CodeB Admin CLI reference.

Every command and parameter of CodeBAdminCLI.exe: enrol NFC cards in Active Directory, create soft tokens, list and remove cards, rotate passwords — with examples and a bulk-enrolment script.

CodeB Credential Provider V2 · User manual · Updated 2026-09-30

In short

CodeBAdminCLI.exe is the command-line tool for administrators. It links card serials to users as a second factor in Active Directory (/add2fa), stores encrypted credential tokens in AD (/add2ad) or as files (/add2fs), lists and removes assignments, and changes a user’s AD password while updating the stored token (/changepw). It needs a valid licence.

Overview

The CLI automates what the GUI linkers do, so one admin workstation can enrol cards for the whole company from a script. It works against Active Directory and local accounts. Download: CodeBAdminCLI.zip (also on the downloads page).

Run CodeBAdminCLI.exe /help (or /h, /?) for the built-in help.

Syntax

CodeBAdminCLI.exe /command [/parameter value] …
  • Switches start with /, - or --.
  • A value can follow after a space, a colon or an equals sign: /pin 1234, /pin:1234 and /pin=1234 are the same.
  • Several commands can be given in one call; they run in this order: /clearad, /add2fa, /changepw, /add2ad, /add2fs, /deletecard, /list2fa, /list2facards, /list2adcards.

Commands

CommandWhat it doesNeeds
/add2fa
alias /2fa
Adds a card serial as a second factor to the user in AD. Command-line equivalent of LinkNFC2AD.exe./user, /cardserial
/add2ad
alias /2ad
Adds (or updates) the encrypted credential token in AD, as LinkNFCCard.exe does with “Store Data in AD”. Run it again with another serial to add another card./user, /password, /cardserial
/add2fs
alias /softtoken
Creates the encrypted soft token as a file (<SERIAL>.b64) in the data folder, as LinkNFCCard.exe does without AD./user, /password, /cardserial
/list2facardsLists all card serials assigned as a second factor to a user./user
/list2adcardsLists all card serials that can log the user on (tokens stored in AD)./user
/list2faReverse lookup: which user a card serial is assigned to./cardserial
/deletecardCleanup: removes the card from the 2FA records and from the credential tokens (in AD and in the data folder)./cardserial; /user for the AD part
/changepwChanges the AD password of the user and updates the soft token stored in AD, so card logon keeps working./user, /password (current), /newpassword
/clearad
alias /cad
Removes all CodeB card links and token data from the user’s AD object./user

Parameters

ParameterMeaningDefault / notes
/user
-u
The user (sAMAccountName) being managed.May also be given as DOMAIN\user; the domain part then replaces /domain.
/domain
-d
The logon domain of the user.—
/cardserial
/serial, /s
The UID of the NFC card (hex).—
/password
/pass, -p
The user’s password; for /changepw the current password.Required for /add2ad, /add2fs, /changepw.
/newpassword
/newpass, /npwd
The new password for /changepw.—
/pinThe PIN for logon with this card.When omitted: the configured default PIN (DefaultSerialPIN, normally 0000 = card-only logon).
/action
-a
What happens when the card is removed: 1 lock screen, 2 log off.0 = nothing; any other value counts as 0.
/datafolderWhere /add2fs writes the token file.Must be a path containing \. Default: the DataFolder registry value, else C:\ProgramData\CodeB\.
/noteA comment stored with the soft token.—

Examples

:: 1. link a card to a user as second factor in AD
CodeBAdminCLI.exe /add2fa /user stefan /domain CodeB /serial AAFFBBCC

:: 2. store the encrypted credential token in AD (card + PIN 1234)
CodeBAdminCLI.exe /add2ad /user stefan /domain CodeB /password letmein /serial AAFFBBCC /pin:1234
:: ... and a second card for the same user
CodeBAdminCLI.exe /add2ad /user stefan /domain CodeB /password letmein /serial CCDDEEFF /pin:0155

:: 3. create a soft token file on a share, lock the screen on card removal
CodeBAdminCLI.exe /add2fs /user CodeB\stefan /password letmein /serial AAFFBBCC /action 1 /datafolder \\server\codeb\

:: 4. list all second-factor cards of a user
CodeBAdminCLI.exe /list2facards /user stefan /domain CodeB

:: 5. which user owns this card?
CodeBAdminCLI.exe /list2fa /serial AAFFBBFF

:: 6. remove a card everywhere (lost card)
CodeBAdminCLI.exe /deletecard /cardserial AAFFBBFF /user stefan

Password rotation without breaking card logon

/changepw sets the new AD password and updates the encrypted soft token stored for the user in AD in the same call. Card logon keeps working — no re-enrolment and no window in which the stored password is outdated.

CodeBAdminCLI.exe /changepw /user testuser /domain codeb /password oldalibaba /newpassword newalibaba

Bulk enrolment from a CSV file

Example PowerShell loop over a CSV with the columns User,Domain,Serial,Pin. It links each card as a second factor and reports failures by exit code. Adapt it to /add2ad if the token itself should be stored in AD (then a password column is needed).

# cards.csv:  User,Domain,Serial,Pin
$cli = "C:\Tools\CodeB\CodeBAdminCLI.exe"
Import-Csv .\cards.csv | ForEach-Object {
    & $cli /add2fa /user $_.User /domain $_.Domain /serial $_.Serial
    if ($LASTEXITCODE -ne 0) { Write-Warning "$($_.User): exit code $LASTEXITCODE" }
}

Exit codes

CodeMeaning
0Finished (also after /help). Read the console output for the result of each command.
1Invalid command line (unknown switch or missing value).
1002The PC is in a domain but no domain controller answered: the Active Directory steps were not done (the tool says so). Run the command again with a connection to the domain.
9999Not licensed. The tool prints “Software is not licensed. Contact info@aloaha.com” and does nothing.
otherA command failed; the console output names the command.

Security notes

  • Passwords given on the command line can end up in shell history, script files and process lists. Run the CLI on a protected admin workstation, read passwords from a secure source in your script and delete temporary CSV files afterwards.
  • With AD storage, only the altSecurityIdentities permission is needed (see storage); no local administrator rights are required on the target PCs.
  • A card linked with the default PIN (0000 unless DefaultSerialPIN says otherwise) logs on with the tap alone. Use /pin when you want card + PIN.

Frequently asked questions

Does CodeBAdminCLI need local administrator rights?

Not for Active Directory operations when the AD permission on altSecurityIdentities is delegated correctly. Writing soft tokens into a protected local data folder needs rights on that folder.

Can I enrol hundreds of cards from a CSV file?

Yes. Loop over the CSV in PowerShell and call CodeBAdminCLI.exe /add2ad or /add2fa per row — see the bulk example. Check the exit code of each call.

Is the card serial the same as the number printed on the card?

Not necessarily. The CLI expects the card UID in hexadecimal as the reader reports it, for example 042C69DA562280. LinkNFCCard.exe shows the UID when the card is placed on the reader.

Stuck on a step?

A real engineer reads every support email. Send the log files from the troubleshooting chapter and we usually answer within one business day.