Skip to main content

5 PalmAI M3 Device User Manual

The User Manual is available for Max and Standard. Use the tabs below to switch between editions.

5.1 Device Overview and Installation

This section describes the main components of the M3, its installation environment, wall and turnstile installation methods, access control wiring, startup procedure, and palm scan precautions.

5.1.1 Device Exterior and Interfaces

The main components of the M3 include the NFC card reader area, display, palm scan camera module, concealed reset button on the left side, pigtail interfaces, and speaker.

ComponentDescription
NFC card reader areaReads access cards. Card-reading capability depends on the on-site access control configuration.
DisplayShows device pages, operation prompts, and processing results.
Palm scan camera moduleCaptures and recognizes palm information.
Concealed reset button on the left sidePress it with a paper clip or similar pointed tool to perform a hardware restart if the device malfunctions.
SpeakerPlays voice prompts and notification sounds.
Pigtail interfacesInclude USB HOST, relay, Wiegand, and RS485 interfaces.

The pigtail interfaces serve the following purposes:

InterfacePurpose
USB HOSTConnects supported USB peripherals.
RelayOutputs a dry-contact signal for connection to a dedicated access control power supply or door lock control circuit.
WiegandOutputs Wiegand signals to the access controller.
RS485Communicates with the access controller over an RS485 bus.

Note

The M3 does not support PoE power. Use the supplied 12 V power adapter.

5.1.2 Indicator Lights

Light statusDevice status
Dim blueSleep mode
Dim whiteStandby
Bright white fill lightRegistering or recognizing a palm
Flashing orangeThe palm is too close to the device
Green onRecognition succeeded
Red onRecognition failed

5.1.3 Installation and Operating Environment

The M3 is intended for indoor or sheltered semi-outdoor environments. Observe the following requirements during installation and use:

  • The device is not waterproof. Prevent liquids and dust from entering it.
  • Do not use the device in extremely cold, hot, or humid environments or near heat sources.
  • Do not drop, strike, throw, or bend the device.
  • Use the device in a clean, low-dust environment, and leave sufficient clearance around it for heat dissipation.
  • Keep accessories and disassembly tools out of the reach of children.
  • Do not install the device near a window or outdoors where there is strong backlight. If necessary, adjust the device angle so that light falls evenly on the user's palm.
  • Adjust the installation height to the average height of on-site users. For details, see "5.1.4.1 Wall Installation."

5.1.4 Installing the Device

5.1.4.1 Wall Installation

An 86-type junction box is recommended for wall installation. Depending on site conditions, set the installation height between 1.4 and 1.6 m.

  1. Route the access control wiring harness through the round hole in the bracket.
  2. Secure the bracket to the 86-type junction box using the M4 screws supplied with the device.

  1. Connect the access control harness to the device pigtail, then arrange the harness inside the junction box without pinching or pulling it.

  1. Align the slots on the device with the tabs on the bracket, then snap the device onto the bracket.

  1. Tighten the two M2.5 screws on the side of the device to secure it to the bracket.

Note

Disconnect all relevant power supplies before installation. Restore power only after confirming that the wire sequence, insulation, and fastening are correct.

5.1.4.2 Turnstile Installation

The M3 can output a door-open signal to an access controller through Wiegand or a relay. It can also connect through RS485 as required by the project integration. The access controller parses the signal and opens the turnstile. Follow the turnstile manufacturer's requirements for the mounting structure, cutout dimensions, and fastening method.

  1. Determine the device position and camera height based on the turnstile structure.
  2. Secure the device at the turnstile mounting position.
  3. Connect the device pigtail to the access controller according to the selected output method.
  4. Check the power supply, grounding, and signal wire sequence.
  5. After configuring permissions and device output in the Admin Console, test opening the turnstile with a palm scan.

5.1.5 Connecting Access Control Wiring

Before wiring, determine whether the site will use Wiegand, RS485, or a relay to open the door. Installation must be performed by qualified access control personnel.

5.1.5.1 Connecting Wiegand or RS485

For Wiegand, connect the device's 12 V, GND, D0, and D1 wires according to the access controller interface definitions. Do not reverse D0 and D1. The device and controller must share a common ground.

For RS485, connect the positive and negative signal terminals of the device to the corresponding controller terminals, and ensure that all devices on the bus share a common ground.

Note

The Wiegand output format and byte order must match the access controller. For long cable runs, use suitable cables and keep them away from high-voltage power lines.

5.1.5.2 Connecting Relay Dry Contacts

The relay outputs a dry-contact signal and can connect to the control terminal of a dedicated access control power supply. Select NO or NC according to the door lock type.

5.1.5.3 Connecting an NO or NC Door Lock

Door locks can be fail-safe (open when power is removed) or fail-secure (remain closed when power is removed). Select the lock type based on fire safety, security, and on-site business requirements, and wire it according to the NO, NC, and COM terminal definitions of the dedicated access control power supply.

The following example connects SS and NO for a fail-safe lock:

  • P1: When power to the lock is removed, the lock physically releases and the door opens.
  • P2: When the lock is powered but the M3 is not, the relay is open and the NO terminal is disconnected. The powered lock remains locked and the door stays closed.
  • P3: When both the lock and M3 are powered, successful verification energizes the relay and cuts power to the lock, opening the door. If verification fails, the relay remains in its default state and the door stays locked.

Warning

Incorrect NO, NC, or power-circuit wiring may cause the lock to operate opposite to the intended behavior. Before powering the lock, use a multimeter to confirm the terminal states and verify the door-opening strategy during a power outage.

5.1.5.4 Receiving a GPIO Signal and Outputting a Relay Signal

The M3 can receive an external GPIO signal and output a control signal through the relay. Wire the external device according to its voltage level, common-ground, and trigger requirements.

5.1.6 Powering On the Device

  1. Confirm that the device is securely installed and all cables are connected according to the interface definitions.
  2. Connect the supplied 12 V power adapter to the device power cable.
  3. Turn on the power and wait for the device to start and display the operation page.

To restart the device, open the Setting page and tap Device Restart, or press the concealed reset button on the left side with a paper clip or similar pointed tool.

5.1.7 Palm Registration and Recognition Precautions

Before registering or recognizing a palm, remove the protective film from the camera area and keep both the camera and palm clean.

  1. Extend the palm naturally with its center facing the center of the palm scan camera module.
  2. Keep the palm approximately 5–12 cm from the device.
  3. Hold the palm steady until capture or recognition is complete.
  4. Face the palm toward the device with a tilt angle of less than 30°.
  5. Keep the palm rotation angle below 180°.
  6. Do not obstruct the palm or use the device in strong backlight.

5.2 Initial Connection and Activation

5.2.1 Initial Connection Process

When connecting the M3 to the Palm Application Platform for the first time, complete activation in the following order:

  1. Configure Ethernet or WiFi and ensure that the device can connect to the network.
  2. Complete License authorization and confirm that the device is licensed to use palm scan algorithms.
  3. Enter the device name and Device SN in the Admin Console.
  4. Use the device to scan the activation QR code generated by the Admin Console to complete IoT activation and bind the device to the Admin Console environment.
  5. Associate the device with the appropriate scene in the Admin Console, then configure the scene strategy, verification rules, and user permissions.

Description

License authorization and IoT activation are separate processes. License authorization grants access to palm scan algorithms, while IoT activation connects the device to the current Admin Console environment. Complete both processes independently.

5.2.2 Configuring the Device Network

The device must be online to perform online authorization, IoT activation, configuration synchronization, verification record reporting, and OTA upgrades.

  1. Tap the settings button in the upper-left corner of the device home page.
  2. Enter the device settings password in the Please input password window. The initial password is 000000.
  3. Tap Confirm to open the Setting page.
  4. Tap Network setting.
  5. Select WiFi or Ethernet based on the on-site network.

Tip

Use a wired network whenever site conditions permit. WiFi is not recommended for deployments with more than 10 devices.

Observe the following requirements when planning a wired network:

  • A single Ethernet cable segment must not exceed 100 m; keeping it within 80 m is recommended. Do not place connectors in the middle of the cable, bend it sharply, or compress it.
  • Use CAT5e or higher-grade cable and standard RJ45 connectors. Before installation, use a cable tester to check the wire sequence and connectivity.
  • Protect cables with PVC conduit or wiring ducts. Use a separate power outlet for each device and avoid sharing a circuit breaker with other equipment.
  • Do not cascade more than three switches on the same LAN.
Number of devicesRecommended bandwidth and network topology
1–4Shared bandwidth of at least 20 Mbps; devices can connect directly to a router.
5–30Bandwidth of at least 100 Mbps with an enterprise-grade router and managed switches; use no more than four managed switches in one network.
31 or moreA dedicated line of at least 100 Mbps, an enterprise-grade router, and Gigabit switches are recommended. Configure VLANs according to the project network plan.

5.2.2.1 Connecting to a Wired Network

  1. Use an Ethernet cable to connect the network interface on the device pigtail to a router or switch.
  2. Go to Setting > Network setting > WiFi.
  3. Turn off the wireless network switch.
  4. Return to Network setting and tap Ethernet.
  5. Enable Ethernet.

Note

Enabling Ethernet and WiFi on the M3 at the same time causes a network conflict that prevents the wired network from operating correctly. Always turn off WiFi before using a wired network.

5.2.2.2 Selecting the Ethernet IP Mode

Ethernet supports two IP modes, DHCP and Static. The default is DHCP.

  1. Go to Setting > Network setting > Ethernet.
  2. Enable Ethernet.
  3. Tap IP Mode.
  4. Under Select IP Mode, select DHCP or Static.

After you select DHCP, the device automatically obtains an IP address from the network.

After you select Static, enter the IP address, gateway, DNS, and other information according to the on-site network plan, then tap Apply.

5.2.2.3 Connecting to WiFi

  1. Go to Setting > Network setting > WiFi.
  2. Turn on the wireless network switch.
  3. Select the target WiFi network from the list.
  4. If the network requires a password, enter it and connect.
  5. Wait for the device to connect.

Note

Wireless capabilities vary between M3 production batches. Some batches support only 2.4 GHz, while others support both 2.4 GHz and 5 GHz. If the device cannot find a 5 GHz network, use a 2.4 GHz network. Unsecured 5 GHz networks may have compatibility issues; use password-protected WiFi or switch to 2.4 GHz. A WiFi password containing a combination of letters and numbers is recommended.

To configure a static IP for the current WiFi network, tap the information button next to the connected network, select static IP mode on the network details page, and enter the IP address, subnet mask, gateway, and DNS according to the on-site network plan.

5.2.2.4 Managing Saved WiFi Networks

  1. Go to Setting > Network setting > WiFi.
  2. Tap Saved in the upper-right corner.
  3. View saved WiFi networks on the Saved networks page.

To delete a saved WiFi network, tap the delete button to its right.

To add a WiFi network manually:

  1. On the Saved networks page, tap Add Wifi.
  2. Enter the WiFi name in ssid.
  3. Enter the WiFi password in password.
  4. Tap Confirm. To cancel, tap Cancel.

5.2.2.5 Connecting to a Hidden WiFi Network

  1. Go to Setting > Network setting > WiFi.
  2. Turn on the wireless network switch.
  3. Tap Other... in the WiFi list.

  1. On the Join hidden network page, tap Network and enter the hidden WiFi network's SSID.
  2. Tap Security and select the security type configured on the router.
  3. If the network requires a password, enter it in Password.
  4. Tap Join and wait for the device to connect.

Note

The SSID of a hidden WiFi network is case-sensitive. Enter it exactly as configured on the router.

5.2.2.6 Resetting Network Settings

Network Reset restores the device network settings to their defaults.

  1. Go to Setting > Network setting.
  2. Tap Network Reset.
  3. Tap Reset in the confirmation window.
  4. Reconfigure WiFi or Ethernet after the reset.

5.2.3 Completing Device Authorization

5.2.3.1 Authorization Preparation

Complete the following preparations before authorization:

  • Confirm whether the device was permanently authorized at the factory. A permanently authorized device does not require on-site authorization.
  • If the device has not been authorized or its authorization has expired, contact Sales or Technical Support for an authorization QR code.
  • Online authorization is recommended by default. Confirm that the device can access the authorization service.
  • Use offline authorization only as a fallback in exceptional cases.
  • Print the authorization QR code on paper so that the device camera can scan it more easily.

When requesting an authorization QR code, provide the APP ID and specify the number of devices, authorization term, and whether online or offline authorization is required.

5.2.3.2 Online and Offline Authorization

Authorization methodNetwork requirement during authorizationUse case
Online authorizationThe device must be able to access the authorization service over the network.Recommended by default for network-connected deployments.
Offline authorizationAuthorization information is embedded in the QR code, so injecting it by scanning does not require a network.A fallback for exceptional cases involving a completely offline standalone device.

Description

An offline authorization QR code already contains the authorization information, so scanning and injecting it does not require a network. IoT activation, configuration synchronization, and online services still require network access.

For online authorization, identify the device's access path based on the deployment network:

  • If the device can access the Internet, it can access the authorization service directly or complete authorization and authentication through the Backend Service Gateway.
  • If the device is on a LAN with Internet access, it can reach the authorization service through the Backend Service Gateway on the same network.
  • If neither the device nor the Backend Service Gateway can access the Internet, confirm that a working local authorization service has been deployed for the project. Otherwise, use offline authorization.

5.2.3.3 Scanning the Authorization QR Code

  1. On the Device authorization page, confirm that the current status is Unauthorized, then tap Scan the QR code.
  2. Hold the authorization QR code approximately 10 cm from the palm scan camera module.
  3. Wait for the device to scan the code.
  4. After the scan succeeds, wait for the module to restart automatically.

After the module restarts, the device displays the authorization result and validity period. If authorization fails, return to the authorization page and scan again. If it fails repeatedly, check the QR code, device time, and network, then contact After-Sales Support.

5.2.3.4 Viewing Authorization Status

After authorization succeeds, the device displays Authorization successful. You can subsequently go to Setting > Authorization, confirm that the status is Authorization Active, and view Authorization status, Validity period, APP ID, and Authorization path. When authorization expires, obtain a new authorization QR code and authorize the device again.

5.2.4 Registering a Device in the Admin Console

  1. Log in to the Admin Console and go to Device Management > Device List.
  2. Click Add Device.
  3. Enter a device name and the Device SN shown on the device label.
  4. Verify the information, then click Submit.
  5. Return to the device list and confirm that the device name and Device SN are correct.

The Device SN uniquely identifies the device and cannot be changed after entry. For batch device registration, see "3.1.1.1 Device Registration" in the Admin Console User Manual.

5.2.5 Activating the Device and Binding the Admin Console Environment

After registering the device, complete IoT activation to connect it to the current Admin Console environment.

  1. Confirm that the device has completed License authorization, is connected to the network, and has been registered in the current Admin Console.
  2. On the Device List page in the Admin Console, click Device Activation to generate an activation QR code.
  3. Scan the activation QR code with the M3.
  4. After activation succeeds, return to the device list and confirm that the device status has changed from not activated to online or offline.

For the complete activation QR code procedure, see "3.1.1.2 Device Activation and Environment Binding" in the Admin Console User Manual.

Note

Activation QR codes expire. If a code has expired, generate a new one in the Admin Console.

If activation fails, follow the applicable instruction:

  • This device is not registered: Confirm that the Device SN has been entered in the Admin Console.
  • The QR code is not a valid activation code: Confirm that you scanned a device activation QR code.
  • This activation code has expired: Generate a new activation QR code.
  • Network error or prolonged lack of response: Check the device network and try again.

5.2.6 Associating the Device with a Scene

After activation, associate the device with the scene where it will be used.

  1. Log in to the Admin Console and go to Verification > Scene Management.
  2. Select the target scene group.
  3. Locate the target scene and click Edit. If it does not exist, click Add Scene.
  4. Select the M3 under Associated device.
  5. Select a recognition strategy under Scene Strategy.
  6. To restrict users and access times, enable Verification Rule and select a verification rule.
  7. Click Submit.

A device cannot be associated with multiple scenes at the same time. To change its scene, first remove it from Associated device in the original scene, then add it to the new scene.

For instructions on creating and editing scenes, see "3.2.2 Scene Management" in the Admin Console User Manual. For rules covering authorized users, valid dates, blocked dates, and time periods, see "3.4 Verification Rules."

5.3 Basic Device Settings

This section describes language, volume, time, password, device information, and restart settings.

5.3.1 Opening the Setting Page

  1. Tap the settings button in the upper-left corner of the device home page.

  1. Enter the device settings password in the Please input password window. The initial password is 000000.
  2. Tap Confirm to open the Setting page. To cancel, tap Cancel.

5.3.2 Setting the Device Language

  1. Go to Setting > System setting.
  2. Tap Language.
  3. Select the desired language.

A selection indicator appears next to the current language.

5.3.3 Setting the Device Volume

  1. Go to Setting > System setting.
  2. Locate the volume slider.
  3. Drag the slider left or right to adjust the volume of voice prompts and notification sounds.

5.3.4 Viewing and Synchronizing Device Time

  1. Go to Setting > Time Configuration.
  2. View Time Zone and Current Time.
  3. To synchronize the time again, tap Resync Time.
  4. After synchronization succeeds, confirm that the device time is correct.

You can only view and resynchronize the time on the device; you cannot change the time zone directly. After the device is activated for the current tenant, its time zone is synchronized with the time zone configured in the Admin Console. A super administrator manages that setting under System > System Settings > Timezone Settings.

5.3.5 Changing the Device Settings Password

  1. Go to Setting.
  2. Tap Password.
  3. Enter a new password.
  4. Tap Confirm.

Note

Store the new password securely. If you forget it, contact After-Sales Support to reset it.

5.3.6 Viewing Device Information

Go to Setting > Device information to view the current tenant, scene, service endpoint, Device SN, IP address, Ethernet MAC, WLAN MAC, and other information.

To view component versions, return to the Setting page and scroll down:

EntryInformation displayed
System updateSystem version
App updateApplication version
Module updateModule version
Algo updateAlgorithm version

5.3.7 Restarting the Device

The M3 supports scheduled automatic restarts, restarts from the Setting page, and restarts using the concealed reset button.

Configure automatic restart

  1. Go to Setting > Soft reboot.
  2. Enable Soft reboot mode.
  3. Select a start time under Select start time.
  4. Tap Confirm.

Each day, the device automatically restarts within the configured time range when no one is performing a palm scan. Enable this feature for devices that run continuously for long periods.

The device selects an idle period within one hour after the chosen start time to restart, minimizing disruption to on-site operations.

To disable automatic restart, turn off Soft reboot mode, then tap Confirm.

Restart from the Setting page

  1. Open the Setting page and scroll to the bottom.
  2. Tap Device Restart.
  3. Tap Restart in the confirmation window and wait for the device to restart.

5.4 Service Activation and Palm Scan

5.4.1 Switching Device Registration and Recognition Modes

The M3 supports four registration methods: phone scan QR, device input, device scan QR, and Mobile Palm Registration. Select mode on the device currently provides only the following four options:

  • Recognition
  • Registration - Phone Scan QR
  • Registration - Device Input
  • Registration - Device Scan QR

Mobile Palm Registration is not a separate device registration mode. The user first preregisters a palm through a mobile App or the Mobile Palm Registration H5 page, then activates it with the first palm scan in Recognition mode.

Registration methodDescriptionDevice mode
Phone Scan QR RegistrationThe device captures the palm first. The user scans the QR code displayed by the device with a phone and enters user information.Registration - Phone Scan QR
Device Input RegistrationThe device captures the palm first, after which the user information is entered on the device.Registration - Device Input
Device Scan QR RegistrationThe user first generates a QR code on the H5 registration page. After capturing the palm, the device scans that QR code.Registration - Device Scan QR
Mobile Palm RegistrationThe user preregisters a palm through a mobile App or the Mobile Palm Registration H5 page, then activates it with the first palm scan on the device.Recognition

To switch modes:

  1. Go to Setting.
  2. Tap Mode.
  3. Select the target mode under Select mode.

Before using a registration feature, confirm that the device has been authorized, connected to the network, activated through IoT, and associated with a scene. In a closed scene, an administrator must first create the user in the Admin Console. The User ID and Username entered during registration must match the Admin Console records. For instructions, see "3.5.1 Create User" in the Admin Console User Manual.

The administrator must also edit the current tenant under System > Tenant Management and enable the registration methods required by the project. For complete tenant registration settings, see "3.9.1 Create Tenant" and "3.9.3 Edit Tenant" in the Admin Console User Manual.

5.4.2 Phone Scan QR Registration

  1. Under Setting > Mode, select Registration - Phone Scan QR.
  2. Hold an unregistered palm over the palm scan camera module and follow the device prompts to complete capture.
  3. After the palm is captured, the device displays a registration QR code.

  1. Scan the QR code displayed by the device with a phone.
  2. Enter User ID, Username, and other information on the phone registration page.
  3. Tap Submit.

  1. Confirm that the phone page reports a successful submission and the device reports successful registration.

5.4.3 Device Input Registration

  1. Under Setting > Mode, select Registration - Device Input.
  2. Hold an unregistered palm over the palm scan camera module and follow the prompts to complete capture.

  1. After the palm is captured, tap Enter ID.

  2. Enter User ID and Username.

  1. Tap Confirm.

  2. Confirm that the device reports successful registration.

5.4.4 Device Scan QR Registration

For the complete procedure for generating a registration QR code on the H5 page, see "4.8 Device Scan QR Registration" in the Mobile Application User Manual.

  1. Open the H5 registration page provided for the current project.
  2. Enter User ID, Username, mobile number, and other information to generate a registration QR code.

  1. Under Setting > Mode on the device, select Registration - Device Scan QR.
  2. Hold an unregistered palm over the palm scan camera module and follow the prompts to complete capture.
  3. When the device opens the QR code scan page, hold the H5 registration QR code in front of the camera.
  4. After the scan succeeds, verify the user information displayed by the device.
  5. Tap the confirm button to complete registration.

Note

A registration QR code is valid for 15 minutes. If it expires, generate a new one on the H5 registration page. If scanning fails, clean the camera and increase the clarity of the phone display before trying again.

5.4.5 Mobile Palm Registration

With Mobile Palm Registration, a user preregisters a palm using a phone camera through a mobile App or the Mobile Palm Registration H5 page, then activates the palm by performing the first palm scan on the M3. After mobile preregistration, the palm cannot yet be used for normal verification.

Prerequisites

  • Mobile Palm Registration has been enabled for the current tenant in the Admin Console.
  • In an open scene, an administrator does not need to create the user in advance. The system creates the user automatically when registration information is submitted in the App.
  • In a closed scene, an administrator has created the user in the Admin Console. The user information entered in the App must match the Admin Console records.
  • The user has installed a mobile App that supports Mobile Palm Registration or can access the Mobile Palm Registration H5 page.

This section uses the PalmMa demo App connected to the Indonesia production environment to illustrate Mobile Palm Registration. You can also experience the same process through the Mobile Palm Registration H5 page. These entry points are provided only for feature evaluation and integration reference. To implement Mobile Palm Registration in a customer service, integrate the Mobile Palm Registration App SDK or H5 SDK by following the Palm Developer documentation and develop the required features. Pages, processes, and environment settings for a production project depend on the customer's actual integration.

For the complete procedures for mobile preregistration, viewing palm status, and managing two palms, see "4.5 Mobile Palm Registration and Palm Management" in the Mobile Application User Manual.

Log in to the PalmMa demo App or Air Enrollment H5

  1. Open the PalmMa demo App or the Air Enrollment H5 page, then enter User ID.
  2. Select a tenant name. Available tenants include open tenants and closed tenants that already contain this User ID. You can check whether a tenant uses an open scene or a closed scene in PalmAI Admin Web under System Management > Tenant Management.
  3. Read and accept the privacy agreement, then tap Submit to open the feature home page.

Preregister the first palm

  1. Tap Registration on the feature home page.

  1. In an open scene, enter a username in the Enter user name dialog during the first registration, then tap OK. The system creates the user and opens the Palm Registration page. In a closed scene, the system uses the user information already created in the Admin Console.

  1. Ensure that the area is well lit and the camera is clean, then tap Scan Palm.

  1. Scan the palm with the phone's rear camera and follow the on-screen prompts to open the hand, make a fist, and complete the other required actions in sequence.

  1. When the page displays Activate your palm, tap Done.

  1. Open the My Palm page and confirm that the preregistered palm is marked Not Activated.

Activate the palm on the M3

  1. Confirm that the M3 has been authorized, connected to the network, activated in the Admin Console environment, and associated with a scene.
  2. Under Setting > Mode on the M3, select Recognition.
  3. Perform the first palm scan with the preregistered palm and wait for the device to display the palm scan success page.

  1. Return to the PalmMa demo App, open My Palm, and tap the corresponding palm. Confirm that its status is now Activated. The first palm activated is marked Main.

Preregister and activate the second palm

  1. Open My Palm and tap Palm Registration or the position for the palm that has not been registered.
  2. Follow the preceding steps to preregister the other palm.
  3. Confirm that the first palm is marked Activated and the newly preregistered palm is marked Not Activated.

  1. Switch the M3 to Recognition, then perform the first palm scan with the second palm to activate it.
  2. Return to My Palm and confirm that both palms are marked Activated. The first palm activated is the Primary Palm, and the palm activated later is the Secondary Palm.

If the device reports that the palm is not registered, confirm that mobile preregistration succeeded. If it reports no access permission or an invalid access time, ask an administrator to check the scene and verification rule. If it reports a network error, restore the network and perform another palm scan.

5.4.6 Primary and Secondary Palm Rules

The same user can register both the left and right palms. To register the second palm, use the same registration method and submit the same user's information.

  • The first palm activated is marked as the Primary Palm, Primary.
  • The other palm, registered and activated later, is marked as the Secondary Palm, Secondary.
  • Either the left or right palm can be the Primary Palm. Primary and Secondary Palm status depends on activation order.
  • If a palm in the same direction has already been registered, the system rejects duplicate registration.
  • When Dual Palm Registration is enabled, each user can consume up to two Palm Database Quota units.

5.4.7 Performing Daily Palm Scan Verification

Prerequisites

  • The device has been authorized, connected to the network, activated through IoT, and associated with a scene.
  • The scene strategy, verification rule, and user access permissions have taken effect.
  • The user has completed Palm Registration. A Mobile Palm Registration user has completed initial activation on the device.
  • When access control output is used, the user has a Physical Card Number, and the device output matches the controller configuration.

Procedure

  1. Go to Setting > Mode.
  2. Under Select mode, select Recognition.
  3. Return to the device home page.
  4. Extend a registered palm naturally with its center facing the center of the palm scan camera module.
  5. Keep the palm approximately 5–12 cm from the device.
  6. Wait for the device to complete capture and verification.
  7. View the verification result. If Additional Verification is triggered, follow the on-screen prompts to complete the additional identity check.

After successful verification, the device displays the success page and turns on the green light. When a user with two registered palms verifies with either activated palm, the device can display Left Hand or Right Hand.

The NFC card reader area can be used to swipe an access card, but its capability depends on the on-site access control configuration. The presence of the NFC area does not mean that the device provides a separate card registration process.

5.4.8 Configuring High-Similarity Deduplication During Registration

High-similarity deduplication determines during registration whether the current palm is highly similar to an existing palm. This feature affects only Palm Registration results and is separate from Additional Verification after a palm scan.

An administrator configures this feature in the Admin Console:

  1. Go to System > Tenant Management.
  2. Locate the current tenant and click Edit.
  3. Locate High Similarity Deduplication and configure the High Similarity Dedup switch.
  4. Click Submit to save the setting.

The switch has the following effects:

High Similarity Dedup enabled

If the system detects a highly similar palm during Palm Registration, it rejects the registration. The M3 displays Palm Already Registered, and the User Status in the Admin Console is Unregistered.

High Similarity Dedup disabled

When a highly similar palm is registered, the M3 still reports successful registration, but the User Status in the Admin Console is Abnormal.

For complete tenant configuration procedures, see "3.9.1 Create Tenant" and "3.9.3 Edit Tenant" in the Admin Console User Manual.

5.4.9 Using Additional Verification

Additional Verification is an additional identity check performed after a palm scan. The device supports three methods: the last four digits of a mobile number, a custom numeric field, and device QR code scanning.

An administrator edits the tenant under System > Tenant Management and configures Verification Method under Verification Configuration. For the complete tenant-level Additional Verification procedure, see "3.9.4 Tenant-Level Additional Verification Configuration" in the Admin Console User Manual.

Verification Method supports:

  • Last 4 Digits of Phone Number
  • Custom Field
  • Device QR Code Scan

When Custom Field is selected, specify the user field to be used for Additional Verification. When Device QR Code Scan is selected, you can configure QR Code Expiration.

5.4.9.1 Additional Verification Using the Last Four Digits of a Mobile Number

  1. The administrator confirms that a mobile number is present in the user's information.
  2. The user completes a palm scan.
  3. When the device displays the numeric input page, enter the last four digits of the mobile number.
  4. Submit the information and wait for the system to complete the additional identity check.

5.4.9.2 Additional Verification Using a Custom Numeric Field

A custom numeric field supports 4–8 digits.

  1. In the tenant settings, the administrator specifies the active field and maintains a corresponding field value for each user.
  2. The user completes a palm scan.
  3. When the device displays the numeric input page, enter the corresponding number.
  4. Tap the confirm button.
  5. View the Additional Verification result. If verification fails, verify the user's field value and try again.

5.4.9.3 Additional Verification by Device QR Code Scan

For the complete procedure for generating an authentication QR code on the H5 page, see "4.9 Additional Verification by Device QR Code Scan" in the Mobile Application User Manual.

  1. The user completes a palm scan.
  2. The device prompts the user to present an authentication QR code and activates the camera.
  3. The user opens the H5 Additional Verification page provided for the current project and follows the page instructions to generate an authentication QR code.
  4. Hold the authentication QR code in front of the device camera.
  5. The device completes Additional Verification after scanning the code successfully.

Note

The validity period of an authentication QR code is configured in the Admin Console and defaults to 60 seconds. If either the QR code or the device's scan wait period expires, perform another palm scan and generate a new authentication QR code.

5.4.10 Configuring Access Control Output and Opening the Door

The M3 can output a door-open signal to an access controller through a relay or Wiegand. Before using Wiegand, an administrator must assign the user a Physical Card Number. This can be an actual card number or a virtual number assigned by the service.

5.4.10.1 Assigning a Physical Card Number to a User

  1. Log in to the Admin Console and go to User Management > User List.
  2. Locate the target user and click Edit.
  3. Enter the Physical Card Number in Physical card number.
  4. Save the user information.

For creating an individual user and entering a Physical Card Number, see "3.5.1 Create User" in the Admin Console User Manual. To modify an existing user, see "3.5.2 Edit User."

Note

M3 access control recognition requires a Physical Card Number for the user. Without one, a palm may register successfully, but a subsequent palm scan may report that no Physical Card Number was read and fail to open the door.

5.4.10.2 Selecting an Output Method

  1. Go to Setting.
  2. Tap Output.
  3. Select an output method under Access Mode. For Wiegand, select the format that matches the access controller:
    • Relay
    • Wiegand 26bit
    • Wiegand 32bit
    • Wiegand 34bit
    • Wiegand -26bit
    • Wiegand -32bit
    • Wiegand 64bit
    • Wiegand -64bit
    • Wiegand 66bit
    • Wiegand -66bit

When Relay is selected, confirm that the relay's NO, NC, and COM wiring matches the door lock type. When Wiegand is selected, confirm that D0, D1, and GND are wired correctly.

5.4.10.3 Setting Physical Card Number Byte Order

  1. Go to Setting.
  2. Tap Card Uid Rule.
  3. Under Select Endian, select:
    • Big Endian
    • Little Endian

The controller parses the same Physical Card Number differently under different byte orders. The byte order must match the access controller's card-number parsing rule.

5.4.10.4 Checking the Wiegand Bit Length

After conversion to binary, the decimal Physical Card Number entered in the Admin Console must not exceed the data-bit capacity of the selected Wiegand format:

Output formatMaximum Physical Card Number bit length
Wiegand 26bit24 bits
Wiegand -26bit26 bits
Wiegand 32bit30 bits
Wiegand -32bit32 bits
Wiegand 34bit32 bits

When using a 64-bit or 66-bit format, also confirm that the controller supports the format and that the card number does not exceed its data capacity.

After completing the settings, test with a registered user who has access permission. Check all of the following:

  • The device reports successful verification.
  • The access controller receives the correct card number.
  • The controller parses the bit length and byte order correctly.
  • The turnstile or door lock operates as configured.

5.4.10.5 Opening the Door with a Card or Palm Scan

After configuring the access control wiring, user Physical Card Number, and access permissions, verify door opening with an access card or registered palm:

  1. Hold the access card near the NFC card reader area, or hold a registered palm over the palm scan camera module.
  2. Wait for the device to read the card number or complete palm scan verification.
  3. Confirm that the device outputs a relay or Wiegand signal according to the current Access Mode.
  4. Confirm that the access controller receives the signal and opens the door lock or turnstile.

Card availability and card-number permissions depend on the on-site access control configuration. The M3 does not provide a separate card registration process.

5.4.11 Reporting and Viewing Verification Records

After the device is online and associated with a scene, it uploads verification results to the Palm Application Platform.

  1. Log in to the Admin Console and go to Verification > Verification Records.
  2. Filter records by time range, scene, User ID, Username, verification status, or source.
  3. Click Search.
  4. View the verification time, verification status, user, scene, verification method, and Device SN.
  5. To save records, export the verification records within the current permission scope.

Device reporting of Verification Records and platform pushes to a third-party system are separate processes. Third-party pushes are configured under Verification Record Push for the tenant. For complete field descriptions, see "3.9.1 Create Tenant" and "3.9.3 Edit Tenant" in the Admin Console User Manual.

5.5 Device Configuration and Routine Maintenance

5.5.1 Configuring and Distributing a Custom UI

An administrator can configure the device home page, verification success page, verification failure page, and result countdown in the Admin Console, then distribute the configuration by scene or Device SN.

  • By Scene: Applies to devices in the selected scene.
  • By Device SN: Applies only to the selected device.

The device checks for Theme Package changes every 10 minutes. When it detects an update, it downloads the package in the background and prompts the user to apply it after the download completes. If no template is configured or the current template has been deleted, the device uses the system default style. The device cannot obtain updates while it is offline or powered off, but will retrieve them during a subsequent check after network connectivity is restored.

After the Theme Package is downloaded, the device indicates that it will apply the new theme automatically in 10 seconds. To apply it immediately, tap the button on the page for immediate use. If the current theme template is deleted, the device automatically restores the system default style.

For the complete procedure, see "3.1.2 Device Configuration" in the Admin Console User Manual.

5.5.2 Running Device Health Check

Device Health Check actively checks the device's current condition. It is not the same as continuous status monitoring in the Admin Console.

  1. Go to Setting.
  2. Tap Device Health Check.
  3. Wait for the device to finish the check.

  1. If the check finishes without detecting an issue, confirm that the page displays Device Normal.
  2. Tap View Report to view the results. To run the check again, tap Re-check.

  1. To view the report on a phone, scan the QR code under Scan to View Report.

5.5.3 Viewing Device Operating Status

An administrator can search for a device by Device SN or device name under Device Management > Device List, then view its online status, component status, resource health information, and versions.

For complete descriptions of the device list and device dashboard, see "3.1.1 Device List" and "3.8.2 Device Dashboard" in the Admin Console User Manual.

5.5.4 Reporting a Device Issue

If registration or palm scan fails, or if a result or interface is abnormal, you can report the issue from the device.

  1. Tap Report technical issue on the verification failure page.

  1. Select the issue type that matches the on-site situation:
    • Palm Scan Failed for Registered User
    • Palm Scan Failed for Unregistered User
    • Registration Failed
    • Palm Scan Result Does Not Match
    • Abnormal Interface Display
    • Palm scan took too long
    • Other Issues

  1. Tap Report.
  2. When the device displays Collecting app logs, wait for log collection and reporting to finish.

  1. When the page displays The issue has been reported, the issue has been reported successfully.

An administrator can view issue reports in the Admin Console. For details, see "3.7.1 Issue Reporting" in the Admin Console User Manual.

5.5.5 Viewing Device Logs

Device Logs require the cloud platform logging service to be enabled.

  1. Log in to the Admin Console and go to Device Management > Device Logs.
  2. Filter by Log ID, Log Date, Device, or Status.
  3. Locate the target log and click Download Logs.

For details, see "3.1.4 Device Logs" in the Admin Console User Manual.

5.5.6 Remote Device Maintenance

An administrator can issue remote commands to online devices from the Admin Console:

  1. Go to Device Management > Device Instruction.
  2. Select a command tab.
  3. Click Send Instruction.
  4. Select the target device and enter the required parameters.
  5. Click Submit.
  6. Return to the command list to view the execution status.

Common remote commands supported by the M3 include:

Command tabFunction and considerations
Device RestartRestarts the entire device remotely.
App RestartRestarts the device application remotely; this does not restart the entire device.
Factory ResetRestores the device to factory settings remotely.
Reset Palm FeaturesResets palm print features on the device.
Reset Blacklist DataResets blocklist data on the device.
Clear Local DataClears local device data.
WiFi SettingsDistributes a WiFi name and password remotely.
Remote Door OpenOpens an access-controlled door remotely; supported only on the M3.

For the complete remote command procedure, see "3.1.5 Remote Commands" in the Admin Console User Manual.

Warning

Remote clearing, reset, and door-opening operations pose security risks. Before issuing a command, confirm the target device, on-site conditions, and operator permissions.

5.5.7 OTA Upgrades and Version Maintenance

The M3 supports OTA tasks distributed from the Admin Console and manual installation of distributed upgrades on the device. The upgradable components are system firmware, module firmware, the application, and algorithm packages.

Before an upgrade, confirm that the device has a stable power supply and remains online. Do not disconnect power or trigger another upgrade during an upgrade or automatic restart.

5.5.7.1 Uploading an Upgrade Package

Before creating an Upgrade Campaign, upload the appropriate component Upgrade Package supplied by the manufacturer to the Admin Console:

  1. Log in to the Admin Console and go to Device Management > Upgrade Package.
  2. Click Add Upgrade Package.
  3. Select and upload the Upgrade Package, enter the version notes, and submit it.
  4. After the upload completes, confirm the version, device model, and other information in the Upgrade Package list.

Upgrade Packages are provided by the original manufacturer's Technical Support team. For instructions on adding, viewing details of, and deleting an Upgrade Package, see "3.1.6 Upgrade Package Management" in the Admin Console User Manual.

5.5.7.2 Creating an Upgrade Task

  1. Log in to the Admin Console and go to Device > Device OTA.
  2. Click Add Upgrade Campaign.
  3. Enter the campaign name, type, model, target version, task validity period, and release notes.
  4. Click Submit.
  5. In the campaign details, click Add Task.
  6. Select all devices or specific devices, then configure Silent Upgrade.
  7. Validate the devices and submit the task.

For the complete procedure, see "3.1.3 Device OTA" in the Admin Console User Manual.

5.5.7.3 Silent and Active Upgrades

Upgrade methodAdmin Console settingDevice behavior
Silent upgradeEnable Silent UpgradeThe device downloads and installs the task automatically after receiving it.
Active upgradeDisable Silent UpgradeAfter receiving the task, on-site personnel tap Upgrade on the corresponding update page.

For an active upgrade:

  1. Open the Setting page and scroll down.
  2. Tap the component entry that shows an update notification.
  3. View the target Version and Upgrade content:.
  4. Tap Upgrade.
  5. Wait for the device to complete installation and restart automatically.

5.5.7.4 Upgrading the System, Module, Application, and Algorithm Package

Open the page for the component to be upgraded, view the current version, and follow the procedure in "5.5.7.3 Silent and Active Upgrades."

Upgrade targetDevice entryDescription
Main controller system firmwareSetting > System updateWait for the device to restart automatically after installation.
Biometric module firmwareSetting > Module updateA module firmware Upgrade Package can include an algorithm package, depending on the package selected in the Admin Console.
Device applicationSetting > App updateAfter installation and automatic restart, open App update again and confirm that the version was updated.
Algorithm packageSetting > Algo updateAlgorithm packages can be upgraded independently. When creating an Upgrade Campaign, set Campaign Type to Algorithm. An algorithm can also be updated with a module firmware Upgrade Package.

For multiple upgrades, use the following order:

Module updateSystem updateApp update

Wait for each installation and restart to complete before proceeding to the next. Algorithm packages can be upgraded independently or included in a module firmware Upgrade Package.

5.5.7.5 Viewing Upgrade Results

After an upgrade, go to Setting and confirm the current version under Module update, System update, App update, or Algo update, as applicable. In the Admin Console, you can view task distribution progress, device upgrade status, and failure reasons.

5.6 Device Cleanup and Decommissioning

5.6.1 Clearing and Resetting the Device

5.6.1.1 Using Data Reset

  1. Go to Setting > Device information.
  2. Tap Data Reset.
  3. Under Reset type, select:
    • Clear palm and user info
    • Clear all app data
  4. Tap Confirm.

Warning

Data Reset deletes data within the selected scope and cannot be undone. Before proceeding, confirm that service operations have stopped and that all necessary data checks are complete.

5.6.1.2 Using Factory Reset

To restore the device to factory settings, go to Setting > System setting, tap Factory Reset, and confirm the operation.

Warning

Factory Reset clears device settings and service data. Afterward, you must reconfigure the network, authorization, IoT activation, and service settings. Use this feature only when decommissioning the device or under guidance from After-Sales Support.

The Admin Console also provides remote commands such as Reset Palm Features, Clear Local Data, and Factory Reset. For the distribution procedure, see "5.5.6 Remote Device Maintenance."

5.6.2 Deleting a Device from the Admin Console

Before deleting a device, disassociate it from its scene. The Admin Console prevents deletion while the device is still associated with a scene.

  1. Edit the original scene under Verification > Scene Management.
  2. Remove the target device from Associated device and save the scene.
  3. Go to Device Management > Device List.
  4. Locate the target device by Device SN or device name.
  5. Click Delete and confirm.

For the complete device deletion procedure, see "3.1.1.4 Delete Device" in the Admin Console User Manual.

After a device is deleted, its Palm Feature Database and rules are removed, and the device can no longer perform palm scans. Existing historical Verification Records are unaffected.

Warning

Before deleting a device, confirm that it no longer supports an active service and notify affected users in advance.

5.7 FAQ

5.7.1 The Device Has No Display After Power-On

  1. Confirm that you are using the 12 V power adapter supplied with the device.
  2. Check that the power outlet, power adapter, and device power cable are securely connected.
  3. Confirm that the adapter output meets the device requirements.
  4. Reconnect the power. If the display remains blank, contact After-Sales Support.

5.7.2 The Device Reports That It Is Not Registered or Not Activated

  1. Confirm the Device SN on the device label or under Device information.
  2. Ask an administrator to confirm that this Device SN has been entered in the Admin Console.
  3. After confirming that the device is online, scan a valid IoT activation QR code again.
  4. If the device has been activated but still reports that it is not registered after a restart, tap the retry button on the page.
  5. If the page does not respond, press the concealed reset button on the left side with a paper clip to restart the device.
  6. If the issue persists, contact After-Sales Support.

5.7.3 A Registered User Is Told That No Physical Card Number Was Read

The M3 access control service requires a Physical Card Number for each user. Ask an administrator to open the user edit page, enter an actual card number or a virtual card number assigned by the service in Physical card number, save the change, and perform another palm scan.

5.7.4 No Wiegand Output or the Door Does Not Open

  1. Confirm that the user's palm scan verification succeeded and the user has access permission for the current scene.
  2. Confirm that the user has a Physical Card Number.
  3. Check the 12 V, GND, D0, and D1 wire sequence. Confirm that D0 and D1 are not reversed and that the device and controller share a common ground.
  4. Go to Setting > Output and confirm that the correct Wiegand format is selected under Access Mode.
  5. Confirm that the device and controller use the same Wiegand bit length.
  6. Under Card Uid Rule, confirm that the byte order matches the controller.
  7. Check for loose or poorly connected terminals.

5.7.5 Wiegand Output Is Unstable

  • When using RVV 0.5 cable, keep the transmission distance within 100 m.
  • When transmitting over a single conductor in a CAT5e cable, keep the distance within 50 m.
  • For a long Ethernet cable carrying GND, D0, and D1, reinforce the ground connection.
  • Keep signal cables away from high-voltage power and interference sources, and confirm that the device and controller share a common ground.

5.7.6 The Access Controller Parses an Incorrect Card Number

  1. Convert the Physical Card Number entered in the Admin Console to binary and confirm that it does not exceed the data-bit capacity of the selected Wiegand format.
  2. Select the correct format according to "5.4.10.4 Checking the Wiegand Bit Length."
  3. Under Card Uid Rule > Select Endian, switch between Big Endian and Little Endian to match the controller's parsing rule.
  4. Perform another palm scan and verify the card number received by the controller.

5.7.7 RS485 Communication Is Abnormal

  1. Check whether the positive and negative RS485 terminals are reversed, and ensure that all devices share a common ground.
  2. Use 0.5–0.75 mm² shielded twisted-pair cable.
  3. Use a daisy-chain bus topology, avoid star branches, and keep the bus away from high-voltage lines.
  4. Keep the bus within 1,200 m. A repeater is recommended when the length exceeds 500 m.
  5. Connect a 120 Ω termination resistor at the end of the bus as required by the controller.

5.7.8 The Relay Opens the Door in the Opposite Direction

  1. Determine whether the lock is fail-safe or fail-secure.
  2. Check the NO, NC, and COM wiring on the access control power supply.
  3. Test the lock with power disconnected and confirm that its behavior meets on-site fire safety and security requirements.
  4. If the correct wiring remains unclear, disconnect power and contact qualified access control personnel.

5.7.9 Does the Device Support PoE Power?

The M3 does not support PoE power. Use the supplied 12 V power adapter.

5.7.10 Ethernet Does Not Work

  1. Go to Setting > Network setting > WiFi and turn off the wireless network.
  2. Check the Ethernet cable, RJ45 connectors, router, and switch ports.
  3. Confirm that both ends of the Ethernet cable use the same standard wire sequence.
  4. Under Ethernet, confirm that the network is enabled and check the DHCP or Static configuration.

Enabling Ethernet and WiFi on the M3 at the same time causes a conflict. WiFi must be turned off when using a wired network.

5.7.11 Cannot Find or Connect to WiFi

  1. Move closer to the wireless router and eliminate metal obstructions and weak-signal conditions.
  2. Some production batches support only 2.4 GHz. Confirm that the router has 2.4 GHz enabled.
  3. A dual-band device may have compatibility issues with an unsecured 5 GHz network. Set a password or use 2.4 GHz.
  4. Use a WiFi password containing letters and numbers, and avoid special characters.
  5. When connecting to an iPhone hotspot, you can enable "Maximize Compatibility" and change the phone name to contain only English letters or digits.
  6. If WiFi is connected but cannot access the network, confirm that Ethernet is disabled and that the router has Internet access.

5.7.12 The Device Application Freezes or the Screen Goes Black

  1. Wait for the device application to recover automatically.
  2. If it does not recover, press the concealed reset button on the left side to restart the device.
  3. Go to Setting > App update and check for available updates.
  4. If the issue recurs, report the device issue and contact After-Sales Support.

5.7.13 OTA Upgrade Is Abnormal

  1. Confirm that the device has a stable power supply and remains online. Prefer a wired network.
  2. Check whether the Upgrade Task has expired or another task of the same type is in progress.
  3. Wait for the current task to finish before trying again. Do not trigger multiple upgrades simultaneously.
  4. For multiple component upgrades, use the order Module updateSystem updateApp update, waiting for each restart to finish before continuing.
  5. If a download times out, restore a stable network and try again.
  6. Do not disconnect power during installation. If the device cannot start normally or repeatedly fails, contact After-Sales Support.

5.7.14 Authorization Fails or Has Expired

  1. Distinguish License authorization from IoT activation. An abnormal authorization page relates to the License; a report that the device is not registered or that the activation code is invalid relates to IoT activation.
  2. For online authorization, check the network and device time.
  3. Confirm that the authorization QR code corresponds to the current device and APP ID and remains valid.
  4. If authorization has expired, contact Sales or Technical Support for a new authorization QR code.
  5. Repeated authorization may consume the available Number of Licenses. Confirm the license quantity before proceeding.

5.7.15 Palm Scan Is Slow or Recognition Fails

  1. Remove the protective film from the camera and clean the camera area.
  2. Keep the palm center clean and free of visible dirt or perspiration.
  3. Hold the palm 5–12 cm from the device with its center facing the camera.
  4. Avoid strong backlight, obstructions, rapid movement, and excessive tilt.
  5. Check the device's network quality.
  6. After repeated failures, ask an administrator to check the user's registration status, scene permissions, and palm print data.

5.7.16 Palm Scan Succeeds but No Verification Record Is Found

  1. Confirm that the device is online and has completed IoT activation.
  2. Confirm that the device is associated with the correct scene.
  3. Confirm that the user has completed Palm Registration and activation.
  4. Confirm that the verification rule and Additional Verification settings have taken effect.
  5. Under Verification Records, check the time, scene, and user filters.

5.7.17 H5 Registration or Device Scan QR Registration Fails

  1. Ask an administrator to confirm that the user has been created in the Admin Console and that the User ID, Username, mobile number, and other information match the H5 entries.
  2. A registration QR code is valid for 15 minutes. Generate a new one after it expires.
  3. Confirm that the device is online.
  4. Clean the device camera and increase the clarity of the phone display.
  5. Confirm that the device is in Registration - Device Scan QR mode.

5.7.18 Phone Scan QR Registration Fails

  1. Confirm that the device is in Registration - Phone Scan QR mode.
  2. Confirm that the corresponding registration method is enabled for the tenant.
  3. In a closed scene, confirm that the user has been created in the Admin Console and that the information entered on the phone matches the Admin Console records.
  4. Capture the palm again and scan the new QR code generated by the device.

5.7.19 Additional Verification by Device QR Code Scan Fails

  1. Confirm that Device QR Code Scan has been selected for the tenant's Additional Verification.
  2. Check whether the authentication QR code has expired. Generate a new one if necessary.
  3. If the device has waited more than 60 seconds for a scan, perform another palm scan to trigger Additional Verification again.
  4. Clean the camera and increase the clarity of the phone display.
  5. Confirm that the user meets the registration and Additional Verification conditions for the current project.

5.7.20 The Device Still Reports an Unregistered Palm After Mobile Palm Registration

Mobile Palm Registration consists of mobile preregistration and device activation. After confirming that mobile preregistration succeeded, switch the device to Recognition and perform the first palm scan with the preregistered palm to activate it. Normal verification becomes available only after this initial activation.

5.7.21 The Device Settings Password Has Been Forgotten

The initial device password is 000000. If the password was changed and then forgotten, contact After-Sales Support to reset it. To prevent unauthorized settings changes, do not post the password near the device.

5.7.22 Device Health Check Reports Insufficient Disk Space

An insufficient disk space warning may affect OTA package download and installation.

  1. Pause new OTA Upgrade Tasks.
  2. Confirm whether routine palm scan functions operate normally.
  3. Report the device issue and contact After-Sales Support to clear storage space.
  4. After After-Sales Support confirms that space is available, distribute the Upgrade Task again.

5.7.23 There Is No Voice Prompt or the Volume Is Too Low

  1. Go to Setting > System setting and increase the volume.
  2. Check whether the speaker opening on the rear housing is obstructed by a bracket, decorative panel, or foreign object.
  3. Restart the device and test again.
  4. If there is still no sound, contact After-Sales Support.

5.7.24 What Is the Difference Between Registration and Recognition Modes?

  • Registration modes capture a palm and bind it to user information. They are not used for routine access verification.
  • Recognition is used for routine verification of registered users and for the first offline activation of Mobile Palm Registration users.

After completing batch user registration, switch the device back to Recognition.

5.7.25 A Palm Is Registered Twice or the Palm Database Is Full

If the device reports that a palm is already registered or is a duplicate, ask an administrator to determine whether the palm is already bound to another user. To register it again, delete the existing palm print record before capturing it again.

If the network and user information are normal but registration still fails, ask an administrator to check the tenant's Palm Database capacity. If it is full, delete unused palm prints or request a capacity increase.

5.7.26 The Device Reports User Not Found for a Registered User

  1. Confirm that the device's current tenant is the same tenant under which the user was registered.
  2. Confirm that the current scene's verification rule includes the user.
  3. If the user was just registered on another device, wait for feature synchronization and try again.
  4. If the issue persists, ask an administrator to check the User Status and contact After-Sales Support to resolve abnormal local feature synchronization.

5.7.27 Recognition Triggers High Similarity or Additional Verification

When the system cannot uniquely determine the user's identity, it may report High Similarity or require Additional Verification.

  1. Follow the device prompts to enter the last four digits of the mobile number or a custom numeric field, or complete Additional Verification by device QR code scan.
  2. If Additional Verification fails, confirm that the corresponding mobile number or custom field is present for the user in the Admin Console.
  3. If High Similarity is triggered frequently, capture higher-quality palm information and check for duplicate users or palm prints.

5.7.28 The Device Reports Restricted Access

After multiple Palm Liveness Detection failures within a short period, the system may temporarily restrict further recognition attempts.

  1. Wait for a period and try again.
  2. Adjust the palm scan distance and angle, keeping the palm center facing the camera.
  3. Avoid strong backlight and clean the camera.
  4. If normal operation continues to be restricted, ask an administrator to check the Blocklist status.

5.7.29 OTA Upgrades Cannot Be Performed on an Internal Network

The device must access the OTA service configured for the project to download Upgrade Packages. If the internal network restricts external access, ask an administrator to confirm the network policy, service address, and access permissions. If necessary, move the device to a network that can access the OTA service before upgrading.

5.7.30 The Remote Door Open Command Fails

  1. Confirm that the target device is an M3 and is currently online.
  2. Confirm that the administrator has remote door-opening permission and selected the correct device.
  3. Check the relay, Wiegand, access controller, and door lock wiring.
  4. View the execution status in the command list. If it failed, issue the command once more.
  5. If the command reports success but the door does not open, ask qualified access control personnel to inspect the controller and door lock circuit.

5.7.31 Installation Location and Waterproofing Requirements

The M3 is not waterproof. Install it indoors or in a sheltered semi-outdoor area away from rain, humidity, and strong backlight. For wall installation, a height of 1.4–1.6 m is recommended. Adjust it based on the average height of on-site users and the turnstile structure.

Use a wired network whenever possible. A wired network is generally more stable than WiFi. WiFi is not recommended as the standard connection for an on-site deployment of more than 10 devices.

5.7.33 What Are the Wired Network Cabling Requirements?

  • A single Ethernet cable segment must not exceed 100 m; keeping it within 80 m is recommended.
  • Do not place connectors in the middle of an Ethernet cable, and avoid sharp bends, compression, and high-voltage interference.
  • Use CAT5e or higher-grade cable and standard RJ45 connectors. Before installation, use a cable tester to confirm that the line works correctly.
  • Protect cables with PVC conduit or wiring ducts.
  • Provide a stable power supply for each device and avoid sharing a power circuit with high-power equipment.

5.7.34 How Much Network Bandwidth Is Required for Different Numbers of Devices?

The following values are recommended. Adjust the actual bandwidth based on on-site network quality and service concurrency:

Number of devicesRecommended bandwidth and network topology
1–4Shared bandwidth of at least 20 Mbps; devices can connect directly to a router.
5–30Bandwidth of at least 100 Mbps with an enterprise-grade router and managed switches.
31 or moreA dedicated line of at least 100 Mbps with an enterprise-grade router, Gigabit switches, and VLANs configured according to the project network plan.

5.7.35 What Are the Restrictions on Switch Deployment?

Do not cascade more than three switches on the same LAN. Too many network layers can increase latency and reduce stability.

5.7.36 What Lighting Conditions Does the Device Require?

Do not use the device outdoors with strong backlight or where brightness changes dramatically. Adjust the device angle so that light falls evenly on the palm and strong light does not shine directly into the camera.

5.7.37 How Should a Palm Scan Be Performed?

  • Extend the palm naturally with its center facing the center of the camera.
  • Keep the palm approximately 5–12 cm from the device.
  • Minimize palm tilt and rotation, and keep the palm steady during recognition.

5.7.38 What Are the Resolution and Frame Rate of the RGB and Infrared Cameras?

Both the RGB camera and infrared camera have a resolution of 1600 × 1200 and a frame rate of 30 FPS.

5.7.39 What Camera Specifications Does Mobile Palm Registration Require?

A mobile device camera with at least 3 megapixels is sufficient.