Gallagher / Cardax
Enterprise access with per-site AES key diversification — a facility guide to Gallagher's credential ecosystem, the Cardax heritage, and where standard open prox still fits.
Can you buy third-party Gallagher / Cardax cards?
Gallagher (formerly Cardax) runs an enterprise access platform whose secured credential is an AES-protected 13.56 MHz smart card diversified with a per-site key that Gallagher provisions — so it's ordered through Gallagher, not an outside supplier. Its Cardax IV 125 kHz format is likewise Gallagher-managed. Where Gallagher Prox readers run multi-format, they accept standard open 26-bit prox, which American Key Cards supplies.
- 13.56 MHz / 125 kHz
- Frequency
- Enterprise access control — AES-secured 13.56 MHz smart credential with site-key diversification, plus the Cardax IV 125 kHz format and standard Wiegand support
- Technology
- 3
- Bit formats
- 1+
- OEM part nos.
- Brand channel
- Order from
Gallagher — built on the Cardax access-control heritage — is a fixture in enterprise, government, and critical-infrastructure security, and its credential model is correspondingly locked down. This page explains that ecosystem: the per-site AES key diversification that makes the secured credential uncloneable, the Cardax IV format, and where standard open prox still fits, which is the side we supply.
Why Gallagher's secured credential can't be reproduced
Gallagher's secured 13.56 MHz smart credential uses AES-128, but the detail that matters operationally is per-site key diversification: each Gallagher installation gets its own site key, so a credential encoded for one site is cryptographically meaningless at another even with identical numbering. Gallagher provisions those site keys, and they never leave its controlled process.
That's the whole reason no outside supplier can produce a Gallagher secured credential — the site key is the lock, and only Gallagher holds it. It's also why Gallagher is trusted for high-consequence environments: the credential can't be lifted, copied, or transplanted between sites.
The Gallagher credential tiers
Gallagher's T-Series and HBUS secured readers work only with native Gallagher credentials — that's the high-security tier, ordered through Gallagher. The Cardax IV 125 kHz format is Gallagher's own legacy proximity encoding, also managed through Gallagher's channel. And Gallagher Prox readers can run in a multi-format mode that additionally accepts standard open Wiegand proximity from the common access-control brands.
So an operational Gallagher site can span three credential worlds. Knowing which reader is which — a secured T-Series reader versus a multi-format Prox reader — determines entirely what can be sourced where.
The open-prox side we supply
Where Gallagher Prox readers are configured in multi-format mode, they accept standard open 26-bit Wiegand proximity — a standard, supply-able credential. That's the piece an independent manufacturer provides: interim credentials during a migration, or ongoing supply for doors deliberately kept on open prox.
We don't touch Gallagher's secured or Cardax IV credentials — those are Gallagher's channel, protected by the site key. But we'll help you identify which of your readers accept open prox, and supply that stock. Send photos of a reader and credential and we'll map it out.
Gallagher / Cardax specifications
- System brand
- Gallagher Group Limited
- Technology
- Enterprise access control — AES-secured 13.56 MHz smart credential with site-key diversification, plus the Cardax IV 125 kHz format and standard Wiegand support
- Frequency
- 13.56 MHz / 125 kHz
- Credential platform
- Gallagher's secured 13.56 MHz smart credential uses AES-128 with per-site key diversification (provisioned by Gallagher); Gallagher Prox readers also handle the Cardax IV 125 kHz format and standard open Wiegand prox
- Bit formats
- Gallagher AES-secured 13.56 MHz smart credential (per-site key diversified), Cardax IV proprietary 125 kHz format, Standard open 26-bit Wiegand H10301 (Gallagher Prox multi-format mode)
- OEM part numbers
- C297472 / C297474 / C297475 / C297478 (Gallagher credentials, ordered through Gallagher)
Specifications reviewed August 2026
How to order Gallagher / Cardax credentials
Gallagher's secured smart credential is AES-protected with a per-site key that Gallagher provisions, so it's ordered through Gallagher or an authorized integrator — an outside supplier can't reproduce a site-keyed credential. The Cardax IV format is likewise a Gallagher-managed credential. Where Gallagher Prox readers run in multi-format mode, they accept standard open 26-bit proximity, which American Key Cards supplies.
Gallagher Prox readers configured in multi-format mode accept standard open 26-bit Wiegand proximity — that open-format stock we supply (see our standard 125 kHz proximity cards). Gallagher's AES-secured smart credential and the Cardax IV format are provisioned through Gallagher.
Editorial reference page. American Key Cards is an independent credential supplier and is not affiliated with, endorsed by, or sponsored by Gallagher Security. We do not sell Gallagher Security's secured credentials (we supply only the open, standard-format proximity credentials described above); brand and product names appear only to identify the technology discussed, and all trademarks remain the property of their respective owners.
Readers in this ecosystem
Related formats
You might also need
ICT Protege
Unified access-and-intrusion control with an AES-secured smart credential — a facility guide to ICT's Protege platform and where standard open prox still fits.
How it worksHID iCLASS SE
HID's second-generation AES-secured smart card and the platform most large sites migrate through — a facility-operations guide to deploying, issuing, and expanding iCLASS SE.
How it worksHID Prox H10301 (Standard 26-Bit)
The most widely deployed proximity format in North America: 26-bit Wiegand — an 8-bit facility code plus 16-bit card number — on the 125 kHz HID Prox platform, live on millions of doors.
View compatible cardsGallagher / Cardax — FAQ
Can American Key Cards supply Gallagher credentials?
Not the secured or Cardax IV credentials — those are provisioned through Gallagher with a per-site key an outside supplier can't reproduce. Where Gallagher Prox readers run in multi-format mode and accept standard open 26-bit proximity, we supply that open-format stock.
Why can't Gallagher's secured credential be cloned or sourced elsewhere?
Because each site gets its own AES site key that Gallagher provisions and controls. A credential encoded for one site is cryptographically meaningless elsewhere, and no outside party holds the key. That per-site diversification is the core of Gallagher's security model.
Do Gallagher Prox readers accept standard prox cards?
In multi-format mode, yes — they accept standard open 26-bit Wiegand proximity from the common brands, which we supply. Native Gallagher T-Series and HBUS secured readers require Gallagher's own credentials.
How do I know which Gallagher readers I have?
Your Gallagher integrator can tell you, or send us photos of the readers and a credential. We'll identify which accept open prox (our lane) versus which require native Gallagher secured credentials (Gallagher's channel).