CodeB Credential Provider V2 user manual.

How to install, configure and run passwordless, two-factor and three-factor Windows logon with NFC cards, USB sticks, TOTP apps, the CodeB Authenticator and X.509 certificates.

CodeB Credential Provider V2 · User manual · Updated 2026-09-30

In short

CodeB Credential Provider V2 (formerly Aloaha Smartlogin) is a Windows credential provider by Aloaha Limited. It adds a logon tile to the Windows logon and lock screen that accepts NFC cards, USB memory sticks, TOTP codes, the CodeB Authenticator app and X.509 certificates — for passwordless logon, two-factor (2FA) or three-factor (3FA) authentication. It works with local, Active Directory and Microsoft Entra ID accounts and runs entirely on your own infrastructure.

What the credential provider does

Windows shows a password tile at logon. The CodeB Credential Provider adds its own tile next to it (or, with the built-in credential provider filter, instead of it). When a user presents a token, the provider unlocks the Windows credentials that were linked to that token beforehand and hands them to Windows. Windows then checks them exactly as if the user had typed them.

You can use the product in three ways, with the same software:

  • Passwordless: the token alone logs the user on (for example “tap to logon” with an NFC card).
  • Two-factor (2FA): token plus password, or password plus a TOTP code.
  • Three-factor (3FA): NFC token and TOTP code and password.

Supported logon tokens

  • USB memory sticks — any plain memory stick can become a logon token.
  • NFC cards, including physical access cards such as tickets, student IDs and bank cards, specifically MIFARE and DESFire.
  • Android phones with NFC running the CodeB Authenticator app.
  • All standard TOTP authenticator apps (RFC 6238).
  • X.509 certificates, ideally on a PKI smartcard.
  • Domain-issued certificates through the CodeB “Kerberos Connector”.

Need a token that is not listed? Write to info@codeb.io.

The two editions

The Credential Provider is security software, so Windows may block the download at first or suggest a virus scan. That is the normal Windows protection for this kind of program.

EditionDownloadBest for
Edition 1 — system traycodeb_tray.zipOne tray application with every tool needed to install, configure and use the Credential Provider. Start the tray application the first time with “Run as administrator”: it installs the credential provider DLL.
Edition 2 — modular (Smartlogin helper)codeb_smartloginhelper.zipCompanies. Installer, credential provider and each tool are separate programs, so you decide which tools users can run and which logon methods they get.

Both editions are on the downloads page. More background: win-logon.com/credential-provider.

What gets installed

ProgramPurpose
codebcredprovider.dllThe credential provider and the credential provider filter that LogonUI loads.
CredentialProviderInstaller.exeInstalls, upgrades, tests and removes the provider; installs licences. See Installation.
SmartLoginLicensing.exeEnters the licence key.
Credential Linkers: Link2FA, LinkTOTP, LinkNFCCard, LinkNFC2AD, LinkX509, LinkMEMStickLink a user’s Windows account to a token. See Linking tokens.
CodeBService.exeWindows service: watches card, USB-stick and Bluetooth tokens for the “on removal” action and starts configured programs in user sessions.
codeb_tray.exeSystem tray application (Edition 1 contains all tools in it).
CodeBAdminCLI.exeCommand-line enrolment for administrators. See Admin CLI.

Quick start: NFC card logon in about ten minutes

This is the classic “tap to logon” setup with Edition 2. Each step links to the full description.

01

Download and unpack

Download codeb_smartloginhelper.zip from the downloads page and extract it on the workstation.

02

Install the credential provider

Run CredentialProviderInstaller.exe as administrator and click Install Credential Provider (or run CredentialProviderInstaller.exe /install). Details.

03

Install the licence

Enter your key with SmartLoginLicensing.exe or CredentialProviderInstaller.exe /license YOUR-KEY. Details.

04

Link the card

Run LinkNFCCard.exe, tap the card, enter the Windows user name and password. Leave the PIN empty for card-only logon (the default PIN 0000 is stored). Details.

05

Log on

Lock the screen or sign out, select the CodeB tile and tap the card. With the default PIN the card is the only factor. What the user sees.

Security note

With card-only logon the card is the credential: whoever holds it can log on. Combine it with a short inactivity lock and a way to block lost cards, or keep the PIN for two-factor logon.

Key terms

Credential provider
A Windows component (ICredentialProvider) that LogonUI loads to show a logon tile. CodeB’s is written in managed .NET code.
Credential provider filter
A component that decides which other credential providers (for example the Microsoft password tile) Windows shows. See Filter settings.
Credential Linker
A small program (Link….exe) that binds a user’s Windows credentials to a token.
Soft token
The encrypted record that holds the linked credentials. It is stored in the data folder (default C:\ProgramData\CodeB\), on a file share, or in the user’s Active Directory object.
Second factor in AD
A card serial that is stored on the user’s AD object (attribute altSecurityIdentities) and must be presented in addition to the password.
Default PIN
The PIN used when a card was linked without a PIN; 0000 unless changed with DefaultSerialPIN.

All chapters

Frequently asked questions

Is CodeB Credential Provider V2 the same product as Aloaha Smartlogin?

Yes. CodeB Credential Provider V2 is the current name of the product previously sold as Aloaha Smartlogin. Registry keys and some file names still carry the Aloaha name.

Which edition should I download?

Take Edition 1 (codeb_tray.zip) for a single PC or a small office: one tray application contains every tool. Take Edition 2 (codeb_smartloginhelper.zip) for companies: installer, credential provider and each linking tool are separate programs, so you decide which tools your users may run.

Do I need Active Directory or an internet connection?

No. The credential provider works with local accounts, Active Directory accounts and Microsoft Entra ID accounts, and it needs no cloud service. Token data can be kept on the PC, on a file share or in Active Directory.

Which Windows versions are supported?

Windows 8 and later, including Windows 8.1, 10 and 11, and the matching Windows Server releases up to Windows Server 2025. The software needs the .NET Framework 4.7.2 or later, which current Windows versions already include.

Stuck on a step?

A real engineer reads every support email. Send the log files from the troubleshooting chapter and we usually answer within one business day.