Door Access with Rhombus
Rhombus door access lets members open your doors with a key fob, managed from Gymdesk. You assign a fob from the member's profile, and access follows their membership: freeze, cancel, or let a membership lapse and the fob stops working, with no manual revoking.
Rhombus makes the hardware and its installer network handles installation. Fobs, doors, hours, and attendance are all managed in Gymdesk. To get started, contact sales@gymdesk.com. We'll work out how many doors you need, get you a hardware and installation quote, and set your account up for door access.
What you need first
Hardware. A DC20 controller (one per four doors) and a DR20 reader on each door. Rhombus's installer network sources a local certified installer, returns a competitive bid, and schedules the work; you pay the installer directly. Gymdesk doesn't supply hardware or create Rhombus accounts.
Check your fobs before you order anything
Rhombus readers only read 13.56 MHz NFC fobs. Plenty of older gym fobs run at 125 kHz, and those won't work — there's no adapter or workaround. If your members carry fobs today, send us a photo of one or the listing you bought them from and we'll check for you.
Fobs aren't proprietary, so you can buy standard NFC fobs yourself for roughly $17–20 per 100.
An API key. Generate one yourself in your Rhombus console under Settings > API Management. Gymdesk stores the key you paste and never creates one for you.
Two things to get right when you create it. Set the auth type to API token — not certificate, which shows an extra text box below it. And give the key the super admin permission group, which Rhombus sets up by default.
Rhombus shows you the key once. Copy it before you close the window, because it can't be retrieved afterwards — if you lose it, delete the key and generate a new one.
You'll need to be the account owner, or have the Manage Door Access permission.
Connecting
Go to Settings > Integrations > Door Access, click the Rhombus tile, and paste your API key. Gymdesk validates it by reading your Rhombus organization and shows you the organization name to confirm — nothing is created in your Rhombus account until the key is accepted. Your doors then sync automatically.
If setup only partly finishes, the page tells you what still needs doing rather than moving on as though everything worked. Your connection is saved either way.
If the key isn't accepted, check you copied the whole value or generate a new one. (A revoked key and a key from another region look the same from Gymdesk's side.) If Rhombus doesn't respond, nothing was changed — try again shortly. If you're told your organization has no locations, add one in Rhombus first.
Your doors
Gymdesk syncs the access-controlled doors from your Rhombus organization and re-syncs daily, so doors added or renamed in Rhombus appear without you doing anything. Each door shows its name, whether it's currently online, and a Members have access toggle — turn that off for staff-only doors like an office or storeroom.
Business hours
Business hours set when doors open for members. Your hours are shown alongside the timezone of your Rhombus location, because Rhombus evaluates them in that timezone — the one your installer set for the building. If the location has no timezone, Gymdesk tells you so; set it in the Rhombus console.
- One set of hours covers your whole gym. Different memberships can't have different hours.
- Leave hours empty for a 24/7 gym. No hours configured means doors open for eligible members at any time.
- Times are set on five-minute boundaries, and overlapping or touching windows merge when you save — 6am–2pm plus 10am–8pm becomes 6am–8pm.
- Windows can't cross midnight. For an overnight gym, leave hours empty for 24/7 access.
Giving members access
Door access is set on the membership, not the individual member. On each membership that should open your doors, enable door access and choose which doors it opens.
A member can open a door when they hold an active, unfrozen membership granting access to it, the membership has started and hasn't expired, and — on a session- or day-capped plan — they have sessions left. A day pass keeps working for a day it's already paid for, so a member who came in the morning can return that afternoon.
On family memberships, each person enrolls their own fob.
Memberships that only grant access for booked sessions can't be used for door access. A member whose only membership works that way can't be issued a fob, so they'll need a membership with door access enabled to get through the door.
Issuing a fob
Open the member's profile, click Enroll in the Door Access panel, and have them tap their fob on the reader. Enrollment stays open for five minutes. The fob is then bound to that member, and every tap from then on is that member and only that member. Starting a new enrollment on a door cancels any enrollment already waiting on it.
That first tap is refused at the door, with the reader's error tone. That's expected — Rhombus doesn't recognise the fob yet, and the refused tap is what tells Gymdesk which fob to bind to the member. Once it's enrolled, the next tap opens the door. You'll see the same thing when you replace a member's fob with a new one.
Each member holds one fob at a time — issuing a new one replaces the old, and revoking a fob frees its number for someone else. If a tapped fob already belongs to another member, Gymdesk won't take it from them; you'll see who holds it so you can revoke it from their profile first. Members without an email address can't be issued a fob, since Rhombus needs one to create their record. Doors are opened with a fob — members can't unlock doors from the Gymdesk app.
Fobs keep working if your internet goes down: the controller holds its own copy of your member list from the last sync, and refreshes when the connection returns.
When a membership changes
| In Gymdesk | At the door |
|---|---|
| Assigned or activated | Access granted |
| Frozen | Access removed, fob suspended |
| Unfrozen or renewed | Access restored, fob reactivated |
| Cancelled or ended | Access removed, fob suspended |
| Changed to a different tier | Access moves to the new membership's doors; fob stays with the member |
| Member deleted | Their Rhombus record is removed |
Suspending keeps the fob bound to the member, so restoring access doesn't mean enrolling them again.
Non-payment
Renewals are payment-gated, so a member whose payments keep failing loses access when their membership lapses at the end of the period they've paid for.
Door access doesn't lock someone out the same day a payment fails — until the membership lapses, they keep access. If you need someone out sooner, freeze or cancel the membership and the door follows immediately.
Attendance and staff tools
Turn on Track attendance and every allowed tap is recorded as attendance against that member, with no front-desk check-in. Re-entry during a single visit doesn't create a second record, so a member stepping out mid-session stays one visit and one session charge.
Staff can unlock any door remotely from Gymdesk — useful for a delivery, or a member who's forgotten their fob.
Staff can also see a member's recent taps from their profile (last 90 days) and a gym-wide history (last year). History is read live from Rhombus, so there's no all-time archive, and taps are matched by the member's current fob — if you've replaced a fob, taps made with the old one no longer appear. Denied taps that fall outside your business hours are labelled as such, which is Gymdesk's reading of the timestamp rather than a reason reported by the reader. Tap history is staff-only.
What it costs
| DC20 controller | $1,598 one-time — runs up to 4 doors |
| DR20 reader | $299 one-time per door |
| Installation | $1,200–1,500 |
| One-time total, single door | ~$3,100–3,400 |
| Monthly to Gymdesk | $100/mo for up to 3 doors, then $29/mo per door |
| Fobs | Bring your own standard NFC, ~$17–20 per 100 |
Hardware and installation are list prices and estimates until your installer's competitive bid comes back; bids typically land at or under list, and installation is paid to the installer rather than to Gymdesk.
The monthly fee is charged per location
Door access at two locations means the $100 base at each. The fee is added to your Gymdesk subscription, separate from your plan. Your door count is read when your bill is prepared, so adding or removing a door takes effect on the next bill rather than mid-cycle.
Turning it off
Disconnecting removes what Gymdesk created in your Rhombus organization and stops the monthly charge. Your business hours are kept, so reconnecting doesn't mean setting them up again. Your API key is yours — Gymdesk never creates or revokes one, so revoke it in your Rhombus console if you want it to stop working.
Cameras, tailgating detection, analytics, sensors, and alarms are Rhombus platform features and live in your own Rhombus console. You don't need a Rhombus login for the day-to-day.