Introduction
The Grandstream SecureAccess App is a unified cloud-based platform designed to simplify door station management for both residents and administrators. It enables everyday users to unlock doors locally or remotely, receive video calls from visitors, and share temporary access keys. At the same time, administrators can provision devices, create organizations, assign permissions, manage users, and configure alarms and schedules.
This FAQ consolidates the most common questions and answers from the official SecureAccess User Guide and Administration Guide. It provides clear explanations and practical troubleshooting steps for both end-users and system administrators to ensure smooth operation and secure access management.
Account & App Setup
Covers installation, login, user creation, and account-related configuration.
Download Grandstream SecureAccess from the App Store or Google Play or use the direct link (https://fw.gdms.cloud/gds/download/)
The app requires Android 10.0 or later or iOS 13 or later. During installation, allow Bluetooth, Location, and Notification permissions so all features work properly.
Access the SecureAccess platform for the first time via www.gdms.cloud and locate the “Register” entry on the login page. Click it to enter the registration process, follow the on-screen instructions to fill in the relevant information, and complete the creation of the super administrator account.
There are two ways:
- Administrators/Property Managers – Contact your organization’s super administrator to create a cloud login account; the initial password will be emailed to you.
- Residents/Employees – Ask your building manager or landlord to create a user account, or register a new account if you are the homeowner.
After registration, open the app, select Administrator or User, and log in. If MFA is enabled, you will be prompted to enter a verification code
In the User Management interface, administrators can modify both administrator and regular user accounts. They can also enable or disable the App User option for each account.
When this option is enabled, the user will count toward the organization’s total number of App users as defined by its plan or specification.
In Management → Administrator, click Add and:
- Enter a nickname and a valid email address for the new administrator.
- Select the type: Organization Administrator (controls a single organization) or Platform Administrator (controls all organizations).
- The account will be created; the administrator must confirm via email before logging in.
For ordinary users, User Permission defines allowed functions:
- All Permissions – Unlock via Bluetooth/NFC, remote unlock, create temporary keys, and manage visitors.
- Local Unlock Only – Restricts to Bluetooth/NFC unlocking; remote unlock and temp keys are hidden.
- Custom – Administrators choose which functions are enabled.
Set user permissions under Management → User Permission → Set User Permission.
You can log in normally after successful activation. Please use the account and password you filled in during registration to log in.
Under Management → User, click Add User and complete the fields:
- Basic information – Name, validity period and optional notes.
- Virtual Number & PIN – The phone extension for calls and a PIN code for keypad unlocking.
- Card Type & Number – Assign an IC or ID card by scanning it via NFC.
- Access Group – Choose which doors the user can unlock.
- App User – Toggle whether the user can unlock via the app.
- Login Credentials – Set the login account and initial password.
- Permissions – Choose Basic, All Permissions or Custom; enable the Monitor Feature if the user needs call and video preview rights.
- SIP Account – Optional, for SIP/UC integration.
After saving, the user’s credentials (virtual number, PIN, login account, etc.) will be shown.
Super administrators can manage multiple independent organizations. To switch or create one:
- Tap the menu icon in the top-left corner.
- Select an existing organization from the list.
- To create a new one, tap the “+” icon and choose either Manual Creation (add the organization and assign devices later) or Import from UC System (import the organization and its devices together).
- Enter the required details and assign devices. Each organization’s devices, users and permissions are isolated.
Switch to the desired organization and navigate to Management → User → Add User. Provide basic information (Name, Valid Time), assign a virtual number and PIN, choose a card type and number, set an access group and enable App User if the person should use the mobile app. Then create login credentials (Login Account and Initial Password). The system will display a success message with the user’s details.
App users can create and log in to their own accounts within the SecureAccess App. After signing in, they can unlock doors, make remote calls, and preview live video from the door station, if the Live Monitor option has been enabled for them by the administrator.
Administrators can also sign in to the App to remotely manage and control door station devices.
When multiple door station devices are added to the same organization, their respective SecureAccess plans are combined to increase the total number of App users available under that organization.
Example:
If Organization A adds two GDS devices:
- GDS Device 1 includes an Extra 50 App Users plan.
- GDS Device 2 includes an Extra 10 App Users plan.
Then, Organization A’s total App user capacity becomes 70 users — calculated as:
Basic Service (10 App users) + Extra 50 App users + Extra 10 App users = 70 App users total.
The free Basic Service (10 App users) for multiple GDS devices cannot be cumulative for calculation. For example, if GDS Device 1 (without additional plans) and GDS Device 2 (without additional plans) are added to Organization A, the organization specification is only 10 App users.
When a GDS372X device (under an organization) or a GSC357X device (under the GDMS UC system) is deleted, the organization’s specification is automatically reduced, meaning the total number of available App users decreases.
If the current number of App users exceeds the organization’s updated limit, App users will no longer be able to sign in to the SecureAccess App. However, the administrator can still sign in and manage the system normally.
Example:
If a GSC357X device with an Extra 50 App Users plan and another GSC357X device with an Extra 5 App Users plan are deleted, the organization’s App user capacity will decrease by 55 users.
If there are 65 App users in the organization after this reduction, exceeding the new specification limit, all App users (except the administrator) will be unable to log in to the App.
Unlocking & Access Control
Focuses on all door unlocking methods, NFC/Bluetooth/IC card/QR code use, and related troubleshooting.
The app supports multiple methods:
- App Button (One‑Tap Unlock) – Tap the blue Key icon on the bottom navigation bar.
- Hands‑Free / Approach to Open – Walk toward the door; requires enabling Hands‑Free in Door Unlock Settings.
- Shake Phone – Shake your phone; set shake sensitivity in Door Unlock Settings.
- NFC – Android only; enable NFC in your phone and in Door Unlock Settings.
- Bluetooth – Enables one‑tap, hands‑free or shake unlock when near the door station.
- IC/ID Card – Bind a card to your profile using NFC.
- PIN Code – Enter your Virtual Number followed by
*PIN#on the door station keypad. - QR Codes (Dynamic or Static) – Scan the QR code at the door station camera.
In Me → Door Unlock Settings, you can enable or disable each mode and choose which doors can be opened with that method.
NFC unlocking works only on Android devices. To use it:
- Ensure your phone’s NFC hardware is switched on.
- In Me → Door Unlock Settings, enable the NFC option (Android only).
- Make sure the door station’s “Allow NFC” setting is enabled by the administrator.
iOS devices do not support NFC unlocking. If NFC is enabled but the door still does not open, check whether your phone’s default payment/wallet app is interfering (some Android models require disabling the manufacturer’s wallet).
Bluetooth unlocking requires:
- Bluetooth enabled on the phone.
- In Door Unlock Settings, enable Bluetooth-based unlocking.
- Open the SecureAccess app and ensure all requested permissions (Bluetooth, Location) are granted.
- Approach the door within one meter and either tap the unlock button, walk closer (Hands‑Free), or shake the phone if that mode is enabled.
- Adjust the maximum unlocking distance from approximately 0.1 m to up to 3 m (actual distance may vary by device)
On Android, you must manually open the app for Bluetooth unlocking to work. On iOS, the app can run in the background but must have location permission set to “Always Allow.”
Remote unlocking must be explicitly enabled on both the door station and the user account. Check the following:
- Device configuration – The door station’s Remote Unlock option must be turned on; if not, the button will be greyed out.
- User permission – The user must have remote unlock permission; this is disabled by default and must be granted by an administrator.
- Device status – Remote unlock cannot work if the door station is offline.
When you have permission, you can tap Remote Unlock next to a door station, or tap Unlock during a call.
After reading an IC card, ensure it has been activated via Android NFC. If the card is unencrypted and activation is skipped, the door station’s Compatible with Unencrypted IC Card option must be enabled. If the card is encrypted, verify that the user has been assigned to an access group, that their validity period is correct and that the user is not disabled. Expired or disabled users cannot unlock doors.
An IC card can only be bound to one organization. If the card has already been activated in another organization, or if it has been encrypted and imported via an encrypted .sec file, it cannot be entered again. To reuse a card, remove it from its current organization first.
Android phones with NFC can write or read IC cards to enhance security. When adding/editing a user:
- Bind a blank IC card using the phone’s NFC to read the card number.
- Generate or enter an encryption key and save it locally so you can reassign the card later.
- To reassign the card, enter the original encryption key. Only MIFARE Classic 1K/4K and MIFARE DESFire cards are supported.
- Delete the card if the user no longer needs it.
You can also use Quick Card Entry to scan multiple cards in succession and add them quickly. After saving, changes are pushed to all assigned devices; offline devices update once they reconnect.
Check that the door station has Static QR Code unlocking enabled. If the setting is disabled, visitors must use a dynamic QR code. Also ensure that the visitor’s validity period has not expired and that their usage count has not been reached.
- Dynamic QR Code – Generated on demand and refreshed periodically. Visitors may be prompted to enter their details (name, phone number, etc.) before the QR is displayed. This adds security because the code is tied to the visitor’s identity.
- Static QR Code – A fixed image that remains valid until the visitor’s expiry date. Requires the door station to have Static QR Code unlocking enabled. No authentication is required when generating a static code.
The administrator chooses the sharing method when creating the visitor. Using authentication ensures that only the intended guest obtains the QR code.
Administrators (and users with “All Permissions”) can go to Visitor → Add or tap Temp Key on the Doors page. Enter the visitor’s name, select the devices they can access, define the visit period (or number of uses), and choose a password (4–11 digits). Optionally set a reason, recurrence, validity and unlock limit. Share the password with the visitor; they can enter it on the keypad to unlock.
In the visitor’s record, select Reset QR Code. This immediately invalidates all previously shared QR codes (both static and dynamic). If you need to revoke access entirely, delete the visitor entry. Visitor access is always limited by a defined validity period or unlock limit; once these are reached, the door can no longer be opened. If the creator’s account is deleted or its permissions change, the visitor’s rights are adjusted or revoked automatically.
Create an access group. In the administrator portal, go to Management → Access Group → Add, give it a name, select the door station(s), choose the list of users and assign a schedule. Only users in that group will be able to unlock the selected doors. Each user can be assigned to a single access group.
On the Doors page, tap My PIN. You can view your assigned personal PIN and, if authorized, modify it. Administrators may also enable Unified PIN mode (a shared PIN for all users) or Card + Personal Password mode, which requires swiping a card plus entering your PIN.
Device & Organization Management
Includes adding devices, configuration, linking to organizations, and permissions.
Administrators can add devices in two ways:
- Bluetooth Scan – Put the door station into Bluetooth configuration mode by pressing its doorbell for ~10 seconds (you’ll hear a voice prompt). In the app, go to Doors → Add Device → Scan via Bluetooth and follow the instructions.
- Manual Entry – In Doors → Add Device, choose Add via MAC/SN and enter the device’s MAC address or serial number.
After adding, agree to the cloud service terms and configure parameters such as relay settings, keypad, snapshots and alarms in Device Settings.
On the door station’s Device Settings page, enable Snapshot Settings to capture photos when a door is unlocked or a doorbell is pressed. Choose the snapshot type (e.g., Unlock Snapshot, Doorbell Pressed Snapshot), set the number of snapshots to take, pick the storage location (local SD card or cloud) and enable notifications. Under Alarm Settings, enable specific alarms (intrusion, anti‑tamper, out‑of‑schedule, unauthorized card/QR, high temperature, etc.) and decide whether snapshots should be taken for alarms.
Go to Management → Access Group → Add to create a group. Specify a name, select the devices, choose the user list and assign a normal schedule or holiday schedule. Schedules define allowed access times (e.g., weekdays, weekends, specific hours) and can be created under Management → Schedule and Holiday. To add a custom schedule, click the “+” icon, choose to define the access period manually or import it from another organization, give it a name and add time ranges. You can also import national holiday sets or manually add individual holidays.
- Platform Administrator (Super Administrator) – Full control over all organizations. Can create and delete organizations, add devices, manage users, assign administrators and view all logs.
- Organization Administrator – Manages devices and users within a single organization. Cannot create or delete organizations.
- General User – Ordinary resident or employee. Can unlock doors using permitted methods (Bluetooth, NFC, PIN, etc.), view personal logs and create temporary keys only if granted permission.
Cloud service plans determine the number of devices and users an organization can support. To upgrade, contact your Grandstream dealer or visit the official website for available plans. Once you purchase a higher‑tier plan, the organization’s capacity will increase accordingly.
Multi‑factor authentication (MFA) can be activated by administrators in the GDMS web portal. After enabling MFA, users must enter a verification code sent to their email or phone when signing in. At present, only administrators can turn on MFA; ordinary residents cannot enable this feature through the app.
A SecureAccess web portal is under development. In the meantime, management tasks are performed through the GDMS cloud portal and the mobile app.
When creating or editing a user, set their User Permission to Local Unlock Only. This permission restricts the user to Bluetooth or NFC door opening and hides the ability to generate temporary passwords and remote unlock buttons. To prevent tenant‑generated visitors entirely, do not enable the All Permissions option for that user.
Monitoring & Logs
It handles videos, snapshots, alarms, call notifications, and record retention.
Check these settings:
- Doorbell call list – The administrator must configure which app accounts receive calls.
- Monitor permission – Your user account must have the Monitor feature enabled and a SIP/virtual number assigned.
- Notifications – Ensure call notifications are allowed in Me → Notification Settings. iOS users should enable critical alerts so calls ring on the lock screen.
If any of these are missing, incoming doorbell calls may not reach the app.
Administrators can view snapshots or video clips captured by a door station from the device details page. Select Replay Preview (or View Replay) to see snapshots and alarm recordings saved to the local SD card or cloud storage. The SD card must be authorized via the device’s web UI for images to be accessible.
- Logs Tab – Divides records into Door Unlock, Call and Other logs. Door unlock logs record the door station, user, time and method; call logs show incoming, outgoing and missed calls; other logs capture temporary password usage and system messages.
- Retention – Logs are stored for 90 days. You can filter logs by date, device or event type, and export them via the administrator portal.
- Alarms – The Alarm List records all alarm events (intrusion, anti‑tamper, unauthorized access, high temperature, etc.). Administrators can subscribe organizations to receive alarm notifications. Alarms include snapshots and video recordings; use the timeline bar to review footage.
Troubleshooting
If you encounter this situation, please check the following steps one by one:
- Verify basic information: Please carefully check whether the entered MAC address and the device’s initial password match exactly.
- Confirm binding status: Verify whether the device’s MAC address has already been registered or bound by another account.
- Reset and try again: If both items above are confirmed correct, it is recommended to restore the device to factory settings and try again.
If you do not receive an email after registration, first check the “Spam” or “Junk mail” folder of your email. Also, confirm that the email address entered during registration is accurate. If you still have not received it, try back to the registration page to resubmit your application.
For account security reasons, activation links have strict time limits. Please carefully read the validity period stated in the email body (e.g., “Valid for 3 days”). If the link is clicked after this time frame, it will be invalid automatically. You will need to return to the platform to re-register and obtain a new link.