
Most keypad buying decisions get made backward.
Someone searches for a product, compares a few specs, and picks one, only to find out three months later that the access control keypad doesn't talk to the rest of the building's access system, or that the outdoor unit they installed on a side gate wasn't rated for the weather it now sits in.
This guide starts with how to evaluate keypads before any product talk, then walks through the types, the wiring, and how to match a decision to your specific building.
TL;DR
An access control keypad is a door-entry device that grants or denies access based on a PIN, checked either by the keypad itself or by a networked controller. Access control keypads split along four lines, and where a given unit falls on each one determines almost everything else about how it fits your building.
A standalone keypad stores its own codes and runs independently of any other system, which makes it cheap and simple but also means every code change happens at the device itself.
A networked or cloud-managed keypad reports to a central controller or dashboard, so codes, schedules, and access logs live in one place across every door.
Some units take a PIN and nothing else.
Others pair the keypad with a card or fob reader on the same housing, so the door can accept either credential type or require both for multi-factor entry.
An interior keypad has no business on an exterior door, and vice versa is a waste of money.
Exterior-rated units carry an IP rating for water and dust resistance and are usually built with more tamper resistance around the keypad face.
Each application has different mounting, wiring, and credential-volume needs, and a unit built for one doesn't always translate cleanly to another.
Before comparing specific products, five questions settle most of the decision:
The table below lays out where each type fits before the deeper walkthrough that follows.
Every keypad entry follows the same basic chain, regardless of type. A person enters a PIN at the reader. The reader passes that code to whatever is checking it. If the code matches an active, permitted entry, a relay fires and releases the lock. The whole sequence usually takes under a second.
Where that verification happens is what separates the keypad types.
On a standalone unit, the keypad checks its own stored list of valid codes and triggers the relay directly. There's no controller, network call, or dashboard involved. This is why standalone keypads keep working without an internet connection, and why changing a code means walking up to the physical unit rather than logging in anywhere.
It also explains the tradeoff most buyers run into eventually.
A shared PIN across a small team is simple until one person needs to be cut off. Since the code isn't tied to an individual, revoking it means changing it for everyone and redistributing the new one.
On a networked or cloud-managed system, the keypad is a reader, not the decision-maker.
It captures the PIN and sends it to an access controller, a hardware unit that holds the actual permission logic and, in cloud-managed setups, stays synced with software running off-site.
The controller checks the code, fires the relay if it's valid, and logs the event.
This is also where individual-level control comes from. In a cloud-managed system like Coram, a person only gets to unlock a door once they've been added as a user, given at least one access method, and explicitly granted permission on that specific door. Nothing opens by default.
Rotating one person's code doesn't touch anyone else's access, and admins manage all of it from a dashboard instead of the device itself.
One controller typically handles several doors at once, which is the practical reason networked systems scale across a building better than standalone units do. The local-storage model simply has no way to centralize once a facility grows past a handful of doors.
These five categories tell you where and how the keypad is used.
Most buying mistakes happen when someone matches the type to the door but skips the management question, ending up with a networked-capable building running a mix of standalone units nobody can update remotely.
A commercial keypad door lock combines the keypad and the locking mechanism into a single unit mounted directly on the door, often replacing or retrofitting a standard door handle. Entering the correct PIN releases the mechanical lock or triggers an electronic strike, depending on the model.
These are built heavier than residential versions and typically hold more stored codes, since a commercial door sees more turnover in who needs access. They work as either standalone units or as part of a networked system, and the door hardware itself doesn't dictate which. What matters more is whether the lock ships with a wired connection point for a controller or is designed to run entirely self-contained.
Standalone keypads are the smallest and simplest category, usually mounted beside the door rather than integrated into the handle itself. A few characteristics define them:
They're the right fit for a single door with a small, stable group of users, and the wrong fit anywhere codes need to change often, or logs need to exist.
Some keypads pair a PIN pad with a proximity or card reader on the same housing, giving a door two credential paths instead of one.
A person can badge in with a card or fob, enter a PIN, or in higher-security setups, do both as a multi-factor requirement.
The wiring for these follows standard reader protocols like Wiegand or OSDP, the same ones used for card-only readers, since the keypad is just an additional input layered onto the same reader hardware. This makes combo units a natural fit anywhere a facility already has card-based access control and wants to add a PIN option, whether as a backup credential or as a second factor for sensitive doors.
Coram's door readers support this kind of combined-credential setup without requiring separate hardware for each method.
Gate keypads exist for a different problem than door keypads: vehicles and pedestrians need to trigger an opener from a distance, often in an exposed outdoor location. A few things set them apart from standard door units:
They show up most often at parking lots, gated communities, and campus or facility perimeters where a card reader isn't practical for vehicle traffic.
Elevator keypads restrict which floors a person can reach rather than which doors they can open. The keypad sits inside the elevator car or at a lobby control point, and a valid PIN doesn't unlock a door; it enables specific floor buttons for that user.
This makes elevator keypads a smaller-scale credential system by design.
A code that works for the building's front entrance won't necessarily do anything on the elevator panel, since floor permissions are usually managed separately from door permissions, even on the same access control platform.
Buildings with restricted-floor tenants, like hospitals or multi-tenant offices, are where this distinction matters most.
This is the part most keypad guides skip entirely, and it's usually where installations go wrong. An access control keypad is only one piece of the circuit. Understanding what it connects to matters more than the keypad itself.
Every wired keypad system runs through an access controller, the hardware that sits between the reader and the lock. The controller receives the code from the keypad, checks it, and sends a signal to a relay.
The relay is what completes or breaks the circuit powering the lock. One controller commonly handles multiple doors rather than running one controller per entry point, which keeps wiring centralized instead of scattered across a building.
The lock itself is typically a standard 12-volt DC electric lock, either a strike or a maglock. A detail that trips up a lot of first-time installs: the controller sends the signal, but it does not supply the lock's power. That has to come from an external power source wired in separately.
Skipping this step is one of the most common reasons a newly installed keypad door fails to release correctly on its first test.
Keypads and combo readers connect to the controller using one of two wiring protocols, Wiegand or OSDP. Wiegand is the older, more common standard; OSDP is newer and supports encrypted communication between the reader and controller, which Wiegand does not.
The detail that matters most during planning: a door can run two readers, but only if they use different protocols. Two Wiegand readers cannot share a single door's wiring. This comes up most often on doors getting both an entry and exit reader, or a keypad-plus-badge combo alongside a separate reader, and it's worth confirming with an installer before hardware is ordered rather than after.
A complete installation usually includes a few components beyond the keypad and lock:
None of this is complicated in isolation, but it adds up to enough interdependent wiring that a facilities team without electrical or low-voltage experience will usually spend more time and money troubleshooting a DIY install than they would have spent on professional installation from the start. For anything beyond a single standalone unit on an interior door, hiring a licensed installer familiar with access control wiring is the practical recommendation, not just a liability disclaimer.
Keypad-only entry solves a real problem and creates a different one. Weighing both honestly matters more than picking a side.
Pros:
Cons:
These tradeoffs are exactly why most facilities with any real security requirement pair a keypad with something else, whether that's a second credential, a rotation policy, or a system that logs every entry attempt rather than relying on the code alone.
A handful of features separate a system that holds up over time from one that becomes a maintenance headache within a year, once the keypad type and management model are settled.
Every entry attempt, successful or not, should be logged with a timestamp and, ideally, the identity of the person who entered it. Without this, a keypad door is a black box: you know it opened, not who opened it or when.
The ability to add, change, or revoke a code from a dashboard rather than at the device itself. This is what turns code rotation from a facilities chore into something that takes seconds.
A keypad that can also accept a card, fob, or mobile credential gives a facility room to add multi-factor requirements later without replacing hardware. This also matters for temporary access: issuing a short-lived code to a contractor or visitor through a proper visitor management system is cleaner than handing out the same standing code you give employees.
Pairing an unlock event with footage from a camera at the door answers the question an access log alone can't: did the person who entered match the credential used? This becomes especially valuable when investigating a shared-code misuse case, which is one of the more common problems with keypad-only entry.
Non-negotiable for any exterior installation. An IP rating tells you what the unit can withstand, not just that it's marketed as "outdoor use."
The right access control keypad depends less on features and more on which scenario describes your building.
A standalone keypad is usually the right call. The management overhead of a networked system isn't worth it for a handful of people who rarely change.
A networked or cloud-managed system pays for itself quickly. Centralized code management and audit logs matter more as door count grows, and retrofitting a standalone setup into a networked one later is more expensive than starting there.
Weatherproofing isn't optional, and it should be the first filter applied before comparing any other feature.
Like a coworking space or a 24-hour gym access control setup, a standalone keypad with a shared code becomes a liability fast. Members or guests coming and going at all hours need individually trackable, easily revocable credentials, which points straight toward a networked system with per-user codes and an audit trail.
A keypad-plus-reader combo, or a plan to add one later, keeps the door from needing a hardware swap when policy changes.
A keypad is one credential option among several. The real decision is what manages it, and that's where cloud-managed access control systems change the equation compared to a standalone device.
Coram supports PIN entry at a door reader alongside keycards and app-based remote unlock, all managed from one cloud dashboard rather than at each individual door. A few things define how that works in practice:
Best for facilities that need PIN entry to work alongside other credential types, across multiple doors, without hiring separate systems to manage each one.
The keypad type matters less than most buying guides suggest. What determines whether an installation holds up is whether the management model, the wiring, and the credential options match how the building operates day to day — a standalone unit for a single door with a small, unchanging team, a networked system once doors, access changes, or turnover start to multiply.
The one question a keypad alone can't answer, on any system, is whether the person who unlocked the door was the person who was supposed to. Coram's access control platform pairs PIN, card, and app-based unlock with video at the door, so that question has an answer instead of a guess. Book a demo to learn more.
Yes, as long as the unit carries a weatherproof rating built for exterior exposure. Interior-rated keypads aren't built to handle moisture or temperature swings and shouldn't be substituted for cost reasons.
Only with a backup battery in place. Most networked systems are designed to fail safely during an outage, either unlocking for exit or holding a stored charge long enough to keep operating, but this depends entirely on whether backup power was included in the installation.
There's no universal number, but a common practice is rotating shared codes quarterly and revoking individual codes immediately when someone no longer needs access. Facilities with higher turnover or shared credentials should rotate more frequently.
Standalone keypads typically run on standard alkaline or lithium batteries housed inside the unit, while networked systems usually rely on a backup battery built into the controller rather than the keypad itself.
An access control keypad verifies a PIN someone types in, while a card reader verifies a physical credential someone taps or swipes. Many facilities use both, either as separate options or combined into one reader for multi-factor entry.
Yes, either as a combo unit with both built in, or as two separate readers, provided they use different wiring protocols. Two readers of the same protocol type cannot share a single door's wiring.
It depends entirely on whether the system is standalone or networked. Standalone units typically cap out at a limited number of stored codes, while networked systems scale to as many users as the platform supports, since permissions live in software rather than on the device.

