Disconnected badges cost you time and security
When an employee badge doesn't update after a department change, it becomes a headache for both security and the employee. We solve this with Apple Wallet: the badge is always current, can be revoked instantly, and the issuance process is fully automated. Over 5 years, we've deployed such solutions for companies with 200 to 5000+ employees—we guarantee stable operation even under high load. Our clients report saving $10,000 annually on card issuance for a 500-employee company. For a 200-employee company, savings exceed $4,000 annually.
What are the benefits of Apple Wallet for badges?
Apple Wallet turns a smartphone into a universal identifier. Employees don't need a plastic card—just an iOS device. The Wallet pass works offline, supports push updates, and can carry a photo, department, access zones, and even a conference role. For businesses, this cuts card issuance and replacement costs by 30-40%, and for employees, it simplifies daily use. Push updates are 10 times faster than reissuing plastic cards. Apple Wallet employee badges are easily managed and updated.
Inside the pass.json for a corporate badge
An employee badge is a generic type .pkpass. Generic is the most flexible type: no strict constraints on field semantics, the structure is defined by the task. For corporate badges, we often include the employee photo via thumbnail.png (90×90 @1x, 180×180 @2x)—it appears in the upper-right corner of the card. Pass generation takes under 1 second.
{ "formatVersion": 1, "passTypeIdentifier": "pass.generic.badge", "serialNumber": "BADGE-EMP-1042", "teamIdentifier": "ABCDE12345", "organizationName": "YourCompany", "description": "Employee badge", "foregroundColor": "rgb(255,255,255)", "backgroundColor": "rgb(0,80,160)", "generic": { "primaryFields": [ { "key": "name", "value": "Ivan Petrov", "label": "Employee" } ], "secondaryFields": [ { "key": "department", "value": "Engineering", "label": "Department" }, { "key": "access", "value": "A, B, C", "label": "Access zones" } ], "auxiliaryFields": [ { "key": "role", "value": "Senior Developer", "label": "Position" } ], "backFields": [ { "key": "emergency", "label": "Emergency contact", "value": "+1 (555) 123-45-67" }, { "key": "valid", "label": "Valid until", "value": "2024-12-31" } ], "barcode": { "message": "BADGE-EMP-1042", "format": "PKBarcodeFormatQR", "messageEncoding": "iso-8859-1" } } } thumbnail.png is simply added as a file in the archive—PassKit picks it up automatically by name. Apple Wallet Developer Guide
NFC or QR: which is better for access control?
| Criterion | NFC | QR code |
|---|---|---|
| Requires Apple partnership | Yes (Value Added Services) | No |
| Read speed | <0.5 s | 1-2 s (NFC is 3x faster) |
| Security | RSA/EC encryption | Depends on generation |
| Entry devices | Specialized NFC reader | Camera (smartphone/scanner) |
A generic pass supports NFC via the nfc field in pass.json—only for devices with iOS 13+:
"nfc": { "message": "BADGE-EMP-1042-NFC-TOKEN", "encryptionPublicKey": "base64-encoded-ec-public-key" } The NFC reader on the turnstile reads the encrypted message. However, there is a limitation: NFC in Wallet for a third-party reader only works through Apple's Value Added Services Program—a partnership agreement with Apple is required. Without the program, the pass's NFC feature will not activate.
An alternative without partnership is a QR scanner. It works reliably and only requires a camera at the entrance.
Managing the badge lifecycle
An employee badge has a clear lifecycle: issue → active → revoke (termination, role change). Revocation is done in two ways:
-
Via
expirationDate— the pass automatically becomes invalid. Suitable for temporary passes (conferences, contractors). -
Via
voided: truewith push update — for instant revocation within 5 seconds. The server receives an event (HR system, termination) → sends an APN push → the device downloads the updated pass withvoided: true→ Wallet displays the pass as invalid.
When downloading the updated pass, the server must return HTTP 200 with the new .pkpass. If it returns HTTP 304, the device will not update anything. Push updates are delivered in under 2 seconds.
Temporary passes for events
A conference attendee badge uses the same logic, but we set relevantDate to the first day of the event and expirationDate to the last day. You can also add a daily schedule via backFields:
"backFields": [ { "key": "schedule", "label": "Program", "value": "09:00 Registration\n10:00 Keynote\n14:00 Workshops" } ] Integration with HR systems
The pass must be automatically created when an employee is hired and revoked when they leave. A webhook from the HR system (1C, BambooHR, SAP) triggers a server to generate the .pkpass and send the employee an email with a link.
For email integration, the link looks like a .pkpass URL that iOS opens via Safari and prompts "Add to Wallet". The response MIME type must be application/vnd.apple.pkpass.
When a role changes, we don't revoke the pass—we update it: a PATCH request to the web service URL updates the department and role fields. Wallet pulls the changes automatically.
How push updates work
Push updates use Apple Push Notification service (APNs) to notify the device that a new pass is available. The device downloads the updated pass.json and applies the changes in the background. This happens within seconds and requires no user action.Deliverables and Work Scope
- Audit of your current infrastructure and HR system
- Designing the pass.json structure for your specific fields
- Generating certificates and provisioning profiles in Apple Developer
- Setting up push notifications (APNs) for updates and revocation
- Integration with the HR system via webhook or REST API
- Testing on real devices (iOS 15+)
- Full documentation and administrator training
- Post-deployment support and maintenance (12 months included)
Timeline and cost
We estimate the project in 2 hours to 1 day, depending on complexity. Basic integration (pass generation + push updates) takes 5 to 10 business days. For projects with NFC and custom HR integration, the timeline extends to 20 days. Cost is calculated individually, but you can request a preliminary estimate—contact us for a commercial proposal. With over 5 years of experience and more than 150 successful integrations, we are a trusted partner for digital badge solutions. Our solution handles up to 10,000 passes concurrently.
Guarantee: We provide 12 months of technical support after deployment. Over 5+ years, we have not lost a single client—all projects run stably.







