HID® Seos®
HID's flagship AES-secured smart credential, built so that the credential is inseparable from its chip — a facility-operations guide to how Seos is deployed, issued, and expanded.
Can you buy third-party HID Seos cards?
HID Seos is HID's highest-assurance access credential: an AES-128-secured 13.56 MHz smart card whose data is cryptographically bound to its chip and issued under HID's own key management. Because a functioning Seos credential can only be provisioned with your facility's HID keys, it is ordered through HID or an authorized integrator — no independent supplier, American Key Cards included, can produce one.
- 13.56 MHz
- Frequency
- 13.56 MHz Contactless Smart Card — ISO/IEC 14443 Type A, NFC-capable, AES-secured
- Technology
- 2
- Bit formats
- 4+
- OEM part nos.
- Brand channel
- Order from
If your building runs HID Seos, you're on the most secure credential HID makes — and this page is the operational picture a facility manager actually needs: how Seos is deployed, how new credentials get issued, how it coexists with your other formats, and why the compatible-card route that works for 125 kHz proximity simply doesn't exist here. We're an independent credential supplier, we don't sell Seos, and we'd rather explain the platform clearly than pretend otherwise.
What Seos actually is, in operational terms
Seos is HID's device-independent credential architecture. Rather than storing an access number in the open the way a 125 kHz proximity card does, Seos wraps your credential data inside a Secure Identity Object — an encrypted, digitally signed container — and ties that container cryptographically to the specific secure-element chip it lives on. The reader and the credential perform a mutual AES-128 authentication before any data moves, so the credential proves it's genuine and the reader proves it's authorized, in both directions, on every tap.
The practical consequence for a facility is that a Seos credential is not a number you can read off and reproduce. It's a cryptographic conversation that only a properly keyed credential and a properly keyed reader can have. That's the entire security proposition, and it's why Seos is chosen for federal, financial, healthcare, and critical-infrastructure sites where identity assurance is non-negotiable.
The same Seos architecture also runs as a mobile credential in HID Mobile Access — the phone becomes the secure element, provisioned over the air. Sites frequently run physical Seos cards and mobile Seos side by side from the same management platform.
How Seos credentials get issued and replaced
Seos issuance happens under HID's Trusted Identity Platform, using cryptographic keys specific to your organization. When a facility is set up, HID and your integrator provision those keys into your readers and into your credential order; from then on, every new card or mobile credential is created against that key set. This is what makes the credentials trustworthy — and also what makes them impossible for an outside vendor to fabricate.
When someone loses a Seos card, the replacement path is the same channel that issued the original: your access-control integrator orders and provisions a new credential to your keys, and you revoke the lost one in your management software so it stops working immediately. There's no bench-programming shortcut, because the whole design goal is that a lost card is a dead card the moment you revoke it.
For bulk reissuance — a big intake of staff, a merged site, a lease turnover — your integrator handles the order against your key set. If you've lost track of who your integrator is, HID's partner locator will connect you to an authorized dealer who can pick up the account.
Reader ecosystem and how Seos fits your building
Seos reads on HID's Signo line and on iCLASS SE and multiCLASS SE readers with Seos enabled. Signo is the current-generation platform and is the usual target for new deployments and reader refreshes because it handles Seos, mobile credentials, and OSDP Secure Channel to the panel out of the box.
Because multiCLASS readers can be configured to accept more than one technology, many facilities run Seos as the primary credential while a reader still accepts a legacy format during a migration window. That flexibility is a deployment tool, not a permanent state — the security benefit of Seos is only fully realized once the older, more copyable technologies are switched off at the reader.
If you're planning doors, the reader decision matters more than the card decision: a Signo or SE reader provisioned with your keys is what makes Seos work, and it's also what will accept your mobile credentials when you're ready for them.
Where American Key Cards fits — and where we don't
We don't sell Seos, and we won't imply we can. What we can genuinely help with is the rest of your credential fleet. Almost every Seos site also runs open 125 kHz proximity somewhere — a parking gate, an older outbuilding, a legacy wing mid-migration — and that's exactly the stock we supply: unbranded, compatible-by-specification proximity cards and fobs programmed to your facility code, with no dealer account required.
If you're mid-migration from a legacy format toward Seos, we can supply the interim proximity credentials while your Seos rollout proceeds through HID's channel, so you're never caught short on the old doors while the new ones come online. And if you're simply trying to figure out which of your doors are Seos and which are still on something we can supply, send us photos of your readers and credentials — we'll tell you honestly which is which.
HID Seos specifications
- System brand
- HID Global / ASSA ABLOY
- Technology
- 13.56 MHz Contactless Smart Card — ISO/IEC 14443 Type A, NFC-capable, AES-secured
- Frequency
- 13.56 MHz
- Credential platform
- HID secure element (high-assurance certified) with an AES-128 cryptographic co-processor; credential data wrapped in HID's Secure Identity Object model
- Bit formats
- Carries any standard HID access format (26-bit H10301, 37-bit H10302/H10304, Corporate 1000) inside an encrypted, device-bound Secure Identity Object, OSDP Secure Channel to the reader
- OEM part numbers
- 5005 / 5006 (Seos card, 16k / 8k), 5015 / 5016 (Seos embeddable card), 510x (Seos + Prox card), 5266 (Seos key fob)
Specifications reviewed August 2026
How to order HID Seos credentials
Seos credentials are issued under HID's Trusted Identity Platform with facility-specific cryptographic keys, so they are ordered through HID or an authorized HID integrator who provisions them to your site's keys. Your access-control installer is the fastest route; if you don't have one, HID's dealer locator connects you to an authorized partner. American Key Cards does not supply Seos credentials — a third party cannot produce one that will enroll.
Editorial reference page. American Key Cards is an independent credential supplier and is not affiliated with, endorsed by, or sponsored by HID. We do not sell HID's secured credentials; brand and product names appear only to identify the technology discussed, and all trademarks remain the property of their respective owners.
Readers in this ecosystem
Related formats
You might also need
HID iCLASS SE
HID's second-generation AES-secured smart card and the platform most large sites migrate through — a facility-operations guide to deploying, issuing, and expanding iCLASS SE.
How it worksHID iCLASS SR
The bridge issuance between legacy iCLASS and the SE platform — a facility guide to where SR fits, how it's ordered, and when to plan past it toward SE or Seos.
How it worksHID Seos
HID's flagship AES-secured smart credential, built so that the credential is inseparable from its chip — a facility-operations guide to how Seos is deployed, issued, and expanded.
How it worksHID Seos — FAQ
Can I buy a replacement Seos card from an independent supplier?
No. A working Seos credential must be provisioned with your facility's HID cryptographic keys under HID's Trusted Identity Platform, which only HID and authorized integrators can do. Any supplier claiming to sell a drop-in Seos replacement is selling something that won't enroll. We tell you plainly and point you to the right channel.
My Seos card was lost — what's the fastest replacement route?
Contact your access-control integrator (the company that services your HID system); they order and provision a new credential to your keys. Revoke the lost card in your management software immediately so it stops working. If you don't know your integrator, HID's authorized-partner locator will connect you.
How is Seos different from iCLASS SE?
Both are modern AES-secured HID credentials using the Secure Identity Object model, but Seos is the device-independent, highest-assurance end-state — the same architecture runs on cards, fobs, phones, and wearables — while iCLASS SE is the card-platform generation many sites migrate through on the way there. Operationally, if you're deploying new, Seos (on Signo readers) is usually the target.
Can American Key Cards help my Seos site at all?
Yes — with everything around Seos. We supply the open 125 kHz proximity credentials most Seos sites still run on secondary doors and gates, and we can carry your interim proximity stock through a migration. We just don't (and can't) supply the Seos credentials themselves.