Integrating ZKTeco terminals with Mawered in under 30 minutes
The ZKTeco ADMS protocol holds no secrets: discover how to configure bidirectional synchronization between your time clocks and Mawered.
Co-founder & CTO, Mawered
Amine has been architecting Mawered's multi-country HRIS since its founding. He specialises in biometric system integration and regulatory payroll engines.
ZKTeco terminals are ubiquitous in companies across the MENA region: across our client network in Tunisia, Morocco and the Gulf, more than 60% of installed biometric terminals are ZKTeco devices — F18, F22, K40, MA300 and SpeedFace leading the way. Whether your company already has them or has just acquired some, this guide explains how to connect them to Mawered in under 30 minutes, using the native ADMS protocol, with no CSV file exports and no custom development required.
Prerequisites: What You Need Before You Start
Before beginning configuration, check the following:
- Compatible terminal model: all ZKTeco terminals supporting the ADMS protocol work with Mawered. The most common models in the region are the F18, F22, K40, MA300, SpeedFace V5L and ZKBio960. If in doubt, check in the terminal menu that the "ADMS Server" or "Cloud Server" option is available.
- Network connectivity: the terminal must have internet access (wired Ethernet or Wi-Fi). Check that outbound port 80 or 443 is not blocked by your firewall.
- Terminal serial number: found in the terminal menu under "System Info" or "Device Info". It will be used to identify the terminal in Mawered.
- Mawered administrator access: you must have the "Biometric Terminal Management" permission in your Mawered profile.
Step 1: Get the ADMS URL from Mawered
In Mawered, navigate to Time Tracking → Biometric Terminals → Add Terminal. On the creation screen, note the ADMS URL displayed — it looks like https://yourdomain.mawered.com/iclock/cdata/. This is the address you will enter in the ZKTeco terminal. Copy it exactly, including the trailing slash.
On this same screen, enter:
- The terminal name (e.g., "Main Entrance - Head Office")
- The terminal serial number (found in the prerequisites step)
- The site it is attached to
Save. Mawered now creates a reception point for this terminal. Proceed to the physical configuration of the device.
Step 2: Configure the ZKTeco Terminal
On the ZKTeco terminal, access the administrator menu (default code: 0000 or 12345 depending on the model). Navigation varies slightly between models, but the path is always similar:
- Go to Network Settings → Cloud Server (or "ADMS Settings" depending on firmware).
- Enable cloud connection: set "Enable" to Yes.
- In the Server Address field, enter the ADMS URL copied from Mawered. If the terminal asks for the domain and path separately, separate
yourdomain.mawered.comand/iclock/cdata/. - Set the port to 443 (HTTPS) or 80 if your Mawered instance is not yet on HTTPS.
- In the Device ID field, enter the serial number exactly as it appears in Mawered — this is the identifier that links the terminal to its record in the platform.
- Save and restart the terminal if prompted.
After restart, the terminal will automatically attempt to contact the ADMS server. You should see a connection indicator (often a network icon or "Server connected" message) activate within 60 seconds.
Step 3: Verify the Connection in Mawered
Return to Mawered on the terminal record you just created. If the connection is established, you will see:
- Status change to "Connected" with the date and time of last contact.
- Terminal information appearing automatically: firmware, memory capacity, number of registered fingerprints.
If the status remains "Disconnected" after 2 minutes, see the troubleshooting section at the bottom of this guide.
Step 4: Map Employees — The Often Overlooked Step
The network connection is established, but time punches will only be correctly attributed to employees if the mapping between terminal data and Mawered records is correct. This is the most commonly missed step during integrations.
ZKTeco terminals identify each employee by a numeric User ID. In Mawered, this User ID corresponds to the employee's registration number (matricule) field — not the badge number, not the contract number, not the internal Mawered ID.
To map correctly:
- Export the user list from the ZKTeco terminal (Employee Management menu → Export).
- In Mawered, verify that each employee record has their registration number filled in, and that this number exactly matches the terminal User ID.
- If not, update employee records in Mawered from the employee management page.
- You can also synchronize users from Mawered to the terminal: on the terminal record, use the "Push Employees to Terminal" option — the HRIS will push the registration number list directly to the device via the ADMS connection.
Step 5: Test with a Real Punch
Once mapping is complete, perform a test punch on the terminal. In Mawered, navigate to Time Tracking → Punch Logs. The log should appear within seconds with:
- The employee name correctly resolved (not an unknown User ID)
- The exact date and time
- The punch type (In/Out depending on terminal configuration)
- The source terminal
If the name doesn't appear and you see "Employee not found" or an unresolved ID, verify that the employee's registration number in Mawered matches the User ID in the terminal.
Troubleshooting Common Issues
Terminal Remains "Disconnected" in Mawered
- Verify the ADMS URL is correct with the trailing slash:
/iclock/cdata/ - Test connectivity from the terminal: some models have a ping tool in network settings.
- Verify that outbound port 443 (HTTPS) or 80 (HTTP) is open on your local network.
- If your Mawered instance is on a custom subdomain (e.g., yourcompany.mawered.com), ensure the SSL certificate is valid — ZKTeco terminals may reject HTTPS connections with self-signed certificates.
Punches Arrive But Are Not Attributed to an Employee
- The User ID in the terminal does not match any registration number in Mawered. Export the User ID list from the terminal and compare with registration numbers in Mawered.
- The registration number may be stored with leading zeros in one system and without in the other (e.g., "042" vs "42"). Standardize the format across both systems.
Punches Are Duplicated
- The terminal is configured with too short a synchronization interval and is resending the same punches multiple times. In the terminal's ADMS settings, increase the sending interval to a minimum of 60 seconds.
- Mawered automatically deduplicates identical punches (same employee, same time, same terminal), but check the logs to ensure no spurious records persist.
Compatible and Validated ZKTeco Models
The following models have been tested and validated in native integration with Mawered. The table below helps you choose the right device for your context:
| Model | Biometrics | Capacity | Connectivity | Best for |
|---|---|---|---|---|
| F18 | Fingerprint | 3,000 fingerprints / 100,000 logs | Ethernet, Wi-Fi (option), USB | Office environments, SMEs 20–100 employees |
| F22 | Fingerprint + RFID card | 3,000 fingerprints / 100,000 logs | Ethernet, Wi-Fi (option), Wiegand | Sites with physical access control |
| K40 | Fingerprint + RFID card | 3,000 fingerprints / 100,000 logs | Ethernet, RS232/485, USB | Industrial environments, workshops |
| MA300 | Fingerprint + RFID card | 10,000 fingerprints / 200,000 logs | Ethernet, Wi-Fi, 4G (built-in SIM slot) | Remote sites, locations without stable wired network |
| SpeedFace V5L | Facial + fingerprint + card | 30,000 faces / 1,000,000 logs | Ethernet, Wi-Fi, 4G (option) | Main entrances, high-volume, contactless |
| ZKBio960 | Facial + fingerprint + card + vein | 50,000 faces / 1,000,000 logs | Ethernet, Wi-Fi, USB | High-security sites, multi-factor access |
| ProFace X | Facial (masked) + fingerprint | 50,000 faces / 10,000 fingerprints | Ethernet, Wi-Fi, USB | Medical environments, post-COVID settings |
For any unlisted model, verify that the firmware supports the ADMS protocol (version 6.60 or higher recommended). Older terminals may require a firmware update before activating cloud connection. If in doubt, the terminal's serial number allows the Mawered team to confirm compatibility before purchase.
Going Further: Bidirectional Commands
ADMS integration is not limited to receiving punches. Mawered can also send commands to terminals:
- Add or remove an employee (User ID and fingerprint addition/deletion)
- Synchronize terminal time from the server
- Trigger a remote restart
- Clear punch memory after confirmed synchronization
These commands are available from the terminal record in Mawered, under the "Commands" tab. They are particularly useful for multi-site deployments: a Mawered administrator can manage all terminals from a central interface without traveling to each site.
Multi-Site Deployment: Architecture and Best Practices
For companies with multiple locations or workshops, Mawered organizes terminals by site. Each site has its own perimeter: attached terminals, schedules, public holiday calendars, and local HR managers. A consolidated view remains accessible at the group level.
What the Site Structure Enables
- View time punch logs by site or aggregated across all locations — without manually merging exports from multiple sources.
- Assign different rotating schedules by site: a Sfax factory on 3×8 shifts and a Tunis head office on fixed hours can coexist in the same Mawered account.
- Restrict local manager rights to their own perimeter. A warehouse supervisor in Monastir cannot access salary data for the sales team in Tunis.
- Consolidate multi-site payroll for the finance director without double entry.
Network Requirements for Remote Terminals
The ADMS protocol is designed to run on basic connections. Minimum requirements:
- One port to open: outbound port 443 (HTTPS) toward the Mawered domain. No inbound port is required — the terminal always initiates the connection to the server.
- 4G is sufficient for an isolated site: the MA300 and SpeedFace V5L models include a built-in SIM slot. A terminal in a warehouse without Ethernet can run on a standard data SIM.
- Resilience to network outages: if connectivity is lost, the terminal continues recording punches in local memory (up to 200,000 logs depending on the model). On reconnection, it automatically transmits the backlog — Mawered deduplicates transactions to prevent double-counting.
Operational Centralization: What You Control Remotely
From the Mawered console, the administrator sees in real time the status of every terminal — connection status, last contact date, number of pending punches, available memory. Remote actions available:
- Forced synchronization: retrieve a terminal's punches immediately before a payroll closing, without waiting for the next automatic cycle.
- Employee list update: push the updated registration number list to all terminals on a site simultaneously after onboarding new employees or after an inter-site transfer.
- Remote restart: reboot a malfunctioning terminal without sending a technician on-site — especially valuable for industrial sites in regional locations.
- Time synchronization: align all terminal clocks from the Mawered NTP server, preventing time drift that distorts lateness calculations.
For Tunisian industrial SMEs with sites in Sfax, Monastir or Sousse, this operational centralization eliminates on-site travel for terminal administration — a real time saving estimated at 1 to 2 days per month for companies operating 5 or more terminals.
See also: Time tracking management module — Planning module — Absence management and biometric time tracking for SMEs
Ready to automate your HR?
Mawered is built for companies in the MENA region. Compliant payroll, native ZKTeco integration, absence and planning management in one tool.
Request a free demo