The NTAG213 TT (Tag Tamper) is a variant of the NTAG213 designed by NXP Semiconductors, enhanced with an opening detection feature. Compliant with the ISO/IEC 14443 Type A standard and the NFC Forum Type 2 format, it offers 144 bytes of user memory and detects, at each power-up, the state of a detection wire connected to the chip. It can be read and written by virtually all NFC-enabled smartphones.
Information
| Manufacturer | NXP Semiconductors |
| Family | NTAG21x (Tag Tamper variant of the NTAG213) |
| Standard | ISO/IEC 14443 Type A (parts 2 and 3) |
| NFC Forum type | Type 2 Tag |
| Operating frequency | 13.56 MHz |
| Data rate | 106 kbit/s |
| Unique identifier (UID) | 7 bytes, factory programmed |
| Operating distance | Up to approximately 10 cm, depending on the antenna and reader |
| Data retention | 10 years |
| Write endurance | 100,000 cycles |
| Total memory (EEPROM) | 184 bytes |
| User memory | 144 bytes |
Memory
The EEPROM memory of the NTAG213 TT is organized into 46 pages of 4 bytes (pages 0 to 45), a structure identical to the NTAG213, completed by a page dedicated to the Tag Tamper message:
| Pages | Content | Access |
|---|---|---|
| 0 to 2 | UID, internal data and static lock bytes | Read-only (UID) / OTP |
| 3 | Capability Container (CC), initialized at the factory | OTP |
| 4 to 39 | User memory (144 bytes) | Read / write |
| 40 | Dynamic lock bytes | OTP |
| 41 to 44 | Configuration: mirror, Tag Tamper, AUTH0, ACCESS, password (PWD) and PACK | Read / write, protectable |
| 45 | Tag Tamper message (TT_MESSAGE) | Read / write, lockable |
For encoding, the NTAG213 TT behaves exactly like an NTAG213: the 144 bytes of user memory hold an NDEF record containing a URL of around 130 characters, as the common prefix (https://www. for example) is compressed into a single byte by the NDEF format. The 4-byte Tag Tamper message, programmed into page 45 during initialization, remains masked as long as no opening has been detected.
Features & security
- Tamper detection (Tag Tamper): at each power-up, the chip measures the state of a detection wire connected to its dedicated pads; a detected opening is stored permanently and can be retrieved with the READ_TT_STATUS command.
- Tag Tamper message: a 4-byte message defined during initialization is revealed once an opening has been detected, either by direct reading or through the ASCII mirror, making it possible for example to display a different URL after opening.
- Password protection: a 32-bit password (PWD), combined with a 16-bit acknowledgement (PACK), restricts write access, or even read access, from a page defined by the AUTH0 parameter.
- Permanent locking: the static and dynamic lock bytes can switch the memory to read-only irreversibly, an operation that can be performed directly from NFC Tools.
- NFC counter: a 24-bit read counter is automatically incremented on the first read after field detection, useful for measuring the number of scans.
- ASCII mirror: the UID, the counter and the Tag Tamper message can be automatically inserted into the NDEF message (mirror function), for example as URL parameters.
- Originality signature: an ECDSA signature programmed at the factory, which can be customized and permanently locked, verifies the authenticity of the chip and helps detect certain counterfeits.
Physically, the NTAG213 TT has four connection pads instead of two: the antenna and the detection loop are independent, which allows a wide variety of seal designs without degrading RF performance.
Compatibility
The NTAG213 TT is compatible with virtually all NFC smartphones. On Android, reading and writing work natively with NFC Tools, without any particular restriction. On iPhone, automatic background reading is available from the iPhone XS and XR onwards; models from the iPhone 7 can read and write the chip via NFC Tools on iOS 15.6 or later, by starting the scan manually from the app.
With NFC Tools, the NTAG213 TT chip supports reading technical information, writing records, erasing, permanent locking and password protection. The list of compatible models is available in the article on compatibility.
NTAG213 vs NTAG213 TT
| Chip | User memory | Tamper detection | Typical use |
|---|---|---|---|
| NTAG213 | 144 bytes | No | Links, business cards, labels |
| NTAG213 TT | 144 bytes | Yes | Electronic seals, packaging, anti-counterfeiting |
Both chips share the same memory, the same security features and the same compatibility: the TT version only adds tamper detection, at the cost of a specific label design integrating the detection loop.
Frequently asked questions
What is the difference between an NTAG213 and an NTAG213 TT?
The memory and basic features are identical. The NTAG213 TT adds tamper detection: a detection wire whose breakage is permanently stored by the chip, with a dedicated message revealed after the event.
How does tamper detection work?
At each power-up in the NFC field, the chip measures the state of the detection wire. If it is broken, the event is permanently recorded and the Tag Tamper message becomes readable, including directly in the URL thanks to the ASCII mirror.
Is the NTAG213 TT compatible with iPhones?
Yes. Background reading works from the iPhone XS and XR onwards, and both reading and writing are possible via NFC Tools from the iPhone 7 on iOS 15.6 or later.
Can an NTAG213 TT be protected against rewriting?
Yes, in two ways: a permanent, irreversible read-only lock, or a reversible 32-bit password protection. Both operations can be performed with NFC Tools.
Useful links
