Co-living: a personal WiFi key per member timed to the stay, staff on EAP-TLS, guests on the portal
Each member gets one xPSK key with an end date from one week to a year, and its own VLAN or role. Community managers sign in on EAP-TLS, event guests use the portal, and shared printers and screens sit on a services VLAN that members reach by policy at your gateway.
- 80,000+ venues in 90 countries
- 99.999% uptime
- 99.9% RADIUS uptime SLA
Who is on the co-living network
Who connects in a co-living building, and where each one lands
Key lifetime equals the booking, from one week to a year, and shared printers and screens are reachable from members' VLANs by gateway policy while private devices never are.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Community hosts on personal phones | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Event guests and members' visitors | Open | Captive portal sign-in, consent recorded (or SSO, social, SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in, session expires on timeout |
| Community managers and operations staff | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Members on short and long stays | xPSK | Individual key, MAC-bound (one key per member, end date set at issue) | A VLAN or role per member, with its own bandwidth limit | Ends on the stay's end date, extended by changing the date |
| Shared printers, screens and speakers in common spaces | xPSK | Individual key, MAC-bound (bound to the device's MAC) | A shared-services VLAN, reachable from member VLANs by gateway rule | One key per device, revoked when the device is swapped |
| Cleaners and maintenance contractors | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A contractor VLAN and bandwidth limit per key | Ends on the day the contract or the job does |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Co-living: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Event guests, visitors and host phones: portal and onboarding lane
Co-living runs community events, and every guest at one is a stranger to the network. They get the guest lane, never a member's VLAN.
- Event guests on the portal. Sign-in by SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA and client isolation on. Under 15 minutes to add the splash URL and RADIUS to a controller.
- Host phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android, then the phone lands on its group VLAN.
Community staff: EAP-TLS and directory groups
One WPA-Enterprise SSID per building. Cloud RADIUS checks the directory and returns the VLAN for the group, so community, operations and finance each land in their own lane.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once, for the whole organization.
- Directory groups decide the VLAN. Entra ID, Okta or Google Workspace over SAML and SCIM. Disable a leaver once and every building stops authenticating them.
Members and shared devices: a key each, timed to the stay
A member's key has an end date and a VLAN. A shared printer has a key and a place on a services VLAN. Neither needs a supplicant, and neither adds an SSID.
- Keys timed to the stay, one week to a year. Set the end date when the key is issued. A member who extends has the date changed, and a member who leaves stops authenticating on the day, with no sweep of expired passwords.
- Shared printers and screens reachable by members, private devices never. Common-space devices sit on a services VLAN, and your gateway allows member VLANs to reach it and nothing else. A member's laptop is never reachable from another member's.
- Contractors with nothing to install. A time-limited key from the self-service portal or the Purple API, ending on the day the job does.
- A private network per room that follows the member. A private network per room that follows the member into the lounge and co-working floor.
Lifecycle
Booking in, booking out: one key per stay
Co-living turns members over week by week, so the key lifecycle runs constantly. Put the end date on the key at issue and the system of record stays your booking list.
Issue with the booking
Create the member's key from the booking: from the console, in bulk for a cohort, or through the Purple API from your own membership system, with the stay's end date set on it.
Place members apart, shared devices together
RADIUS returns the VLAN, role or group policy, depending on your vendor. Member VLANs stay apart, and the one rule that lets them reach the services VLAN is written at your gateway.
Operate every house from one log
Every accept and reject carries its reason, by building, member and device, and streams to Microsoft Sentinel, Splunk, Elastic or Datadog.
End on the date, or sooner
A key stops authenticating on its end date. An early departure withdraws it at once, with RADIUS CoA ending the live session on access points that support it.
One authentication log
One authentication log across every house and every stay
Short stays mean a lot of keys in flight. The log is how you know which are live, which expired cleanly and which never connected.
- Which member keys are live in each building today, and which end this week.
- Which issued keys have never authenticated, so a member's first night is not the first you hear.
- Why a device was rejected: an expired key, a revoked key or an unbound MAC address.
- Which shared devices are authenticating on the services VLAN.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Resident networks at scale
About 1 million students and residents run on Purple's community networks, on the access points their operators already owned.
- ~1M
- students and residents on Purple community networks
- 80,000+
- venues run on Purple, in 90 countries
- 99.999%
- uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
- 99.9%
- cloud RADIUS uptime SLA, in your contract
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need new access points in our houses?
No. Purple Access is a cloud overlay on the access points your houses already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Is xPSK one SSID or one per household, tenant or device?
One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
What happens when a member extends their stay?
You change the end date on their key. The key, the VLAN and the devices bound to it stay as they are, so the member notices nothing and nobody changes a password.
A member leaves three weeks early. What do we do?
Revoke the key. Their devices fail the next authentication, RADIUS CoA ends the live session on access points that support it, and every other member stays connected.
Book a demo: we issue and revoke a key on a live network
Bring a house's worth of devices: a member's phone, a shared printer, a cleaner's phone and a community manager's laptop. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.