Browse software

ZKTeco ADMS server: how push mode works

Your attendance machine can send every punch to a server on the internet by itself. Here is what that server does, how the conversation works, and what you need to run your own.

Updated 4 October 2026 · 6 min read

Pull vs push: two ways to get punches off a machine

For years, attendance machines worked in pull mode: desktop software on an office PC connects to the machine over the local network and downloads the punches. It works — but the PC must stay on, it only sees machines on its own network, and every branch needs its own copy.

Most ZKTeco and eSSL machines made in recent years also support push mode, known as ADMS (on newer firmware the menu is called Cloud Server Setting). In push mode the machine starts the conversation: it calls a server address you give it and sends each punch as it happens.

Pull (desktop software)Push (ADMS server)
Who connectsThe PC connects to the machineThe machine connects to the server
Fixed IP at the officeNeeded for remote accessNot needed
PC left runningYesNo
Many branchesOne copy per site, or VPNAll machines call one server
Punches arriveWhen someone downloads themLive, within seconds

What actually happens on the wire

The push protocol is plain HTTP. The machine identifies itself with its serial number and talks to a few addresses under /iclock/:

  1. Hello and settings — the machine asks GET /iclock/cdata and the server replies with its options (for example how often to check in). Newer firmware first registers itself at /iclock/registry.
  2. Sending punches — each new punch is sent with POST /iclock/cdata?table=ATTLOG: the employee's PIN, the time, and how they punched (finger, face, card).
  3. Asking for work — every so often the machine asks GET /iclock/getrequest: "do you have a command for me?" This is how a server can ask it to re-send old punches, send its user list, or restart.
  4. Reporting back — after running a command it answers at /iclock/devicecmd.

Because the machine always makes the call, it works through an ordinary office router with no port forwarding. If the internet drops, the machine keeps its punches in memory and sends them when it is back.

What a good ADMS server must do

What you need to run your own

  1. A machine with an ADMS / Cloud Server Setting menu — check Menu → Comm.
  2. Web hosting with a domain — ordinary PHP hosting is enough; port 80 must be reachable (almost every host).
  3. ADMS server software — you can write it yourself from the steps above, or install a ready one.
  4. Five settings on the machine — explained in How to connect a ZKTeco machine to a cloud server.
The setting that trips most people: with port 80, HTTPS must be OFF on the machine. If it is ON, the machine never reaches the server even with perfect internet.
Topics:ZKTecoADMSPush protocoleSSLAttendance machine
Want a ready ADMS server? PunchSync speaks this protocol out of the box: machine approval, no doubled punches, unmatched-PIN list, live machine status and full attendance reports — on your own hosting. Try the live preview.

Related guides

ZKTeco and eSSL are trademarks of their respective owners. Menu names and protocol details can differ slightly between models and firmware versions.