As of September 2026, a security gateway does not stop you reading the car — it stops you writing to it. That single distinction explains almost every “my scan tool sees everything but will not let me do anything” call this desk takes, and it is why a $2,000 aftermarket tool and a $200 pass-thru can both be equally blocked.
Gateways are the reason the independent side of this trade changed shape over the last several years. They are also badly explained almost everywhere, usually by someone selling a tool that claims to “bypass” one. This post is the working version: what a gateway actually is, which authorisation routes are legitimate, what each one costs you in time, and where a remote OE session fits when none of them are available to you today.
What a gateway is, mechanically
On a pre-gateway vehicle, the OBD port is electrically connected to the vehicle's internal networks. Anything you plug in can, in principle, address any module. That was convenient and it was also a security problem: research through the 2010s demonstrated repeatedly that a port with unmediated bus access is a port an attacker can use.
A gateway module sits between the diagnostic connector and the internal buses and acts as a filter. Diagnostic reads — codes, live data, the things a state inspection or a basic scan needs — pass through freely, because blocking those would break the legally mandated emissions-diagnostics function of the port. Write operations do not pass unless the requesting tool has authenticated. Programming, configuration, actuator commands, adaptation resets and immobiliser functions all sit on the far side of that wall.
So the symptom is distinctive and easy to recognise once you have seen it: full data, zero authority. If your tool reads every module happily and then fails the instant you ask it to change something, you are looking at a gateway, not a fault.
“Guys spend a week convinced the tool is broken. It is not broken. It is doing exactly what it is designed to do, which is nothing, because nobody authenticated it.” — Diagnostic technician, independent shop
The four legitimate routes past a gateway
| Route | What it gives you | What it costs |
|---|---|---|
| OE application with a valid subscription | Full authority, exactly as a dealer has | Per-day or per-year subscription cost |
| Third-party authorisation service | Your aftermarket tool authenticated for write access | Registration, vetting, an annual fee |
| Credentialed secure-access registry | Immobiliser and security functions specifically | Individual vetting you must hold yourself |
| Remote session on somebody else's subscription | Authority for one job, no standing cost | $100–$250 per session |
There is no fifth row. Anything marketed as a gateway “bypass” is either one of the four above wearing a different name, or a physical workaround that involves unplugging the gateway and connecting to the bus behind it — which is not authentication, leaves the vehicle in a non-standard state, and is not something we do or recommend.
FCA/Stellantis: the one everybody meets first
Chrysler, Dodge, Jeep and Ram brought a security gateway into the fleet earlier and more visibly than most, which is why “SGW” became shorthand for the whole category among independents. The practical position on those vehicles is that write operations require authenticated access, and there are two legitimate ways to have it: run the OE application on a current subscription, or hold a third-party authorisation registration that vouches for your aftermarket tool.
Our Mopar sessions run on wiTECH with authorised gateway access, which is why the platform card carries a warning we put nowhere else: first-time J2534 registration takes around 24 hours. That is not us being slow. It is the authentication step doing its job, and it is the single most common reason a Mopar booking has to be made a day ahead rather than thirty minutes out like every other platform. Plan for it.
The Mopar-specific split between what a session covers and what needs a file operation on a locked GPEC controller is laid out in our wiTECH session versus GPEC unlock guide, and it is worth reading before booking either, because the two are frequently confused by customers describing the same car.
Everyone else, briefly
The trend is universal even where the implementation differs. GM, Ford, Toyota, Honda, the VAG group and the European premium brands have all moved toward authenticated diagnostics on newer architectures, with the strictest protection reserved for immobiliser and key functions. The details differ by manufacturer and by model year in ways that make general advice useless; what generalises is the shape.
For immobiliser and security functions specifically, the U.S. route is the National Automotive Service Task Force Vehicle Security Professional programme. That credential is personal, vetted, and non-transferable — nobody can perform those operations on your behalf using their own registration and call it your job. If you do all-keys-lost work, this is infrastructure rather than an optional extra, and the routing side of that is in our all-keys-lost decision guide.
What gateways changed about running a shop
The technical description undersells the business effect. Three things shifted, and they are still shifting.
Tool purchases stopped being sufficient. For twenty years the independent playbook was: buy the best aftermarket scanner you can afford and you can do most of what a dealer does. That is no longer true on gatewayed vehicles, where the tool is necessary and not sufficient. The recurring cost moved from hardware to authorisation, and shops that budgeted for one and not the other got caught.
Diagnosis and repair separated. You can now fully diagnose a car you cannot fix, which is a genuinely new and deeply annoying situation. It is also the entire reason a per-job authority model exists: the diagnosis was correct, the shop was competent, and the only missing ingredient was permission.
Planning ahead started mattering.Registration and vetting take time — the 24-hour first-time J2534 registration on Mopar is the small version; credentialed secure-access vetting is the large one. Neither can be done while a customer waits. If you intend to do this work, start the paperwork before you need it.
The right-to-repair backdrop
None of this happened without a fight, and the fight is not over. The legal framework that keeps the OBD port open at all comes from emissions law: the Clean Air Act obliges manufacturers to make emissions-related diagnostic information and tools available to independents, which is why the read side of the port cannot simply be closed. Write access sits outside that obligation, which is exactly where gateways were placed.
The commercial stakes are large enough to explain the energy on both sides. S&P Global Mobility put the average age of light vehicles on U.S. roads at 12.6 years in its 2024 study, and the independent aftermarket services the overwhelming majority of that fleet. A gateway that quietly routes configuration work back to franchised dealers is not a small change to that market, which is why the standards bodies, the trade associations and the legislatures have all had something to say about it.
Where a remote session fits
The fourth row of that table is our entire business model, and it exists for a specific economic situation rather than as a philosophical position. If you meet a gatewayed VW twice a year, an ODIS subscription cannot be justified — but the two cars still need doing, and turning them away is a loss you take forever.
A session hands you the authority for one job. You plug a J2534 device into the car and install IgniteRemote; your device presents itself to our bench as though it were plugged in here; we run the manufacturer application against your vehicle with a Google Meet call alongside so you can see everything happening. $100 for GM, $150 for Ford/Lincoln, Nissan/Infiniti and Mazda, $250 for Toyota/Lexus, Volvo, VW/Audi and Mopar. Booking is 9 AM to 9 PM Central, seven days, earliest slot thirty minutes out — with the Mopar registration caveat above.
What you bring is hardware and a stable car. The device compatibility matrix lists what is known-good, and our J2534 buyer's guide covers the difference between a device that reads and a device that reliably programs — a distinction gateways have made more expensive to get wrong.
How to tell a gateway from the four things it gets blamed for
Gateways have become the default explanation for any refused operation, which means real faults get misdiagnosed as authentication problems and vice versa. The differential is straightforward once you know what to look at.
| What you see | Most likely cause |
|---|---|
| Reads everything, refuses every write | Gateway — not authenticated |
| Reads some modules, others silent | Network or module fault, not a gateway |
| Write starts, then fails partway | Voltage, interface or connection — not authorisation |
| One specific operation refused, others fine | Security-level function needing credentials |
| Tool cannot see the vehicle at all | Interface, cable or power — check the obvious first |
Row three deserves emphasis because it is the expensive one to misdiagnose. A write that begins and then stops is almost never an authentication problem — authentication fails at the start, not in the middle. A write failing in the middle is a power or connection problem, and treating it as an access problem means retrying instead of fixing the actual cause. The full list is in our six causes of failed remote sessions.
What a gateway is not responsible for
Two failure modes get blamed on gateways and are not their fault.
A locked controller. Gateway authentication and controller locking are different mechanisms at different layers. Authenticating past a gateway does not unlock a GPEC2A PCM; that is a separate operation on the controller itself, which is our file unlock service at $150 uploaded or $250 mailed in. Plenty of people buy the wrong one of those two because the marketing language overlaps.
A module that has stopped communicating.If the controller does not answer at all, no authorisation route reaches it, because there is nothing at the other end to authorise against. That is a bench problem — see our interrupted-flash recovery guide if a write failed, our U0100 guide if the network went quiet after a swap, and the read-method comparison for what physical access actually reaches.
We do not provide emissions defeat, delete files, or services intended to bypass emissions laws. Our services exist for tuning preparation, diagnostics, repair, motorsport, and off-road use where legally permitted. Customer is responsible for confirming legal use in their location and application.
Worth restating in this context specifically, because “gateway bypass” and “emissions bypass” marketing frequently come from the same accounts. They are different things, but a provider casual about one is usually casual about the other, and our provider red-flags guide treats both as the same signal.
The short version
A gateway blocks writes, not reads — full data with no authority is the fingerprint. There are four legitimate routes past one and no fifth. If you do this weekly, buy the subscription or the authorisation registration; if you do it occasionally, a sessiongives you the authority for one job at $100 to $250. Budget a day ahead for a first Mopar booking, and do not confuse a gateway with a locked controller — the free identifier will tell you which one you are actually looking at.