For charge-point operators, fleet depots, housing societies and charger OEMs, the RFID card for EV charging is still the most dependable way to say “this user may charge here”. Apps stall on weak signal, QR stickers get scratched, and a driver at 11 pm does not want to install anything. This guide covers how card authorisation works with OCPP, which chip to choose, how cards are personalised, and what to put in a bulk purchase order.
To be clear up front: Identium manufactures the RFID cards and readers, not chargers or charge-management software (CMS), so treat the OCPP notes below as buyer’s guidance rather than a firmware specification.
Why EV chargers still rely on RFID cards
- Offline authorisation. Basement and highway sites lose connectivity; a charger holding a local whitelist can still start a session from a card tap.
- Fleets. A card tied to a vehicle or driver gives clean per-vehicle energy accounting without every driver holding an app account.
- Shared parking. In societies and offices one charger serves many flats or employees; the card is the billing key.
- No-app users. Not every driver has a smartphone with data, or wants an account for a single top-up.
How RFID authentication works with OCPP
OCPP (Open Charge Point Protocol) is the open standard for messages between a charger and its CMS. It is widely used by Indian charger OEMs and CPOs, and as of 2026 it is reported to be referenced in central guidelines for public charging infrastructure — confirm the current requirement with your CPO or consultant. In OCPP the card is represented by its idTag — in practice the UID the charger’s built-in reader pulls off the card, formatted as a hex string.
The flow:
- Driver taps; the charger reads the UID.
- Charger sends an
Authorizerequest to the CMS with the idTag. - CMS answers Accepted, Blocked, Expired or Invalid.
- If accepted, the charger starts the transaction and reports it against that idTag.
For offline working, OCPP 1.6 defines a Local Authorization List (pushed down by the CMS) and an Authorization Cache (recently seen tags). OCPP 2.0.1 replaces idTag with a richer IdToken carrying a type such as ISO14443 or ISO15693. Field lengths and permitted characters differ between versions and firmware builds, so check the OCPP 1.6J or 2.0.1 spec your charger firmware actually implements before you fix a UID format.
The gotcha that bites most projects is not the protocol but UID formatting. Some firmware reports the UID most-significant byte first, some least-significant first; some upper-case, some lower-case; some truncate a 7-byte UID to 4 bytes. Before ordering thousands of cards, tap a sample on the real charger and note the exact string the CMS receives — that is what should be printed on the card and delivered in the UID list.
Which card technology: 125 kHz vs MIFARE Classic vs DESFire/NTAG
Most chargers authorise on the UID alone, whatever the chip. So the chip mainly determines reader compatibility, cloning resistance and cost — the real security lives in the CMS (whitelisting, blocking, session limits).
| Chip family | Frequency / standard | UID | Cloning risk (UID-only use) | Relative cost | When it fits |
|---|---|---|---|---|---|
| 125 kHz (TK4100 / EM4200) | LF, read-only ID | 5-byte | High — cheap duplicators copy it in seconds | Lowest | Only if the charger reader is LF-only or a legacy estate |
| MIFARE Classic 1K/4K (S50/S70) | 13.56 MHz, ISO 14443A | 4- or 7-byte | Moderate — UID-changeable “magic” cards exist | Low | The default for chargers with ISO 14443A readers |
| NTAG 213/215/216 | 13.56 MHz, NFC Forum Type 2 | 7-byte | Moderate — an originality signature can be checked where the reader supports it | Low–mid | Cards that should also open a URL or app on a phone |
| DESFire EV2/EV3 | 13.56 MHz, ISO 14443A | 7-byte (random-UID option) | Low if the reader authenticates with keys; same as Classic if UID-only | Highest | Corporate campuses, high-value fleets, upgrade path |
A DESFire card only earns its price if the charger reader and firmware can perform key-based authentication — many cannot, so confirm with the OEM first. And 125 kHz cards will not read on a 13.56 MHz charger reader; they are different radios, as our UHF vs HF vs NFC explainer sets out.
Indian use cases
- Public CPOs issue cards as a fallback for drivers without the app, for corporate accounts, and for sites with poor connectivity.
- Fleet depots (buses, last-mile vans, cab fleets) map one card per vehicle or driver, keep an offline whitelist on every charger and pull energy per cost centre from the CMS.
- RWAs and societies put a card against each flat so a shared charger bills correctly; the same 13.56 MHz card can double as the vehicle parking or lobby credential if the systems share a UID database.
- Corporate campuses and hotels often already run access-control cards; reusing them for staff charging is realistic if the protocol matches (see FAQ).
- Charger OEMs bundle pre-printed cards with each unit, UIDs pre-registered in the CMS.
Personalisation and issuance
- Printing: full-colour CMYK on CR80 PVC or PETG — logo, network name, helpline, terms on the reverse. PETG typically stands up better to a hot dashboard.
- Numbering: a short human-readable serial on the face, plus the UID printed exactly as the charger reports it. This one detail saves hours of enrolment mistakes.
- UID list: each batch ships with a CSV/Excel of UID, printed serial and carton sequence, ready to import into the CMS or push out as a Local Authorization List.
- Encoding and keys: for DESFire, decide who holds the master keys. We can encode with customer-supplied keys or ship factory-blank; either way, document key custody first.
- Enrolment desk: a desktop HF reader at the office lets staff bind cards to accounts without walking to a charger.
Buying in bulk: what to write in the PO
Cost is driven by chip family (LF cheapest, DESFire dearest), printing (blank, one-colour, full-colour both sides), variable data and encoding, body material, and quantity. Those variables move the number a lot, so request a manufacturer quote against your spec rather than a list price. Smart cards are commonly classified under HSN 8523 in India, but confirm the code and GST rate with your CA; our HSN and GST guide has the background.
A tight PO specifies:
- Chip and exact variant (e.g. MIFARE Classic 1K, 4- or 7-byte UID; NTAG216; DESFire EV3 4K) and protocol (13.56 MHz ISO 14443A), matched to the charger reader.
- UID format required on print and in the list (byte order, case, separators).
- Card body: CR80, 0.76 mm, PVC/PETG, matte or gloss.
- Artwork files, colour references, variable-data fields (serial range, QR/barcode).
- UID list format; encoding requirements and key custody, if any.
- Sample approval: 5–10 pilot cards tested on the actual charger and CMS before the run.
- Quantity, phased delivery, packaging (per-100 boxes, sequential) and replacement terms for cards that fail to read on receipt.
Ask about MOQ and lead time at quote stage; blank stock cards ship far faster than printed, encoded runs. Every batch is tested in-house before dispatch.
Cards vs app/QR vs autocharge: where cards still win in 2026
Apps suit public roaming users with accounts and data. QR codes are cheap but need a phone, an intact sticker and no fraudulent overlay. Autocharge and ISO 15118 Plug & Charge, where the vehicle identifies itself over the cable, are reported to be growing but as of 2026 depend on vehicle-side support that is still uneven in India. Cards win wherever the session must start in two seconds regardless of connectivity, phone or driver — fleets, societies, campuses and any charger that must work offline. Most operators run cards alongside the app, not instead of it; our NFC and HF tag range also covers key fobs for drivers who prefer not to carry a card.
FAQ
Can one card work on multiple charging networks? Technically yes — a UID is just a number, and any CMS that whitelists it will accept it. Whether networks honour each other’s cards is a commercial roaming question that changes; we do not track which Indian networks accept which cards, so ask each CPO directly.
Can I reuse existing access-control cards? Often, if they are 13.56 MHz ISO 14443A and the charger authorises on UID. Test a handful first — some readers return only 4 bytes of a 7-byte UID, and 125 kHz cards will not read at all.
How do I block a lost card? Mark it Blocked in the CMS so Authorize is refused, then push an updated Local Authorization List so offline chargers reject it too. Issue a new card with a new UID; never re-issue the old number.
Planning a card programme? Send us the charger make, OCPP version, quantities and artwork and we will come back with a spec and a manufacturer quote — get in touch or WhatsApp +91 70110 01472.