How it differs from a captive portal
A captive portal is an interruption by design: connect, wait, read, tap, then browse. Passpoint removes the interruption. The device queries nearby networks before associating, learns which identity providers they accept, matches that against credentials it already holds, and joins with enterprise-grade encryption automatically. The guest sees connected WiFi and nothing else. That is a materially better experience, and it is the reason large venues, transport hubs and carrier offload programmes have adopted it.
What a venue gives up
The trade-off is direct. No portal means no splash screen, no email capture, no consent moment, and no branded surface. Identity lives with the credential issuer, typically a carrier or a roaming federation, not with the venue. For a venue whose goal is a guest marketing list, Passpoint alone delivers none of it. For a venue whose goal is frictionless connectivity at scale, that is exactly the point. The two models answer different questions and are not really competitors.
Running both
The common pattern in larger venues is a Passpoint-enabled SSID for seamless roaming alongside a conventional portal SSID for guests without credentials. Returning guests get instant access, first-time guests go through the portal, and the venue still builds a list from the population that has no roaming credential. It requires more configuration and a certificate infrastructure, so it is generally worth it for airports, stadiums, hotel groups and large retail estates rather than a single independent venue.
See passpoint (hotspot 2.0) in a live portal
VoqadoWiFi runs branded guest portals on TP-Link Omada and Ubiquiti UniFi networks. The Starter plan is free forever: one location, 25 logins a month, consent logging included.
Passpoint (Hotspot 2.0) — common questions
Can I capture guest emails with Passpoint?
Not through Passpoint itself, because there is no portal step. Venues that need both typically run a Passpoint network alongside a portal-based guest network.
Is Passpoint more secure than an open guest network?
Yes. Passpoint connections use enterprise-grade encryption and mutual authentication, which is considerably stronger than a traditional open network.
Related terms
Passpoint (Hotspot 2.0) rarely comes up on its own. These are the entries operators usually read next.
Captive Portal
A captive portal is the web page a network forces a device to load before it grants internet access. The network intercepts the fi…
CAPPORT
CAPPORT is an IETF standard that lets a network tell a device, in a structured way, that it is behind a captive portal, where the…
RADIUS
RADIUS, or Remote Authentication Dial-In User Service, is a standard protocol that lets network equipment ask a central server whe…
SSID
SSID stands for Service Set Identifier: the human-readable name of a wireless network, up to 32 characters, that devices display i…
More in Networking