Ambimat Group Ambimat AmbiSecure eSIM Initiative Engineering Blog Ahmedabad · India · Est. 1981
FIDO2 Smart Card

AmbiSecure OnePass Card

A FIDO2 smart card with resident credentials. Tap or insert — no PIN entry, no shared secret, no phishable seed. Brandable, deployable as employee ID and authenticator in one.

FIDO2 U2F NFC USB PIV-compatible
AmbiSecure OnePass Card — FIDO2 smart card with ISO 7816 contact pad, NFC, and USB
Why a card

When the security key needs to be the badge.

Two devices in one

Replace the corporate badge and the security key with a single card. Lower issuance cost, fewer items lost.

Phishing-resistant

FIDO2 binds the credential to the relying party origin. Adversary-in-the-middle phishing pages cannot harvest it.

Brandable

Custom artwork, employee photo, magnetic stripe, embossing, contactless logo. Looks like a badge, works like a Yubikey.

Battery-free

Powered by NFC field or USB. Thousands of authentications without service.

Resident credentials

Discoverable credentials for username-less, passwordless flows — the smoothest authentication UX FIDO2 offers.

Auditable

Cards are issued through your existing badge personalisation line, or our personalisation tooling. Every key has provenance.

Specifications

What is on the card.

Form factorISO/IEC 7810 ID-1, 85.6 × 53.98 mm, ISO/IEC 7816 contact + ISO/IEC 14443 Type A contactless
InterfacesNFC (ISO/IEC 14443 Type A); USB-A or USB-C (variant SKU)
ProtocolsFIDO2 (CTAP2); FIDO U2F (CTAP1); PIV-compatible applet (optional SKU)
CryptographyECC P-256 (FIDO2); ECC P-384 (optional); RSA 2048 / 3072 (PIV); SHA-256 / SHA-384
Resident credentialsUp to 25 discoverable credentials (depending on chip variant)
Operating systemJavaCard 3.x with GlobalPlatform 2.3.1
CertificationFIDO Certified L1 (target); Common Criteria EAL5+ chip
PersonalisationCompatible with our Multi-Card Applet Loading Tool, NDEF Personalisation Tool, and Security Key Manager
CustomisationArtwork, photo ID, magnetic stripe, embossing, NDEF URL, logo
MOQPilot batches from 100 units; production from 1,000 units
Lifecycle

From wafer to wallet.

A FIDO card is only as trustworthy as the line that personalised it. Here is how ours works.

01

Chip

Common Criteria EAL5+ secure element from a partner vendor.

02

Applet load

FIDO + optional PIV/OpenPGP applets loaded over SCP03.

03

Personalise

Issuer keys derived per-card. Credentials, AAGUID, attestation cert.

04

Brand

Artwork, photo, embossing, magnetic stripe.

05

Issue

Hand to user. Existing badge issuance lines work fine.

Pilot a hundred OnePass Cards.

Tell us your form factor preference, target deployment, and certification target. We can usually ship a personalised pilot batch within 6–8 weeks.

Request a pilot