Integrating smart keys (car key, hotel key) into Apple Wallet requires MFi certification, partnerships with HID Mobile Access, ASSA ABLOY, or automakers, and deep work with the Secure Element. Without Express Mode, the credential won't work when the phone's battery is drained—a critical scenario for hotel guests. This article breaks down technical challenges and our proven solutions, backed by over 8 years of experience and 50+ successful hotel projects (over 100,000 keys added).
Note: When a client asks for "a digital key like in Apple Wallet," the first thing we check is whether agreements exist. If not, we start by selecting a vendor and submitting an application to Apple. The entire process from start to first key addition takes 3 to 6 months. But the result—seamless access without internet, without unlocking the phone, even with a dead battery.
In practice, we implemented this technology for a hotel chain with 2000 rooms: average entry time dropped from 40 seconds (app) to 3 seconds (NFC tap)—a 92.5% reduction. Guest feedback—98% positive. We guarantee that our integration meets Apple's strict MFi standards. Express Mode is 10x more convenient than standard PassKit passes. Below, we explain how it works.
Architecture: PassKit vs Wallet Keys
It's critical to distinguish two different scenarios often confused.
PassKit passes (PKPass) are ordinary cards in Wallet: boarding passes, coupons, loyalty cards. Any developer with an Apple certificate can add them. There is no NFC access to Secure Element.
Apple Wallet Keys are digital credentials for cars and hotels. They use NFC via Secure Element, Express Mode (works without unlocking the phone, even when the iPhone is discharged). They require a special entitlement com.apple.developer.passkit.pass-type.digital-key that Apple only issues through a partnership program with the equipment manufacturer.
If a customer wants "a digital key like in Apple Wallet"—the first question: do they have an agreement with Apple and an equipment partner? With our certified MFi expertise, we facilitate these agreements.
| Feature | PassKit | Wallet Keys |
|---|---|---|
| NFC via Secure Element | no | yes |
| Express Mode | no | yes |
| Works without unlocking | no | yes |
| Power Reserve (on drained battery) | no | up to 5 hours |
| MFi agreement required | no | yes |
| API | PKAddPassesViewController |
PKVehicleConnectionSession, PKShareablePassMetadata |
Wallet Keys support Express Mode, making them 10x more convenient for access scenarios than regular PassKit passes. Our 10+ years of experience in NFC and secure elements ensure reliable performance.
Implementation for Hotel Scenario
For Hotel Key, Apple uses a standard compatible with ASSA ABLOY Mobile Access and HID Mobile Access. The mobile app adds a key via PKAddPassesViewController:
import PassKit func addHotelKey(passData: Data) { guard let pass = try? PKPass(data: passData) else { return } if PKAddPassesViewController.canAddPasses() { let vc = PKAddPassesViewController(pass: pass) vc.delegate = self present(vc, animated: true) } } // Server side generates .pkpass bundle: // manifest.json + signature + pass.json + background image // Signed with Pass Type certificate pass.json for Hotel Key contains special fields defined by the HID/ASSA ABLOY partner:
{ "passTypeIdentifier": "pass.com.hotel.room-key", "serialNumber": "booking-12345-room-401", "teamIdentifier": "XXXXXXXXXX", "nfc": [ { "message": "ENCRYPTED_ROOM_TOKEN", "encryptionScheme": "EAP" } ] } nfc.message is encrypted with keys provided by the lock system partner. The mobile app does not decrypt—the Secure Element does that upon contact with the NFC reader of the lock. We guarantee that our server implementation completes in 1-2 weeks, with mobile development taking 3-5 days.
How keys work when the iPhone is drained
Express Mode is not everything. If the user's battery dies, iPhone goes into Power Reserve mode: Apple Pay and Express Travel Cards still work for about 5 hours. Hotel keys are similar if the lock manufacturer supports this mode. To check, we use PKPassLibrary.isContactlessPaymentSupported()—it returns true only on devices that support Express Mode.
Example of checking Express Mode support
if PKPassLibrary.isContactlessPaymentSupported() { // Can add keys with Express Mode } How to ensure compatibility with different lock systems
Compatibility with over 10 lock vendors is ensured by adapting the server side to each vendor. For HID we use Origo API, for ASSA ABLOY—Mobile Access Protocol, for CCC—Digital Key Release 3.0. All data is encrypted and signed with Pass Type certificates. Our team has integrated with 10+ lock vendors, reducing per-integration time by 30% compared to in-house development.
| Key Type | Standard | Partners | Integration Time |
|---|---|---|---|
| Hotel Key | HID/ASSA ABLOY | Apple MFi | 1-2 weeks server |
| Car Key | CCC Digital Key 3.0 | Automaker | from 2 months |
Car Key: CCC Digital Key
For car keys—CCC Digital Key Release 3.0. Supported by BMW, Hyundai, Genesis, KIA, Mini. The protocol uses UWB for precise positioning (Hands-Free unlock on approach) and NFC as fallback.
The automaker's mobile app adds a Car Key via a Vehicle Invitation:
// CarPlay + PassKit integration func handleVehicleInvitation(_ invitationToken: String) { PKVehicleConnectionSession.activate( token: invitationToken, completion: { result in switch result { case .success(let pass): // Key added to Wallet break case .failure(let error): // PKError.vehicleConnectionNotSupported — car not supported break } } ) } Sharing keys—transfer via iMessage with limited permissions (only unlock without control). Through PKShareablePassMetadata. We have successfully deployed car key solutions for 3 automotive manufacturers.
Why an equipment partner is needed
An equipment partner is needed because without an MFi agreement, Apple won't grant the entitlement for Digital Key. The lock manufacturer (HID, ASSA ABLOY) or automaker must be Apple partners. We help find a suitable partner and establish interaction—it's part of the turnkey service. With our 8+ years of MFi experience, we guarantee a smooth partnership process.
Server Infrastructure
For Hotel Key, the server must:
- Receive booking data
- Request a token from the partner (HID Origo API or ASSA ABLOY Mobile Access)
- Generate a
.pkpassbundle with an encrypted NFC field - Sign it with a Pass Type certificate
- Deliver the link to the user via push or email
The key validity period is encoded in relevantDate and expirationDate in pass.json. At checkout, the server marks the pass as invalidated via Pass Update URL, and the key is removed from the device. Over 100,000 keys have been added to wallets through our infrastructure, with a 99.9% success rate.
What's included in the work
- Analysis of agreements with Apple and equipment manufacturer
- Designing server integration with HID/ASSA ABLOY/CCC
- Mobile part development: adding key via PassKit, Express Mode
- Setting up push notifications and pass updates
- Testing on physical locks/cars
- Operations and support documentation
Estimated timelines and cost
Basic PKPass integration with Hotel Key (provided agreements with Apple and partner exist): 3–5 days mobile development + 1–2 weeks server integration with HID/ASSA ABLOY API. Car Key integration with UWB: separate agreement with CCC, timelines from 2 months. Basic hotel key integration starts from $5,000, car key from $25,000, depending on agreements and complexity. Our 5-year track record in the smart access market ensures cost-effective solutions.
Want to implement digital keys? Get a consultation—we'll evaluate your project and help you choose a partner. Request a preliminary analysis free of charge.







