Revoking a User's Wallet Credentials

Andrea
Andrea
  • Updated

Overview
Use this when a user's HID Wallet passes need to be revoked and reissued — most often when the user has a new phone, has lost their phone, or receives an "Unexpected Error" while setting up a pass on a second device. There are limits on how many Wallet passes can be provisioned to the same account, so the older pass needs to be cleared out before a new one can be created.

Applies to
Sites with the HID Wallet integration enabled — the "Revoke All Wallet Passes" button only appears on those sites. 

Who can do this
Building Admins. If you do not see the button, either your role does not have access to it or the HID Wallet integration is not enabled at the site.

Before you revoke

Revoking is immediate and cannot be undone. Confirm all three of these first:

  • The user's email in the access control system exactly matches the email they use to sign in to Cove. A mismatch is the most common reason a reissued pass fails right afterward — see Mobile Access: We Couldn't Find Your Account.
  • The user is not suspended — see Suspend or Unsuspend Users.
  • The user no longer needs the old device. This revokes passes on every device tied to the account, not just the old one, so anyone relying on an existing pass will lose access as soon as you confirm.

Where to find it

  1. Go to the User Directory and select the pencil icon on the affected user to open their User Details page.
  2. Scroll to the bottom of the user profile. If HID Wallet integration is enabled at the site, you'll see a "Revoke All Wallet Passes" button at the bottom of the form.
Revoke.png

How it works

  1. Click "Revoke All Wallet Passes."
  2. A confirmation modal will appear before anything happens — review it and confirm.
  3. The system queries HID for all Wallet passes tied to that user, then revokes each one.
  4. HID Origo sends callback events to sync these deletions with the Access Control System.
  5. Once complete, the user can start fresh and re-provision their Wallet pass on the new device.

Reissuing on the new phone

  1. Ask the user to delete the old Cove pass from the wallet on any device that still has one.
  2. Allow 5–10 minutes for the revocation to sync to the access control system before they try again.
  3. Have the user set up mobile access again from the Cove app on the new device: HID Wallet (Apple) or HID Wallet (Google).
  4. Ask them to test at a reader they use regularly, not only the lobby turnstile.

If setup fails with a "we couldn't find your account," "invalid email," or "incorrect email" message, the email in the access control system does not match their Cove login — see Mobile Access: We Couldn't Find Your Account.

 

Related to

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request