User Authentication

Every way to sign in to your Wi-Fi

  • Captive portal sign-in, from click-through and OTP to vouchers, plus xPSK, Passpoint and 802.1X with a range of EAP methods.

  • Our RADIUS servers run in the cloud or on your premises.

  • Authenticate users against the user databases you already have.

Wi-Fi user authentication methods: captive portal, email and SMS OTP, vouchers, xPSK, Passpoint and 802.1X with EAP

Authentication methods for every network

Use one method or combine several, depending on who's connecting and from which device.

Captive Portal

A branded sign-in page for guests, with click-through, OTP, vouchers, payment and more.

Learn more

xPSK

A unique Wi-Fi password for every user: iPSK, MPSK, DPSK or PPSK.

Learn more

Passpoint (Hotspot 2.0)

Passwordless, automatic and secure connections through a profile installed on the device.

Learn more

802.1X / WPA-Enterprise

Individual credentials or certificates for every user, with the EAP method that fits your devices.

Learn more

Captive Portal

Captive portal sign-in options for every venue

Click-Through

Guests accept your terms and get online with a single click.

Email Verification (OTP)

Guests confirm their email address with a one-time code.

SMS Verification (OTP)

Guests confirm their phone number with a one-time code sent by SMS.

Vouchers

Hand out voucher codes that guests enter to get online.

Payment

Charge guests for Wi-Fi access before they connect.

Form Submission

Ask for the details you need, such as name, email or phone number, with a custom form.

Shared Password

Give all your guests one common Wi-Fi password.

Username & Password

Individual accounts for each user, such as members, staff or residents.

802.1X with the EAP method you need

The most common EAP methods, and others when you need them. Choose what fits your users, devices and security requirements.

EAP-TLS

Certificate-based authentication on both the client and the server. The strongest option, with no passwords to steal.

PEAP

Username and password sent inside an encrypted TLS tunnel. Widely supported and easy to roll out.

EAP-TTLS

Username and password inside a TLS tunnel, with flexible inner authentication methods for different directories.

Other EAP Methods

Need something else? We can work with other EAP methods your devices or network require.

Cloud RADIUS
On-Premises RADIUS
Your User Databases
Multi-Factor Authentication
RADIUS & Directories

Built on RADIUS, connected to your users

  • Our RADIUS servers run in the cloud or on your premises, whichever suits your network.

  • Integrate with your existing user databases, such as SQL databases, Google Workspace, LDAP, Active Directory, Microsoft Entra ID and other identity providers.

  • Let users sign in to WPA-Enterprise Wi-Fi with their Google Workspace accounts. See how with FreeRADIUS and Secure LDAP

  • Add multi-factor authentication for stronger protection of network access. See our RADIUS/AAA services

The right method for every user

Different people connect in different ways. We'll help you match each group with the method that fits.

Guests & Visitors

A captive portal for quick, branded sign-in, or Passpoint for returning visitors and loyalty app users.

Employees

802.1X with individual credentials or certificates, or Passpoint profiles pushed through your MDM.

Residents & Devices

xPSK gives every resident, student or device its own password, including devices that don't support 802.1X.

Companies all over the world are using our products and services

Frequently Asked Questions

Common questions about Wi-Fi user authentication.

Which authentication methods do you support?

Captive portal sign-in, xPSK, Passpoint (Hotspot 2.0) and 802.1X (WPA-Enterprise) with a range of EAP methods, all backed by our cloud or on-premises RADIUS servers.

Which captive portal sign-in options are available?

Click-through, email and SMS verification with a one-time code (OTP), vouchers, payment, form submission, a shared password, and username and password.

How do I choose between captive portal, xPSK, Passpoint and 802.1X?

It depends on who's connecting. A captive portal suits guests, Passpoint suits returning visitors and managed devices, xPSK suits residents and devices without 802.1X support, and 802.1X suits employees. We'll help you choose.

Can I use more than one method on the same network?

Yes. Many networks combine methods, for example a captive portal for guests, 802.1X for staff and xPSK for devices.

Which EAP methods do you support?

We support EAP-TLS for certificate-based authentication, plus PEAP and EAP-TTLS for username and password logins inside an encrypted tunnel. We can also work with other EAP methods your devices or network require.

Is your RADIUS server in the cloud or on-premises?

Either. Cloud RADIUS suits networks spread across many locations, while on-premises RADIUS keeps authentication and user data inside your own network.

Can it use our existing user database?

Yes. We integrate with SQL databases, Google Workspace, LDAP, Active Directory and Microsoft Entra ID, among others. If your directory isn't listed, get in touch.

Do you support multi-factor authentication?

Yes. You can require a second verification factor on top of the password for stronger protection of network access.

Have more questions? Ask your question here

Talk to our team about how your users should sign in