HITAG 2 key fob
ABS key fob for access-control readers.
HITAG 2 epoxy tag
Epoxy-domed key tag with a metal eyelet and a printable face.
HITAG 2 transponder module
HITAG 2 transponder modules (NXP SOT385-1 package shown).
RFID Cards
A HITAG 2 (HITAG2) card is a 125 kHz RFID card built on NXP’s HITAG 2 transponder IC, the chip family behind the PCF7936 car-key immobiliser transponder. It stores 256 bits in eight 32-bit pages, including a 32-bit read-only serial number and 128 bits of user memory, and runs in password mode, crypto mode (48-bit key) or a read-only public mode A, B or C.
Choose it to match HITAG 2 readers you already run: practical attacks on its cipher were published in 2012, so a new secure system should use an AES card instead. Send the reader type or a working card and we confirm the mode on a sample before production.
Free standard samples · Quotation within one business day
| Item | HITAG 2 card |
| Chip | HITAG 2 transponder IC (NXP HT2x family); exact part confirmed per order |
| Frequency | 125 kHz (low frequency), half-duplex |
| Memory | 256-bit EEPROM in 8 pages of 32 bits |
| Serial number | 32 bits, read-only, programmed at chip manufacture |
| User memory | 128 bits (pages 4–7) |
| Modes | Password mode, crypto mode (48-bit key) and read-only public modes A, B and C |
| Anti-collision | None; a HALT function allows multi-tag operation in read/write mode |
| Chip data retention | 10 years |
| Chip write endurance | 100,000 erase/write cycles |
| Card material | PVC, PET, PETG, ABS |
| Size | CR80 / ISO ID-1 (85.6 × 54 mm) or custom |
| Colour | Custom |
| Reading distance | 2–10 cm, depending on the reader and antenna |
| Working temperature | -40 °C to 65 °C |
| Printing options | Silk-screen, CMYK full colour, Pantone, digital printing, etc. |
| Crafts available | Number printing, laser engraving, DOD, barcode, QR code, magnetic stripe, encoding, etc. |
Chip figures come from NXP’s HITAG 2 data sheet. Card material, size, printing and read distance are confirmed for your order, and checked on a sample with your reader.
HITAG 2 is a 125 kHz transponder IC from NXP (originally Philips), introduced in 1996. A HITAG 2 card is an ISO ID-1 card, key fob, epoxy tag or glass tube with that chip and a coil inside. It has no battery: the reader’s field powers the chip, and the two exchange data in half-duplex, the reader modulating its field to send commands and the chip answering by modulating that field in turn. NXP supplies the IC as sawn wafer and in two plastic module packages (HT2MOA4S20 and HT2DC20S20); the PCF7936 is its HITAG 2 security transponder for vehicle immobilisers.
NXP now lists the HITAG 2 transponder IC as not recommended for new designs, as it does HITAG 1 and HITAG S. HITAG 2 cards are still ordered because systems built around HITAG readers need replacement cards that speak the same protocol and mode.
The 256-bit EEPROM is divided into 8 pages of 32 bits: 128 bits of control data and secrets in pages 0–3, and 128 bits of user data in pages 4–7. What pages 1 and 2 hold depends on the mode (NXP HT2x data sheet).
| Page | Crypto mode | Password mode |
| 0 | 32-bit serial number (read-only) | 32-bit serial number (read-only) |
| 1 | Secret key, low 32 bits | Reader password, 32 bits |
| 2 | Secret key, high 16 bits (rest reserved) | Reserved |
| 3 | Configuration byte (8 bits) + tag password (24 bits) | Configuration byte (8 bits) + tag password (24 bits) |
| 4–7 | User data, 4 × 32 = 128 bits | User data, 4 × 32 = 128 bits |
The configuration byte selects the mode and the access rights. Memory flags can make pages read-only or block reading altogether, so a card can be locked after personalisation and its key pages kept unreadable.
| Mode | How it works | Typical use |
| Password mode | Reader and card authenticate each other by exchanging passwords: the 32-bit reader password (page 1) and the 24-bit tag password (page 3). Data then travels unencrypted. | Legacy access control and industrial identification |
| Crypto mode | Mutual authentication with a 48-bit shared secret key; commands and data are then encrypted with the proprietary HITAG 2 stream cipher. | Vehicle immobilisers and HITAG systems built for crypto mode |
| Public mode A | Read-only broadcast that emulates MIRO and EM H400x-type read-only transponders, so a reader for that EM format can normally read the card. | Installations with EM-format 125 kHz readers |
| Public mode B | Read-only broadcast in the ISO 11784/11785 animal-identification format. | Animal identification |
| Public mode C | Read-only broadcast compatible with PIT transponders (PCF793x). | Older PIT-based systems |
In a public mode the chip simply broadcasts the contents of its user pages as soon as it is powered, with no password and no encryption, so any compatible reader can read it. Data from the chip are Manchester or biphase coded, data to the chip use pulse-duration coding, and the link uses amplitude-shift keying. The mode is set in the configuration byte at encoding time to match your reader, which is why we need the reader type or a working card before production.
Not by current standards. HITAG 2 uses a proprietary stream cipher with a 48-bit key. Its design was reverse-engineered in 2007, and in 2012 Roel Verdult, Flavio Garcia and Josep Balasch published three practical attacks that recover the secret key using only radio communication (“Gone in 360 Seconds: Hijacking with Hitag2”, USENIX Security 2012). The most serious needs a valid transponder ID and 136 partial authentication attempts, collected in about a minute from the reader (in the paper, the car) by an emulated card, and then less than five minutes on an ordinary laptop. The same paper found that the transponder has no random-number generator, which leaves its authentication open to replay; that password mode exchanges passwords in the clear; and that the tag password has only 24 bits of entropy.
In practice, a card in public mode can be read by anyone with a compatible reader and duplicated; in password mode the passwords can be captured and replayed; and in crypto mode the key can be recovered with the published attacks. Use HITAG 2 to stay compatible with readers you already run, or for low-risk identification such as asset, tool or gas-cylinder ID where the site accepts that cloning risk. Do not use it as the security layer of a new system.
For a new access-control system, or whenever the readers are being replaced anyway, choose a 13.56 MHz card with AES-based authentication such as MIFARE DESFire; our guide to RFID key fobs for access control compares 125 kHz and DESFire credentials. For immobilisers, the same paper notes that NXP’s HITAG AES / HITAG Pro transponders use AES.
NXP’s public short data sheet gives no read range for HITAG 2, only that the reading and writing distances are the same, so a card can be encoded at the distance at which it is read. Range is set by the reader’s antenna and power and by the size of the coil in the card or tag. On typical desk and wall readers an ID-1 card reads at about 2–10 cm; long-range 125 kHz readers with large antennas, and thicker clamshell cards with a bigger coil, read further. Test a sample on your own reader before writing a distance into a specification.
Car immobilisers are HITAG 2’s best-known use. When Verdult and colleagues studied it in 2012 it was the most widely used immobiliser transponder, fitted by at least 34 car makes in more than 200 models: a transponder in the key head authenticates in crypto mode to a reader coil around the ignition, and the engine starts only after a correct response. That installed base is why HITAG readers are common and why the protocol still turns up in vehicle and fleet systems. We supply cards, fobs and tags; for the automotive transponder see our car transponder chip page, and for gate and fleet set-ups the vehicle RFID identification guide.
In access control, HITAG 2 cards and fobs serve sites whose readers were installed for HITAG, working in password or crypto mode, or read in public mode A by EM-format readers. A replacement credential has to match the reader’s chip family, mode and data layout, which is why we ask for a working card.
NXP lists logistics, livestock tracking, asset tracking, gas cylinder ID, casino and gaming, and industrial automation among HITAG 2 applications. For tags fixed to metal or embedded in plastic, such as gas cylinders, tools, moulds and returnable containers, tell us the reader, the mode and the mounting surface, and we confirm the construction and test a sample before production.
A HITAG 2 card works only with a reader whose firmware supports HITAG 2 in the mode the card is set to; NXP’s own reader IC for the HITAG family is the HTRC110. Mode matters as much as chip: a reader that expects a public-mode broadcast gets nothing from a card in password or crypto mode, because the card then answers only HITAG 2 commands, and a password-mode reader cannot authenticate a card personalised with a crypto key.
Readers are rarely interchangeable across chip families. A HITAG 2 reader does not read HITAG 1 or HITAG S unless it supports several HITAG modes, and an EM4100-type reader can read a HITAG 2 card only in public mode A, which emulates EM H400x-type tags; confirm that on a sample with your reader. If your readers are EM-format readers, an EM4200 card, EM4305 card or T5577 card is the simpler order.
| HITAG 1 | HITAG 2 | HITAG S | |
| Memory | 2048 bits (64 pages × 4 bytes) | 256 bits (8 pages × 4 bytes; 128-bit user data) | 256 or 2048 bits (HITAG S256 / S2048) |
| Anti-collision | Yes (AC mode, mainly for long-range operation) | No (HALT function for multi-tag operation) | Yes (fast: 100 tags in 3.2 s) |
| Security | Mutual authentication, encrypted transmission | Password mode, or crypto mode with a 48-bit key | 48-bit secret-key encrypted authentication |
| Frequency / standards | 125 kHz | 125 kHz; public modes A/B/C incl. ISO 11784/11785 | 100–150 kHz; ISO 11784/11785, ISO 14223, ISO 18000-2 |
| Applications named by NXP | Logistics, asset tracking, gas cylinder ID, industrial automation | Logistics, livestock, asset tracking, gas cylinder ID, casino, industrial automation | Animal ID, laundry, beer kegs and gas cylinders, brand protection |
| NXP status | Not recommended for new designs | Not recommended for new designs | Not recommended for new designs |
The families are not interchangeable at the reader. HITAG µ is a further NXP family, aimed at ISO 11784/11785 and ISO 14223 animal identification, and is not read by a HITAG 2-only reader either. Figures are from NXP’s HITAG 1, HITAG 2 and HITAG S product pages.
ABS key fob for access-control readers.
Epoxy-domed key tag with a metal eyelet and a printable face.
HITAG 2 transponder modules (NXP SOT385-1 package shown).
We produce the cards, fobs and tags in our Shenzhen factory, configured to the system owner’s specification; numbered cards are delivered with an Excel, CSV or XML file listing each card’s 32-bit serial number beside the number printed on it. We do not supply access-control readers or software and do not duplicate credentials from systems the buyer does not administer. Related pages: 125 kHz RFID cards, vehicle RFID identification and RFID key fobs for access control.
Sources: NXP HITAG 2 transponder IC data sheet (HT2x, Rev. 3.1) and product pages for HITAG 2, HITAG 1 and HITAG S; R. Verdult, F. D. Garcia and J. Balasch, “Gone in 360 Seconds: Hijacking with Hitag2”, USENIX Security 2012. Chip documentation describes IC capabilities; it does not establish stock or a finished card’s compatibility with your system.
A 125 kHz RFID card, fob or tag built on NXP’s HITAG 2 transponder IC. The chip has 256 bits of memory in 8 pages, including a 32-bit read-only serial number and 128 bits of user data, and works in password mode, crypto mode or a read-only public mode. Today it is best used to match HITAG readers already installed in access, vehicle and industrial systems.
One of three read-only modes set in the configuration byte. In public mode A the card broadcasts its user data as soon as it is powered, emulating MIRO and EM H400x-type read-only transponders, so a reader for that EM format can normally read it without a password. Public mode B uses the ISO 11784/11785 animal-ID format, and public mode C is compatible with PIT (PCF793x) transponders.
Both are read/write modes that require authentication first. In password mode the reader and card exchange passwords, the 32-bit reader password and the card’s 24-bit tag password, and data then travels unencrypted. In crypto mode they authenticate each other with a 48-bit secret key, and the session is encrypted with the HITAG 2 stream cipher. The mode is set in the configuration page at encoding time.
Not for a new security-critical system. Its proprietary 48-bit cipher has been broken in published research: Verdult, Garcia and Balasch (USENIX Security 2012) recovered the secret key in minutes using only radio communication, and showed that its authentication can be replayed. NXP lists the chip as not recommended for new designs. Use HITAG 2 to stay compatible with installed HITAG readers; for a new system choose an AES card such as MIFARE DESFire.
Memory, anti-collision and security. HITAG 2 has 256 bits, password and crypto modes and no anti-collision, although a HALT function allows multi-tag operation. HITAG 1 has 2048 bits and HITAG S 256 or 2048 bits, both with anti-collision so several tags can be read in one field. A reader configured for one family does not normally read the others.
Readers whose firmware supports HITAG 2 in the mode your cards use; NXP’s reader IC for the HITAG family is the HTRC110. An EM4100-type reader reads a HITAG 2 card only in public mode A, which emulates EM H400x-type read-only tags, and even then confirm it on a sample with your reader. In password or crypto mode the card does not broadcast; it answers only HITAG 2 commands, which an EM-only reader does not send. If all your readers are EM-format, an EM4200, EM4305 or T5577 card is usually the simpler choice. We supply the cards, fobs and tags, not the readers.
It depends on the reader and antenna far more than on the chip, and NXP’s public short data sheet gives no figure. On typical access readers an ID-1 card reads at about 2–10 cm; long-range 125 kHz readers with larger antennas, and clamshell cards with a bigger coil, read further. Test a sample on your reader.
Yes, for the organisation that administers the system. Send the reader type or a working sample and the data to be written, and we configure the mode, then write and lock the pages. Each encoded card is read back to confirm the write, and a data report goes out with the order; see the RFID encoding service.
Send the product, quantity and application so we can confirm the options and pricing for your project.