UniFi supports two different approaches for public or guest connectivity: a traditional captive portal and Passpoint, also known as Hotspot 2.0.
They solve different problems. Choosing the wrong one can create a poor guest experience or eliminate features the venue expected to use.
The short answer
Choose a captive portal when guests should see a splash page, accept terms, authenticate through an external service, enter information, or be redirected through a branded experience.
Choose Passpoint when the priority is seamless, profile-based access for compatible devices across one or more venues, without a captive-portal redirect.
Ubiquiti states that Passpoint-enabled SSIDs do not support captive portals or redirects. (help.ui.com)
What a captive portal provides
A UniFi Hotspot Portal can present a landing page and support authentication options such as passwords, vouchers, payment, RADIUS, or an external portal server. (help.ui.com)
An external portal can add workflows such as:
- Branded guest onboarding
- Newsletter or contact capture
- Hotel-style authentication
- Payment or entitlement checks
- A post-login redirect
- Custom authorization rules
UniFi’s External Hotspot API describes a flow in which the guest begins unauthorized, is redirected to the external portal, and is authorized through the Network API after the required steps are complete. (help.ui.com)
What Passpoint provides
Passpoint is designed to let compatible devices connect automatically after a user has an appropriate profile. This is useful for operators that want a more seamless experience across multiple participating locations.
The Passpoint setup requires a supported UniFi Network version, compatible AP firmware, and a configured RADIUS profile. Ubiquiti also notes that a third-party RADIUS server is currently required. (help.ui.com)
Passpoint is not a replacement for a splash page. There is no captive-portal redirect on a Passpoint-enabled SSID.
Decision table
| Requirement | Captive portal | Passpoint |
|---|---|---|
| Branded splash page | Yes | No redirect |
| External portal integration | Yes | No captive portal |
| Guest form or contact capture | Possible | Not through a portal |
| Seamless profile-based access | No | Yes, for compatible devices |
| RADIUS integration | Optional depending on design | Required in current UniFi guidance |
| Best for first-time visitors | Usually | Only if they already have a profile |
| Best for multi-venue roaming | Limited by portal workflow | Strong fit |
| Marketing CTA after connection | Possible | Requires a separate experience |
Choose a captive portal when marketing matters
A captive portal is usually the better fit when the venue wants to make the WiFi interaction part of the customer journey.
Examples include:
- A café showing its menu or loyalty offer
- A hotel collecting guest details during access
- A gym promoting a membership trial
- A visitor attraction directing guests to an event guide
- A retailer presenting a promotion after sign-in
The key advantage is not simply collecting a field. It is having a controlled interaction before access and a defined next step afterward.
If collecting contact details for marketing, explain the purpose clearly and use an appropriate consent design. This article is technical guidance, not legal advice.
Choose Passpoint when frictionless connectivity matters most
Passpoint may be a better fit when the operator prioritizes:
- Automatic access for returning or subscribed users
- Roaming across participating venues
- Reduced dependence on browser-based captive-portal detection
- Identity-based authentication through a managed provider
- A consistent network-access experience rather than a marketing page
Passpoint does not automatically create a marketing audience. If the business needs a form, offer, survey, or branded post-login action, a separate customer interaction is required.
Can a venue use both?
Potentially, but treat them as separate SSIDs and separate user experiences. Do not expect one SSID to provide both Passpoint profile access and a captive-portal redirect.
A practical design might be:
- Passpoint SSID for subscribed or roaming users
- Captive-portal SSID for first-time visitors and marketing-led guest access
- Separate VLAN and policy decisions for each network
Test the experience on real devices before promising automatic connection behavior. Compatibility, installed profiles, RADIUS configuration, and venue coverage all matter.
Installer planning checklist
Before selecting the model, ask:
- Do guests need to see a branded page?
- Does the venue need contact capture or consent?
- Do users already have a Passpoint profile?
- Is roaming across multiple venues a core requirement?
- Is RADIUS available and supported operationally?
- Does the venue need a post-login destination?
- Will first-time visitors understand the connection flow?
- Are the portal and Passpoint SSIDs clearly documented?
- Have both iOS and Android workflows been tested?
- Are the networks segmented and monitored separately?
A hosted portal option
If the venue needs an external captive portal but does not want to build and maintain the integration, LiquidEdge is developing a hosted WiFi marketing workflow for businesses operating hosted UniFi controllers.
Need to evaluate the fit? Contact LiquidEdge for an availability check and UniFi deployment discussion.
Do not assume self-service account creation is currently available; confirm capability status before directing operators to signup.
Bottom line
Use captive portals for controlled guest interactions, branding, external authentication, and marketing workflows.
Use Passpoint for seamless, profile-based access where a captive-portal redirect is not required.
The right choice depends less on the AP model than on the guest journey the venue is trying to create.
