Automotive Key Programming Standard
Purpose
Automotive key programming is the only routine job in this shop that destroys property the technician cannot see. An all-keys-lost relearn on most immobilizer platforms erases every key the module currently recognizes, so the spare in a drawer at the customer's house, or the one the co-owner carries, stops working the moment the session completes. Nobody notices until somebody tries to start the car, and by then the truck is three towns away.
The second failure is quieter and more expensive: a module that loses supply voltage part way through a write comes back unresponsive, and what began as a key job becomes a module replacement on a vehicle that was driving fine when you arrived. This procedure exists so the key inventory is established and consented to before any erase, the vehicle's power is held stable through every write, and the count of working keys at the end matches what the customer was told to expect.
Scope
Covers transponder and proximity key origination, add-a-key, all-keys-lost relearn, remote and fob registration, and mechanical key cutting from code or from a decoded lock, on customer vehicles at the roadside or in the shop bay.
Does not cover the identity and authority gate, owned by the Identity and Authority Verification SOP; automotive all-keys-lost is one of its elevated classes and takes a live second-channel call to the titleholder. Does not cover ignition lock or steering-lock mechanical repair, module replacement, or any work on a vehicle reported stolen or held under a lien dispute, which stops on discovery and goes to the owner. Does not cover heavy trucks or equipment on proprietary fleet telematics, which route to the dealer.
Roles and responsibilities
| Role | Owns | Handoff |
|---|---|---|
| CSR or dispatcher | Year, make, model, VIN, key type, and the count of keys the customer still has that work | Passes the job class (add-a-key or all-keys-lost) on the ticket; a ticket with no key count is not dispatchable |
| Technician | VIN verification, consent, power setup, cutting, the programming session, handover count | Returns the session log and the final key count the same day |
| Owner or lead | Holds the shop's registered credential for manufacturer key codes and security gateway access, and its expiry date | Notifies technicians before a credential lapses; a lapsed credential cancels gateway jobs rather than routing them around the gateway |
The handoff that matters is CSR to technician on the key count. The office is told "I lost my only key" more often than it is true, and the technician is the last person who can ask again before the erase.
Procedure
Step 1: Classify the job and confirm authority before quoting. Decide add-a-key or all-keys-lost, because they are different jobs with different risk. Run the elevated authority path: identified person plus a title, current registration matching the VIN on the dash plate, or a live callback to a titleholder who is not the person standing there. Acceptance: job class recorded, plus the authority documents photographed and the second-channel call logged with time and person reached. Wrong looks like programming from a registration alone on a vehicle whose title is held by an ex-spouse or a lender. Stop rule: possession is not authority; no titleholder confirmation on an all-keys-lost job means no session, and the customer is told to bring the title.
Step 2: Establish the real key inventory, out loud, before anything is erased. Ask three separate questions: how many keys or fobs exist anywhere in the world, where each one physically is, and whether anyone else drives the car. Write down the answers. Acceptance: a written count of existing keys with a location for each, and the customer confirming that count back to you. Wrong looks like a customer who says "this is my only key" and remembers the valet fob in a kitchen drawer after the relearn. Stop rule: any key that exists but is not present pauses the job while the customer decides whether to fetch it or accept losing it, and that decision goes in writing before step 3.
Step 3: Verify vehicle identity from two independent places. Read the VIN from the dash plate and again from the door-jamb label or the registration, and confirm both against the ticket. Acceptance: the two readings agree character for character, and the key blade profile or fob part number matches what that VIN calls for. Wrong looks like a swapped dash plate, a jamb label that has been peeled, or a VIN that decodes to a different body style than the car in front of you. Stop rule: any mismatch between the two VIN sources ends the job on the spot and goes to the owner, because the most common reason those two disagree is that somebody wanted them to.
Step 4: Secure the vehicle and stabilize supply before the tool is connected. Transmission in park, wheels chocked, parking brake set, vehicle out of any traffic lane. Put a programming-grade power supply on the battery, not a jump pack and not a charger in boost mode, and confirm it holds the voltage the tool's own documentation specifies for a session. Acceptance: supply steady at the tool's stated requirement, vehicle immobile against a firm push. Stop rule: a battery that will not hold that voltage under load gets charged or replaced before any session begins, because a write interrupted by a sagging supply is a module replacement, not a retry. Hazard: work under the dash puts your hands beside the steering column, so treat the airbag and clockspring as live and follow the manufacturer's disable and wait interval before reaching behind it; if the procedure calls for the engine to run, the bay door is open or the exhaust is on extraction, because carbon monoxide gives no warning.
Step 5: Cut the mechanical key and prove it works before writing anything. Cut from code where the code is available under your shop's registered credential, or decode the door lock or ignition and cut from that. Test the blade in the door and in the ignition or slot before the transponder is written. Acceptance: the blade turns the door lock through lock and unlock, and turns the ignition through every detent, with no binding and no need to jiggle. Wrong looks like a key that works after wiggling, which is a key that will fail in a parking garage in six weeks. Stop rule: a blade that binds gets recut before programming; never write a transponder to a key whose mechanical cut is not right, because you will have spent a key slot on a key the customer will bring back. Hazard: key cutting throws brass swarf, so eye protection stays on and the machine's guard stays down.
Step 6: Run the programming session on the platform's published path. Follow the procedure for that platform, including any timed security access delay, which on some platforms runs to tens of minutes (several General Motors immobilizer relearns run three ten-minute cycles for a thirty-minute total). Where the vehicle carries a security gateway module, authenticate through the manufacturer's approved access programme under the shop's own registered credential. Acceptance: the tool reports the expected number of keys learned, and the security light or immobilizer indicator behaves as the platform's procedure says it should at each stage. Wrong looks like an aborted session because somebody assumed a silent ten-minute wait had failed. Stop rule: if gateway authentication is refused, stop and resolve the credential; do not defeat a security gateway on a customer vehicle to finish a job tonight, because that is the one shortcut that turns a service call into an allegation.
Step 7: Verify every key and remote, then reconcile the count. Start the engine with each key in turn, cycle every remote function, and lock and unlock the vehicle with each fob from a normal standing distance. Acceptance: every key delivered starts the vehicle and every remote function responds, and the delivered count equals the count promised in step 2. Wrong looks like handing over two keys after testing one. Stop rule: if a key programmed but will not start, do not hand it over as a spare; re-run it or replace it before you leave, because a spare that has never been tested is the one the customer will be holding at the airport.
The record this produces
One programming block on the work order, filled in at the vehicle:
- Job class (add-a-key or all-keys-lost) and the authority documents plus the second-channel call
- VIN as read from both sources, with the source of each
- The step 2 key inventory: count, location of each existing key, and the customer's signed decision on any key not present
- Key and fob part numbers written, and the tool and software revision used
- Supply voltage held during the session, and any timed security delay observed
- Gateway access method and the credential used, or the reason the job was declined
- Final verification: each key started the vehicle, each remote function tested, delivered count and customer signature
Readers later: the owner handling a comeback, the customer's insurer if a theft claim follows, and the next technician who needs to know how many keys this VIN is carrying before adding another.
Worked pass: an all-keys-lost sedan where two steps stop the job
Call at 08:20, customer states the only key is gone. Step 1: class recorded as all-keys-lost, title photographed, customer is the sole titleholder so no third-party callback is needed, and the reason is recorded as a lost key rather than a dispute.
Step 2 fails. On the third question the customer remembers a spare fob his adult daughter keeps, roughly forty minutes away. The relearn on this platform erases every recognized key, so that fob dies with the session. Stop rule taken: the technician pauses, explains that fetching it now costs one trip while replacing it later costs another key, and the customer calls her. She arrives at 09:35, and the job is re-scoped in writing from a one-key origination to a two-key relearn.
Step 3 passes, dash plate and jamb label agreeing character for character. Step 4: supply steady at the tool's stated requirement, wheels chocked, vehicle in the driveway rather than the street. Step 5: the ignition is decoded and a blade cut from the decode; the first cut binds at the last detent so it is recut rather than programmed, and the second blade turns the door and every detent cleanly.
Step 6 fails. This vehicle sits behind a security gateway and authentication is refused, because the shop's access credential lapsed two days earlier and nobody flagged it. Stop rule taken: the technician does not fit a bypass, says plainly why the job is stopping, and leaves the cut blades on site so nothing is lost. The lead renews the credential that afternoon and the session runs the next morning at 09:10, including a thirty-minute timed relearn the technician waits out rather than aborting.
Step 7: both the new key and the daughter's fob start the engine, all remote functions respond, the delivered count of two matches the count agreed at 09:35, and the customer signs for two.
Two visits instead of one, and roughly an hour of the first visit spent waiting on a fob. Against that, the alternative on step 2 was a customer finding a dead fob a week later, and the alternative on step 6 was defeating a manufacturer's security gateway on somebody else's car. Neither is a trade worth making to save a return trip.
References
- NASTF Secure Data Release Model and the Vehicle Security Professional registry, which is the legitimate route to manufacturer key codes, PINs and security gateway access for an independent locksmith
- Vehicle manufacturer service information for the specific platform, which owns the relearn sequence, the timed security delay and the maximum key count; a procedure remembered from a similar model is not that information
- Programming tool manufacturer documentation for the supply voltage required during a session, which is the figure step 4 is measured against
- 29 CFR 1910.133 for eye protection during key cutting; supplemental restraint system disable and wait intervals come from the vehicle manufacturer, not from a general standard
- See related: Identity and Authority Verification Before Any Work SOP, After-Hours Emergency Lockout Response SOP, Broken Key Extraction Standard SOP