What is Public Key Open Credential (PKOC)?
The Public Key Open Credential (PKOC) specification represents a major evolution in physical and mobile access credentials, providing a secure, interoperable, open-standard alternative to traditional proprietary credential formats.
Open, secure, and free from proprietary limits
Delivering the highest security levels
Unlike many legacy access credentials that rely on symmetric encryption and vendor-specific implementations, PKOC is based on asymmetric cryptography. Each credential contains a unique public-private key pair, with the private key securely stored within the device’s secure hardware element and never shared. This architecture significantly improves security and helps prevent credential cloning or unauthorized duplication.
Designed for open interoperability
PKOC is license-free and vendor-agnostic, designed to be open and accessible by multiple platforms, readers, cards, and mobile devices. This interoperability simplifies integration and reduces costly vendor lock-in while enabling organizations to deploy credentials across multiple hardware and software platforms.
Enabling flexible deployments
By supporting both NFC and Bluetooth Low Energy (BLE) mobile credentials and physical cards, PKOC enables flexible deployment models that meet modern enterprise requirements. Integrators and end users benefit from greater choice, lower long-term costs, and a credential framework aligned with modern IT security principles.
Deploy PKOC at scale
Building on its open and license-free foundation, PKOC provides a deployable, enterprise-ready framework for secure credential issuance and management at scale, enabling interoperable credential enrollment while preserving flexibility across vendors and technologies.
Sentry Interactive and Public Key Open Credential (PKOC)
Find out how our mobile credentials deliver to PKOC specifications, pioneering the future of open standard credentials.
Find out about the benefits of mass enrollment capabilities of Public Key Open Credentials (PKOC) for enterprises.
Learn more in an article exploring how the Sentry Interactive SDK is enabling mass enrollment of PKOC credentials for enterprises.
Enroll your users with PKOC credentials today
By integrating our SDK, you will have the ability to enroll users at scale with mobile credentials that follow PKOC specification. Embrace the future of open standard credentials today.
Connect with a member of our team within 24 hours.
Get a system audit for integration.
Deploy and activate mobile credentials within days.
Frequently asked questions
PKOC (Public Key Open Credential) is an open-standard specification for physical and mobile access credentials. It uses asymmetric cryptography — a unique public-private key pair per credential — to provide a secure, interoperable alternative to traditional proprietary credential formats. The private key is stored in the device’s secure hardware element and is never shared.
Unlike legacy credentials that rely on symmetric encryption and vendor-specific implementations, PKOC uses asymmetric cryptography. Each credential has its own unique key pair, with the private key never leaving the device’s secure hardware element. This architecture significantly reduces the risk of credential cloning or unauthorised duplication.
Yes. PKOC is designed to be vendor-agnostic and license-free, meaning it works across multiple platforms, readers, cards, and mobile devices. It supports both NFC and Bluetooth Low Energy (BLE), enabling flexible deployment alongside existing infrastructure without costly hardware replacement.
No — avoiding vendor lock-in is one of PKOC’s core advantages. Because it is and license-free organizations can deploy credentials across different hardware and software platforms, giving them freedom of choice over readers, credential providers, and mobile applications.
Yes. PKOC supports enterprise mass enrollment, allowing organizations to issue and manage PKOC credentials at scale. Sentry Interactive’s SDK enables bulk remote enrollment of PKOC-compliant mobile credentials, turning what was traditionally a manual process into a streamlined, large-scale rollout.