ID card software that makes issuing cards easy

CardOffice is card personalisation software that makes producing student and staff ID cards quick and simple. Design templates and enter cardholder details in a clear, uncluttered interface, or sync cardholders straight from your directory. Then print on the card printer you already own, or issue the same credential to Apple Wallet and Google Wallet.

A card office counter: the CardOffice cardholder screen showing an approved photo, a card printer beside it, and a smiling cardholder waiting behind the counter

In production A New Zealand tertiary card office moved a twenty-year-old card system onto CardOffice in a single day, and kept issuing throughout.

  • 12,500 cardholder records migrated
  • No inbound firewall rule
  • 0 issue-number drift at reconciliation
Read the case study
Simple by design

Easy to learn, quick to use

CardOffice is built to be easy to use and good to look at. Each screen does one job, says what it needs in plain words, and puts the next thing to do in front of you, so issuing cards takes less time and less explaining.

  • It opens on what needs doing. Photos waiting, people to chase and orders in progress, each one a click away.
  • One click sends a photo link. One key approves a photograph.
  • Design a card by dragging. Preview it at print quality before anything is printed.
  • Nothing to install for your staff. It runs in a browser, in a light or a dark theme.
  • It works on a phone or an iPad. Take the photo with the device's camera and send the card to your printer from the same screen. See it on both.
The CardOffice dashboard: a notice that 8 photos are waiting for review, four live counts, and a chart of cards produced over twelve months.

The dashboard, shown with a fictional institution.

What we do

One ID card, on plastic and on the phone

An ID card is not a printing job. It is a record of who somebody is, what they are entitled to, and whether that is still true today. CardOffice treats it that way: the card in a pocket and the pass on a phone are the same credential, carrying one serial number and one verification code. Issue either on its own, or both together, printing a card months later never creates a second identity.

Card design

Design card artwork in the browser, bind fields to cardholder data, and lock a version so every card in an order prints exactly as approved. The same design drives the plastic card and the wallet pass, so the two never drift apart.

Cardholders

One record per person, kept across every card they are ever issued, fed from your directory rather than a spreadsheet.

Card printing

Print on your own printer or one we supply, batch runs or one at the counter, with magnetic stripe and RFID encoding. Or have us print the cards at our site and ship them to you.

Digital ID

Apple Wallet and Google Wallet, certified and live. Passes update over the air and can be revoked remotely.

Integrations

SCIM provisioning, single sign-on, a REST API with webhooks, and RFID encoding into access control.

Architecture

Web-native, with a thin agent where the hardware is

There is no fat client to install and licence on every workstation. The platform runs in a browser. The only thing installed locally is a lightweight print agent on the PC beside the card printer, and it connects outbound over HTTPS, so it works through the firewall you already have, without an inbound rule or a port opened for it.

  • Printer-agnostic. Any card printer with a Windows or Linux driver. Zebra ZXP-series printers get the full experience today, ribbon tracking, cleaning reminders and built-in mag-stripe encoding, with other brands added as customers need them.
  • Two ways to issue. Batch printing for enrolment-week bulk runs, or walk-up kiosk mode for a replacement card over the counter.
  • Live operational view. A dashboard showing every print agent online or offline, per-printer status, and queue health, so a stalled run is visible before anyone rings to complain.
Simple black and white diagram of how CardOffice works: cardholders from your HR system, a directory or CSV file, or a photo taken on their phone go into the secure CardOffice browser app, which has a card designer and a photo check, then prints to your printer and encodes the card for door access, or issues a phone wallet pass
How it works

From a photograph on a phone to a finished ID card

  1. Connect your cardholders

    Entra ID and Google Workspace sync automatically over SCIM, straight into the cardholder roster. A new starter appears ready to be photographed, a name or department change flows through on the next provisioning cycle, and a leaver's card deactivates itself. No CSVs, no re-keying.

  2. Collect photographs

    Send a photo invitation by email and the cardholder submits from wherever they are, phone, laptop, tablet, or a dedicated station in the card office. Distance and off-campus students stop being a special case. Automated quality checks catch a bad photograph before it is submitted. How the photo link works.

  3. Review and approve

    Staff approve or reject in a purpose-built queue, with the reason sent back to the cardholder so they can try again without a phone call.

  4. Order and produce

    Release a batch to the print agent, or issue one card at the counter. Ribbon levels, cleaning intervals and card stock are tracked as you go. Ordering finished cards from us instead gives you packing lists, tracking and an invoice per shipment or rolled up monthly.

  5. Issue, verify, revoke

    Every card and wallet pass carries a verification code that checks against the live system, so anyone can confirm an ID is real and current in seconds. A lost or stolen card is revoked instantly, no reprint needed to shut off access.

Integrations

Connected to the systems you already run

Card issuance sits downstream of your directory and upstream of your access control. It only works if it talks to both.

SCIM provisioning

Entra ID and Google Workspace push into the cardholder roster. Employee number, department and holder type, student, staff, contractor, visitor, map from your directory's own fields rather than a fixed schema, and sensible matching means provisioning adopts existing holders instead of duplicating them.

Single sign-on

Entra ID, Google Workspace and Okta, with two-factor authentication enforced per organisation. SSO and SCIM are separate and complementary, one controls who can log into the portal, the other keeps the roster in step. Set up either, or both.

REST API and webhooks

Full coverage of card holders, cards, orders and photos, with real-time events on every status change, secured by scoped API tokens. Tested, and running in production.

RFID encoding

A configurable encoding interface rather than a fixed format. The door credential is written to the card's chip, read back to confirm it, and recorded against the cardholder. Magnetic stripe encoding is built in on supported printers.

Legacy systems

Proven against a live legacy student-records database, not just a directory. A production sync bridge keeps CardOffice in step with an existing system today, using outbound-only connections, no firewall hole, no shared database credential. The same pattern extends to other legacy systems.

Finance and shipping

Reporting and billing are built in. Usage reports show what was issued and what it cost, down to the card. Shipments carry packing lists and tracking, and are invoiced on account, per shipment or monthly.

0 installs
Nothing to deploy to a workstation; it runs in the browser
2 wallets
Apple Wallet and Google Wallet, certified and live
1 record
Per cardholder, across every card they hold
Who we work with

Built for the way institutions actually issue ID cards

A university card office, a school running photo day, a government agency issuing contractor passes and a business with thirty staff have very little in common except the card itself. Each has its own page.

Universities & polytechnics

Enrolment-driven issuance at scale, replacement cards over the counter, and a digital ID students can add the day they enrol.

Secondary schools

Photo day without the paperwork, year-level rollovers, and cards that can be reprinted without starting the whole process again.

Government

Staff, contractor and visitor credentials with audit logging, single sign-on and configurable retention.

Business

Staff ID cards without running a card office. Order printed cards with no subscription, or print your own the same day.

Common questions

Frequently asked

Do we have to replace our existing card printer?

Almost certainly not. Printing goes through a lightweight agent that drives any card printer with a Windows or Linux driver. Zebra ZXP-series printers get the deepest support today, ribbon tracking, cleaning reminders and built-in mag-stripe encoding, and other brands are added as customers need them. Tell us what you have before you budget for anything new. If you have no printer, we can supply one with the system and supplies, or print your cards at our site and ship them.

Can we host it ourselves, or does our data go offshore?

You can host it yourself. CardOffice runs on our New Zealand hosting or inside your own infrastructure, so cardholder records and photographs stay in the jurisdiction your policy requires. That is a deployment choice, not a paid tier of trust.

Can students add their ID to their phone?

Yes. The same credential is issued to Apple Wallet and Google Wallet, both certified and live, carrying the same serial number and verification code as the printed card. Passes update over the air and can be revoked remotely.

Does it keep up with our directory on its own?

Yes. Entra ID and Google Workspace provision over SCIM directly into the cardholder roster, a new starter arrives ready to be photographed, a department change flows through on the next cycle, and a leaver's card deactivates itself. Field mapping is configurable, so employee number, department and holder type come from your own directory fields.

How are photographs checked?

Cardholders submit from any device with a camera, and each image is screened automatically against ICAO 9303 portrait rules, head size and position, background, sharpness and exposure, before it reaches a staff member. Staff make the final call, and rejection reasons go back to the cardholder.

Can it work alongside our student management system?

Yes, and it already does. A production sync bridge keeps CardOffice in step with a live legacy student-records database today, over outbound-only connections that need no inbound firewall rule and no shared database credential. Beyond that there is a full REST API and a webhook system covering card holders, cards, orders and photos.

How does an ID get verified?

Every card and wallet pass carries a verification code that checks against the live system. Anyone can confirm in seconds that an ID is genuine and still current, which is the part a photocopied card cannot fake.

Talk to someone who has done this before

Tell us how you issue cards today and we will show you what the platform would look like for your institution. No obligation, and no sales script.