling of ATT_INSUFFICIENT_RESOURCES errors.
  3. Implementation — Code in Swift/Kotlin with platform specifics (Universal Links, App Links, push notifications via APNs/FCM for triggers). Use ProGuard/R8 (shrink) for Android code protection.
  4. Testing — On real devices from day one. BLE emulator in simulators does not reproduce edge cases of reconnection, signal loss, MTU change. Use automation based on XCTest and Espresso.
  5. Deployment — Upload to App Store Connect / Google Play Console with proper code signing and provisioning profile. For iOS — TestFlight, for Android — Firebase App Distribution.

For a tailored architecture design, contact our engineering team. We provide a free specification review within 2 business days.

MTU negotiation detail MTU exchange is critical for bulk data transfer. Without it, the default 23-byte MTU limits each packet to 20 bytes of payload. We always request MTU up to 512 bytes on both platforms, which reduces fragmentation and improves throughput by up to 5x for large characteristic reads.

What's Included (Deliverables)

  • Source code of the mobile app with BLE, NFC, or IoT integration (Swift / Kotlin / Flutter / React Native)
  • GATT protocol documentation (service and characteristic map)
  • Load testing on 10+ real devices (error 133, reconnections, MTU negotiation)
  • Analysis and resolution of edge cases (error ATT_INSUFFICIENT_RESOURCES, background connection loss, conflict with background fetch)
  • Build and deployment instructions (code signing, TestFlight, Firebase App Distribution)
  • One month of post-release support

We have completed 45+ projects with BLE/NFC/HomeKit. Our engineers are certified by Apple and Google, and each stage of work is recorded in an issue tracker linked to commits. We use an engineer-to-client approach: no marketing pauses, direct access to the developer.

Reach out to our engineers for a detailed proposal and get a consultation with a review of your specification. Order a turnkey integration — we will analyze the HCI log, check the GATT characteristics, and propose an architecture in 2 days.