Skip to main content

How to Redeem a Mobile Wallet Pass via Web?

Issue an HID mobile wallet badge from a web browser without downloading the Genea Mobile app.

Written by Hiral Dave

TL;DR

  • What it does: Lets you issue an HID mobile badge that a user adds straight to Apple Wallet or Google Wallet from a browser — no app download required.

  • Where to find it: Send a Wallet invite from Add Card, a user’s Preferences, a User Group, or the All Users page.

  • Who can use it: Operators and admins on an account with an active HID Origo subscription and wallet functionality enabled, once the Apple and Google prerequisites are complete.

  • How the user redeems: They get an email, sign in to Genea, and tap Add to Apple Wallet or Add to Google Wallet.

Overview

Currently, creating a mobile key meant downloading the Genea mobile app and signing in first — an added, mandatory step even for users who didn’t want to install the app. Web Provisioning removes that requirement. You issue a mobile badge the same way you’d issue a keycard — pick the user, pick Wallet, send — and the user adds the credential to Apple or Google Wallet from an authenticated browser page. The app remains available as an optional second path.

The mobile credential is never carried by the email or the link. It is created only after the user signs in to Genea and then into their wallet account, so a badge is never exposed to an unverified user.

Web Provisioning is available for HID credentials only. It is not supported for WaveLynx at this time.

Prerequisites

To turn on Web Provisioning for your HID Origo account, you must complete the Apple and Google prerequisites to successfully use this feature.

Using a Genea-managed account? These prerequisites are already completed for Genea-managed Origo account, so Web Provisioning is ready to use — you can skip straight to Step 1.

You’ll also need, in all cases:

  • An active HID Origo subscription with wallet functionality enabled.

  • Available wallet licenses in your Origo pool.

1. Apple Wallet

Apple enablement is handled directly with HID. Please contact HID to enable Web Provisioning for your account, along with your card artwork.

2. Google Wallet

Google enablement is to be completed in the Google Cloud Console:

  1. Go to the Google Cloud Console and open APIs & Services → Credentials.

  2. Create a new project.

  3. Configure the OAuth consent screen — provide your app name and user support email, choose the audience (Internal or External), and add contact information.

  4. Create an OAuth client to generate your Client ID and Client Secret (used for secure communication between your web application and Google APIs).

  5. Allowlist your Client ID by submitting it through Google’s API allowlist request form. Allowlisting is mandatory to enable Web Provisioning.

HID also provides a JSON file used to initiate the provisioning workflow for both wallet types. For full technical detail, see HID’s Web Provisioning Prerequisites reference.

Step 1 — Enable Mobile Wallet Access

Mobile Wallet Access is the permission that lets a user create a wallet pass. Enabling it grants the permission only — it sends no email and reserves no credential.

You can enable it in two ways:

  1. On a User Profile, open Preferences and turn on Mobile Wallet.

  2. On a User Group, under Mobile Key Management, turn on the Mobile Wallet toggle to grant it to every member of the group.

The standalone Send Wallet Invite actions on the User Profile and User Group appear only after Mobile Wallet Access is enabled.

The Add Card and All Users send paths are the exception — they enable Mobile Wallet Access for you as part of the send.

Step 2 — Send a wallet invite

You can start a wallet invite from any of the following places, depending on whether you’re issuing to one user, a group, or all active users.

1. From Add Card (single user)

  1. Open Add Card for the user.

  2. In the key-type selection, choose Wallet (shown alongside Keycard and App-Based Key).

  3. If the user has no email on file, enter one when prompted — it’s saved as their default email. (You can’t overwrite an existing email here; edit that from the User Profile.)

  4. On confirming, Genea enables Mobile Wallet Access for the user, runs a license check, and emails the invite. No credential is created at this step.

“Mobile Key” is now labelled App-Based Key — the credential provisioned and used through the Genea mobile app. Wallet is the new browser-based path.

2. From a User Profile (single user)

  1. On the user’s Preferences (with Mobile Wallet Access enabled), click Send Wallet Invite.

  2. The invite is emailed to the user’s configured address. A license check runs on send. The action is unavailable for suspended or deleted users.

3. From a User Group

  1. On the group, click Send Wallet Invite. This emails all group members — whether or not they already hold a pass.

  2. Before sending, Genea warns if the license limit is reached (however, it sends the invite to users holding at least one Active wallet pass). Members without an email are skipped automatically.

  3. Optionally, turn on Auto-send to new members so anyone who later joins the group — by directory sync or manual add — is invited automatically. This control is off by default.

4. From the All Users page (org-wide)

  1. On the All Users page (Global or Location overview), open More options and choose Send Wallet Invite to all active users.

  2. Confirm the pop-up, which states that Mobile Wallet Access will be enabled and the link will be sent to all active users.

  3. On confirmation, the invite goes to every active user via email, and their Mobile Wallet Access is enabled. Suspended, inactive, and email-less users are excluded or skipped.

A license check runs on confirmation and warns you if there aren’t enough licenses. Users who already hold at least one Active pass aren’t counted toward the pending-license total but still receive the invite.

What the users will see (redemption)

  1. The user receives a wallet invitation email with a link. (The email leads with the wallet path and includes an app-based option to redeem the wallet pass as a secondary option at the bottom.)

  2. The link routes to Genea login first. SSO customers sign in with email and password; non-SSO customers use email 2FA. No wallet button or credential detail appears until they’re authenticated.

  3. After sign-in, both Add to Apple Wallet and Add to Google Wallet buttons appear. Both are shown regardless of the device they’re browsing on, so they can add the pass to whichever phone they own.

  4. Apple takes them to iCloud login and device selection; Google takes them to Google account login. The credential is tied to the wallet account they sign in to.

Adding to Apple Wallet

  1. The user taps Add to Apple Wallet. Genea generates the wallet token and reserves the credential at HID, and a license is consumed (only for the user’s first pass). The pass appears as Pending in the Cards table.

  2. The user signs in to iCloud when prompted.

  3. The user selects which device(s) to add the pass to — for example, iPhone and/or Apple Watch.

  4. The pass is added to Apple Wallet on the selected device and moves from Pending to Active. The credential is tied to the iCloud account the user signed in to.

If the user abandons at iCloud login or device selection, the Pending pass self-heals — it expires after 72 hours, and the license is released back to your pool.

Adding to Google Wallet

  1. The user taps Add to Google Wallet.

  2. The user signs in to their Google account when prompted.

  3. On successful sign-in, Genea generates the wallet token and reserves the credential at HID, and a license is consumed (only for the user’s first pass). The pass appears as Pending in the Cards table.

  4. The pass is added to Google Wallet and moves from Pending to Active. The credential is tied to the Google account the user signed in to.

A cancelled or failed Google sign-in generates no token, reserves no credential, and consumes no license.

The redemption link is generic and has no expiration; also, a forwarded link grants nothing without the recipient authenticating as an active user.

Pass statuses and licensing

As a badge moves through redemption, its status updates in the Cards table:

  • Pending — the user has started to create the pass (a token was generated and a credential reserved at HID), but it isn’t on their device yet.

  • Active — the pass has been added to the wallet.

  • Expired — a Pending pass whose token wasn’t redeemed within 72 hours. The reserved license is released back to your pool automatically, so abandoned redemptions self-heal.

  • Revoked — the credential was revoked. Re-issuing always starts a brand-new lifecycle.

One license per user. A user who adds both an Apple and a Google pass still consumes only one license. Your Subscription page shows the Apple and Google counts separately, while the usage bar counts per user — so the two platform counts may sum to more than the bar.

There is no Resend action on a Pending wallet pass — redemption can’t resume mid-flow. To invite again, use any of the standard Send Wallet Invite entry points above.

Troubleshooting

  • “Send Wallet Invite” isn’t showing. Mobile Wallet Access isn’t enabled for that user (or the group’s Mobile Wallet toggle is off). Enable it first — or use Add Card / All Users, which enables it as part of the send.

  • The send was blocked by a license check. There aren’t enough wallet licenses in your Origo pool. Mobile Wallet Access still stays enabled, so you can free up or add licenses and send later from the user’s Preferences.

  • The user sees “Invalid Invitation Link.” The user was deleted. Confirm the account, then re-issue.

  • Credential creation failed on the user’s device. The user can retry from the redemption page; after repeated failures they’ll be directed to contact support.

If you have any questions about Web Provisioning, please reach out to Genea Support at acsupport@getgenea.com.

Did this answer your question?