Intercom Configuration & Access Management

Ekinex Studio application
EKINEX STUDIO - Application Manual
RELATED PRODUCTS:
EK-EK-5DP-VI  ·  EK-ACC-KEY-IP
EK-DEL-4PAN-S / EK-DEL-8PAN-S / EK-DEL-10PAN-S
EK-DEL-10PAN-PL / EK-DEL-15PAN-PL
Version 1.1

Introduction

Scope of this manual

This document contains the instructions for the configuration, with the Ekinex Studio software, of an intercom solution based on the following products:

NameDescriptionModel(s)
DICODoor phone with face recognitionEK-EK-5DP-VI
ACCEDO KEYIP access-control reader (card / PIN / face), placed at building or apartment levelEK-ACC-KEY-IP
DELÉGO PANELSeveral models of wall-mounted touch panelsEK-DEL-4PAN-S, EK-DEL-8PAN-S, EK-DEL-10PAN-S, EK-DEL-10PAN-PL, EK-DEL-15PAN-PL

This manual is intended for installers and system integrators with a good knowledge of networking and of the related products.

Conventions

[KEY]Keyboard keys the installer must press are shown in square brackets.
CourierSoftware messages generated by Ekinex Studio are written in a monospaced font.
Function nameNames of buttons, table fields or other graphic elements of Ekinex Studio are shown in a distinct style.
Information noteBlue boxes provide additional information and recommendations.
Important warningYellow boxes highlight critical points that may affect the correct behaviour of the system.

Copyright

© Ekinex S.p.A. 2026. This manual and the Ekinex Studio software are subject to copyright; all rights are reserved. Copying, reproduction, translation and/or modification, even partial, are expressly prohibited unless approved in writing by EKINEX®. EKINEX® is a registered trademark of Ekinex S.p.A.

Open source licenses

Ekinex Studio makes use of open source libraries and software components. In case of ownership of one or more related products, for a period of 3 years from the last production date, it is possible to request from EKINEX the source code of the components licensed under the GNU General Public License (GPL) or the GNU Lesser General Public License (LGPL). These components can be used, distributed and modified in accordance with their respective licenses.

EKINEX cannot be held responsible in any way for the source code thus distributed, which is provided without guarantees, nor for any damage resulting from modifications made to this software by third parties unless specifically authorized.

More information

For further information on Ekinex Studio, contact Ekinex technical support at support@ekinex.com. The company reserves the right to make changes to this documentation without notice.

General concepts

The chapters gathered here describe the foundations shared by every Ekinex Studio project, regardless of whether it implements video intercom, access control, or both: the general system overview and software settings, how a project is created and managed, how the building structure is organised, and how devices are added and prepared. The two application domains that build on these foundations, video intercom and access control, are covered in Video intercom and Access control.

Overview

System architecture

The following diagram describes the typical configuration of an intercom system based on Ekinex products, configurable with the Ekinex Studio software:

System architecture diagram
Typical intercom system architecture.

In the local network, one or more DICO door phones can be installed to welcome guests and control doors and gates. Video calls from visitors can be answered on several models of DELÉGO PANEL and, additionally, received on smartphones while on the move.

Local vs cloudThe local configuration of DICO and the DELÉGO PANEL(s) can be entirely done in Ekinex Studio. Cloud management instead requires a preliminary setting in the DICO app before integrating it in Ekinex Studio.

The doors under the control of DICO can be opened in different ways:

  • with the internal relay of DICO;
  • with a security relay connected to the RS485 port of DICO;
  • with a KNX actuator controlled by a Delégo Server.
Door opening options
The ways a DICO can open a door: internal relay, security relay, or a Delégo Server.
Door capacityEach DICO can manage a maximum of 6 doors: one connected to the internal relay, one to the security relay, and up to 4 controlled through HTTP commands sent to a Delégo Server.

Requisites

Software requirements

Ekinex Studio can be installed on a computer running one of the following operating systems:

  • Windows 11 or higher
  • macOS 13 (Ventura) or higher

Firmware requirements

For each product family, a specific minimum firmware version must be present on the devices in order to configure them with Ekinex Studio. The table lists the versions that can be updated directly from Ekinex Studio; devices with older versions must first be updated via their web interface.

ProductModelLatest firmware
(configure in Studio)
Earlier supported versions
(configurable / updatable in Studio)
DICOEK-EK-5DP-VI216.43.0.46216.43.0.31 / .34 / .35 / .42 / .43
Accedo KeyEK-ACC-KEY-IP108.43.10.11108.43.10.4 / .9 · 108.43.110.4 / .9
Delégo Panel 4"EK-DEL-4PAN-S51.110.23.8551.110.23.47 / .49 / .50 / .52 / .55 / .56
Delégo Panel 8"EK-DEL-8PAN-S563.43.14.303563.43.12.706 / 563.43.13.303
Delégo Panel 10"EK-DEL-10PAN-S567.43.14.301567.43.13.303 / 567.255.12.773
Delégo Panel 10" PLEK-DEL-10PAN-PL381.110.40.64381.110.40.40 / .41
Delégo Panel 15" PLEK-DEL-15PAN-PL937.43.14.309937.43.14.304 / .308
Older firmwareDevices running a version older than those listed above cannot be detected / configured directly and must first be updated via their web interface, as described in Devices (Devices). The listed versions can be configured in Ekinex Studio and, if not already at the latest, updated from within the software.

Previous configuration

Ekinex Studio is designed to configure devices that have never been configured manually via their web interface. If a device contains a previous configuration, unpredictable conflicts can occur with the settings applied in Ekinex Studio; proceed at your own risk.

Start from empty devicesEkinex Studio cannot read the configuration present in the devices, even if it was made by another instance of Studio. Always start from empty devices, importing a previously saved project if needed.

Preliminary operations

Software installation

Install Ekinex Studio using the SETUP on Windows or the DMG on macOS, like any other standard software, and accept the permissions requested for network interaction and notifications.

Devices connection

Connect the DICO door phone(s) and the DELÉGO PANEL(s) to the same network subnet, using a PoE switch or PoE injectors; alternatively, a dedicated power supply can be used. It is not necessary to identify the connected devices on the network, nor to perform any preliminary configuration on the display or the integrated web interface.

Ekinex cloud account

An Ekinex cloud account is required to use Ekinex Studio. The first time the software is opened, enter the user e-mail and the corresponding password:

Login dialog
Cloud account sign-in.

If you do not yet own an account, create one for free using the link at the bottom of the dialog and filling in the requested information:

Account creation form
Creating a new Ekinex account, directly in the software.

Settings

Press the Settings button on the right of the toolbar (gear symbol) to open the settings dialog. The options are organised in groups; the current software version is shown at the bottom of the dialog.

Ekinex Studio settings dialog
The Ekinex Studio settings dialog.
General
LanguageThe language used for the software user interface (Italiano, English, Français, Deutsch, Español, Português). It can differ from the language assigned to the devices in a project. Changing it reloads the application.
In-app notificationsHow many in-app notifications are shown: Enable (all), Alerts only, Errors only, or Disable.
Network
Network InterfaceThe computer network interface used to reach the devices. Options: Automatic (the interface preferred by the OS, whose current IP address is shown next to the option), All interfaces (search on all networks - Ethernet, Wi-Fi… - simultaneously), or a specific interface among those detected on the computer.
Updates
Update channelThe online distribution channel for Ekinex Studio updates: Production (default - stable public releases) or Beta (early access to features not yet publicly released). Selecting Beta requires accepting a disclaimer and is not recommended on production installations, as experimental versions may be unstable.
Diagnostics
Collect usage dataWhen enabled, Ekinex Studio collects anonymous usage and diagnostic data to help improve the software.
Analytics levelThe detail level of the collected diagnostics: All, Info (default), Warning or Error.
Log - ExportExports the local usage log to a file, for example to attach to a support request.
Diagnostics options appear on demandThe Analytics level and Export controls are shown only while Collect usage data is enabled.

System update

Ekinex Studio periodically checks for available software updates on the cloud. You can trigger a check manually with the Check for updates… menu item:

Check for updates menu
Manual check for software updates.

When an update is found, a red indicator in the bottom bar informs about it; press the contained link to download and apply the new version directly inside the software. The configuration is not lost or altered during the update.

Projects

Introduction

Ekinex Studio works with projects. A project contains the configuration of the intercom system of one or more buildings that need to be treated together. A project can be exported, shared and imported into another instance of Ekinex Studio; an unlimited number of projects can be created on the same computer.

New project

Open the project selector at the top-left of the header and press Create a new project.

Choose the project type first (new in v1.1)In Ekinex Studio v1.1 the very first step of a new project is choosing its type. The type determines how users and access permissions are managed throughout the project and cannot be changed afterwards, so select it according to the installation.
Project type selection
The Project type dialog shown when creating a new project.
TypeIntended forAccess-management behaviour
VillaSingle dwellingOwner users have visibility over all installed devices. Access is defined explicitly through groups; there is no apartment subdivision.
BuildingNon-residential building with multiple areas / zonesAimed at creating multiple users for different areas and zones; owner users still have visibility over all installed devices. Like Villa, every device is selectable in the access groups.
ApartmentsResidential apartment complexEach apartment can have one owner user and up to 3 secondary users. Users are assigned to an apartment and inherit access to its devices; access groups expose only the public (shared) devices.
Where the difference showsThe practical consequences of the project type on users, groups and time profiles - in particular the difference between Apartments (implicit per-apartment access) and Villa / Building (all devices explicit in groups) - are detailed in Users & Access Management (Project types: Apartments vs Villa / Building).

After choosing the type, the project is created with a default name that can be edited from the project selector (see Delégo Panels).

Import / export & project management

All projects are managed from the project selector in the header (top-left). It lists the Last opened project and the Other projects, and provides the create and import actions.

Project selector dropdown
The project selector: create, import, and the list of existing projects.
  1. Edit - rename the project.
  2. Save - export the project to a file on the computer.
  3. Delete - remove the project.
  • Create a new project - starts the new-project flow described in Dico.
  • Import project - imports a project file previously exported from this or another instance of Ekinex Studio.
  • For each listed project, hovering reveals the three actions numbered in the figure above: edit, save and delete.
BackupExporting a project (save) produces a file that can be re-imported later as a backup, on the same or another computer. An unlimited number of projects can coexist on the same installation.

Buildings

Introduction

Each project is made of at least one Building, which can contain:

  • one or more DICO door phone(s);
  • one or more Accedo Key access-control reader(s);
  • one or more Apartment(s) representing the internal spaces to be called, each containing one or more DELÉGO PANEL(s) (and, optionally, their own Accedo Key).

The following example - a project with two buildings - shows how these items are organised in the navigation tree:

Two-building project tree
A project with two buildings. Building 1 pairs a DICO with an Accedo Key in different apartments (video intercom and access control); Building 2 has only a DICO and an Ekinex Touch panel (video intercom only).
Accedo Key placementThe Accedo Key access reader can be placed at different levels of the structure: directly under a Building (to control a shared/common entrance) or inside an Apartment / zone (to control that unit's own access). Its position determines whether the device is treated as public or as belonging to a specific unit - which, in Apartments projects, drives how access is granted (see Users & Access Management).

When a new project is created, the first Building with a single Apartment is automatically added to it.

Recommended orderCreate the Building structure as the first operation, before assigning the devices.

Buildings

Add a new building

To add one or more Buildings to the project, press the Add building button at the bottom of the project tree column on the left:

Add building
The Building view and its settings in the Devices area.
  1. Press Add building, at the bottom of the project tree column, to add a Building to the project.

Remove a building

A Building can be removed by pressing the corresponding bin symbol; all the contained devices are automatically removed from the project.

Minimum structureAt least one Building must be present in the project.

Building settings

Selecting a Building in the project tree lets you enter the following information, referred to the entire building and its devices:

AddressThe street address of the building: Street, City, ZIP code, Province, Country.
Devices languageThe language used on the display of the devices belonging to the building.
Date and time modeDetermines whether date/time is retrieved automatically from the internet or assigned manually.
TimezoneThe time zone of the building's region, used to determine date/time in automatic mode.

Devices status

This tab contains the overview of all the devices associated with the Building; see the Download chapter for details.

Apartments

Add a new apartment

To add a new apartment to a Building, press the [+] button that appears when moving the cursor over it. The apartment requires:

NameThe identifier of the apartment.
Important - changed in v1.1The Enable smartphone calls and Apartment number parameters are no longer set on the apartment. In Ekinex Studio v1.1 they have been moved to the individual user, in Users › Edit, and are configured per user (see User properties). Set them there when editing each apartment's user(s).

Remove an apartment

To remove an apartment from the project, press the corresponding bin symbol; all the contained devices are automatically removed.

Third level: organising devices (Room / Zone)

Starting from v1.1, a third level can be added below the second-level node (the Apartment, in Apartments projects) to arrange its devices into sub-areas. The label of this level depends on the project type:

Project typeSecond levelThird level (new in v1.1)
ApartmentsApartmentRoom
VillaFloorRoom
BuildingAreaZone

To add it, hover over a second-level node and press the [+] button, exactly as when adding an apartment.

Purely organizational - devices inherit the apartmentArranging devices into these third-level areas is only an organisational convenience - a way to group an apartment's devices into rooms/zones; it does not change their behaviour or the way access is granted. In practice a device placed in a third-level area belongs to, and inherits the properties of, its parent Apartment: in an Apartments-type project it is treated exactly as if it were placed directly under the apartment, keeping the same apartment inheritance for access control (see Users & Access Management).

Devices

Introduction

To add a device to the current project, drag & drop it from the right panel into the desired position in the existing Building structure. Two approaches are available:

  • add a generic item from the Library and associate it with a real device later;
  • Discover the available device(s) on the network and associate them directly with the project.
Recommended orderAdd all devices to the project as one of the first operations, before starting their configuration. This makes it easier to establish the relations among devices.

Library

Adding devices to the project

This section of the right panel contains all the device types that can be added to the project:

CategoryModelDevice
Outdoor unitsEK-EK-5DP-VIDICO door phone
EK-ACC-KEY-IPAccedo Key access-control reader
Indoor unitsEK-DEL-4PAN-SDelégo Panel 4" (Smart)
EK-DEL-8PAN-SDelégo Panel 8" (Smart)
EK-DEL-10PAN-SDelégo Panel 10" (Smart)
EK-DEL-10PAN-PLDelégo Panel 10" (Plus)
EK-DEL-15PAN-PLDelégo Panel 15" (Plus)

By dragging an element into the project (the DICO in a Building, the Panels in an Apartment), a generic device of the selected family is used, not yet associated with a real unit. This approach is especially helpful when preparing a project in advance (offline), when the effective installed devices are not yet available on the network.

Firmware assumptionBy assigning a device from the Library, it is assumed it will have the latest firmware available for that family.

MAC address assignment

Later, when the corresponding device is available, associate its MAC address by entering it manually or searching for it on the network:

MAC address assignment
MAC address assignment.

Only devices of the appropriate family that have not already been associated with the project are listed in this drop-down menu.

Manual IP assignment

If a device does not appear in the list of available MAC addresses, enter it manually by pressing the Add manually button:

Add manually dialog
Manual MAC / IP assignment.

A dialog box asks for the MAC address and the actual IP address of the device.

Retrieving the device IP addressDICO: press and hold 10 seconds on the display; enter the admin password (default admin) and confirm; select Network and note the IP address.
Delégo Panel: go to the Settings area; open Device information (note the LOCAL IP) or, otherwise, Device settings › Network (note the LAN IP). When requested, enter the installer PIN (default 123456).

If the entered MAC and IP match and the device has the expected model, Ekinex Studio communicates with it exactly as if it had discovered it on the network.

IP changesIf the IP address of a manually assigned device changes, the assignment must be repeated, because Ekinex Studio cannot detect it automatically on the network.

Discover

This section of the right panel contains the devices detected on the network; items already associated with the project are shown in gray.

Assignment to the project

When dragging an element from Discover, it is automatically associated with the MAC address of the specific device (no later assignment is needed); in this case the firmware version of the actual device is used instead of the latest one.

Old firmwareIf the selected device has a firmware too old to be configured in Ekinex Studio, you are asked to update it (procedure described below).

If the desired device is not in the list, try one of the following:

  • run the network scan again by pressing the Refresh symbol on the Discover tab title;
  • change the computer's Network interface used for the scan in the Settings;
  • try the manual IP assignment as explained above.
Devices requiring manual IPManual IP assignment is necessary for Delégo Panel Smart 8" and Smart 10" on firmware 563.43.12.706 / 567.43.12.704 / .706 / .707, which cannot be detected on the network before updating them. Older versions must be updated outside Ekinex Studio first (see New project).

Manual update before assignment

If the device still cannot be added, it has a firmware not yet compatible with Ekinex Studio and must be upgraded first:

  1. Add an item of the appropriate product family from the Library.
  2. Select the System tab and download the latest firmware version to your computer.
    System tab firmware download
    Downloading the latest firmware from the System tab.
    1. Open the device's System tab, which shows its firmware information.
    2. Press Download latest firmware to fetch the newest official firmware, ready to be applied.
  3. Identify the device IP address (as described for manual IP assignment).
  4. Enter the device's IP address in a web browser and log in with the default credentials (typically admin / admin).
  5. Open the firmware upgrade section (Settings › Basic or Upgrade › Basic), press Upgrade, select the downloaded file and press Submit.
    Web UI firmware upgrade
    Firmware upgrade through the device web interface.
  6. Wait for the procedure to end and run the network scan again.

Network ports for device discovery and communication

For Ekinex Studio to discover devices on the network and communicate with them, the following ports must be open on the firewall / router:

ProtocolPortTypePurpose
COMMUNICATION (proprietary)8500UDP, bidirectionalDevice configuration read/write (GetParam / SetParam)
COMMUNICATION progress8200UDP, outboundOperation progress notification to device display
HTTP80TCPDevice REST API: login, config, system info, firmware/audio upload
HTTPS443TCPSame as above, when device supports HTTPS
UDP return trafficBecause ports 8500 and 8200 use UDP, the client's firewall / router must allow return traffic on the same flow (stateful), not just outbound requests.
Device discovery over VPNIf the installer is connected to the system via VPN, device discovery (network scan) cannot be performed, even with the ports above open. However, if devices have IP addresses reachable over VPN, configuration download is still possible.

If the client also uses Ekinex Cloud (WireGuard VPN) for remote access, or downloads firmware updates from the same network, these additional endpoints must be reachable:

ServiceEndpointPort
Ekinex Cloud auth / APIcloud.ekinex.comTCP 443
Ekinex Cloud MQTT (VPN state)cloud.ekinex.comTCP 8884 (WSS)
WireGuard tunneldynamic (from .conf file)UDP, port assigned by server
Firmware downloadwww.ekinex.comTCP 443
App auto-updatewww.domoticalabs.comTCP 443

Passwords

When a new device is associated with the project, Ekinex Studio assigns it a securely generated password instead of the default admin. If the device is not new and a different password was previously assigned, you are asked to enter it:

Existing-password prompt
Existing-password prompt.

In that case the original password is used by Ekinex Studio instead of a generated one. If the original password is unknown, it can be reset from this dialog; for security reasons the device serial number (SN), printed on the back of the device, is required, along with an internet connection.

Strong passwordsFor security reasons it is recommended to manually assign a strong password, made of upper- and lower-case letters, numbers and symbols.

Once the device is correctly assigned, its System tab lets you copy the username and password - useful for the web interface or third-party integrations:

Copy credentials
Copying the device credentials from the System tab.
  1. Open the device's System tab.
  2. Press the copy icon next to Password to copy it to the clipboard (a confirmation message appears at the top).

Some devices, like the DICO door phone, use several passwords / PINs for different operations:

Administrator passwordAccess to the device web interface.
HTTP API (communication) passwordSending commands to the device on the network (e.g. to open a lock).
PINNumeric code to log in on the device display.

Each can be copied to the clipboard with its corresponding copy symbol.

Firmware update

When a device is added from Discover, its firmware version is checked for compatibility. If it is too old to be configured, you are asked to update it and the following dialog is shown:

Firmware update dialog
Firmware update prompt.
  1. Press Download firmware to download the latest firmware from the cloud to your computer.
  2. Press Device firmware update to start the update on the device using the downloaded file.

The update dialog then lets you choose how to update: Automatic - Ekinex Studio downloads and installs the latest official firmware from the cloud (recommended) - or Manual, to install a firmware .rom / .zip file from your computer.

Firmware update dialog
Choosing how to update the firmware: Automatic (from the cloud) or Manual (local file).
Start from factory conditionIt is strongly recommended to start configuration from a factory condition, especially for devices previously configured via their web interface.

During the update, a dialog informs on the operation in progress. You can leave this window and configure other devices meanwhile; the progress dialog reappears when selecting the same device until the update completes.

Update progress
Firmware update in progress.

When closing the dialog, Ekinex Studio refreshes the device information and, after a few seconds, the new version becomes visible in the System tab. If it does not update automatically, press Read device information at the bottom of the screen.

Read device information
The “Read device information” button.
  1. Press Read device information to query the device and refresh its data (model, firmware version, reachability).

Video intercom

This chapter covers the configuration of a video-intercom system, built with DICO door phones and Delégo Panel indoor units. It opens with an overview and reading guide, then details each device.

Overview

Ekinex Studio v1.0 was dedicated exclusively to the configuration of video-intercom systems. Starting from v1.1, the software also introduces a complete access-control layer. The two domains are configured in different areas of the application, but share the same final step.

The main navigator, at the top of the window, gives access to the three working areas used throughout this manual:

Main navigator: Devices, Users, Download
The main navigator - the Devices, Users and Download areas.
PurposeDevices involvedWhere you work
Video intercomDICO door phones and Ekinex Touch (Delégo Panel) indoor unitsDevices area only
Access control (new in v1.1)Adds the Accedo Key readerDevices area and the Users area
Common step - DownloadWhichever the purpose, the configuration prepared in Ekinex Studio only becomes effective once it is transferred to the physical devices through the Download area (Download). Both video intercom and access control end with this step.

The overview below shows a minimal video-intercom example - focusing on the project navigation tree - and points you to the specific chapters to deepen. Access control is covered separately in Access control.

This section is a reading guide: it points you to the chapters to focus on when the installation is a pure video-intercom system. Such a project is built entirely in the Devices area - a DICO door phone at the building entrance and one Ekinex Touch (Delégo Panel) inside each apartment to answer the calls:

Project tree of a video-intercom project
Video-intercom project tree: a DICO at the building level and an Ekinex Touch panel in each apartment.
Chapters to read
  • Dico - call contacts, homepage layout, relays and audio/video hardware of the door phone.
  • Delégo Panels (Ekinex Touch) - door-opening buttons and display options of the indoor units.
  • Download - transfer the configuration to the physical devices.
No Users area requiredFor a purely video-intercom installation there is no need to open the Users area (Users & Access Management): calls and door opening are configured directly on the devices.

Dico

Introduction

The DICO door phone(s) can be configured in Ekinex Studio for all intercom functionalities in the local network, by adding one or more to a Building. The configurable parameters are organized in the sections described below.

Contacts

This section defines the possible recipients of calls made by the DICO door phone; each contact can ring one or more Delégo Panel(s) and/or the smartphones of one or more users. A first contact is already available on first entry; press Add Contact to create more. Each contact requires:

NameThe label identifying the contact.
Contact imageAn optional picture for the calling button(s) or the DICO address book. Maximum size 300×300 pixels.
Devices to CallIn the Devices to Call tab, select from the building structure which Delégo Panel(s) must ring when the contact is called.
Users to CallIn the Users to Call tab, select which users are called on their smartphone when the contact is called (see below).
DICO contacts
Defining a DICO contact.
  1. Press Add Contact to create a new contact.
  2. Use the delete icon to remove the selected contact.
  3. Drag the handle beside the thumbnail to reorder the contacts.

Users to Call links the contact to the Users area (Users & Access Management). It lets the DICO place a call to a user on their smartphone: only users that have an Apartment Number assigned appear in this tab. The Apartment Number is set per user in Users › Edit, and becomes available once Enable Smartphone Calls is turned on for that user (see User properties). This replaces the old per-apartment smartphone setting (Add a new apartment).

Layout

This section defines the graphical aspect of the product display, and the number and functionality of the buttons. The typical homepage layout (shown when a visitor approaches, before interacting) contains:

DICO homepage layout
DICO homepage layout elements.
Main buttonsUp to 3 buttons at the bottom of the display. Normally used for general functions (QR code, PIN access, face recognition), they can also call a contact.
Additional buttonsUp to 8 buttons organized in 4 rows along the main part of the screen.
Building informationStreet address and number, company/family name and additional info (e.g. opening hours) shown in the upper part, if space allows.
Background pictureCustomizable background image.

Each row of additional buttons can host two half-width buttons or a single extended button; numbering starts from the bottom row (closest to the main buttons) upward:

Additional button rows
Numbering of the additional buttons (from the bottom row upward).

The first element in the DICO Layout tab lets you choose the preferred layout, which determines the number of available buttons:

Layout choice
DICO - Layout tab.

The following additional data can be set before customizing the buttons:

Name / Street number / Address / Working hoursBuilding address information shown in the header.
Button font sizeSize of the labels inside the buttons.
Background imagePicture placed on the homepage background. Maximum (and suggested) size 900×1600 pixels.

For each button row you can enable one or more buttons; they adapt their width automatically. Each button is customized with:

TypeThe button function: Contact (calls a set contact), QR code (reads a QR with the front camera), PIN code (shows the numeric keypad), Face recognition (identifies an enrolled face), Tenants list (shows the full address book), Free text (a custom label), HTTP command (sends an HTTP string, e.g. to switch a KNX light through a Delégo Server).
NameThe label displayed in the button.
IconThe graphical symbol inside the button. For contact buttons, selecting Contact picture uses the contact's image.
ColorThe background colour of the button.
OpacityThe degree of transparency of the button against the background colour.

The preview shows in advance the graphical result on the display after the download.

Layout preview
Live preview of the DICO homepage.

Display

The general aspect of the display is set with:

Timeout before display off or screensaverInactivity timeout for the automatic switch-off (or screensaver) of the display (from 5 seconds to 30 minutes).
Wake up modeSwitch-on strategy: Manual (press on the display), Auto (proximity sensor), or Touch-here icon.
Keypad display modeOrder of the numeric keys. The Random option places numbers in casual order for higher security.
Home page return timeoutSeconds before automatic return to the homepage after a visitor opens a different section (0–300).
Face recognition movedIn v1.1 the face-recognition options (including Background face recognition) are grouped under the Hardware tab - see Hardware.

The following options refer to the screensaver:

ScreensaverEnables the screensaver.
Screensaver timeInactivity timeout before the screensaver activates.
Screensaver picture intervalSeconds between two consecutive images.

To change the default screensaver pictures, delete them with the bin and press [+] to browse for a new one:

Screensaver pictures
DICO - Display tab.

Relays

Internal relay

If the internal relay opens a door, enable it with the corresponding checkbox; the following parameters can be set:

NameLabel identifying the door opened by the relay.
Pulse durationSeconds of activation of the relay.
Default relaySelect if the internal relay is the default for the DICO door phone.
Internal relay
DICO - Relays tab.

Security relay

A secondary lock can be commanded by connecting a security relay to the RS485 port of DICO. The same settings seen for the internal relay are available.

External relays

DICO can open up to 4 external relays by sending HTTP commands on the local network:

Enable flagEnable this checkbox to use the relay.
NameLabel identifying the door opened by the relay.
HTTP commandThe HTTP URL called when the relay is triggered.
Action URL (v1.1)In addition to the relays, the Relays tab exposes an Action URL section: a set of HTTP URLs that DICO calls automatically in response to access events - on a valid face recognition, an invalid face recognition and a relay trigger. This allows integrating the door phone with third-party systems (e.g. logging or automations) beyond simply opening a lock.

Commands with Delégo Server

The external relays of DICO can send a command to a Delégo Server, for example to trigger a KNX actuator. Compose the HTTP command as follows. Open the Delégo Server web interface in the administration space and activate Expert mode in the toolbar:

Delégo Server expert mode
Activating Expert mode in the Delégo Server web interface.

For KNX commands, if you do not yet have a widget containing the group address to command, create one:

  1. Select Technologies › KNX › KNX Widgets › Other and open the page.
  2. Select Single value in the drop-down to the left of the Add button.
  3. Press Add, wait for the new entry and open it with the edit button.
  4. On the Single value line, in the KNX addresses section, enter the group address in the Main field and any feedback in the Feedback field (or drag them from the ETS project tree).
  5. If you do not want this widget in the supervision, do not select any Room or Function.
KNX widget
Creating a KNX single-value widget in the Delégo Server.

If the widget already exists, open its detail sheet, locate the group address entry in the KNX addresses section and open its detail; the object ID is the first entry in the details section:

Object ID detail
Locating the object ID in the widget detail sheet.

For MODBUS widgets, proceed similarly, identifying the sub-object corresponding to the register to control and detecting its ID. Once the object ID is known, compose the command string as follows:

http://<IP>/www/modules/system/soapwrapper.php?format=json&username=<user>&password=<pwd>&function=runonelement&id=<id>&action=<action>&payload=<payload>

IP addressDelégo Server IP address.
username / passwordValid credentials of a local Delégo Server user.
idID of the previously identified object.
actionDepends on the object type: SETVALUE (KNX or MODBUS commands) or EXECUTE (Delégo scenarios).
payloadFor SETVALUE actions, the numeric value to send to the object (e.g. 1 for an ON command on the KNX bus).

Hardware

DICO Hardware tab
DICO - Hardware tab (Camera, Audio, White light, Tamper alarm).
Camera
Video areaOrientation of the video stream: horizontal or vertical.
CalibrationOpens a popup to set, for a horizontal stream, the height of the camera image to be streamed.
Audio
Microphone / Speaker / Sounds volumeVolume level for the corresponding audio element.
Allow volume adjustment during callIf enabled, visitors can calibrate the audio volume during the call from the DICO display.
Face recognition
Face recognitionEnables face-recognition access on the door phone.
Background face recognitionIf enabled, face recognition runs continuously in the background without showing the front camera; no message is displayed unless a valid face is detected.
Offline facial learningAllows enrolling faces directly on the device, without a cloud connection.
Facial recognition sensitivityRecognition threshold: Low / Normal / High / Very high.
Anti-spoofing sensitivityStrictness of the liveness / anti-spoofing check: Normal / High / Very high.
Facial recognition intervalMinimum interval between two consecutive recognitions (1–8).
White light
ModeWhether the white LED on top of DICO (to highlight visitors in low light) is activated by the motion sensor (Automatic) or Off.
BrightnessIntensity of the LED if enabled.
Tamper alarm
EnabledIf selected, the internal sensor is activated and a sound alarm plays in case of tampering.
Note on volumesOn some touch devices the maximum volume depends on the power source (12 V or PoE).

Network

This section assigns the desired IP addressing to the DICO door phone:

DICO Network tab
DICO - Network tab.
Network configurationWhether the IP address is obtained automatically (DHCP) or assigned statically.
IP address / Subnet mask / Gateway / Preferred DNS / Alternate DNSThe IP address components, to be assigned in case of static IP.
Use static IPIt is strongly recommended to assign static IP addresses to all devices configured with Ekinex Studio, to avoid malfunctioning due to address changes over time.

The bottom of the screen reports the actual IP address of the device (if associated with a MAC address and reachable); it can differ from the desired configuration until a Download is performed.

System

This tab contains information read from the device (if a MAC address has been entered).

DICO System tab
DICO - System tab.
Device information
ModelThe part number of the device.
MAC addressThe MAC address of the device.
Credentials
UsernameUser to access the web interface.
Administrator passwordPassword to access the web interface.
Communication (HTTP) passwordPassword for HTTP commands to the DICO door phone.
PINNumeric PIN to access the settings on the display.
Advanced configuration
Link to web pageOpens the DICO web interface for advanced settings not managed by Ekinex Studio.
Do not change managed settingsDo not manually change any settings already configured by Ekinex Studio via the web interface; this could lead to malfunctioning and unpredictable behaviour.
System update
Firmware versionFirmware detected on the connected device.
Latest firmware availableMost updated version on the cloud; the link downloads it to your computer.
Firmware updateStarts the update procedure (see Firmware update).
System actions & reachability
Reset to factoryClears all settings and returns the device to factory defaults.
RebootRestarts the device without other modifications.
Read device informationRequests updated information from the device.

Delégo Panels

Introduction

The Delégo Panels can be configured in Ekinex Studio for all intercom functionalities, by adding one or more to an Apartment. The configurable parameters are organized in the sections below.

Other panel functionsThe other functions of the panels - Delégo Server visualisation, SENTIO audio system management and third-party app installation - remain configurable directly on the display.

Layout

This section configures up to three buttons, shown during the preview and video call, to open doors or gates:

Delégo Panel layout buttons
Delégo Panel door-opening buttons.
EnableSelect the checkbox to enable the button on the display.
NameThe label associated with the button on the display.
Device / RelayAmong the devices offering one or more relays, select which is opened when the button is pressed.

A preview of the final result is shown on the right; the actual result may differ slightly depending on the panel model.

Display

Display
Auto brightnessAutomatic adaptation of the display luminosity.
Brightness levelManual adjustment of the brightness.
Motion
Proximity sensorEnables the motion sensor to switch on the display.
Proximity detection distanceShort or long detection distance.
Screensaver
ScreensaverEnables or disables the screensaver on the display.

To change the default screensaver pictures, delete them with the bin and press [+] to browse for a new one:

Delégo Panel screensaver
Delégo Panel - Display tab.
Model differencesSome options may differ slightly according to the specific panel model.

Hardware

This section is available only on certain panel models; on the models that expose it, it offers:

AvailabilityThe Hardware tab is not shown on all Delégo Panel models (for example it is absent on the 4" Smart and 10" Plus tested with this manual). When present, it provides the options below.
Internal relay
EnableEnable the relay so it can be associated with a button on the display (of the same or another panel).
NameLabel identifying the relay.
Pulse durationSeconds for the relay triggering.
Volume
Ringtone / Call / Microphone / Media volumeVolume level for the corresponding audio element.

Network

This section assigns the desired IP addressing to the Delégo Panel:

Delégo Panel Network tab
Delégo Panel - Network tab.
Network configurationWhether the IP address is obtained automatically (DHCP) or assigned statically.
IP address / Subnet mask / Gateway / Preferred DNS / Alternate DNSThe IP address components, to be assigned in case of static IP.
Use static IPIt is strongly recommended to assign static IP addresses to all devices, to avoid malfunctioning due to address changes over time.

System

This tab contains information read from the device (if a MAC address has been entered): Device information (Model, MAC address), Credentials (Username, Password), Remote control (link to the web page), System update (firmware version, latest available, update button), and System actions (Reset to factory, Reboot, Read device information). The behaviour is the same as described for the DICO in System.

Delégo Panel System tab
Delégo Panel - System tab.
Do not change managed settingsDo not manually change, via the web interface, any settings already configured by Ekinex Studio; this could lead to malfunctioning and unpredictable behaviour.

Access control

This chapter covers access control, introduced in v1.1 with the Accedo Key reader and the Users area. It opens with an overview, then details the reader and the full user / access-management workflow.

Overview

This section is the reading guide for when, besides video intercom, the installation also requires access control. On top of the video-intercom project you add one or more Accedo Key readers - typically one inside each apartment (and, optionally, one at a shared entrance). The navigation tree then also contains the readers:

Project tree with Accedo Key readers added
The same project with an Accedo Key added to each apartment.
Chapters to read (in addition to those for video intercom)Besides Dico, Delégo Panels and Download listed in Overview, also read:
  • Accedo Key - configuration of the access reader in the Devices area.
  • Users & Access Management - who may open which reader and when (users, groups, time profiles, credentials).
Now the Users area is requiredAs soon as an Accedo Key is part of the project, the Users area becomes necessary: there you create the users, assign them to their apartment, and define groups, time profiles and access credentials (PIN, Face ID, RFID). This is what actually grants each person access to the readers.

Accedo Key

Introduction

The Accedo Key (EK-ACC-KEY-IP) is an IP access-control reader that opens doors and gates by PIN code, QR code or RFID card. As described in the Buildings section (Buildings), it can be added either directly under a Building - to control a shared / common entrance - or inside an Apartment / zone, to control that unit's own access.

The configurable parameters are organized in the sections described below.

Relays

The Accedo Key can command locks both through its own relays and through HTTP commands sent on the network, and it can trigger custom actions in response to access events.

Accedo Key Relays tab
Accedo Key - Relays tab.
Internal relayThe on-board relay. Set a Name (label of the door) and a Pulse duration (0–60 s).
Security relayA secondary lock connected to the RS485 port, with the same Name and Pulse duration options.
External relay [1…4]Up to 4 external relays commanded via HTTP on the local network (for example a KNX actuator through a Delégo Server - see Commands with Delégo Server).
Action URLHTTP URLs called automatically on specific access events: valid QR code, invalid QR code and valid code entered.

Hardware

This section sets the physical feedback of the reader:

Accedo Key Hardware tab
Accedo Key - Hardware tab.
Audio
Keypad sounds volumeVolume of the keypad feedback tones (1–15).
Speaker volumeVolume of the speaker (0–15).
Voice alertsSpoken confirmations for Access allowed, Access denied and Code cleared (each can be previewed).
Status light & backlight
Status lightMode (Off / Automatic) and Brightness (1–5).
Backlight keypadMode (Automatic / On) and Brightness (1–5).
Tamper alarm
EnabledActivates the internal tamper sensor; the alarm can be disarmed when needed.

Network

This section assigns the desired IP addressing to the Accedo Key:

Accedo Key Network tab
Accedo Key - Network tab.
Network configurationWhether the IP address is obtained automatically (DHCP) or assigned statically.
IP address / Subnet mask / Gateway / Preferred DNS / Alternate DNSThe IP address components, to be assigned in case of static IP.
Use static IPAs for all devices, it is strongly recommended to assign static IP addresses, to avoid malfunctioning due to address changes over time.

The bottom of the section reports the connection status and offers the Read device information action.

System

This tab contains information read from the device (if a MAC address has been entered): Device information (MAC address), Credentials (Username, Password), Remote control (Link to web page), System update (firmware version, latest available, update button) and System actions.

Accedo Key System tab
Accedo Key - System tab.
Reset to factory deletes dataThe Reset to factory action on the Accedo Key clears all settings and data and returns the reader to factory defaults; use it only when re-commissioning the device.

Users & Access Management

This chapter covers the configuration of users, access groups and time profiles - the access-control area of Ekinex Studio, reached from the Users entry in the application header.

Introduction

The Users area is the section of Ekinex Studio dedicated to access control: it defines who may operate the intercom and access-control devices of a project, on which devices, and when. It is reached from the Users entry in the application header.

The area is organised into three subsections, selectable from the tabs at the top of the left panel:

  • Users - the individual people (residents, staff, guests) who are granted access.
  • Groups - named sets of users that share the same device permissions and schedules.
  • Time profiles - the schedules that determine the time windows during which access is granted.
Users area overview
The Users area with the Users subsection active. Left: the user list and the subsection tabs. Right: the properties of the selected user.
Users, Groups and Time profiles tabs
The three subsection tabs. The number badge indicates how many items each subsection currently contains.
PrerequisitesAccess management operates on the intercom / access-control devices of the project (Dico door phones and Accedo Key readers). Add these devices to the project structure in the Devices area before configuring users and permissions.

Access management model

Access is never granted directly from a user to a device. It is the result of the combination of the three subsections:

The access chainA User is a member of one or more Groups. Each Group authorises a set of Devices (its Access Control list) and is associated with one or more Time profiles. A user may therefore operate a device only when all of the following are true:
  1. the user belongs to a group;
  2. that group authorises the device;
  3. the current moment falls inside one of the group's active time profiles.

A newly created group is automatically associated with the system time profile Always (00:00–23:59, every day), so that access is granted at all times until a more restrictive schedule is applied.

EntityAnswers the questionKey relationships
UserWho?Belongs to one or more Groups; (Apartments projects) is assigned to an Apartment.
GroupWhat? (which devices)Contains Users; authorises Devices; uses Time profiles.
Time profileWhen?Associated with one or more Groups.

The Users subsection

The Users subsection lists every person defined in the project. Select a user in the left list to edit its properties on the right, or click ADD USER to create a new one. The search field at the top of the list filters users by name.

User properties

The upper part of the detail panel holds the identity and, in Apartments-type projects, the apartment association of the user.

User properties and apartment assignment
User identity fields and - in Apartments-type projects - the Apartment assignment.
FieldDescription
NameDisplay name of the user.
EmailOptional e-mail address of the user.
ApartmentApartments-type projects only. The apartment the user belongs to. The user inherits access to every device located in that apartment (see Project types: Apartments vs Villa / Building).
Enable Smartphone CallsEnables forwarding of intercom calls to the user's smartphone.
Apartment NumberThe dialing / directory number associated with the user's apartment.

Credentials

The Credentials tab defines how the user physically authenticates at a device.

User credentials: PIN, Face ID, RFID
The credential types available for each user.
  • PIN - a 2 to 8 digit numeric code.
  • Face ID - face enrolment for facial-recognition access.
  • RFID Cards - up to 5 RFID cards per user.

Group membership

The Groups tab of a user shows the groups the user belongs to. Use Add group to add the user to further groups.

User group membership
The selected user is a member of the All Residents group.

Authorized devices

The Authorized devices tab is a read-only summary of the devices the user can actually operate, computed from all the mechanisms described in this chapter. Each entry carries a tag that explains why access is granted.

Authorized devices summary
Authorized-devices summary for Owner Garden Unit.
Authorized devices detail with access tags
Access tags: the public Dico is granted through the All Residents group; the Garden Unit reader is granted by apartment inheritance. The Penthouse Unit reader (a different apartment) is denied - greyed out with a red marker.
Reading the tagsA green check with a group-coloured tag (e.g. All Residents) means access via a group. A green check with an apartment tag (e.g. Garden Unit) means access inherited from the user's apartment. A red marker on a greyed device means no access.

The Groups subsection

A Group ties together a set of users, a set of authorised devices and one or more time profiles. Groups are the central mechanism for granting access to shared / public devices. Each group has a Name, an optional Description and a Color used for its tags throughout the interface.

The group detail is organised in three tabs:

Access Control

Selects the devices the group authorises, presented as the project's device tree. Use the checkboxes (or Select all) to grant access.

Group Access Control
The All Residents group and its Access Control device tree.
NoteWhich devices appear in Access Control depends on the project type. In Apartments-type projects only public devices are listed; in Villa / Building projects every device is listed. This is detailed in Project types: Apartments vs Villa / Building.
Users (members)

Lists the members of the group. Use Add member to add users.

Group members
Members of the All Residents group.
Time profiles

Associates the group with one or more time profiles and shows a Calendar Preview of the resulting weekly access window. A group with no active schedule denies access to its devices.

Group time profiles and calendar preview
The group is associated with the Always profile; the calendar preview shows access granted 24/7.

The Time profiles subsection

A Time profile defines the time windows during which the groups that use it grant access. Select a profile to edit it, or click ADD TIME PROFILE to create one.

The Always system profile

Every project contains a built-in profile named Always (00:00–23:59, every day). It cannot be modified or deleted and is automatically assigned to every newly created group.

Always system time profile
The Always system profile and its informational notice.
System profile behaviourThe Always profile cannot be edited or deleted. You may remove its association from a group at any time; however, if a group is left without any active schedule, its members lose access to the devices authorised for that group.

Creating a custom time profile

A custom profile is built from one or more time slots. For each slot you select the weekdays it applies to and its Start and End times. Enable Custom date range to further restrict the profile to a specific calendar period (for example a temporary guest access).

Time slot editor
The time-slot editor: weekday selector (M T W T F S S) and the Start / End times of the slot.
Custom time profile editor
A custom profile, Daytime Staff Access (08:00–18:00, Monday to Friday), with its calendar preview.

Restricting a profile to a calendar period (Custom date range)

By default a time profile repeats indefinitely, week after week. Enable the Custom date range toggle to make the profile valid only within a specific calendar period. Two date fields appear:

  • From - the first date on which the profile is active.
  • To - the last date on which the profile is active.

Outside this window the profile grants no access, regardless of its weekly time slots. This is the recommended way to model temporary access - for example a contractor or a holiday guest who should reach the devices only for a limited number of days.

Custom date range fields
With Custom date range enabled, the profile is limited to the FromTo period (here 01/08/2026 – 15/08/2026).
Weekly pattern still appliesThe date range restricts which calendar days the profile covers; the weekday and time-slot selection still determines the access windows within that period.

Combining multiple time profiles (summation)

A group is not limited to a single schedule: it can be associated with several time profiles at the same time. When it is, the profiles are added together - the group's effective access window is the union of all its profiles. A moment grants access if it falls inside any of the associated profiles.

Add profiles to a group from the Time profiles tab of the group, using the Add time profile chip. The Calendar Preview immediately reflects the combined result.

In the example below the group Combined Schedule Example is associated with two profiles:

  • Daytime Staff Access - Monday to Friday, 08:00–18:00;
  • Weekend Access - Saturday and Sunday, 00:00–23:59.

The calendar preview shows both contributions at once: the weekday daytime band and the full weekend columns.

Two time profiles combined on a group
The group carries two profile chips; access on weekdays starts at 08:00 while weekends are covered from 00:00.
Calendar preview showing the summation of two profiles
Calendar Preview of the union: Daytime Staff Access (weekdays 08:00–18:00) summed with Weekend Access (weekends, all day).
Removing all schedulesIf every time profile is removed from a group, that group grants no access at all - its members lose access to the devices authorised by the group until at least one active schedule is associated again.

Relationship combinations

The three subsections can be combined in several ways to model real access scenarios. The most common combinations are summarised below.

GoalConfiguration
Permanent access for a household to a shared entranceGroup with the entrance device + the Always profile; add the household users as members.
Staff access on working hours onlyGroup with the relevant devices + a custom profile (e.g. Mon–Fri 08:00–18:00); add the staff users.
Temporary guest accessCustom profile with Custom date range limited to the stay; assign it to a dedicated group.
Different schedules on the same devicesAssociate several time profiles with the same group, or create multiple groups over the same devices with different profiles.
A user with more than one access ruleAdd the user to several groups; the effective access is the union of all groups (evaluated with each group's schedule).
Union of permissionsWhen a user belongs to multiple groups, access to a device is granted if any of the user's groups authorises that device and one of that group's time profiles is currently active.

Project types: Apartments vs Villa / Building

The behaviour of the Users area differs depending on the project type chosen when the project was created. There are two families of behaviour.

Apartments-type projects

In an Apartments project the building is divided into residential units (apartments). Access management follows two rules:

  • Apartment devices - implicit access. Each user must be assigned to an Apartment (User properties). The user then automatically inherits access to all devices located inside that apartment. No manual configuration is required, and this access is always granted.
  • Public devices - explicit access. Access to public devices (common areas, entrances, condominium areas) is granted through the Groups subsection.

As a consequence, the Access Control tree of a group in an Apartments project lists only public devices. Apartment-internal devices are intentionally hidden, because they are handled automatically by the apartment assignment.

Apartments group access control - public only
Apartments project. The group Access Control tree lists only the public Dico; apartment units and their internal devices are not shown.
On-screen notice (Apartments projects)When an Apartments project has no public device available, Ekinex Studio displays the following message in the group Access Control tab:

"For Building-type projects it is not possible to enable access to internal apartment devices. In this type of configuration, devices located within residential units are managed automatically: access permissions are assigned implicitly and are always granted to users associated with the respective apartment. Therefore, access groups may include only public devices, i.e. those located in common areas or outside apartments (for example entrances, shared spaces or condominium areas), while internal devices cannot be manually configured in access groups."

Villa and Building projects

In Villa and Building projects the apartment distinction does not exist. There is no implicit apartment inheritance and no public/internal separation: every device of the project - including devices nested under sub-nodes such as floors - can be selected in a group's Access Control tree. All access is therefore defined explicitly through groups.

Villa group access control - all devices
Villa project. The group Access Control tree lists the full structure, including the Accedo Key nested under Floor 1 - which would be hidden in an Apartments project.
Side-by-side comparison
Apartments - public devices only
Apartments access control
Apartments project: the group Access Control lists only public devices.
Villa / Building - all devices
Villa access control
Villa project: the group Access Control lists all devices, including nested ones.
ApartmentsVilla / Building
User → ApartmentRequired; grants implicit access to apartment devicesNot applicable
Groups → Access Control showsPublic devices onlyAll devices (incl. nested)
Internal / nested devicesManaged automatically (implicit)Configured manually in groups
SummaryUse apartment assignment for per-unit access in Apartments projects and reserve groups for shared / public devices. In Villa and Building projects, model all access through groups.

Configuration case histories

This section applies everything described so far to two complete, real-world configurations - one for each project family. Each case history lists the device inventory, the step-by-step configuration recipe, and a summary of the resulting access.

Case 1 - Multi-apartment condominium

ScenarioA residential condominium with two apartments. Two shared intercoms - a Main Entrance door phone and a Pool door phone for the common pool area (accessible 08:00–22:00) - plus one Accedo Key reader inside each apartment. Residents must reach the shared devices and, automatically, their own apartment reader.
Device inventory
DeviceTypeLocationAccess rule
Main EntranceDicoPublic (building)All residents, always
PoolDicoPublic (building)All residents, 08:00–22:00
Accedo Key (Garden Unit)Accedo KeyInside Garden UnitImplicit - Garden Unit residents
Accedo Key (Penthouse Unit)Accedo KeyInside Penthouse UnitImplicit - Penthouse Unit residents
Configuration recipe
  1. In Devices, add the two public door phones to the building and name them Main Entrance and Pool. Add one Accedo Key inside each apartment.
  2. Assign each user to its Apartment (User properties). This alone grants each resident implicit access to their own apartment's Accedo Key.
  3. In Time profiles, create Pool Hours - every day, 08:00–22:00.
  4. In Groups, create Main Entrance Access: authorise the Main Entrance device, keep the Always profile, and add all residents.
  5. Create Pool Access: authorise the Pool device, replace Always with Pool Hours, and add all residents.
Pool Access group authorising only the Pool public device
The Pool Access group authorises the public Pool door phone (Apartments projects expose only public devices in Groups).
Pool Access group with the Pool Hours schedule
The Pool Access group carries the Pool Hours profile; the calendar preview shows access every day from 08:00 to 22:00.
Resulting access

Because both residents are members of both shared-device groups and assigned to their apartment, the Authorized devices tab of a resident summarises all three access sources at once.

Authorized devices for a condominium resident
Owner Garden Unit: Pool and Main Entrance via groups, the Garden Unit reader via apartment inheritance; the Penthouse Unit reader (a different apartment) is denied.
UserApartmentGroupsReaches
Owner Garden UnitGarden UnitMain Entrance Access, Pool AccessMain Entrance (always), Pool (08–22), Garden Unit reader (implicit)
Owner Penthouse UnitPenthouse UnitMain Entrance Access, Pool AccessMain Entrance (always), Pool (08–22), Penthouse Unit reader (implicit)

Case 2 - Independent house (Villa)

ScenarioA single-family villa with two access points - a Main Gate door phone at the street and a Main Entrance reader at the house door. Four family members must be able to open both, at any time, using either a PIN or Face ID.
Device inventory
DeviceTypeLocationAccess rule
Main GateDicoStreet gateAll family members, always
Main EntranceAccedo KeyHouse doorAll family members, always
Configuration recipe
  1. In Devices, name the door phone Main Gate and the reader Main Entrance.
  2. In Users, create the four family members. For each, open the Credentials tab and enable both PIN (a unique code is generated automatically) and Face ID.
  3. In Groups, create a single Family group: authorise both devices, keep the Always profile, and add all four users. (In a Villa project every device - including the reader nested under the floor - is selectable.)
No apartment inheritance hereVilla projects have no apartment concept, so all access is defined explicitly through the group. A single group with both devices and the Always profile is enough.
Family member with PIN and Face ID enabled
Each family member has both PIN and Face ID enabled.
Family group authorising both villa devices
The Family group authorises both Main Gate and Main Entrance; all four members belong to it.
Resulting access
Authorized devices for a family member
Every family member reaches both Main Gate and Main Entrance through the Family group.
SummaryCase 1 mixes implicit apartment access with explicit group access to shared devices, and uses a schedule to limit the pool. Case 2 models everything with a single explicit group and per-user credentials. Together they cover the two access-management patterns of Ekinex Studio.

Download

Introduction

The configuration of the devices described in the previous chapters remains inside Ekinex Studio until a Download is performed into the actual devices. A project can be done entirely offline (dragging products from the Library instead of Discover) but, at some point, the actual devices must be associated with their MAC address and the configuration transferred to them.

Devices overview

Press the Download button in the top navigator to open the devices overview. In this version all the buildings of the project are shown together on the same screen; the previous Select building selector is no longer present. The devices are organised following the project tree, and each Building and Apartment group can be expanded or collapsed. A badge on each Building header reports how many of its devices still require a download.

Opening the devices overview
The Download area: all buildings of the project are listed together, organised by the project tree.
  1. Press Download in the top navigator to open the devices overview.

The device list contains:

DeviceName of the device in the project and its product model.
MAC addressThe unique MAC address of the device.
Network configNetwork settings assigned to the device (Static IP or DHCP, IP address). May differ from the actual address, typically before downloading.
Actual IPThe actual network configuration detected on the device.
FirmwareThe expected firmware version used for configuration. A different detected version is reported in red as a warning.
OnlineWhether the device is detected on the network.
SyncedWhether the device is aligned with the project or needs a download.

The last column indicates the device state and offers one of the following actions:

DownloadTransfers the configuration into the device (up to a minute; a progress bar indicates the advance). After a first full download, only effective changes are transferred. Button colour: yellow = changes to transfer, green = last download successful, red = error (details in the tooltip).
Update / UpdatingA firmware update, or an alignment with the device's firmware version, is needed. Blue = update action available; gray = update already in progress (label becomes "Updating").

If the column is empty or a button is semi-transparent, the device cannot be reached at the moment. Example of multiple device states:

Device states example
Example of the different device states in the overview.
  1. A semi-transparent (grayed) Download button means the device cannot be reached at the moment, so the configuration cannot be written.
  2. A solid Download button means the device is reachable and ready to receive the configuration.

Cloud VPN

Introduction

Starting from version 1.1, it is possible to connect directly to the home network where DELÉGO SERVER is installed, from a PC / Mac, through a VPN connection based on the Ekinex cloud.

This connection is useful to remotely:

  • Program KNX devices or do diagnostics with ETS PROFESSIONAL.
  • Change the configuration of Ekinex connected devices (DICO intercom, Delego Panels etc.).
  • Access any other network-based device, in the same way it would be possible being physically attached to the LAN.
VPN connection architecture overview
VPN connection architecture overview

Each DELÉGO SERVER has its own dedicated VPN, isolated from the others, and uses the Wireguard tunnel technology, to ensure the maximum degree of robustness and security. No configuration is required on the internet router / firewall.

ImportantThe cloud VPN service is available only on the 4 DIN rail module hardware version of DELÉGO SERVER. The older version of 2 DIN rail modules does not support it.
NoteThe "old" local VPN, based on an internal server and requiring a port forwarding rule on the router, is no longer available. Only the cloud-based VPN is supported in this version.

Cloud login

Before doing any configuration on the cloud VPN, at least one cloud account must be enabled and associated with DELÉGO SERVER.

Being the cloud VPN a way to access the IP home network of the building, for security reasons, it is strongly recommended to differentiate the users by doing the following configuration:

  • Create (at least) one DELÉGO SERVER user for the "property manager" of the building (e.g. the home holder) and bind it as OWNER to his / her cloud account.
  • Dedicate a different DELÉGO SERVER user to the installer / system integrator, binding it as INSTALLER to the corresponding cloud account
NoteOnly the cloud accounts associated with local users of DELÉGO SERVER, are entitled to control / connect to the VPN. On the mobile app, the cloud account must be entered in the app settings, in order to see and manage the VPN associated with the servers.

In this way:

  • The owner can (with the Délego mobile app)
    • enable or disable the VPN at any moment.
    • grant the access for the installer(s).
  • The installer can (with the Délego mobile app)
    • ask to connect (if the VPN is disabled, or the account is not granted).
    • start and stop the VPN.
  • (with the PC / Mac)
    • connect to the home network.
Owner and installer VPN access flow
Owner and installer VPN access flow

Service activation

In the administration area, after having done a cloud login with a valid Ekinex cloud account, select the following item in the tree menu

SETUP > EKINEX CLOUD > CLOUD SERVICES

and identify the VPN service, like in the following screenshot:

VPN service activation in Cloud Services
VPN service activation in Cloud Services

Press the ACTIVATE button and wait until the list reloads, and the service becomes active.

NoteThe VPN service will "belong" to the cloud account used to activate it. It is your choice to associate it to the installer account, or the property manager (owner) one.

VPN creation

Once the VPN service has been activated, enter the section

SETUP > EKINEX CLOUD > VPN

and enter a name, to be associated with the VPN. This name will be reported in email and push messages, therefore it is suggested to give a name reminding the building / installation.

VPN creation form
VPN creation form

By default, for security reasons, DELÉGO SERVER does not allow access to any other device in the home network (LAN) except itself.

It is possible to optionally expose one or more devices, or network subnets, by entering the following information:

  • To expose a single IP address, enter it in the text fields, and press ADD.
  • To expose a subnet, enter only the first parts of the address, by leaving empty the last part(s). In this case, all the IP devices matching the entered numbers, will be reachable remotely
InformationIn some sections of the webserver, mobile app and client for the VPN connection, the so-called "CIDR" notation is used to represent the exposed addresses. Please refer to the following table, containing some examples, to clarify the different notations.
DELEGO SETTINGCIDR NOTATIONREACHABLE IP ADDRESS(ES)
192.168.1.1192.168.1.1/32192.168.1.1
192.168.1.XXX192.168.1.0/24192.168.1.1
192.168.1.2
[...]
192.168.1.254
192.168.XXX.XXX192.168.0.0/16192.168.1.1
192.168.1.2
[...]
192.168.1.254
192.168.2.1
[...]
192.168.254.254

Press the CREATE button and wait until the VPN information will appear in the page.

ImportantIf you want to reach DELÉGO SERVER with its IP address in the home network (LAN), this address must be added to the exposed IP addresses list.

Otherwise, DELÉGO SERVER will be only reachable with its VPN address, as shown below.
ImportantThe new VPN is enabled by default; it means that all the cloud accounts, entitled to have a connection, will be able to connect.

Deselect the corresponding flag and press the UPDATE button to make it disabled by default; the owner(s) will enable it with the Délego mobile app, as described below.

Connections

In order to connect to the VPN, installers must own one or more CONNECTION(s) for each PC / Mac they will use to remotely access the home network.

Press the ADD button and enter the following information:

  • A label that identifies the PC / Mac used for the connection.
  • The cloud account associated with the connection.
  • The enable (grant) status of the connection.
NoteOnly the cloud accounts associated with DELÉGO SERVER can be selected for the connections. In order to grant access to new accounts:
  1. Create a new local user in DELÉGO SERVER in the USERS AND PERMISSIONS section
  2. Enter with these credentials and login with the desired cloud account in the SERVICES > CLOUD > PRODUCT REGISTRATION
  3. Bind the cloud account as OWNER or INSTALLER by pressing the corresponding button (once the cloud login has been done)

Once pressed the SAVE button, two buttons will be enabled:

  • The DOWNLOAD button is used to download the configuration file, necessary to set up the VPN connection on the PC/Mac of the installer that needs to connect to DELÉGO SERVER.
  • The QR CODE button is used to download the QR code that can be used on a VPN tool to set up automatically the VPN connection to DELÉGO SERVER.
VPN connections panel
VPN connections panel
ImportantAny time a change is done on the configuration of the VPN (e.g. changing the exposed IP addresses) it is necessary to download a new configuration file or QR code.

In that situation, a yellow warning indicator blinks close to the connections to be downloaded again.

Starting and stopping the VPN

The default state of a VPN is stopped and must be manually started when there is the need to remotely connect to the home network. This can be done by pressing the START button in the VPN configuration page in DELÉGO SERVER, or with the mobile app (as described in the dedicated section later). A VPN connection will stay active for 2 hours; after 2 hours it will stop. To stop it manually, press the STOP button, when it is no longer needed.

NoteIf a longer connection is needed, the VPN can be simply stopped / started again, any desired number of times.

The STATUS section contains also the IP address of DELÉGO SERVER in the VPN:

VPN status panel
VPN status panel

Use this IP address to "point" to the webserver, in order to:

  • Access its web pages .
  • Use it as an IP interface for ETS PROFESSIONAL.

Control with the mobile app

Requirements

The Délego mobile app can be used to control the VPN associated with a DELÉGO SERVER. In order to do so, the following requirements must be met:

  • An Ekinex cloud account must be entered in the settings area of the app
  • At least one DELÉGO SERVER must be configured with a valid cloud remote address
  • The DELÉGO SERVER(s) must be associated with the entered cloud account, with OWNER or INSTALLER rights

The VPN enabled projects show a "lock" symbol on the right in the title:

VPN lock symbol legend
VPN lock symbol legend

When pressed, this symbol opens the VPN control screen, as better illustrated in the following paragraphs.

Owner view

The following picture shows the typical VPN section content for an owner account:

VPN owner view in the mobile app
VPN owner view in the mobile app

Each account with an associated connection, can be enabled or not, by acting on the corresponding control: in general, a VPN can be enabled (green indicator in the initial part of the screen) but the single users can be disabled. In this case, they cannot connect. When a user connects through one of these connections, the state goes to green.

The server info section contains details about the connection of the webserver to the VPN, its IP address, and all the other reachable IP addresses.

ImportantIf the owner is not associated with a connection, the START / STOP button is not visible; this action, in fact, is useful only for users who need to connect from their PC / Mac.

If the VPN is not enabled, all the contents are hidden, and the only possible action is to enable it:

VPN disabled view in the mobile app
VPN disabled view in the mobile app

Each account with an associated connection, can be enabled or not, by acting on the corresponding control: in general, a VPN can be enabled (green indicator in the initial part of the screen) but the single users can be disabled. In this case, they cannot connect. When a user connects through one of these connections, the state goes to green.

Installer view

The VPN section view for an installer, contains fewer information, like in the following example:

VPN installer view in the mobile app
VPN installer view in the mobile app

If the VPN is disabled, or the installer is not granted to connect, the only allowed action is to send a request to connect:

Request VPN access screen
Request VPN access screen

Notifications

When an installer asks to connect, a push notification and an email message are immediately sent to all the owners of the webserver. By pressing on the notification, the DÉLEGO mobile app is opened directly in the section of the interested VPN: it is just needed to act on the ENABLE controller.

Push notifications and email messages are also sent when:

  • A VPN is enabled or disabled.
  • A VPN is started or stopped.
  • A connection (user) is granted or not.

Remote VPN Connection

Cloud login

ImportantOn the Ekinex Studio application, it is necessary to be authenticated with an Installer user, previously configured in DELÉGO SERVER, as indicated in the previous chapters.

Connecting to your systems via VPN requires authentication with your EKINEX cloud account, the same one used to authenticate on Ekinex Studio, as illustrated in Ekinex cloud account.

Accessing the VPNs

If the connection to the cloud is successful, a menu appears in the system bar containing the list of CLOUD VPNs to which your account has access.

If one or more web servers have also been configured as systems (see next point) they appear at the beginning of the list, vice versa they are listed in the "OTHER VPNs" section, as in the following example (which shows the MAC version):

List of VPNs in the system bar menu
List of VPNs in the system bar menu

The first time you connect to a VPN, you need to press the SETTINGS item; a screen similar to the following is displayed:

First VPN connection settings screen
First VPN connection settings screen

In the CONNECTIONS section, a new connection is automatically created for your PC / MAC, associated with your cloud account. This connection is initially disabled; if you have an installer profile, you must request access via the appropriate button at the top of the popup, and wait for the building owner to authorize your user to connect.

If, on the other hand, you are the owner, you can enable the connection, with the appropriate selector.

By pressing the CONNECT button, you can establish a connection to the building's local network through the CLOUD VPN; after a few seconds, the status indicators turn green, and the statistics on connection time and exchanged data traffic begin to update.

Connected VPN status detail
Connected VPN status detail

The IP address of the web server in the VPN is shown in the section below, containing the server data; you can copy it to the clipboard with the appropriate button, to be able to easily insert it into other applications (e.g.: ETS professional).

After the first connection, you can monitor connection statistics, start or stop the connection, directly from the system tray. It also displays'also the time remaining before the connection automatically stops, and it is possible (via the dedicated button, by opening the settings) to reset the countdown, if the maintenance intervention requires more than 2 hours.