Skip to content
Residential: Co-living

Co-living: a personal WiFi key per member timed to the stay, staff on EAP-TLS, guests on the portal

Each member gets one xPSK key with an end date from one week to a year, and its own VLAN or role. Community managers sign in on EAP-TLS, event guests use the portal, and shared printers and screens sit on a services VLAN that members reach by policy at your gateway.

  • 80,000+ venues in 90 countries
  • 99.999% uptime
  • 99.9% RADIUS uptime SLA
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the co-living network

Who connects in a co-living building, and where each one lands

Key lifetime equals the booking, from one week to a year, and shared printers and screens are reachable from members' VLANs by gateway policy while private devices never are.

Who connects in a co-living building, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Community hosts on personal phonesOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the group VLANEnds with the directory account
Event guests and members' visitorsOpenCaptive portal sign-in, consent recorded (or SSO, social, SMS)Guest VLAN, client isolation onConsent recorded at sign-in, session expires on timeout
Community managers and operations staffSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory groupAccount disabled, and RADIUS CoA ends the session
Members on short and long staysxPSKIndividual key, MAC-bound (one key per member, end date set at issue)A VLAN or role per member, with its own bandwidth limitEnds on the stay's end date, extended by changing the date
Shared printers, screens and speakers in common spacesxPSKIndividual key, MAC-bound (bound to the device's MAC)A shared-services VLAN, reachable from member VLANs by gateway ruleOne key per device, revoked when the device is swapped
Cleaners and maintenance contractorsxPSKIndividual key, MAC-bound (time-limited, no MDM)A contractor VLAN and bandwidth limit per keyEnds on the day the contract or the job does

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Co-living: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Event guests, visitors and host phones: portal and onboarding lane

Co-living runs community events, and every guest at one is a stranger to the network. They get the guest lane, never a member's VLAN.

  • Event guests on the portal. Sign-in by SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA and client isolation on. Under 15 minutes to add the splash URL and RADIUS to a controller.
  • Host phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android, then the phone lands on its group VLAN.
Illustration

Lifecycle

Booking in, booking out: one key per stay

Co-living turns members over week by week, so the key lifecycle runs constantly. Put the end date on the key at issue and the system of record stays your booking list.

Issue with the booking

Create the member's key from the booking: from the console, in bulk for a cohort, or through the Purple API from your own membership system, with the stay's end date set on it.

Illustration

Place members apart, shared devices together

RADIUS returns the VLAN, role or group policy, depending on your vendor. Member VLANs stay apart, and the one rule that lets them reach the services VLAN is written at your gateway.

Illustration

Operate every house from one log

Every accept and reject carries its reason, by building, member and device, and streams to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

End on the date, or sooner

A key stops authenticating on its end date. An early departure withdraws it at once, with RADIUS CoA ending the live session on access points that support it.

Illustration

One authentication log

One authentication log across every house and every stay

Short stays mean a lot of keys in flight. The log is how you know which are live, which expired cleanly and which never connected.

  • Which member keys are live in each building today, and which end this week.
  • Which issued keys have never authenticated, so a member's first night is not the first you hear.
  • Why a device was rejected: an expired key, a revoked key or an unbound MAC address.
  • Which shared devices are authenticating on the services VLAN.
Illustration

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Resident networks at scale

About 1 million students and residents run on Purple's community networks, on the access points their operators already owned.

~1M
students and residents on Purple community networks
80,000+
venues run on Purple, in 90 countries
99.999%
uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
99.9%
cloud RADIUS uptime SLA, in your contract

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Do we need new access points in our houses?

No. Purple Access is a cloud overlay on the access points your houses already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Is xPSK one SSID or one per household, tenant or device?

One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

What happens when a member extends their stay?

You change the end date on their key. The key, the VLAN and the devices bound to it stay as they are, so the member notices nothing and nobody changes a password.

How do members reach a shared printer without reaching each other?

Each member's key returns its own VLAN or role with client isolation on. The printer's key places it on a services VLAN, and the one rule that lets member VLANs reach that VLAN is yours to write at the gateway. Purple returns attributes, and your access points and gateway enforce them.

A member leaves three weeks early. What do we do?

Revoke the key. Their devices fail the next authentication, RADIUS CoA ends the live session on access points that support it, and every other member stays connected.

Book a demo: we issue and revoke a key on a live network

Bring a house's worth of devices: a member's phone, a shared printer, a cleaner's phone and a community manager's laptop. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.