Stadiums and arenas: fans on the portal, staff on EAP-TLS, a personal WiFi key per accreditation tier
Event day brings caterers, press, stewards and security from a dozen employers. Each tier is a role and VLAN with its own bandwidth limit and an expiry, scanners and registers get MAC-bound keys, and fans use the portal or OpenRoaming.
- SoFi Stadium runs on Purple
- 80,000+ venues in 90 countries
- 500 million logins a year
- OpenRoaming: 5 million+ hotspots worldwide
Who is on the stadiums and arenas network
Who is on the event-day network, and the tier each one gets
Accreditation tiers are roles that expire after one event, and scanners and point-of-sale devices sit on MAC-bound keys, so a dozen employers share the bowl's access points and nothing else.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Fans | Open | Captive portal sign-in, consent recorded (or SSO, social, SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in |
| Venue operations, security control and IT | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Stewards and event-day agency staff | xPSK | Individual key, MAC-bound (one tier, valid for the event, no MDM) | A staff-tier VLAN with a bandwidth limit per key | Expires with the event |
| Press and broadcast crews | xPSK | Individual key, MAC-bound (an accreditation tier) | A press-tier VLAN, apart from fans and from staff | Expires with the accreditation |
| Caterer and vendor staff | xPSK | Individual key, MAC-bound | A network per vendor, its own VLAN and key set | Revoked at the end of the contract, one vendor at a time |
| Ticket scanners and point-of-sale registers | xPSK | Individual key, MAC-bound | Locked-down device VLANs, one per class | One key per device, rotated or revoked alone |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Stadiums and arenas: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Fans and staff phones: portal, OpenRoaming and onboarding lane
The public lane for the crowd, and the BYOD lane for regular staff who bring their own phone.
- A portal sized for the crowd. SSO, Google, Apple, Facebook or SMS with consent recorded for GDPR and CCPA, and under 15 minutes to add the splash URL and RADIUS to a controller.
- OpenRoaming for fans who return. Fans with a profile connect automatically at the gate, across 5 million+ hotspots worldwide, with no portal in the queue.
- Regular staff on personal phones. Sign in once in the Purple app and a WiFi pass installs on Windows, macOS, Linux, iOS and Android, with no MDM enrollment.
Operations and security staff: EAP-TLS, groups decide the VLAN
One WPA-Enterprise SSID for the venue's own managed devices. Cloud RADIUS checks the directory and returns the VLAN for the group.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once.
- Control room and operations by group. Entra ID, Okta or Google Workspace over SAML and SCIM. A leaver is disabled once and every concourse stops authenticating them.
Accreditation, vendors and scanners: a key each
Event-day workers have nothing to install and scanners have no supplicant. A key per person or device on one SSID gives each tier its own VLAN and its own expiry.
- A key per accreditation tier, valid for that event only. Staff, press, hospitality and contractors each map to a role and VLAN. Keys carry the event's end date, so the next fixture starts clean.
- Ticket scanners and registers on locked-down keys. Each device on a MAC-bound key and a device VLAN, with no certificates to push to hundreds of handhelds before kick-off.
- Caterers and vendors in their own networks. A key set and VLAN per vendor, apart from fans, from staff and from each other, revoked when the contract ends.
Lifecycle
Key lifecycle: accredit, place, run the event, expire
The unit is the event: keys come from the accreditation list and vendor roster, and end with the fixture.
Issue from the accreditation list
Import the accreditation list and the vendor roster and each line becomes a key with the event's end date. Scanners and registers are keyed from the device register, each bound to its MAC.
Place each tier in its lane
RADIUS returns the tier's VLAN, role or group policy, depending on your vendor, with a bandwidth limit per key. The limit is a cap on that key, and your access points and gateway enforce the lanes.
Operate from one log on event day
Every accept and reject carries the tier, the vendor and the reason, so a steward's rejected key is a lookup at the gate and not a radio call.
Expire with the event
Event keys stop on the date set. To end one early, revoke that key alone, and RADIUS CoA ends the live session on access points that support it.
One authentication log
One authentication log from the gate to the press box
Fans, staff tiers, vendors and devices share one log, so event-day questions are queries.
- Which accreditation tier each connected device belongs to.
- Which vendor's registers authenticated, and which were rejected and why.
- Which scanners are online per gate, and on which VLAN.
- Which event keys are still live after the fixture.
Audit
Concession payments apart from the bowl: what the assessor tests
Vendors take cards on the venue's access points. Purple never touches card data, and segmentation hands the assessor each vendor's VLAN map and log.
PCI DSS v4.0.1 Req 2.3.2
Wireless keys must change when anyone who knows them leaves. A key per device makes that one rotation, and not every register in every kiosk.PCI DSS Req 8 and 10
Every authentication is logged with the identity and the reason, and streamed to your SIEM as evidence.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Stadiums run on it
- SoFi
- Stadium runs on Purple
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- 5M+
- OpenRoaming hotspots worldwide
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need new access points in the stadium?
No. Purple Access is a cloud overlay on the access points your venue already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
How do event-day keys expire without someone clearing them?
Each key is issued with an end date, so it stops authenticating when the event ends. Revoke a key early and RADIUS CoA ends the live session on access points that support it.
Is the per-key bandwidth a guarantee?
No. It is a limit: a cap RADIUS returns for that key. It does not reserve capacity for it.
How do ticket scanners with no supplicant join?
To the scanner its key is an ordinary WPA2-Personal passphrase, so there is no supplicant, certificate or portal. The per-device key is held on the access point side under each vendor's name for it (Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK).
Does xPSK take our WiFi out of PCI scope?
Purple never touches payment card data. Each register and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.
Book a demo: we issue and revoke a key on a live network
Bring one event day's worth of lanes: a steward, a caterer's register, a scanner and a press pass. We issue each a key, place it in its tier and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.