Start your EVOTECH request in under a minute.
Door Reader Programming in Katy, TX 77494
A card reader that beeps is not a card reader that works. Most of the calls we take in 77494 come from amenity centres, dental suites and daycare vestibules where the hardware is fine and the credential layer underneath it has drifted — wrong bit format, a facility code nobody wrote down, or three hundred resident fobs that were never properly enrolled in the first place.
A reader is three separate programming jobs stacked on each other
Programming a door reader covers at least three separate pieces of work, and they fail in ways that look nothing alike. Working out which layer is broken is most of the visit; the fix, once you know, is usually quick.
| Layer | What gets configured | How it looks when it is wrong |
|---|---|---|
| Reader to controller | Wiring, output protocol, OSDP address and baud rate, or the Wiegand bit format the reader emits | The reader lights and chirps on every presentation, and the controller log stays completely empty |
| Credential to reader | Which card technologies and which encryption keys that reader is permitted to read | The same fob works at the back door and is ignored at the front |
| Cardholder database | People, credential numbers, access levels, schedules, expiry dates | The controller logs the card by number and refuses it — a clean, informative denial |
That last row is the good outcome: a logged denial means every wire, antenna and key is doing its job and somebody simply lacks permission — a five-minute software change. The empty log in the first row is the expensive one, because the reader is talking happily to nobody.
The number printed on the fob is only half of what the reader sees
Three generations of credential are in daily use around Katy, often in the same building, and they are not equivalent in security even when identical in shape.
| Credential | How it proves it is genuine | What that means for you |
|---|---|---|
| 125 kHz proximity (the classic thick white card or teardrop fob) | It does not. It broadcasts a fixed number to anything that energises it | Copy devices are inexpensive and sold openly. Treat the number as public |
| 13.56 MHz MIFARE Classic | A cipher whose workings were published years ago | Convenient and cheap, but plan for it the way you plan for plain proximity |
| 13.56 MHz DESFire EV2 / EV3 | AES challenge and response, with a key derived per card | A reader must hold the matching site key before it will read anything |
| Encrypted smart card lines such as iCLASS SE and Seos | Mutual authentication against site-specific key material | Cards must be ordered on your site key, not bought generically |
| Phone credentials over Bluetooth or NFC | Cryptographic token bound to that handset and that user | Revoked centrally the moment somebody leaves, with no plastic to chase |
This catches people out during upgrades. Move a site to DESFire and the new cards read as nothing at all on any reader not yet loaded with the site key — not denied, not logged, invisible. The reader is behaving as designed: it ignores what it cannot authenticate.
Most modern readers are multi-technology and can accept legacy proximity and an encrypted smart card at once. That dual window is what makes a phased migration possible instead of one disruptive swap — and closing it afterwards is the step that gets forgotten.
Why a perfectly good card comes back as an unknown card
A Wiegand reader pushes a raw string of bits down two data lines and the controller decides how to carve them up. The long-standing default is the 26-bit format, and a surprising number of odd faults live inside it.
| Bit position | Contents | Range |
|---|---|---|
| 1 | Even parity over the first half | — |
| 2–9 | Facility code | 0 to 255 |
| 10–25 | Card number | 0 to 65,535 |
| 26 | Odd parity over the second half | — |
Eight bits of facility code allow 255 usable site codes across the entire installed base of that format. Two unrelated buildings sharing a code and overlapping card numbers is not coincidence, it is arithmetic — the strongest argument for moving a growing site to a wider format such as 35-bit Corporate 1000, or to credentials ordered on your own site key.
Present a 35-bit card to a controller expecting 26 bits and the parity check fails or the number truncates, so the log fills with entries matching no card you own. One card getting different answers at two doors usually means two readers are emitting different formats into the same panel.
The order we work through it
- Present the card and capture the raw event at the controller, including the bit count, not just the friendly card number.
- Compare that bit count against the format the controller is configured to parse.
- Check whether the facility code that arrives matches the code the rest of the cards use.
- Where the reader is switchable, confirm what output format it is actually set to rather than what the paperwork says.
- Only then touch the cardholder record.
On newer sites the reader talks OSDP over a shielded twisted pair instead. That removes the bit-format guessing and replaces it with two settings that must line up: a unique address on the bus and a matching baud rate. It also carries an encrypted secure channel, so a reader left on the well-known commissioning key is a job only half finished.
Loading several hundred amenity fobs without losing a weekend
An amenity centre in a west Katy master-planned community is a different data problem from an office with eleven staff: several hundred households, each entitled to a pool gate, a fitness room and often a dog park or mail kiosk, with turnover every month.
New fobs from one order normally arrive in a consecutive number range, so the whole batch can be entered as a range in a single operation instead of presented one at a time to a desk reader — the difference between an afternoon and three days. Loose credentials gathered from residents over the years cannot be ranged, which is worth knowing before anyone promises a date.
Structure that survives turnover
We build the database around groups, not individuals: one access level for residents in good standing, one for the board, one for the pool contractor that expires on a date, one for the landscape crew limited to weekday daylight hours. Adding a household becomes one assignment, and a new management company inherits something legible.
Deactivating a credential is safer than deleting it. A disabled record keeps the history attached to it, so when a question arises about who opened the fitness room at two in the morning the log still names somebody. Delete the record and the events become orphan numbers.
What is usually behind the reader on this side of the Grand Parkway
77494 is dominated by large master-planned neighbourhoods and the retail that serves them, and that mix produces a particular set of access control jobs.
- HOA amenity centres. Pool gates, fitness rooms open around the clock, clubhouse rentals, sometimes a mail kiosk. High credential counts, constant turnover, and the system frequently changes hands when the management contract does.
- Pool and gate pedestals. Outdoors, sun-exposed, often on a separate power path from the clubhouse, and mounted on metal posts that affect how a low-frequency reader tunes.
- Professional suites in newer retail. Dental, orthodontic and therapy offices along the 99 and Cinco Ranch corridors — typically one or two controlled doors between waiting room and clinical area, plus a back door onto the service drive.
- Daycare and school-adjacent vestibules. A controlled outer door with an intercom release and a staff-only inner door. The programming here is mostly about schedules and about who can release the outer door during drop-off.
- Church and community campuses. Several buildings, volunteer key holders, and doors that unlock on a schedule for services and lock hard the rest of the week.
The construction stock helps. Most of this ZIP is recent slab-on-grade with accessible attic space and, in tenant suites, conduit already stubbed in the frames. Pulling a fresh home run to a controller is straightforward here in a way it is not in older commercial stock — and a clean new run often beats nursing a marginal legacy one for another five years.
What our technician does once through the door
- Walk every controlled opening and record what is actually installed: reader model, lock type, request-to-exit device, door position switch, and whether the door closes and latches on its own.
- Open the controller enclosure and document the panel, firmware, power supply, battery date and how the readers are wired in.
- Present a known-good credential at each reader while watching the live event log.
- Measure supply voltage at the reader terminals during a read, not at the panel where it always looks fine.
- Confirm the bit format, or the OSDP address and baud, against the controller configuration.
- Rebuild access levels and schedules around how the building is really used, then enrol credentials.
- Test every door against every access level, denials included — a level that admits the wrong person is a failure the log will never flag.
- Hand over administrator credentials, a door schedule and a printed credential list, and show whoever runs the building how to add and disable a person.
Where a magnetically locked door is tied to fire alarm release, that release path is tested during the visit, and the authority having jurisdiction has the final say on the arrangement.
The variables that actually change a Katy estimate
We quote after seeing the doors, itemised, and never over the phone — the same sentence describes wildly different jobs. What moves it:
- How many credentials must be read individually instead of entered as a consecutive range.
- Whether the existing readers can be reconfigured or have reached the end of what they will accept.
- Whether anyone holds the administrator login to the existing software, or the system has to be adopted from scratch.
- Cable condition and length back to the controller, and whether the shield was ever landed correctly.
- Outdoor and gate positions, which add enclosure, surge protection and mounting concerns indoor doors do not have.
- Whether the site is migrating credential technology, and how long the dual-read window needs to stay open.
- Schedules and holiday calendars, which take real conversation time on a multi-building campus.
Related services
Frequently asked questions
Can you program the readers we already have, or does everything need replacing?
In most cases the existing readers stay. A multi-technology reader made in the last decade can usually be pointed at a different output format, moved from Wiegand to OSDP, or loaded with new key material without coming off the wall. The ones we do replace are readers locked to a single obsolete technology, units with water ingress, and any reader whose format cannot be changed on a site that needs a wider one. We tell you which you have during the free on-site estimate.
Somebody copied a resident fob. What actually stops that?
Plain 125 kHz proximity cannot be protected against copying — it holds no secret and announces a fixed number to anything that powers it. The fix is a credential that authenticates: DESFire EV2 or EV3, or an encrypted smart card line ordered against your own site key, with readers loaded with the matching key so a blank clone carries nothing they accept. Phone credentials solve it differently, by binding the credential to one handset and one person.
Our management company changed and nobody has the software login. Where does that leave us?
One of the more common calls we take from Katy HOA boards. Depending on the platform, an administrator account can sometimes be recovered through the manufacturer with proof of site ownership. Where it cannot, the controller is reset and the database rebuilt, which means recreating the credential list — exactly why we hand over a printed list and the admin login at the end of every job. Recovery is nearly always cheaper, so we try it first.
How long does loading a few hundred residents actually take?
Almost entirely down to whether the credentials arrived as a consecutive batch. A sequential range is entered once for the whole block, so the work becomes matching households to numbers. A pile of assorted fobs collected over years must be read one at a time on a desktop enrolment reader — a slow manual afternoon or more. Tell us which you have and we can be specific about the schedule.
If the internet drops, do the doors stop working?
On a properly specified system, no. The controller at the door holds the credential list and schedules in its own memory and keeps deciding on its own. What you lose is the remote view — live events, remote unlock, adding or removing a person from off site — and that catches up when the link returns. Battery backup in the enclosure covers a power cut for a period that depends on the battery and the lock hardware, which we check and note on the site visit.
Book a free on-site access control review in Katy
Tell us how many doors and roughly how many credentials, and we will come read the hardware and the log before anyone quotes a number. Licensed, insured, 5.0 rated and local since 2004.
Book a Free Consultation
Ready for EVOTECH to help?
Before you leave, send the quick version. We will review the page you came from and reply with the clean next step.
