Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
This compliance documentation page provides the essential security and inspection guides required to ensure the physical integrity of DynaFlex II Go secure card readers before and after deployment.
Applies to: DynaFlex II Go
Reference Section
Information Available
A manual that outlines the step-by-step procedures for visually inspecting the DynaFlex II Go's hardware label, physical appearance, and tamper indicators to verify its authenticity and security before use.
A guide that details how to examine the device's secure packaging for signs of tampering during storage or transit, helping to ensure the reader has not been compromised before deployment.
This document addresses the proper use of the DynaFlex II Go family of secure card readers (SCR) in a secure manner.
Need Help?
For additional support, please contact MagTek Support:
Technical Support:
📧 Email: support@magtek.com
📞 Phone: 1-800-788-6835 (US) | +1-562-546-6616 (International)
🕐 Hours: Monday-Friday, 6:00 AM - 5:00 PM PST
Online Resources:
🌐 Official Site:
💬 Developer Forum:
Documentation Feedback:
Help us improve this documentation!
This document addresses the proper use of the DynaFlex II Go family of secure card readers (SCR) in a secure manner. This includes information about key-management responsibilities, administrative responsibilities, device functionality, identification, and environmental requirements.
The use of this secure card reader in any method not described in this security policy will invalidate the PCI PTS POI v6.2 approval of the device.
Throughout this document:
DynaFlex II Go products refers to all products in the DynaFlex II Go product family, including DynaFlex II Go models equipped with a barcode reader (BCR) and Bluetooth LE connectivity.
Need Help?
For additional support, please contact MagTek Support:
Technical Support:
📧 Email:
📞 Phone: 1-562-546-6800 (US)
🕐 Hours: Monday-Friday, 5:30 AM - 5:00 PM PST
Online Resources:
🌐 Support Portal: developer.magtek.com
Documentation Feedback:
Help us improve this documentation! feedback@magtek.com
This document addresses the proper use of the DynaFlex II Go family of secure card readers (SCR) in a secure manner. This includes information about key-management responsibilities, administrative responsibilities, device functionality, identification, and environmental requirements.
Reference Section
Information Available
Addresses the proper use of the DynaFlex II Go family of secure card readers (SCR) in a secure manner.
After receiving the device, the customer should visually inspect the product as follows:
Inspect the label found on the bottom of the device (see section 2.3.1 Hardware Identification) and make sure the label is not missing, obscured, or modified.
Check the PCI Hardware Identifier on the device label and make sure it matches the Hardware # listed for the device on the PCI web site for Approved Devices. Go to the PCI compliance web page and search for MagTek, and find the product name, DynaFlex II Go. Compare the Hardware ID and Firmware ID: https://www.pcisecuritystandards.org/assessors_and_solutions/pin_transaction_devices
Note: Firmware ID is accessible by connecting DynaFlex II Go to a host device via USB or Bluetooth LE, using the latest software provided by MagTek (see section 2.3.2 Firmware Identification).
Check the Device serial number (SN) and make sure it matches with labels on shipping materials and documentation.
Visually inspect the device, per D998200593 DynaFlex II Go, Device Inspection Document, which is included in the package with each device. See section 4.1 Periodic Inspection for more information regarding visual inspection of the device.
Follow the steps in section 2.3.2 to view the PCI firmware versions installed on the device. Make sure this matches one of the Firmware # values listed on the PCI web site for DynaFlex II Go. Note that in PCI listings, lowercase “x” is a wildcard meaning ‘any single character.’
Connect the device to a USB host for control and power (if battery power is not sufficient). DynaFlex II Go products are designed to provide flexible mounting options such as:
External clip
Embedded lanyard
The specified environmental conditions to operate and store the device are:
Operating temperature range: 0°C to 35°C / 5% to 90% RH
Storage temperature range: -20°C to 45°C / 5% to 90% RH
For safety, battery charging is disabled when the device is outside the recommended operating temperature range.
The security of the reader is not compromised by altering the environmental conditions outside the stated operating ranges above. Any temperature or operating voltage outside the values in the table below will trigger environmental security protections, resulting in a tamper condition. The device will need to be returned to the factory for inspection before this condition can be cleared.
DynaFlex II Go products support a USB interface using the USB-HID protocol, and a Bluetooth LE interface. Transactions, configuration, firmware updates, and key injection can all be performed using these interface types. Use of any method not listed in this security policy will invalidate the device’s PCI PTS approval.
The device requires Bluetooth LE hosts to use version 4.2 or higher and use LE Security Mode 1 Level 4 (Secure Connections) only. “Just Works” cannot be used at any time. The device does not support or allow for the use of insecure communication options such as, but not limited to, LE Security Mode 2, and levels 1, 2, and 3 of LE Security Mode 1 and the “Just Works” secure pairing option of Security Mode 1.
DynaFlex II Go products ship from the factory fully secure. The devices have no configuration settings that require modification by the user to meet PCI security requirements.
REGISTERED TO ISO 9001:2015
Copyright © 2006 - 2024 MagTek, Inc.MagTek® is a registered trademark of MagTek, Inc.MagnePrint® is a registered trademark of MagTek, Inc.MagneSafe® is a registered trademark of MagTek, Inc.Magensa™ is a trademark of MagTek, Inc.AAMVA™ is a trademark of AAMVA.American Express® and EXPRESSPAY FROM AMERICAN EXPRESS® are registered trademarks of American Express Marketing & Development Corp.Apple Pay® is a registered trademark to Apple Inc.D-PAYMENT APPLICATION SPECIFICATION® is a registered trademark to Discover Financial Services CORPORATIONMasterCard® is a registered trademark and PayPass™ and Tap & Go™ are trademarks of MasterCard International Incorporated.Visa® and Visa payWave® are registered trademarks of Visa International Service Association.ANSI®, the ANSI logo, and numerous other identifiers containing "ANSI" are registered trademarks, service marks, and accreditation marks of the American National Standards Institute (ANSI).ISO® is a registered trademark of the International Organization for Standardization.PCI Security Standards Council® is a registered trademark of the PCI Security Standards Council, LLC.EMV® is a registered trademark in the U.S. and other countries and an unregistered trademark elsewhere. The EMV trademark is owned by EMVCo, LLC. The Contactless Indicator mark, consisting of four graduating arcs, is a trademark owned by and used with permission of EMVCo, LLC.UL™ and the UL logo are trademarks of UL LLC.All other system names and product names are the property of their respective owners.
DynaFlex II Go is a secure card reader authenticator in a small form factor that is ready to accept tap, swipe, and dip payments in a wide variety of retail environments. The small form factor is ready for countertop and mobile devices with USB or Bluetooth® LE connection. Start accepting mobile wallets including Samsung® Pay, Google® Pay and Apple® Pay via NFC Contactless or accept card payments via EMV® Contactless, EMV Contact Chip, and magnetic stripe.
Check the overall form factor for signs of attempted entry or tampering. The form factor is a smooth shell. The seam between the top and bottom shells are molded together. There are no additional electronics or wires. Any breaks in the plastic, scuffs, or damage could be signs of physical tampering and should be reported. Look for any added components, size, or weight: Dimensions: 2.76 in.x2.57 in.x0.79 in. (70.10mm x 65.3mm x20.1mm) DynaFlex II Go (w/BCR and Bluetooth LE): 92 grams, DynaFlex II Go (with Bluetooth LE): 90 grams.
Top of Device: This is the location of the EMV Chip Card insert position and magstripe swipe card reader slot.
Payment Methods: Directional icons for magstripe, EMV chip insert, and contactless tap landing pad are printed on the device front.
The device always encrypts account data from all three reader types using 112-bit TDEA, 128-bit AES, or 256-bit AES algorithms with X9.24 DUKPT key management. This device does not support any mechanisms such as whitelists or SRED disable that would allow the data to be sent out unencrypted.
The device includes the following cryptographic algorithms:
AES
TDEA
Sensor
Low Threshold Value
High Threshold Value
Internal Voltage
1.60V ± 0.055V
3.775V ± 0.1V
Temperature
-45°C ± 15°C
120°C ± 10°C
102
December 20, 2023
Update Table 2‑3 - Main Firmware Version and Associated Variables, Table 2‑4 - Boot Firmware Version and Associated Variables, Table 2‑5 - Bluetooth LE Firmware Version and Associated Variables
110
October 28, 2024
Update HW IDs in 2.3.1 Hardware Identification; Update FW IDs and Added new ID for main FW with newer EMV Kernels in 2.3.2Firmware Identification
120
April 1, 2026
Update Table 2-1 PCI Hardware Identifier, 2-2 Hardware Versions with Description of Associated Variables and associated screen shots
Rev Number
Date
Notes
100
October 25, 2023
Initial Release
101
November 21, 2023

Update 3.4 Communications and Security Protocols with Bluetooth LE Secure Connections content , Update 4.4 Passwords and Certificates with Bluetooth LE Pass Key content.
Swipe Path: The swipe path is smooth. The only moving part is the spring-mounted read head that depresses into the device as the card’s magnetic stripe makes contact with the read head. There are no mechanics, electronics, or wires in the swipe path.
Front Face Contactless Landing Zone: The Contactless landing zone is a smooth front cover with no moving parts and only the contactless symbol in the landing zone. Contactless indicator mark orientation may vary depending on installation.
Front Face (BCR ONLY) Barcode Reader: In barcode reader models (BCR), a barcode reader is along the right-facing side of the reader with a QR Code icon and directional arrow.
Front Face LED Feedback: There are four LED lights. These provide signals to the user. See installation and operation manual for complete LED signaling.
Front Face Devices Without Barcode Reader: These devices will have no lens or barcode icons.
Right-facing Side of Device Pushbutton: There is a tactile button with no other extraneous parts.
Bottom of Device USB-C Cable: There is a USB-C receptacle on bottom of the device. The USB-C cable is provided to power and charge. Ensure there are no extraneous cables. (Cable not shown to scale.)
Back Side of Device Product Label: The product label is located on the underside of the device. The Serial Number, Rev, Date, Part number (PN), and Hardware PN (HW) are listed as appropriate.
Back Side of Device Certificate Logos: Imprints in the plastic form factor of certification logos and patent information are listed.
To check for PCI Validation check the Hardware and Firmware ID. Hardware ID is printed on the label. The Firmware ID is accessible via the device. Go to the PCI compliance web page and search for MagTek, and find the product name, DynaFlex II Go. Compare the Hardware ID and Firmware ID: https://www.pcisecuritystandards.org/assessors_and_solutions/ pin_transaction_devices
As part of your inspection, include the following for your device inspection audit:
Be certain to have a list of the devices and include the details listed on the product label.
It may be helpful to take photos of the front, back, and sides of each device.
Be certain to check device part numbers, serial numbers, and IDs and check physical connections. Use the chart below as a checklist to inspect the device for signs of tampering.
Are there signs of tampering:
Signs of tampering
Site Inspection
YES
NO
Form Factor - check overall form factor
FCC INFORMATION
This device complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions: (1) This device may not cause harmful interference, and (2) This device must accept any interference received, including interference that may cause undesired operation.
CANADIAN DECLARATION OF CONFORMITY
This digital apparatus does not exceed the Class B limits for radio noise from digital apparatus set out in the Radio Interference Regulations of the Canadian Department of Communications.
Le présent appareil numérique n’émet pas de bruits radioélectriques dépassant les limites applicables aux appareils numériques de la classe B prescrites dans le Réglement sur le brouillage radioélectrique édicté par le ministère des Communications du Canada.
This Class B digital apparatus complies with Canadian ICES-003.
Cet appareil numérique de la classe B est conformé à la norme NMB-003 du Canada.
INDUSTRY CANADA (IC) RSS
This device complies with Industry Canada licence-exempt RSS standard(s). Operation is subject to the following two conditions: (1) This device may not cause interference, and (2) This device must accept any interference, including interference that may cause undesired operation of the device.
Le présent appareil est conforme aux CNR d’Industrie Canada applicables aux appareils radio exempts de licence. L’exploitation est autorisée aux deux conditions suivantes: (1) L’appareil ne doit pas produire de brouillage, et (2) L’utilisateur de l’appareil doit accepter tout brouillage radioélectrique subi, même si le brouillage est susceptible d’en compromettre le fonctionnement.
CUR/UR
This product is recognized per Underwriter Laboratories and Canadian Underwriter Laboratories 1950.
CE STANDARDS
Testing for compliance with CE requirements was performed by an independent laboratory. The unit under test was found compliant with standards established for Class B devices.
EU STATEMENT
Hereby, MagTek Inc. declares that the radio equipment types Wideband Transmission System (802.11 wireless and Bluetooth® Low Energy), and Non-Specific Short Range Device (contactless) are in compliance with Directive 2014/53/EU. The full text of the EU declarations of conformity is available at the following Internet addresses: https://www.magtek.com/content/documentationfiles/d998200650.pdf
Safety
This product has been tested to IEC 62368-1 -Audio/Video, information and communication technology equipment - Part 1: General Requirements plus U.S., Canadian, Australian & New Zealand National Deviations by an ISO 17025 Accredited Testing Laboratory.
ROHS STATEMENT
When ordered as RoHS compliant, this product meets the Electrical and Electronic Equipment (EEE) Reduction of Hazardous Substances (RoHS) Directive (EU) 2015/863 amending Annex II to Directive 2011/65/EU. The marking is clearly recognizable, either as written words like “Pb-free,” “lead-free,” or as another clear symbol ( Pb ).
PCI STATEMENT
PCI Security Standards Council, LLC (“PCI SSC”) has approved this PIN Transaction Security Device to be in compliance with PCI SSC’s PIN Security Requirements.
When granted, PCI SSC approval is provided by PCI SSC to ensure certain security and operational characteristics important to the achievement of PCI SSC’s goals, but PCI SSC approval does not under any circumstances include any endorsement or warranty regarding the functionality, quality or performance of any particular product or service. PCI SSC does not warrant any products or services provided by third parties. PCI SSC approval does not under any circumstances include or imply any product warranties from PCI SSC, including, without limitation, any implied warranties of merchantability, fitness for purpose, or non-infringement, all of which are expressly disclaimed by PCI SSC. All rights and remedies regarding products and services which have received PCI SSC approval shall be provided by the party providing such products or services, and not by PCI SSC.
UKCA STATEMENT
Hereby, MagTek Inc. declares that the radio equipment types Wideband Transmission System (Wireless LAN and Bluetooth Low Energy), and Non-Specific Short Range Device (contactless) are in compliance with Radio Equipment Regulations 2017 Directive S.I.2017:1206. The full text of the UKCA declarations of conformity is available at the following Internet addresses: https://www.magtek.com/content/documentationfiles/d998200651.pdf

Notice: If there is forced entry, the security switches built into the electronics will be tripped. If they are tripped the sensitive data such as encryption keys and certificates are cleared as part of security measures mandated by PCI and the device will not be available to make transactions.
If the security switches have been tripped, DynaFlex II Go Products cannot be repaired in the field and must go back to the factory for repair. Follow return material authorization (RMA) procedures. User must report all signs of tampering as per standard protocol.
Note: This equipment has been tested and found to comply with the limits for a Class B digital device, pursuant to part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference in a residential installation. This equipment generates, uses and can radiate radio frequency energy and, if not installed and used in accordance with the instructions, may cause harmful interference to radio communications. However, there is no guarantee that interference will not occur in a particular installation. If this equipment does cause harmful interference to radio or television reception, which can be determined by turning the equipment off and on, the user is encouraged to try to correct the interference by one or more of the following measures:
Reorient or relocate the receiving antenna.
Notice: If there is forced entry, the security switches built into the electronics will be tripped. If they are tripped the sensitive data such as encryption keys and certificates are cleared as part of security measures mandated by PCI and the device will not be available to make transactions. If the security switches have been tripped, DynaFlex II Go Products cannot be repaired in the field and must go back to the factory for repair. Follow return material authorization (RMA) procedures. User must report all signs of tampering as per standard protocol.
CAUTION: Changes or modifications not expressly approved by MagTek could void the user’s authority to operate this equipment.
Need Help?
For additional support, please contact MagTek Support:
Technical Support:
📧 Email:
RSA
ECDSA (P256 and P521 curves)
SHA-256
The device implements the original AES/TDEA DUKPT as its only key management method. Use of any other method will invalidate PCI approval. DUKPT derives a new unique key for every transaction. For more details, see ANS X9.24 Part 3:2017.
Key Name
Size
Algorithm
Purpose
Transport Keys
32 bytes
AES X9.143 KBPKs
Key Injection
The device does not support manual or plaintext cryptographic key entry. Only specialized tools, compliant with key management requirements and cryptographic methods, specifically ANSI X9.143, can be used for key loading. Use of any other methods will invalidate PCI approval.
Keys should be replaced with new keys whenever the original key is known or suspected to have been compromised, and whenever the time deemed feasible to determine the key by exhaustive attack has elapsed, as defined in NIST SP 800-57-1.
Name, appearence, and Identification
Inspection, installation, environmental conditions, security protocols, configuration settings.
Inspection, self-test, roles & responsibilities, Password & Certificates, Tamper Response, Patching & Updating, Decommissioning
Account data protection, algorithms supported, Key Management, key loading, key replacement.
Acronyms
Versions of this document
Need Help?
For additional support, please contact MagTek Support:
Technical Support:
📧 Email: support@magtek.com
📞 Phone: 1-562-546-6800 (US)
🕐 Hours: Monday-Friday, 5:30 AM - 5:00 PM PST
Online Resources:
🌐 Support Portal: developer.magtek.com
Documentation Feedback:
Help us improve this documentation!
Acronym
Definition
AES
Advanced Encryption Standard
BCR
Barcode Reader
Account Data Key
16 bytes for TDEA and AES-128
32 bytes for AES-256
AES and TDEA DUKPT (ANS X9.24-3)
Encrypt and MAC Account Data
Firmware Protection Key
64 bytes for
ECDSA Curve P-256
ECDSA and SHA-256
Checks integrity and authenticity of firmware
EMV CA Public keys
Varies per issuer
RSA
Authenticate card data and keys
CTLS
Contactless
DES
Data Encryption Standard
DUKPT
Derived Unique Key Per Transaction
ECC
Elliptic-Curve Cryptography
ICCR
Integrated Circuit Card Reader
MAC
In cryptography: Message Authentication Code
In networking: Media Access Control [address]
MSR
Magnetic Stripe Reader
NFC
Near Field Communication
POI
Point Of Interaction
S/N
Serial Number
SCRA
Secure Card Reader Authenticator
SHA
Secure Hash Algorithm
SRED
Secure Reading and Exchange of Data
TDEA
Triple Data Encryption Algorithm
USB
Universal Serial Bus
USB HID
USB Human Interface Device
Increase the separation between the equipment and receiver.
Connect the equipment into an outlet on a circuit different from that to which the receiver is connected.
Consult the dealer or an experienced radio/TV technician for help.
📞 Phone: 1-562-546-6800 (US)
🕐 Hours: Monday-Friday, 5:30 AM - 5:00 PM PST
Online Resources:
🌐 Support Portal: developer.magtek.com
Documentation Feedback:
Help us improve this documentation!
Front
4 LEDs
EMV/NFC Contactless landing zone
Barcode reader (BCR models only)
Printing and icons
Overall form factor
Sides and Top
Magnetic stripe swipe path
EMV contact card slot
Form factor
Right Facing Side: Push Button
Bottom Side: USB-C port
Cables and charging cradle
USB-C cable and port
Back
Certificate logos imprinted
Form factor
Cable connection
Pushbutton
Labels






The following documents may be used to provide additional details about the device and this security policy:
DynaFlex II Go Installation and Operation Manual
DynaFlex II Go Programmer’s Manual (COMMANDS)
DynaFlex II Go Device Inspection Document
DynaFlex II Go Package Inspection Document
NIST SP 800-57-1 Recommendation for Key Management
ANS X9.24 Part 3:2017, Retail Financial Services Symmetric Key Management, Part 3: Derived Unique Key Per Transaction Using Symmetric Techniques
X9 TR-31:2010, Interoperable Secure Key Exchange Key Block Specification for Symmetric Algorithms
DynaFlex II Go products are PCI PTS v6.x SCR, certified. The packaging is designed to be tamper evident and the closure uses security tape. Any attempt to open the package shows signs of tampering. This document explains how to detect tampering.
The basic form factor of the package is a folded white cardboard box with a cardboard insert where the device is nestled into Korrvu plastic wrap packaging. There are no rips or added materials on the package other than product and Lot labels. The package only has one color ink printed on the package: black. The box is made with corrugated white cardboard.
Certification Compliance Logos: Industry certification logos showing compliance are printed on the back of the package as shown. Manufacturer address is shown.
The front cover of the package lists the product name, MagneSafe Security information, PCI revision information, product read capability icons, QR Codes, and description.
On the left side of the package is printed a list of the package contents and the product label is adhered.
The right side of the package shows the storage requirements and CAUTION content.
The front of the package lists the product name, category, PCI certification, and Security Tape.
Security tape wraps onto the bottom of the package from the front flap of the package.
Adhered
Here security tape is applied and secured. Wrapping front to bottom of package.
Tape
Tape is removed VOID and OPENED appear on tape.
Package
Security tape wraps onto the bottom of the package from the front flap of the package.
Bottom
Security Tape: The Security Tape wraps from the front flap to the bottom of the package. Make certain there are no signs of tampering.
Lot Label: The lot label is placed on the bottom of the box. Make certain there are no false labels added or tampering.
Inside
DynaFlex II Go products are nestled inside the package with Korrvu packaging that uses cling wrap to hold the device securely in place for transit. The cling wrap is attached to an insert that has thumb-hole cuts on either side to make it easier to remove from the outer packaging. The package includes the device, cable(s), device inspection document, and quick installation guide.
To check for PCI Validation check the Hardware and Firmware ID. Hardware ID is printed on the label. The Firmware ID is accessible via the device. Go to the PCI compliance web page and search for MagTek, and find the product name, DynaFlex II Go. Compare the Hardware ID and Firmware ID: https://
As part of your inspection, include the following for your device inspection audit:
Be certain to have a list of the devices and include the details listed on the product label.
It may be helpful to take photos of the front, back, and sides of each device.
Be certain to check device part numbers, serial numbers, and IDs and check physical connections. Use the chart below as a checklist to inspect the device for signs of tampering.
Front
Check form factor
Look for signs of tamper
Check printing and no added labels
Left, Right, and Back Sides
Check form factor
Look for signs of tamper
Check printing and no added labels
Check product label
Front Flap
Check Security Tape
Look for signs of tamper
Check printing and no added labels
Check form factor
Bottom
Check Security Tape
Look for signs of tamper
Check printing
Check form factor
Check lot Label
Are there signs of tampering:
Signs of tampering
YES
NO
Form Factor - check overall form factor
NOTICE: Follow RMA procedures. User should report all signs of tampering as per standard protocol.
Need Help?
For additional support, please contact MagTek Support:
Technical Support:
📧 Email: support@magtek.com
📞 Phone: 1-562-546-6800 (US)
🕐 Hours: Monday-Friday, 5:30 AM - 5:00 PM PST
Online Resources:
🌐 Support Portal: developer.magtek.com
Documentation Feedback:
Help us improve this documentation!










The merchant or acquirer should daily check the appearance of secure card reader:
Inspect the appearance of secure card reader to make sure it is the right product.
Inspect whether the Swipe Path has an additional card reader or other inserted bugs, See Figure 4‑1, below.
Inspect whether the product appearance has been changed.
Check if the firmware version is correct.
Power on the secure card reader and check that the firmware runs well, as the startup will inspect the hardware security, authenticity, and integrity of firmware. Only the leftmost LED should be on and blinking green
Figure 4‑1 - Chip Card Insertion Slot and Swipe Path Examples
MagTek strongly recommends performing security inspections on a regular schedule. Additional information can be found in DynaFlex II Go, Device Inspection Document. If any problems are detected, stop using the device, set it aside in a secure location, and contact the manufacturer or your acquirer for further advice.
DynaFlex II Go performs self-tests at power-up and after reset. By default, the device automatically resets and performs self-tests every 23 hours if it is configured to automatically reset 23 hours after booting, otherwise the device automatically resets and performs self-tests every 24 hours if it is configured to automatically reset at a specific time of day. No manual intervention by the operator is required. Self-tests include:
Checking the integrity and authenticity of the firmware and cryptographic keys.
Checking security mechanisms for signs of tampering.
The secure card reader has no functionality that gives access to security-sensitive services based on roles. Such services are managed through dedicated tools, using cryptographic authentication.
DynaFlex II Go products ship from the factory fully secure. There are no security default values that require modifications by the user to meet PCI security requirements, except the “Bluetooth LE passkey.” MagTek recommends one of two options:
Devices are ordered with the default passkey changed by MagTek during device configuration prior to shipping
The customer change the default passkey with a software utility that changes Property 1.2.2.3.1.9 Bluetooth LE Passkey described in DynaFlex II Go Programmer’s Manual (COMMANDS).
If the device senses a physical or environmental attack, it erases all sensitive keys, and will have limited functionality. While powered on, the SCR indicates it is in a tampered state by flashing green LEDs 1,3, and 4 as depicted in Figure 4‑2 Tamper Response. If this occurs:
Remove the device from service immediately.
Store it securely for possible forensics investigation.
Contact the manufacturer for assistance. The device will likely need to be returned to the manufacturer for diagnosis and servicing.
Figure 4 2 Tamper Response
DynaFlex II Go products support file-based updates of the device’s core firmware (main firmware) and authorized commands for updating sensitive configuration. For optimal device security, MagTek recommends the latest versions of firmware should always be installed.
Firmware updates are provided as files that have been signed by MagTek. The firmware files can be loaded locally through USB or Bluetooth LE connection by using update tools available from the MagTek web site. The device verifies each update is newer than the installed version, and cryptographically authenticates the file. If version checking or authentication fails, the device erases the update file and reports an error to the host.
For help with updates to EMV configuration, contact Magensa Remote Services.
Before DynaFlex II Go products are permanently removed from service, all the keys and sensitive data must be erased. One way to accomplish this is by temporarily removing the back cover, which forces a tamper response.
If removal from service is only temporary, no action is required. All sensitive data will continue to be protected by the device’s physical and logical protection mechanisms.
Need Help?
For additional support, please contact MagTek Support:
Technical Support:
📧 Email:
📞 Phone: 1-562-546-6800 (US)
🕐 Hours: Monday-Friday, 5:30 AM - 5:00 PM PST
Online Resources:
🌐 Support Portal: developer.magtek.com
Documentation Feedback:
Help us improve this documentation!



The front view of all DynaFlex II Go models (with and without BCR), are shown in Figure 2‑1 below. The back view of all DynaFlex II Go devices are identical, as seen in Figure 2‑2.
All DynaFlex II Go products include USB communications, a magnetic stripe reader (MSR), a contact chip card reader (ICCR), a contactless card reader (CTLS), and may also be purchased with an embedded barcode reader (BCR) and Bluetooth LE connectivity.
DynaFlex II Go models can be used as desktop or handheld devices. They are approved as a secure card reader (SCR) under PCI PTS POI v6.2 requirements.
Usage in any other environment will invalidate the approval.
To find important product identification, look on the printed product label on the back face of the device as shown in Figure 2‑3 below.
Figure 2 3 - DynaFlex II Go Device Label Location
The product label includes the following elements of device identification information, indicated by the numbered callouts in Figure 2‑4 and Figure 2‑5.
Product Name
PCI Hardware Identifier (“HW”)
Figure 2 4 - DynaFlex II Go Device Label
Figure 2 5 DynaFlex II Go with Bluetooth LE Device Label
The label also contains other supporting information about the device.
All DynaFlex II Go product family hardware configurations are listed in Table 2‑1 below. The device utilizes two interface types, USB and Bluetooth LE. Use of any interface other than USB or Bluetooth LE will invalidate PCI approval.
The most recent firmware versions for DynaFlex II Go products are 1000009446-AB0-PCI for the secure bootloader (Boot1 FW), 1000009421-AC0-PCI and 1000009714-AC0-PCI for the core firmware (Main FW), and 1000009327-AB0-PCI for the Bluetooth LE Firmware Version. The X in firmware versions indicates minor non-security related changes. The secure bootloader firmware version also covers the initial bootloader (Boot0) permanently programmed into the device. Any changes to either Boot0 or Boot1 will result in a change to the Boot1 FW version that is visible to the user, reported by the device, and listed on the PCI Approved Devices website.
All device identification information, including firmware versions and PCI Hardware ID, is accessible by connecting DynaFlex II Go to a host device via USB or Bluetooth LE, using the latest software provided by MagTek, as seen in Figure 2‑6 - Device Information Screen.
The host user can also can retrieve device information at any time using Command 0xD101 Get Property as described in DynaFlex II Go Programmer’s Manual (COMMANDS).
42PCI50B0BB0
DynaFlex II Go, PCI, BCR, BLACK, BLUETOOTH LE
42PCI30U0BC0
DynaFlex II Go, PCI, BLACK
42PCI50U0BC0
DynaFlex II Go, PCI, BCR, BLACK
42PCI30B0BC0
DynaFlex II Go, PCI, BLACK, BLUETOOTH LE
42PCI50B0BC0
DynaFlex II Go, PCI, BCR, BLACK, BLUETOOTH LE
42PCI30U0BD0
DynaFlex II Go, PCI, BLACK
42PCI50U0BD0
DynaFlex II Go, PCI, BCR, BLACK
42PCI30B0BD0
DynaFlex II Go, PCI, BLACK, BLUETOOTH LE
42PCI50B0BD0
DynaFlex II Go, PCI, BCR, BLACK, BLUETOOTH LE
10
11
12
PCI Hardware ID Number
4
2
P
C
I
3
0
U
0
B
B
PCI Hardware ID Number
4
2
P
C
I
5
0
U
0
B
B
PCI Hardware ID Number
4
2
P
C
I
3
0
B
0
B
B
PCI Hardware ID Number
4
2
P
C
I
5
0
B
0
B
B
PCI Hardware ID Number
4
2
P
C
I
3
0
U
0
B
C
PCI Hardware ID Number
4
2
P
C
I
5
0
U
0
B
C
PCI Hardware ID Number
4
2
P
C
I
3
0
B
0
B
C
PCI Hardware ID Number
4
2
P
C
I
5
0
B
0
B
C
PCI Hardware ID Number
4
2
P
C
I
3
0
U
0
B
D
PCI Hardware ID Number
4
2
P
C
I
5
0
U
0
B
D
PCI Hardware ID Number
4
2
P
C
I
3
0
B
0
B
D
PCI Hardware ID Number
4
2
P
C
I
5
0
B
0
B
D
6
Front options
3 = Standard
5 = includes Barcode Reader
7
Option RFU (Reserved for Future Use)
RFU 0 = as Certified
8
Interface Options
U = USB only
B = USB + Bluetooth LE
9
Option RFU (Reserved for Future Use)
RFU 0 = as Certified
10
Cover Color:
B = Black
11
Version
B and C and D = as Certified
12
minor fixes not adding functionality or related to security (e.g., change component value for antenna matching):
0 = as certified
9
10
11
12
13
14
15
16
17
18
1
0
0
0
0
0
9
4
2
1
-
1
0
0
0
0
0
9
4
1
1
-
1
0
0
0
0
0
9
4
2
1
-
1
0
0
0
0
0
9
7
1
4
-
1
0
0
0
0
0
9
7
1
4
-
1
0
0
0
0
0
9
4
2
1
-
1
0
0
0
0
0
9
7
1
4
-
14
Minor revisions, bug fixes
16-18
PCI = PCI version of firmware
9
10
11
12
13
14
15
16
17
18
1
0
0
0
0
0
9
4
4
6
-
A
14
Minor revisions, bug fixes
16-18
PCI = PCI version of firmware
9
10
11
12
13
14
15
16
17
18
1
0
0
0
0
0
9
3
2
7
-
A
14
Minor revisions, bug fixes
16-18
PCI = PCI version of firmware
PCI ID Tag
Configuration Description
42PCI30U0BB0
DynaFlex II Go, PCI, BLACK
42PCI50U0BB0
DynaFlex II Go, PCI, BCR, BLACK
42PCI30B0BB0
DynaFlex II Go, PCI, BLACK, BLUETOOTH LE
PCI Hardware ID Number
1
2
3
4
5
6
7
8
Fixed Position
Variable “X” Position
Description of Fixed or Variable “X” in the Selection Position
1-2
42 = DynaFlex II Go
3-5
Firmware Number
1
2
3
4
5
6
7
Fixed Position
Variable “x”
Position
Description of Fixed or Variable “x” in the Selected Position
1-10
1000009421, 1000009714 = DynaFlex II Go Main firmware part number
12-13
Firmware Number
1
2
3
4
5
6
7
Fixed Position
Variable
“x” Position
Description of Fixed or Variable “x” in the Selected Position
1-10
1000009446 = DynaFlex II Go Boot firmware part number
12-13
Firmware Number
1
2
3
4
5
6
7
Fixed Position
Variable
“x” Position
Description of Fixed or Variable “x” in the Selected Position
1-10
1000009327 = DynaFlex II Go Bluetooth LE firmware part number
12-13








9
PCI = PCI Hardware
8
1000009421 - AA, AB, and AC = Certified Version
1000009714 - AB and AC = Certified Version
8
AA = Certified Version
8
AA = Certified Version
0
0
0
0
0
0
0
0
0
0
0
0
A
A
X
-
P
C
I
A
B
X
-
P
C
I
A
C
X
-
P
C
I
A
B
X
-
P
C
I
A
C
X
-
P
C
I
A
C
x
-
P
C
I
A
C
X
-
P
C
I
A
x
-
P
C
I
A
x
-
P
C
I