Registry settings reference.

Every documented registry value of the CodeB Credential Provider with its default and effect: logon tile, texts, tokens and Active Directory, removal actions, provider filter, automatic logon, folders and logging.

CodeB Credential Provider V2 · User manual · Updated 2026-09-30

In short

All settings are registry values under HKLM\SOFTWARE\CodeB (mostly Config and CP) and HKLM\SOFTWARE\Aloaha. On 64-bit Windows the CodeB components read them from the 32-bit view: HKLM\SOFTWARE\WOW6432Node\CodeB\…. Switches take 0 or 1; a missing value is created with its default the first time it is read.

How settings are stored

  • Location. Unless a table says otherwise, paths are relative to HKLM\SOFTWARE\CodeB\, and Config is HKLM\SOFTWARE\CodeB\Config.
  • 32-bit view. On 64-bit Windows use HKLM\SOFTWARE\WOW6432Node\CodeB\… and HKLM\SOFTWARE\WOW6432Node\Aloaha\…. The exceptions are the filter values under HKLM\SOFTWARE\Aloaha\CP, which live in the normal 64-bit view.
  • Types. On/off switches are DWORD or string values 0/1. Paths and texts are strings.
  • Defaults. The provider writes a missing value with its default when it first reads it, so after the first logon screen most values are visible and can be edited.
  • When changes apply. Tile settings apply the next time the logon or lock screen opens; settings of the CodeB service apply within its next check or after a service restart.
  • Deployment. Group Policy Preferences, .reg files, SCCM/Intune or scripts. CodeB ships no ADMX template; the values are listed here.

Logon tile — Config

ValueDefaultEffect
HideUsernameField01 hides the Username field on the CodeB tile.
HideOptionalSecretField01 hides the Optional Secret or Password field. Without it, the field is also hidden automatically when no linked token needs it. Has no effect while AlwaysShowOptionalSecretField or Use_AD_altSecurityIdentities is 1.
AlwaysShowOptionalSecretField01 always shows the Optional Secret or Password field. It is also shown whenever Use_AD_altSecurityIdentities is 1.
HideTOTPField01 hides the TOTP or PIN field.
HideShowCharacters01 hides the Display typed values check box.
HideExtraTile01 hides the extra “Other User” tile, so only the tiles of known users are shown.
ActiveField3Field that has the focus: 1 Username, 2 Optional Secret or Password, 3 TOTP or PIN. 3 becomes 2 when the TOTP field is hidden.
ShowWrongPasswordDialog11 shows a message when the stored credentials are wrong (for example after a password change). 0 turns it off.
DoNotAllowMagicWords01 disables the keywords nfc, 2fa, changepwd and time in the logon fields (see keywords). Recommended for hardened PCs.

Tile texts — Strings

String values under HKLM\SOFTWARE\CodeB\Strings replace the English texts on the tile, for example to translate them.

ValueDefaultEffect
UsernameUsernameLabel of the user name field.
OptionalSecretOrPasswordOptional Secret or PasswordLabel of the password / optional secret field.
TOTPorPINTOTP or PINLabel of the TOTP / PIN field.
ConfirmPasswordConfirm passwordLabel of the confirmation field (change-password screen).
UnmaskFieldsDisplay typed valuesLabel of the check box that shows typed values.
CodeBLogonOther UserTitle of the extra tile.
EnterYourCredentialsEnter your CodeB CredentialsText shown on the selected tile.
FailedCredentialsPlease make sure that you present your token.Message when no token or no matching credentials were found.

Tokens & Active Directory — Config

ValueDefaultEffect
DelayCardRemovalEventSEC10Seconds the provider waits after a card was lifted before it treats the card as removed, so a quick tap still completes the logon. 0 = no delay. Very long values usually hide another problem (reader driver, cold-boot timing).
Use_AD_altSecurityIdentities11 looks up card links and tokens in the user’s AD attribute altSecurityIdentities. 0 uses only local or share data.
ADAutoSync1For cards pre-enrolled for a “new user” in AD: 1 writes the card serial to the user’s AD object the first time the card is used; 0 only records it in the data folder (newuser\<user>.user).
UseDomainDPAPI01 additionally protects new tokens with Windows DPAPI for the user and the domain computers, so only domain PCs can decrypt them.
AutoUpdateADToken01 allows the CodeB helpers to update the password stored in the user’s AD soft token after a password change.
RestartSmartCardServiceIfNoReaderDetected01 restarts the Windows Smart Card service when the logon tile finds no reader. Leave it off for Remote Desktop use.
Value (other key)DefaultEffect
HKLM\SOFTWARE\Aloaha\CSP\DefaultSerialPIN0000PIN used for cards that were linked without a PIN (in the linking tools and in CodeBAdminCLI when /pin is omitted). Changing it affects the logon of all such cards.

Removal actions — CP

What happens when a token is taken away while the user is logged on. The effective action is the highest of the global LogoffAction, the value of the token type and the action chosen when the token was linked.

ValueDefaultEffect
CP\LogoffAction0Action for every token type when the token is removed: 0 nothing, 1 lock (disconnect in Remote Desktop), 2 log off.
CP\CardToken\LogoffAction0Same for NFC cards and smartcards.
CP\USBStick\LogoffAction0Same for USB memory sticks.
CP\Bluetooth\LogoffAction0Same for Bluetooth tokens.
CP\DoActionOnNoReader01 also runs the action when no card reader is present.
CP\DoActionOnNoCard01 also runs the action when no card is in any reader.
Written by the product

Subkeys such as CP\CardToken\<user> (values serial, Action, ts, SessionID) record the tokens of logged-on users. They are managed by the CodeB service — do not edit them.

Filter: hide other credential providers

The CodeB credential provider filter decides which other providers the logon screen shows. Hiding the Microsoft password tile with the filter is safer than disabling the Microsoft provider system-wide.

ValueDefaultEffect
HKLM\SOFTWARE\Aloaha\CP\<provider CLSID>01 hides that credential provider. The value name is the provider’s CLSID without braces, for example Microsoft Password Provider 60b78e88-ead8-445c-9cfd-0b87f74ea6cd, Windows Hello PIN d6886603-9d2f-4eb2-b667-1971041fa96b. The same value under HKU\.DEFAULT\Software\Aloaha\CP is honoured too.
HKLM\SOFTWARE\Aloaha\CP\AllowPasswordChange11 shows all providers on the Windows change-password screen; 0 filters there too.
HKLM\SOFTWARE\Aloaha\CP\AllowPreLogonAccessProvider11 does not filter pre-logon access providers (for example VPN before logon); 0 filters them.
Filter\ProcessExceptions\<process>see text1: no filtering in credential prompts of that program (lower-case process name). Default 1 for credentialuibroker, consent (UAC) and systempropertiesadvanced, 0 for others.
Filter\UserExceptions\<user>01: this user may log on on the CodeB tile with user name and password only, without a token (for example a service or emergency account).
Do not lock yourself out

Before hiding the password provider, test token logon for every account that needs it and keep an emergency path (a UserExceptions account or remote registry access).

Automatic logon after boot

ValueDefaultEffect
DefaultUserName—User for automatic logon. If empty, Windows’ own Winlogon\DefaultUserName is used.
DefaultPassword—Password for automatic logon. If empty, Winlogon\DefaultPassword is used.
Config\AutologonTimeout60Automatic logon happens only within this many seconds after Windows started (minimum 10). Later, for example after sign-out, the user has to log on normally.
Security

Automatic logon stores a password in the registry where administrators can read it. Use it only for kiosk or machine accounts.

Kerberos & authentication

ValueDefaultEffect
CP\ForcedAuthPackage0Windows authentication package to use. 0 = automatic (recommended).
CP\ForceKerberosUPNnoneFixed UPN for certificate (Kerberos Connector) logon. none = off.
CP\ForceKerberosDomainnoneFixed domain for Kerberos logon. none = off.
Config\CryptoProviderCodeB Credential ProviderName of the cryptographic service provider used by the Kerberos Connector.
CP\TilePathnoneFull path of a bitmap shown as the tile picture. none = built-in picture.

Folders & programs

ValueDefaultEffect
DataFolderC:\ProgramData\CodeB\ Local folder for soft tokens and other data. Must be a full path.
RemoteDataFoldernoneUNC path of a shared data folder (for example \\server\codeb\) used for tokens that must work on several PCs.
2FAPath—Full path of Link2FA.exe, opened by the 2fa keyword.
SystrayPath—Full path of the tray application; set by the installer.
CP\AutoStart\Systray01: the CodeB service starts the tray application in every active user session.
CP\AutoStart\PathnoneProgram the CodeB service starts in every active user session.
CP\AutoStart\PathParameternoneCommand-line parameters for that program.

DataFolder and RemoteDataFolder are also accepted in the 64-bit view.

Tray application

ValueDefaultEffect
Software\CodeB\Systray\enabled\onlinehelpon0 or false removes Online help from the tray menu.
Software\CodeB\Systray\enabled\joinmeetingon0 or false removes Join meeting.
Software\CodeB\Systray\enabled\abouton0 or false removes About.

These values can be set in HKCU (per user) or HKLM (all users); a value in HKLM wins.

Debug logging

ValueDefaultEffect
HKLM\SOFTWARE\Aloaha\pdf\debug01 writes detailed logs of the credential provider and its helpers to C:\Windows\Logs\CodeBProvider\. See Troubleshooting. Turn it off again afterwards.

Example .reg file

A hardened NFC setup on 64-bit Windows: card PIN field focused, keywords off, lock on card removal, Microsoft password tile hidden.

Windows Registry Editor Version 5.00

; CodeB settings (32-bit view on 64-bit Windows)
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\CodeB\Config]
"ActiveField"=dword:00000003
"DoNotAllowMagicWords"=dword:00000001
"HideExtraTile"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\CodeB\CP\CardToken]
"LogoffAction"=dword:00000001

; filter (64-bit view): hide the Microsoft password tile
[HKEY_LOCAL_MACHINE\SOFTWARE\Aloaha\CP]
"60b78e88-ead8-445c-9cfd-0b87f74ea6cd"="1"

Frequently asked questions

Why can't I find HKLM\SOFTWARE\CodeB on a 64-bit PC?

The CodeB components read their settings from the 32-bit registry view. On 64-bit Windows look under HKLM\SOFTWARE\WOW6432Node\CodeB. Most values appear there automatically, with their default, the first time the logon screen reads them.

How do I hide the Microsoft password tile?

Set the string value HKLM\SOFTWARE\Aloaha\CP\60b78e88-ead8-445c-9cfd-0b87f74ea6cd to 1. The CodeB filter then hides the Microsoft Password Provider. Make sure every user can log on with a token first.

How do I make the card PIN field the focused field?

That is the default: ActiveField = 3 focuses the TOTP or PIN field. Use 2 for the password field and 1 for the user name.

Stuck on a step?

A real engineer reads every support email. Send the log files from the troubleshooting chapter and we usually answer within one business day.