Installation & licensing.

Install the CodeB Credential Provider with the tray application or CredentialProviderInstaller, license it, share encryption certificates between PCs and deploy it silently.

CodeB Credential Provider V2 · User manual · Updated 2026-09-30

In short

Run CredentialProviderInstaller.exe /install as administrator to register the CodeB credential provider, add /license KEY to license it and /cert when several PCs must share soft tokens. /upgrade, /checkupgrade and /remove keep it current or take it off again. Edition 1 users simply start codeb_tray.exe as administrator once.

Requirements

  • Windows 8, 8.1, 10 or 11, or Windows Server up to 2025.
  • .NET Framework 4.7.2 or later (already part of current Windows versions).
  • Administrator rights to install, upgrade or remove.
  • For NFC and smartcards: a PC/SC card reader with its driver and the Windows Smart Card service.
  • For storing tokens in Active Directory: read/write permission on the user attribute altSecurityIdentities (see Where token data is stored).

Edition 1: install with the tray application

  1. Extract codeb_tray.zip.
  2. Right-click codeb_tray.exe and choose Run as administrator. The first elevated start installs the credential provider DLL and copies the tray application to C:\Program Files\CodeB\codeb_tray.exe, from where it is started for every user.
  3. Use the tray menu for licensing, linking tokens and settings. Later starts do not need administrator rights.

Edition 2: CredentialProviderInstaller

CredentialProviderInstaller.exe installs, upgrades and removes the Credential Provider components. Started without switches it shows three buttons:

  • Install Credential Provider — installs (or reinstalls) and registers the libraries.
  • Remove Credential Provider — deregisters and removes them.
  • Test Credential Provider — opens a Windows credential prompt so you can try the CodeB tile without signing out. Any credentials can be typed for the test.

Installer command-line switches

Every switch works with / or - (for example /install or -install) and is not case-sensitive. With /install, /remove, /upgrade, /checkupgrade, /test or /silentlicense the installer does its job without showing its window and then exits. /license or /cert on their own do their job and then show the window.

SwitchAliasesWhat it does
/install/registerInstalls or reinstalls the Credential Provider libraries and registers them.
/remove/uninstall, /unregisterDeregisters and removes the libraries.
/upgrade/updateUpgrades all installed Credential Provider libraries.
/checkupgrade/checkupdateChecks whether an update is needed by comparing the installed build (registry value CompileTime) with its own build. If they differ it upgrades; otherwise it exits silently.
/license KEY—Installs the given licence key. Replace KEY with your licence string.
/silentlicense KEY—Installs the licence key and exits immediately, without doing anything else.
/cert—Installs the shared CodeB encryption certificates, for soft tokens used on several machines. See below.
/test-simulateOpens the test credential prompt (same as the Test button).

Switches can be combined. The installer handles them in this order: licence, certificates, upgrade check or upgrade, then one of install, remove or test (install wins if both install and remove are given).

:: install, license and prepare for shared tokens in one call
CredentialProviderInstaller.exe /install /license YOUR-LICENCE-KEY /cert

Shared encryption certificates (/cert)

Soft tokens are encrypted with certificates in the local machine certificate store. By default each PC uses its own certificates, so a token created on PC A cannot be opened on PC B.

When users should log on at several PCs with the same token — token data on a file share or in Active Directory — install with /cert on every PC. It installs the common certificates CodeB_Encryption and CodeB_TOTP into the machine store, but only if the machine does not already have both.

Consistency matters

Shared tokens only work if all PCs use the same certificates. Install every PC of a group with /cert before the first tokens are linked. Tokens linked with a PC’s own certificates must be linked again after switching.

Licensing

Enter the licence key with SmartLoginLicensing.exe, from the tray application (Edition 1), or with /license / /silentlicense of the installer. Every feature is enabled on every licence. Licences are counted by the higher of users or machines; prices are on the pricing page.

The CodeB Admin CLI refuses to work without a valid licence.

Silent deployment to many PCs

Any tool that can run a command as administrator can deploy the provider — Group Policy startup scripts, SCCM/Intune, PDQ, Ansible, PowerShell remoting. An MSI package is available on request.

:: first installation (run once per PC, as administrator)
"\\server\share\CodeB\CredentialProviderInstaller.exe" /install /license YOUR-LICENCE-KEY /cert

:: afterwards, e.g. in a computer startup script: upgrades only when the build differs
"\\server\share\CodeB\CredentialProviderInstaller.exe" /checkupgrade

Settings are ordinary registry values (see Registry settings), so Group Policy Preferences, .reg files or scripts deploy them.

Upgrading

Run CredentialProviderInstaller.exe /upgrade with the new installer, or /checkupgrade to upgrade only when the build differs. Linked tokens and settings stay in place. A restart may be needed if the old version was still loaded.

Removing the credential provider

Click Remove Credential Provider or run CredentialProviderInstaller.exe /remove as administrator. Before you remove it from a PC where the CodeB filter hides the Microsoft password tile, make sure a user can still log on with a password.

Frequently asked questions

Do I have to restart Windows after installing?

Usually not, because the logon screen loads the provider the next time it starts. A restart may be needed if an older version was still loaded, for example after an upgrade.

How do I install on many PCs without clicking?

Run CredentialProviderInstaller.exe /install /license YOUR-KEY from Group Policy, SCCM/Intune, PDQ or any tool that runs a command as administrator. Add /cert if the PCs must share soft tokens. Settings are plain registry values, so the same tools can deploy them.

How do I keep all PCs on the latest version?

Run CredentialProviderInstaller.exe /checkupgrade from a startup script. It compares the installed build with its own build and upgrades only when they differ; otherwise it exits silently.

Stuck on a step?

A real engineer reads every support email. Send the log files from the troubleshooting chapter and we usually answer within one business day.