Key takeaways
- EM4100 and compatible chips such as TK4100 transmit a fixed 40-bit ID in a 64-bit frame; nothing on the card can be written or changed.
- T5577 is a rewritable 125 kHz chip with configurable modulation and data rate, so it can be programmed to read like an EM4100 card or a prox-style card.
- EM4305 is a 512-bit read/write chip with a fixed 32-bit UID and a 32-bit password, and the usual choice for ISO 11784/11785 FDX-B animal ID.
- None of the three performs cryptographic authentication, so any of them can be copied; clone resistance needs 13.56 MHz cards such as DESFire EV2/EV3 with AES-128.
- An RFQ should state the chip, the data format, the number range, the printed number format (10-digit or 'xxx,xxxxx') and whether rewritable chips must be locked.
EM4100 is a read-only 125 kHz chip that transmits a fixed 40-bit ID. T5577 is a rewritable 125 kHz chip that can be programmed to behave like an EM4100 card or several other LF formats, and EM4305 is a 512-bit read/write chip best known for ISO 11784/11785 FDX-B animal ID. For access control, EM4100-compatible cards suit existing EM systems, T5577 suits custom numbers and formats, and none of the three stops cloning.
Comparison table: read-only vs rewritable, memory and formats
All three are passive low-frequency (LF) chips powered by the reader’s magnetic field, and all three answer by load modulation. The differences are in what they store, whether that data can be changed, and how they encode it.
| EM4100 (and TK4100, EM4102) | T5577 | EM4305 | |
|---|---|---|---|
| Carrier frequency | 125 kHz (chip range about 100–150 kHz) | 125 kHz (about 100–150 kHz) | 125 kHz or 134.2 kHz (about 100–150 kHz) |
| Read/write | Read-only; ID fixed at manufacture | Read/write EEPROM | Read/write EEPROM |
| Memory | 64-bit frame carrying 40 data bits | 7 × 32-bit user blocks (224 bits); 6 blocks (192 bits) with password mode | 512 bits as 16 × 32-bit words |
| Fixed unique ID | Yes, the 40-bit ID itself | No; it sends whatever was programmed | Yes, a fixed 32-bit UID in its own word |
| Password | None | Optional, 32-bit | 32-bit |
| Permanent write lock | Not needed (ROM) | Lock bit per block | Protection (lock) words |
| Modulation and encoding | ASK; Manchester at RF/64 (about 2 kbit/s) on access cards | ASK, FSK or PSK; Manchester, biphase or NRZ; RF/8 to RF/128 | ASK; Manchester or biphase |
| Common formats | EM4100 64-bit | EM4100, prox-style FSK formats and others | FDX-B; EM4100-compatible |
| Typical uses | Access cards and fobs, time and attendance | Custom-numbered and replacement cards, format testing | Animal ID transponders, rewritable cards and tags |
| Clone resistance | None | None | Low: the password protects memory, not the transmitted ID |
TK4100 vs EM4100. TK4100 and EM4102 are compatible chips that transmit the same 64-bit frame as EM4100. A standard EM reader cannot tell them apart and derives the same card number from each, so cards sold as EM4100, EM4102 or TK4100 are interchangeable at the door. What matters on a quote is the number format, the number range and a sample read on your own reader.
What EM4100 numbers mean: 10-hex, 8H10D and decimal
An EM4100 chip repeats one 64-bit frame for as long as it is powered: nine header bits set to 1, then 10 rows of 4 data bits each followed by an even parity bit, then 4 column parity bits and a stop bit of 0. At RF/64 each bit lasts 512 µs at 125 kHz, so a full frame takes about 33 ms. There is no command set, no anti-collision and nothing to authenticate.
The 40 data bits are written as 10 hex digits: an 8-bit version or customer field followed by a 32-bit ID. Cards are printed in decimal, and readers can be set to show different slices of the ID, which is why one card can appear as several numbers. Here is one example card, ID 0A1B3C4D5E:
| Representation | Bits used | Value for the example card |
|---|---|---|
| Full ID in hex (10H) | 40 | 0A1B3C4D5E |
| Full ID in decimal (10H13D) | 40 | 0043406609758 |
| 8H10D: the 10-digit number printed on many cards | Low 32 | 0456936798 |
| 32-bit output (such as Wiegand 34), split 16/16 | Low 32 | 6972 and 19806 |
| 6H8D | Low 24 | 03951966 |
| 26-bit output, printed as “xxx,xxxxx” | Low 24 | 060,19806 (facility code 60, card number 19806) |
Three practical rules follow from the table:
- The 10-digit printed number matches a reader that outputs the full 32-bit ID: Wiegand 34, or a USB reader set to 10-digit decimal.
- The “xxx,xxxxx” number matches Wiegand 26. It uses only the low 24 bits, so the 10-digit number cannot be recovered from a 26-bit read, and two different cards can produce the same 26-bit number.
- Neither printed number includes the version byte. Two cards that differ only in their first two hex digits look identical to a controller that receives 26-bit or 32-bit data.
If a controller shows a different number from the one printed on the card, check the reader’s output format before suspecting the card. Some readers also reverse the bit or byte order. Our Wiegand 26-bit format guide walks through the bit layout and conversions, and the USB reader output formats guide covers desktop readers that type the number into software.
T5577 for programmable IDs and emulated formats
T5577 stores its data in 32-bit blocks. Page 0 holds a configuration block (block 0) and seven user blocks (blocks 1–7). The configuration block sets the modulation, the data rate, how many blocks the chip transmits and whether password mode is on. In its normal read mode the chip streams its data blocks in a loop, much as an EM4100 repeats its frame.
That flexibility is what makes T5577 useful. To behave as an EM4100 card, the 64-bit EM frame is written into blocks 1 and 2 and the configuration is set to Manchester encoding at RF/64; an EM reader then sees an ordinary EM4100 card. Other settings produce FSK prox-style formats or PSK formats, so one chip type covers several reader families.
Typical reasons to specify T5577:
- Pre-programmed number ranges. The cards are encoded with a sequential range or a list you supply, rather than the preset, unordered IDs of EM4100 chips.
- Replacements for your own system. New cards can be encoded to fit a number range your controller already uses.
- Format testing. Integrators use T5577 cards to check which LF formats a reader or controller accepts.
Rewritability cuts both ways. A T5577 that has not been locked can be overwritten by anyone with a writer, and a blank T5577 is the standard card used to duplicate LF credentials. Two controls exist:
- Lock bits. Each block has a lock bit that makes it permanently read-only. Locking cannot be undone, so program and verify the cards first.
- Password mode. A 32-bit password in block 7 blocks casual rewriting, at the cost of one user block. The password is sent over the air as plain data, so it is not cryptographic protection.
Writing also needs the card closer to the antenna than reading does, so use a desktop writer that supports T5577 rather than a door reader.
EM4305 and FDX-B animal ID
EM4305 holds 512 bits as 16 words of 32 bits. One word carries a 32-bit UID fixed during chip production, one holds a 32-bit password, one is the configuration word and two are protection words that permanently write-lock chosen words. The rest is user memory. The chip supports read, write, login (password), protect and disable commands, and it operates across roughly 100–150 kHz, so the same tag answers a 125 kHz access reader and a 134.2 kHz animal reader.
Its best-known job is FDX-B animal identification:
- ISO 11784 defines a 64-bit code with flag and reserved bits, a 10-bit country code and a 38-bit national identification code. It is usually shown as 15 digits: a 3-digit country code (ISO 3166 numeric) or a manufacturer code in the 900–998 range, then a 12-digit national ID.
- ISO 11785 defines the air interface. The reader’s activation field is 134.2 kHz. An FDX-B tag answers while the field is on, using amplitude modulation and differential biphase encoding at about 4.2 kbit/s (the carrier divided by 32), and each telegram adds a header, control bits and a 16-bit CRC to the 64-bit code.
- HDX is the other ISO 11785 method, a half-duplex FSK system. EM4305 is an FDX-B chip, so specify HDX tags separately where an HDX system is in use.
The format decides what reads it. An access reader set for EM4100 will not decode FDX-B, and a 134.2 kHz animal reader will not necessarily decode EM4100. When a datasheet lists “EM4305” as supported, it means the reader reads the chip when it is programmed in a format the reader decodes. The 125 kHz reader modules we supply list EM4305 among supported chips; if you are integrating FDX-B tags, confirm the format with a sample before ordering.
In access control, EM4305 appears in rewritable cards and fobs programmed with EM4100-compatible data. It behaves at the door like T5577 set to EM4100: interchangeable with EM4100 on standard readers, and just as easy to copy.
Security: why 125 kHz IDs are copyable
An EM4100 card sends its complete ID to any reader that powers it. There is no challenge, no key and no way for the reader to prove the card is genuine. A handheld duplicator can read the ID and write it to a T5577 blank in seconds, and the access controller cannot tell the copy from the original.
The rewritable chips don’t change this. T5577 and EM4305 passwords protect the chip’s memory from being rewritten; they do not hide the ID the chip transmits in normal operation, and both passwords cross the air as plain data. Anything a legitimate reader can read, a copier can read too.
Some readers sold as “anti-copy” 125 kHz readers try to detect rewritable chips and refuse them. That stops casual copies onto T5577 blanks, but it also rejects legitimate T5577 or EM4305 cards, and it does not stop dedicated LF emulators.
Where 125 kHz stays in service, reduce the risk at the door: pair the card with a PIN on higher-risk entrances, keep audit logs, and delete lost cards from the controller promptly. Where clone resistance matters, the fix is a different credential: 13.56 MHz cards such as MIFARE® DESFire® EV2/EV3 read with AES-128 authentication by encrypted anti-clone readers. Our 125kHz vs 13.56MHz guide covers migrating a site with dual-frequency readers so existing EM cards keep working during the changeover.
Which chip to specify in an RFQ
Start from what the cards must do, then match the chip:
| Your situation | Specify | Notes |
|---|---|---|
| Adding cards to an existing EM4100 system | EM4100-compatible (EM4100, EM4102 or TK4100) | State the printed number format and check the range against enrolled users |
| Cards must carry a set number range | T5577, pre-programmed and locked | Supply the start number or number list; ask for a programming report |
| Testing readers across LF formats | T5577, not locked | Keep test cards out of circulation |
| Animal ID to ISO 11784/11785 | EM4305 programmed as FDX-B | Specify country or manufacturer code, 15-digit numbering and 134.2 kHz readers |
| Rewritable LF ID tags for equipment | EM4305 or T5577 | Decide who writes the data and whether to lock it |
| New site that needs clone resistance | None of the three | 13.56 MHz DESFire EV2/EV3 with encrypted readers |
Put these details in the RFQ so the quote matches your readers the first time:
- Chip: EM4100-compatible, T5577 or EM4305, and whether compatible chips (such as TK4100) are acceptable
- Data format: EM4100 64-bit, FDX-B or another LF format the reader decodes
- For T5577 and EM4305: supplied blank or pre-programmed, and locked, password-protected or left open
- Number range: preset chip IDs in no particular order, a sequential start number or your own list, with no overlap with enrolled cards
- Printed number: 8H10D 10-digit, “xxx,xxxxx”, both or none, plus its position on the card
- Reader output the numbers must match: Wiegand 26, Wiegand 34, RS485 or USB keyboard emulation
- Form factor: ISO/IEC 7810 ID-1 card (85.60 × 53.98 × 0.76 mm), clamshell card, key fob, wristband or tag
- Printing: thin PVC cards for card printers, or pre-printed artwork
- A sample batch read on your own reader and controller before the bulk order
Browse cards, key fobs and wristbands with the list in hand, and order samples of the card and reader together.
Next steps
Send us a sample card or a photo of both sides, the reader output your controller expects and the number range you need. We will confirm the chip and format, encode and lock rewritable cards where required, and test a sample batch before dispatch. Request a quote or samples and we will reply within 24 hours.
Frequently asked questions
What is the difference between EM4100 and T5577?
EM4100 is read-only: its 40-bit ID is fixed when the chip is made. T5577 is rewritable and configurable, so it can be programmed with an EM4100-format ID or with other 125 kHz formats, and rewritten unless its blocks are locked.
Is TK4100 the same as EM4100?
For a reader, yes. TK4100 is a compatible chip that transmits the same 64-bit EM4100 frame, so EM readers read it and derive card numbers in exactly the same way.
Can a T5577 card be used as an EM4100 card?
Yes. Programmed with an EM4100-format ID and set to Manchester encoding at RF/64, a T5577 reads like an ordinary EM4100 card. Lock the blocks after programming if the number must not be changed later.
What does 8H10D mean on a card or reader?
It means the last 8 hex digits of the EM4100 ID shown as a 10-digit decimal number. It is the number printed on many EM cards, and it matches a reader that outputs the full 32-bit ID, such as Wiegand 34.
Is EM4305 more secure than EM4100?
Only slightly. Its 32-bit password protects memory from being read or rewritten, but the ID it transmits in normal operation is sent without authentication and can be copied like any other 125 kHz ID.
Do EM4305 tags work at 134.2 kHz?
Yes. The chip operates across roughly 100–150 kHz, which covers both 125 kHz access readers and 134.2 kHz animal ID readers. The reader must also decode the format the chip is programmed with, such as FDX-B or EM4100.
Want a second opinion on your spec?
Send us your controller, credential type and environment — we'll recommend compatible hardware and quote within 24 hours.