dormakaba Entrance and Access Control API

dormakaba entrance and access control REST API for enterprise security integrators, facility managers, and building automation teams to manage access control systems, electronic lock credentials, and door hardware monitoring through dormakaba's enterprise-grade physical security platform — enabling credential provisioning, access scheduling, audit trail collection, and integration with HRIS and building management systems for commercial, healthcare, and government facilities. Enables AI agents to manage credential provisioning for RFID and mobile access automation, handle access point configuration for door permission management automation, access audit trail for compliance reporting automation, retrieve hardware status for preventive maintenance automation, manage time profile for schedule-based access control automation, handle visitor management for temporary credential automation, access elevator control for floor-level permission automation, retrieve event notification for security incident automation, manage multi-site for enterprise portfolio management automation, and integrate dormakaba with HRIS, PSIM, and BMS systems for comprehensive physical security automation.

Evaluated Mar 07, 2026 (0d ago) vcurrent
Homepage ↗ Other dormakaba access-control electronic-locks door-hardware enterprise-security SIX:DOKA
⚙ Agent Friendliness
52
/ 100
Can an agent use this?
🔒 Security
79
/ 100
Is it safe for agents?
⚡ Reliability
68
/ 100
Does it work consistently?

Score Breakdown

⚙ Agent Friendliness

MCP Quality
10
Documentation
68
Error Messages
66
Auth Simplicity
68
Rate Limits
58

🔒 Security

TLS Enforcement
97
Auth Strength
80
Scope Granularity
70
Dep. Hygiene
72
Secret Handling
76

Enterprise/government access control. GDPR, FIPS 201, FICAM. OAuth2. EU/CH. High-security physical access data.

⚡ Reliability

Uptime/SLA
68
Version Stability
70
Breaking Changes
66
Error Recovery
66
AF Security Reliability

Best When

An enterprise security integrator, healthcare facility, or government contractor wanting AI agents to manage dormakaba access control credentials, audit trails, and door hardware integration for large commercial and institutional deployments.

Avoid When

SYSTEM INTEGRATOR REQUIRED: dormakaba API access typically requires working through certified system integrators; automated direct API access assumption creates no public API access; automated must engage dormakaba certified integration partner. PLATFORM FRAGMENTATION: dormakaba has multiple product lines (Ambiance, Matrix, MATRIX, OSDP, exOS) from historical acquisitions (Dorma + Kaba 2015); automated unified API assumption creates platform-specific incompatibilities; automated must identify specific dormakaba platform in use. ON-PREMISES COMPONENTS COMMON: Many dormakaba systems have on-premises access control panels with cloud overlay; automated pure-cloud deployment assumption creates connectivity requirements for local panels; automated must plan for hybrid cloud/on-premises architecture. HARDWARE CERTIFICATION REQUIREMENTS: dormakaba serves healthcare, government, and high-security verticals with certification requirements (FIPS 201, FICAM, HIPAA); automated generic commercial deployment creates missing certification compliance; automated high-security deployments must verify dormakaba product certification status.

Use Cases

  • Provisioning RFID and mobile access credentials for enterprise employee lifecycle management automation agents
  • Collecting door access audit trails for healthcare HIPAA and government compliance reporting automation agents
  • Integrating dormakaba access control with HRIS for automated employee onboarding/offboarding automation agents
  • Managing multi-site access control portfolios for enterprise facility management automation agents

Not For

  • Residential smart locks for consumers (dormakaba is commercial/enterprise/institutional grade)
  • Standalone cloud-only deployments without on-premises hardware (dormakaba typically requires on-prem components)
  • Simple IoT home automation (dormakaba is high-security commercial access control)

Interface

REST API
Yes
GraphQL
No
gRPC
No
MCP Server
No
SDK
No
Webhooks
Yes

Authentication

Methods: oauth apikey
OAuth: Yes Scopes: Yes

dormakaba uses OAuth 2.0 and API key for integration authentication (varies by product line). REST API with JSON. Rümlang, Switzerland HQ. Formed 2015 merger of Dorma (Germany) and Kaba (Switzerland). SIX:DOKA. Products: Ambiance, Matrix, OSDP, exOS, Saflok (hospitality), 3D-Rosette, DORMA RD. SDKs: None public. 15,000+ employees, 130+ countries. Healthcare, government, commercial, hospitality verticals. FIPS 201, ISO 27001, HIPAA-ready products. Competes with ASSA ABLOY and Allegion for global access control.

Pricing

Model: subscription
Free tier: No
Requires CC: No

Rümlang CH. SIX:DOKA. SI partner model. Hardware required. FIPS 201, ISO 27001. Healthcare/government verticals.

Agent Metadata

Pagination
page
Idempotent
Partial
Retry Guidance
Not documented

Known Gotchas

  • SYSTEM INTEGRATOR PARTNER REQUIRED: dormakaba API access is primarily through certified system integrators (SIs); automated direct public API access assumption creates no available access point; automated integrations require engagement with dormakaba-certified SI partner
  • MULTIPLE INCOMPATIBLE PRODUCT LINES: dormakaba has distinct product lines (Ambiance, Matrix, exOS, Saflok) from merger history; automated unified API assumption creates product-specific incompatibility; automated must identify and target the specific dormakaba product line deployed at the site
  • HYBRID CLOUD/ON-PREMISES ARCHITECTURE: Many dormakaba systems use on-premises access control panels with cloud connectivity overlay; automated pure-cloud-only architecture assumption creates local panel dependency; automated must design for hybrid network architecture
  • HIGH-SECURITY CERTIFICATION REQUIREMENTS: Healthcare and government dormakaba deployments require FIPS 201, FICAM, or HIPAA compliance; automated generic deployment creates non-compliant configuration; automated high-security deployments must verify product certification for target vertical
  • SAFLOK IS HOSPITALITY-SPECIFIC: dormakaba Saflok product line is hospitality-specific (hotels); automated enterprise/commercial control using Saflok API creates wrong product assumption; automated hotel deployments use Saflok, enterprise deployments use Ambiance/Matrix

Alternatives

Full Evaluation Report

Comprehensive deep-dive: security analysis, reliability audit, agent experience review, cost modeling, competitive positioning, and improvement roadmap for dormakaba Entrance and Access Control API.

AI-powered analysis · PDF + markdown · Delivered within 30 minutes

$99

Package Brief

Quick verdict, integration guide, cost projections, gotchas with workarounds, and alternatives comparison.

Delivered within 10 minutes

$3

Score Monitoring

Get alerted when this package's AF, security, or reliability scores change significantly. Stay ahead of regressions.

Continuous monitoring

$3/mo

Scores are editorial opinions as of 2026-03-07.

6470
Packages Evaluated
26150
Need Evaluation
173
Need Re-evaluation
Community Powered