# Access control

> Who is allowed to charge at a station, how a charge is authorised at the moment it starts, and how RFID, roaming and car recognition fit in.

Access control decides who may charge at a station and on what terms. A public station takes anyone who can pay; a depot takes only a fleet's own drivers. Underneath they are the same mechanism: which tokens are allowed on which connectors, and at what price.

## Access groups

An **access group** ties a set of tokens to a set of connectors. It can be attached to a whole station or to individual connectors, and connector-level groups take priority over station-level ones. Members are identified by their RFID card, by its uid or its printed visual number, or by the user who holds them.

A group is either open or **restricted**. On a restricted group only its members may start a charge on the connectors it covers, and a non-member is turned away. A group can also carry its own pricing, so a fleet or a staff cohort charges at its own rate: a member can be set to charge **free**, at a **custom** per-kWh rate, or at the standard tariff with access alone. Access groups are managed over the [EVSE Access Control API](/docs/platform/reference/platform-api/evse-access-control).

## Open, restricted and free

On top of its access groups, a station takes one of three postures, set by two switches:

- **Restricted** (neither switch on). Only the tokens in the station's access groups may charge. This is a depot or a private site.
- **Public.** The station also accepts cards from other networks, authorising them over [roaming](/docs/emobility/ocpi) against the driver's home provider. A token that belongs to no access group is allowed only when the station is public.
- **Free.** The station lets anyone charge with no authorisation at all. It suits a genuinely open, no-cost site, and it cannot be combined with public roaming charging.

## Tokens

A **token** is what identifies a driver to a station:

- **Your own tokens**, the RFID cards and fobs you issue. You assign them, group them, and block a lost one.
- **Roaming tokens**, carried by drivers from other networks. Each time one charges at your station the platform checks it live with the driver's home provider before allowing it, the [roaming](/docs/emobility/ocpi) side of access.

## How a charge is authorised

When a driver presents a token, the station asks the platform whether to allow the charge, and the platform answers in a single pass. It works through a few things in order: a station that is disabled or has no owner cannot charge; a free station accepts at once; a session started from a payment terminal or an app is matched to that; otherwise the token is judged on its own, against the connector's access groups and, for an outside card, its home network. The answer is allow, or refuse with a reason such as blocked, expired, or not permitted here. Every decision is recorded, so a refusal can be explained rather than guessed at.

## Charging through a connectivity gap

A charge should not fail because the network blips. When a station loses its connection it can still start a charge, and the platform takes those transactions in and settles them once the station is back in touch. Authorisation is deferred and reconciled rather than checked against a list held on the station, so a site keeps working through an outage instead of turning drivers away.

## Recognising the car

A station can start a charge from the car itself, with no card or app, by matching the identifier the vehicle presents over the cable (its EVCCID) to a token the platform already knows. A related path links a particular vehicle, a Tesla for instance, to an existing card, so that car autocharges wherever the card is accepted. Both are newer capabilities, offered in preview.

## Where this is heading: charging policies

Access is moving into the same **charging policies** that carry [pricing](/docs/platform/charge-point-operation/tariffs-and-pricing). There, drivers are gathered into **customer groups** (a named set of tokens, matched by account, user, card issuer and the like) and connectors into **charging groups**. A policy's rules then pair a customer group with a price: a rule applies only to the tokens in its group, and when it matches it both authorises the session and prices it. Access and price stop being two separate things.

Customer groups and charging groups are in per-provider preview, running alongside the access groups above rather than having replaced them, and existing access groups can be migrated across. They are reachable through the [Charging Groups](/docs/platform/reference/platform-api/charging-groups-beta) and [Customer Groups](/docs/platform/reference/platform-api/customer-groups-beta) APIs.
