Skip to content

HID Token Configuration for Mideye

Mideye supports HID Mini Token cards as a second authentication factor. Instead of receiving one-time passwords on a mobile phone, users obtain OTPs from a physical token card.

HID mini token. Weight 16 gram, expected lifetime 6 years.

Token cards are ordered from Mideye Support. These tokens are integrated into the Mideye system — the only difference compared to phone-based authentication is that the user is assigned a token serial number (e.g., AI0123456789) instead of a mobile number.


For LDAP users, there are two ways to assign token authentication:

Option A — Token serial in the mobile phone field

Section titled “Option A — Token serial in the mobile phone field”

Register the token serial with the AI prefix (e.g., AI0750123456) in the mobile phone field. Mideye Server automatically assigns the Token authentication type. Set the Token Number parameter in the User tab to the mobile phone field.

Option B — Separate field with authentication type

Section titled “Option B — Separate field with authentication type”

In addition to the token serial field, assign another vacant LDAP attribute to indicate the authentication type:

ValueType
1Password
2Mobile
3Token
4Concatenated
5Plus
6Touch
7Touch-Plus
8Touch-Mobile

Configure this via the LDAP profile → Authentication tab → Authentication Type Attribute. Check Read Optional Attributes.


  1. Obtain the serial number from the back of the token. All Mideye-dispatched tokens start with AI.

  2. Add the serial to the user repository. By default, Mideye Server searches the ipPhone attribute. In Active Directory, open the user properties → Telephones tab → enter the serial in the IP Phone field.

  3. Set authentication type to Token. In the LDAP profile → Authentication tab, check Read Optional Attributes and specify an attribute (e.g., pager) for the Authentication Type Attribute.

    Enable Read Optional Attributes

  4. Set the value to 3 in the user’s pager field (3 = Token). See Authentication Types for all values.


Token cards generate OTPs in a sequence unique to each token (time and event synchronous). If more than 10 OTPs are generated without being validated by the server, the token becomes out of sync.

  • Automatic re-sync: Within a window of 100 OTPs — enter a new OTP for verification.
  • Manual re-sync: If out of sync by more than 100 OTPs — contact Mideye Support with the serial number and counter value.

If the printed serial is not readable:

  1. Press and release the button to generate an OTP.
  2. While the OTP is displayed, press and hold the button until you see alternating strings:
    • SN
    • 1= XXXXX
    • 2= YYYYY
  3. The serial number is AIXXXXXYYYY.
  1. Follow the serial number steps above.
  2. When the serial is displayed, release and press-hold again until:
    • SN
    • 1= XXXXX
    • 2= YYYYY
  3. The clock value is XXXXXYYYYY.
  1. Follow the clock value steps above.
  2. When the clock value is displayed, release and press-hold again until:
    • Count
    • 1= XXXXX
    • 2= YYYYY
  3. The counter value is XXXXXYYYYY.