Supported NFC card types

Review the Near Field Communication (NFC) card types that the NFC authenticator is designed to support, including which ones are hardware-protected against cloning.

Early Access release. See Enable self-service features.

Category Security model Supported card types
Hardware-protected (non-cloneable) These cards contain a secure element with encryption keys that can't be extracted or duplicated. If someone obtains the card and attempts to copy it, the copy is rejected. During authentication, Okta verifies that the card is genuine, which protects against interception attacks.

These cards may be preferable for orgs where card theft is a major risk, for example, in environments where badges are shared or are visible.

MIFARE DESFire EV2 and EV3
Basic security (cloneable)

These cards are data storage tags with no built-in security. They hold an ID value that Okta writes during enrollment and reads during authentication. Because the ID can be copied by anyone with an NFC reader, the PIN is the only defense against an attacker who may have cloned or stolen the card.

These cards are best suited for orgs where the risk of card cloning is low and the PIN requirement provides an acceptable level of assurance, for example, retail or warehouse operations.

NXP NTAG 213, 215, and 216