Biometric attendance

Biometric attendance integration

HRMSMax receives punches directly from eSSL and ZKTeco biometric terminals that support the ADMS protocol (often labelled "Cloud Server" or "PUSH" in the terminal's settings), over the internet, and can also poll terminals on a local network. Every punch lands in the same attendance engine as self-service punches, is de-duplicated, and is judged against the employee's shift.

Two ways to connect a terminal

MethodHow it worksSuits
ADMS pushThe terminal sends punches to HRMSMax over HTTPS (port 443) as they happen, and collects commands on the same connection. Terminals are identified by serial number, not by IP address.Any site with an internet connection, including a dynamic IP or a mobile-data router.
LAN pullHRMSMax connects to the terminal on the local network and reads new punches every minute, with a "Sync now" button.Terminals on a network the HRMSMax server can reach.

Both paths feed one pipeline, which drops duplicates of the same employee, terminal and time — so a punch sent twice is counted once.

Keeping one company's terminals out of another's attendance

Each company pushes to its own ingest address with its own key. A terminal is bound to one company; a punch from a terminal bound elsewhere is rejected, and a serial number nobody has claimed is quarantined rather than accepted into any company's attendance.

Managing terminals from HRMSMax

  • Send an employee to a terminal, or remove them from it.
  • Send an employee's face photo to terminals that accept one, and delete face or fingerprint templates.
  • Copy templates from a master terminal to others, so an employee enrolled once can punch at every gate.
  • Reboot a terminal, read its information, and clear its logs or photos.
  • Photos taken at the moment of a punch are received from terminals that capture them, over ADMS push.
  • Contract workers can be synced to terminals the same way as employees.

Command support depends on the terminal's firmware. Remote fingerprint enrolment is not confirmed on eSSL terminals — many only enrol at the terminal's own menu — so plan to enrol fingerprints at the device.

Which terminals work

eSSL and ZKTeco terminals whose communication settings offer ADMS or a cloud-server address work over push; terminals that expose the standard ZK SDK port on the local network work over pull. Firmware varies between models, so we confirm your models before a rollout.

  • Not supported: terminals that only speak eSSL's JSON "DM" protocol (used by the eSSL desktop client and some Android face terminals). They will not connect.
  • Not integrated: ZKBioTime.

Moving from eTimeTrackLite

Punch history can be imported from an existing eTimeTrackLite 12.0 database when a company moves to HRMSMax, so past months are available in the same attendance records as new punches.

Questions

Which biometric devices work with HRMSMax?

eSSL and ZKTeco terminals that support ADMS (cloud server) push, and terminals reachable on a local network through the ZK SDK. Terminals that only use eSSL's JSON "DM" protocol do not connect, and ZKBioTime is not integrated.

Does the terminal need a static IP address?

Not for ADMS push. The terminal calls HRMSMax over HTTPS and is identified by its serial number, so a dynamic IP or a mobile-data connection works.

What happens if the same punch is sent twice?

It is counted once. Punches are de-duplicated on terminal, employee and time before they reach attendance.

Can fingerprints be enrolled remotely?

Not reliably. Remote fingerprint enrolment is firmware-dependent and not confirmed on eSSL terminals. Enrol at the terminal, then copy templates to other terminals from HRMSMax.

See it on your own rules

A walkthrough of HRMSMax set up with your shifts, leave policies and salary structures.

Sign in to HRMSMax

Use the mobile number your company registered.

Loading…