Linking tokens & logging on.

Use the Credential Linkers to bind Windows accounts to NFC cards, USB sticks, TOTP apps, the CodeB Authenticator and certificates, choose where token data lives and what happens when a card is removed.

CodeB Credential Provider V2 · User manual · Updated 2026-09-30

In short

Before a token can log a user on, a Credential Linker binds the user’s Windows credentials to it: LinkNFCCard for NFC cards and phones, LinkMEMStick for USB sticks, LinkTOTP for authenticator apps, LinkX509 for certificates and Link2FA/LinkNFC2AD for second factors. The encrypted result is stored on the PC, on a share or in Active Directory.

How linking works

Each Credential Linker asks for the Windows user name, the domain (or the PC name for local accounts) and the password, and reads the token (card serial, stick, certificate or authenticator). It then stores the credentials encrypted as a soft token. At the logon screen the token unlocks the soft token and the credential provider passes the credentials to Windows.

Pick the linker by what you want the user to present:

ScenarioLinker
Tap an NFC card or NFC phone to log on (passwordless, 2FA or 3FA)LinkNFCCard
Password plus card or TOTP as second factor; card + TOTP + password for 3FALink2FA
Card as second factor stored centrally in Active DirectoryLinkNFC2AD
Type a one-time code instead of the passwordLinkTOTP
Certificate in the local store or on a PKI smartcardLinkX509
Plain USB memory stick as a keyLinkMEMStick

In Edition 1 the same tools are in the tray menu. All card enrolments can also be scripted with the CodeB Admin CLI.

Where token data is stored

  • On the PC (default): in the data folder C:\ProgramData\CodeB\ (subfolders such as totp, 2FA, CodeBSerialCredentials, CodeBX509Credentials, CodeBBluetooth). Change it with the registry value DataFolder.
  • On a file share: set RemoteDataFolder to a UNC path. Simple, no AD changes; permissions live on the share.
  • In Active Directory: tick Store Data in AD in LinkNFCCard (or use CodeBAdminCLI /add2ad). The data travels with the user object, so one admin PC can enrol cards for the whole company.

Both central options behave the same at logon, and you can switch later without reissuing cards. For tokens that must work on several PCs, install every PC with the shared certificates (/cert).

Active Directory permission

Storing in AD needs one attribute permission: altSecurityIdentities on the user objects must be readable and writable by Domain Computers (that is, LocalSystem on the joined PCs), ideally also by the user for their own object. LinkNFCCard confirms a successful write and warns if the permission is missing.

Link2FA — second and third factor

Link2FA.exe associates a user’s credentials with an NFC token or a TOTP authenticator. Either can be used alone as the second factor next to the password. If both are linked, both are required: NFC token plus TOTP code plus password — three-factor authentication.

LinkTOTP — one-time code instead of the password

LinkTOTP.exe (window “Link TOTP to User”) replaces user name and password with a TOTP one-time password. Users can keep a long, complex Windows password they never type and log on with the code from their authenticator app.

  1. Enter the TOTP Key and add the same key to the user’s authenticator app. Choose TOTP Digits and TOTP Algorithm to match the app.
  2. Enter user name, optional domain and password (twice).
  3. Optional: an Optional Secret that must be typed together with the code, and Store Data in AD.
  4. Click Link TOTP.
App compatibility

Most TOTP apps support only 6 digits with SHA-1. For other code lengths or stronger hash algorithms, use the CodeB Authenticator. The PC clock must be correct — see TOTP codes rejected.

LinkNFCCard — NFC cards and NFC phones

LinkNFCCard.exe links NFC cards — and Android phones with NFC running the CodeB Authenticator — as a second or third factor, or for passwordless “tap to logon”.

  1. Start LinkNFCCard.exe (window “NFC Token”), select the Card Reader and place the card on it. The Card Serial (UID) appears.
  2. Enter Username, Optional Domain and the Password twice. Validate checks the credentials first.
  3. Enter a Logon PIN (twice) for card + PIN logon, or leave it empty for card-only logon. An empty PIN stores the default PIN (0000, see DefaultSerialPIN).
  4. Choose the Action on card removal (lock or log off) and, if you like, a Comment.
  5. Options: Store Data in AD stores the soft token in Active Directory; Link Card as 2nd Factor in AD requires the card next to the password; a configured Bluetooth device can be used as an extra factor or as the trigger for the removal action.
  6. Click Link Card.

For help designing a tap-to-logon rollout, write to info@codeb.io.

LinkNFC2AD — card as second factor in Active Directory

LinkNFC2AD.exe writes a card serial to the user’s AD object as a second factor. The command-line equivalent is CodeBAdminCLI.exe /add2fa.

LinkX509 — certificates and PKI smartcards

LinkX509.exe associates user name and password with an X.509 certificate from the local certificate store or — the best option — on a PKI smartcard. Select the certificate in the list, enter the Windows credentials (and an optional secret) and click Link Certificate.

LinkMemStick — USB memory stick as a key

LinkMEMStick.exe turns a standard USB memory stick into a logon token. Insert the stick, enter the Windows credentials and link. Plain memory sticks are ideal for evaluation; for production use NFC cards or smartcards.

Card removal: lock or log off

For card, USB-stick and Bluetooth tokens, Windows can react when the token is taken away. The action is chosen when the token is linked (CLI parameter /action) and can be enforced for everybody with the registry values LogoffAction. The stricter of the two wins.

ValueAction on removal
0Nothing (default).
1Lock the screen. In a Remote Desktop session the session is disconnected.
2Log the user off.

The CodeB service starts the tray application in the user’s session to watch the token. Actions are recorded in the Windows Application event log under the source CodeB Credential Provider V2.

Logging on

At the logon or lock screen, select the CodeB tile (for a user that is not listed, the extra “Other User” tile). Depending on the settings, the tile shows these fields:

  • Username — hidden when the tile already belongs to a known user.
  • Optional Secret or Password — the Windows password, or the optional secret of a token.
  • TOTP or PIN — the one-time code or the card PIN.
  • Display typed values — shows what was typed.

Then present the token: tap the NFC card, insert the USB stick or smartcard, or type the TOTP code. A card linked with the default PIN logs on with the tap alone. Field labels, visibility and the focused field can be changed in the registry.

If the domain controller cannot be reached (laptop offline), Windows logs on with its cached credentials as usual. CodeB notices that the domain is unreachable and skips its AD lookups, so the offline logon is not delayed.

Keywords in the password or PIN field

Typing one of these words into Optional Secret or Password or TOTP or PIN on the logon tile opens a helper directly from the logon screen:

TypeOpens
nfcThe NFC card linking dialog.
2faLink2FA (path from 2FAPath).
changepwdThe change-password dialog.
timeA dialog to check and set the date and time (useful when TOTP codes fail because of a wrong clock).
Hardening

In locked-down environments disable the keywords with DoNotAllowMagicWords = 1.

When a Windows password changes

A soft token holds the password that was valid when the token was linked. After a password change, token logon fails until the token is updated:

  • Link the token again with the same linker, or
  • for tokens in Active Directory, change the password with CodeBAdminCLI.exe /changepw, which sets the new AD password and updates the stored soft token in the same call (example).

Frequently asked questions

Stuck on a step?

A real engineer reads every support email. Send the log files from the troubleshooting chapter and we usually answer within one business day.