Biometric Devices (ZKTeco)
Some companies use ZKTeco fingerprint or face terminals that push each punch to ANTE the moment it happens. This page is where you register those terminals, give each one its credentials, and watch what it has been sending. Punches that arrive become BIOMETRICS entries in Raw Logs, and the affected days are recalculated for Time Keeping automatically.
Where to Find It
Go to Manpower → Time & Attendance → Device Management and click Biometric devices at the top of the page. You need the Device Management permission. (Face-recognition terminals are a different kind of device — see Device Management.)
The Device List
Each registered terminal is one row:
| Column | Meaning |
|---|---|
| Name / Serial number / Location | How you identify the terminal. |
| Proof of identity | Shows Secret ...XXXX (last four characters of its secret) or IP allowlist. |
| Status | Enabled or Disabled. A disabled terminal is refused. |
| Last seen / Last punch push | When the terminal last contacted ANTE, and when it last delivered a punch. |
| Punches | How many punches ANTE has received from it. |
| Last error | The most recent problem, if any. |
Row actions are Activity, Edit, Rotate secret, Enable / Disable and Remove.
Registering a Terminal
- Click Register terminalThe Register biometric device dialog opens.
- Fill in the device detailsSerial number*The serial printed on the terminal. It must be unique within your company.Name*A friendly name, for example "Warehouse gate".LocationWhere the terminal is installed.Terminal time zoneThe time zone the terminal's own clock runs in.Punch modeAutomatic (alternate IN/OUT) alternates in and out for each employee, while Use the terminal IN/OUT key trusts the IN/OUT button pressed on the device.Proof of identityDevice secret is the strongest option and the default. Use IP allowlist only for terminals whose firmware cannot carry a secret.Allowed addressesOnly for the IP allowlist: the terminal's IP addresses or ranges, separated by commas. Very broad ranges are not accepted. The form also shows a warning: an IP allowlist is only safe when the server accepts traffic exclusively through Cloudflare, and it should not be used for terminals behind a shared internet connection. If another company already holds the same serial number, the IP allowlist is refused and you must use a device secret.
- Save and copy the credentialsA Terminal credentials dialog shows the Server path and, for a device secret, the Secret. Use Copy path, then click I saved it.
- Configure the terminalIn the terminal's Cloud Server settings, enter the server address and port provided by your IT team and, where the firmware allows a path, the server path from the credentials dialog. Otherwise ask IT to add the path at your network gateway.
It cannot be recovered afterwards. If it is lost, use Rotate secret to issue a new one.
Rotating a Secret
Click Rotate secret on the row and confirm. A new secret is issued, the old one stops working immediately, and the terminal must be reconfigured with the new path before it can send punches again.
Checking Activity
Activity opens two lists: Recent pushes (what the terminal sent, with counts of recorded, duplicate, unmapped and skipped records) and Recent punches with the terminal user ID, the employee, what it was recorded as, and the Result:
| Result | Meaning |
|---|---|
| Recorded | The punch became a raw log. |
| No matching employee | The terminal user ID is not linked to any employee yet. |
| Cutoff locked | The punch falls in a cutoff that payroll has already locked. |
| Ignored (double scan) | A repeat scan within moments of the first. |
| Already imported | The same moment was already imported from a file. |
| Out of order | The punch arrived out of sequence. |
After linking an employee or unfreezing a cutoff, use Reprocess unmapped and locked punches to retry them.
Editing, Disabling and Removing
- Edit changes the name, location, time zone, punch mode and proof of identity.
- Disable refuses the terminal until you click Enable again.
- Remove deletes it; the terminal is refused until it is registered again.
A terminal that is not registered, or that does not present its secret or come from an allowed address, is turned away and creates nothing in your timekeeping.
If punches stop arriving, check Last seen and Last error first, then confirm the terminal can reach your IT-provided server address.
How It Connects
Set up first
- Employee Records — an employee's biometrics number must match the ID on the terminal so a punch reaches the right person.
Feeds into
- Raw Logs — each accepted punch appears there as a Biometrics entry.
- Payroll Time Keeping — the affected days are recalculated automatically.