Skip to content
Network 1: open

Guest WiFi and captive portal, live on your controller in under 15 minutes

Guests sign in through your captive portal, consent is recorded, and BYOD and unmanaged devices get an onboarding lane to a certificate. Add RADIUS and the splash URL to the controller you already run, and it is live.

  • Under 15 minutes per controller
  • 80,000+ venues
  • Consent for GDPR and CCPA
Illustration
Illustration: a captive portal on a phone offering SSO, Google, Apple, Facebook, SMS and room number sign-in, with consent recorded.
Book my design session

Guest WiFi

A guest network kept apart from everything that matters

Guests land on their own VLAN, away from tills, staff devices and internal systems, with a branded sign-in at every site.

  • Isolated by designAccess points place guest devices on a guest-only VLAN, so a visitor's device never sees a till.
  • One portal, every venueDesign the sign-in once and publish it to every SSID across the estate.
  • No new access pointsRuns as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet.

Captive portal

Every sign-in method your venues ask for

Run different methods on different SSIDs from the same dashboard.

  • SSOMembers and staff sign in with single sign-on.
  • Google, Apple and FacebookSocial sign-in for guests who want one tap.
  • SMS one-time passcodeEvery connection tied to a verified number.
  • Custom fieldsAsk for the fields you need and nothing more.
  • Hotel PMS room checkGuests verified against the property management system with their room number.
Illustration

The onboarding lane

The portal is how a device graduates to the secure network

BYOD and unmanaged devices start on the open network, then move to a certificate or a Passpoint profile.

Sign in on the open SSID

The device joins the open network and the user signs in through the captive portal.

Illustration

Install a profile once

A Passpoint profile or the Purple app installs at the end of that one sign-in.

Illustration

Connect securely from then on

Next visit, the device joins the secure network on its own, encrypted from association, with no portal.

Illustration

Visitor pre-arrival

Visitors are online before they reach reception

Invite a visitor and the WiFi is sorted before they leave home. No forms, no manual approval, no password at the desk.

The calendar invite carries the WiFi

The host books the meeting and the visitor's invite brings their WiFi access with it.

Illustration

Their device connects on arrival

The visitor walks in and their device joins automatically, on the guest VLAN, with no portal and no password at the desk.

Illustration

The host is notified

The moment the visitor connects, their host gets a notification that they have arrived.

Illustration

Add-on: Purple Shield

Make this network safer and faster with Purple Shield

Purple Shield bolts onto Access or runs standalone. Set a different DNS policy per VLAN and by time of day, so staff, guests and residents each get the filtering that fits them, with dashboard analytics. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Common questions

What is a captive portal?

The web page a guest sees before getting internet access on an open network. It signs them in by SSO, social login, SMS passcode, custom fields or room number, asks them to accept your terms and records their consent.

Which access points does the captive portal run on?

Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet, as a cloud overlay. You keep the hardware.

How long does it take to set up?

Adding the RADIUS and splash URL settings to an existing controller takes under 15 minutes.

Do we need RADIUS for guest WiFi?

A basic captive portal does not. Purple runs cloud RADIUS for you when you want per-user or per-device authentication on the secure and xPSK networks.

Can visitors be connected before they arrive?

Yes. The visitor's calendar invite carries their WiFi access, their device connects automatically when they walk in, and their host is notified.

Put the open network on your hardware

Tell us which access points you run and how guests should sign in. Your controller is under 15 minutes from live. All in a 45-minute design session.

  1. Get your three-SSID plan in 45 minutesTell us what runs on your WiFi today, and a Purple network engineer maps it with you.
  2. Map your SSIDs onto threeOpen, secure and xPSK, on the access points you already own. You leave with the plan.
  3. Prove it on one site firstJudge the result on tickets and audit evidence, then roll out.

Your design session

45 minutes. Your estate. A plan you keep.

Led by a Purple network engineer. No slides. You keep the plan.