Juniper Mist external guest portal, explained
Mist lets a guest WLAN send guests to a portal you host, and documents a signed redirect to authorize them, with a test endpoint for checking the signature. Here is how it fits together.
Not supported by VoqadoWiFi. Written from Juniper Networks (HPE) documentation read on 7 October 2026.
What Mist is and who runs it
Juniper Mist is Juniper’s wireless platform. Guest access is configured per WLAN, and a guest WLAN can use the portal Mist hosts, with the authorization options below, or an external portal you host.
How the external portal authorizes a guest
You set up an external portal by entering the Portal URL, starting with http:// or https://. Extra fields let you allow only certain subnets or hostnames before the guest is authorized.
When the guest has finished on your portal, the portal sends their browser to Mist’s /authorize endpoint with three values. The token is a base64 string of wlan_id/ap_mac/client_mac/authorize_min/0/0/0, so it names the WLAN, the access point, the guest device and how many minutes to allow. The signature is a base64 SHA1 hash of the request using the guest WLAN’s API secret as the key. expires is an epoch timestamp after which the authorization link stops working.
You can add guest details to the authorization in a set format: forward, name, email, company and field1 to field4, each base64 encoded. Mist also provides /authorize-test, which accepts dummy example values, so a portal can check its signing code before any access point is involved.
Guest WiFi you can run on Juniper Mist today
| Option | What it does | Source |
|---|---|---|
| Passphrase | Guests enter a passphrase you define. | Vendor docs |
| Authentication code via email | Guests enter an email address and receive a code to finish signing in. | Vendor docs |
| Authentication code via text message | Guests enter a phone number and receive a code. | Vendor docs |
| Sponsored guest access | A sponsor approves guests before they can use the network. | Vendor docs |
| Social sign in | Guests connect with Google, Facebook, Amazon or Microsoft Azure. | Vendor docs |
| External portal | Guests are sent to a portal you host, which authorizes them with a signed redirect. | Vendor docs |
For each option you choose how long devices stay authorized, for example 60 minutes, 2 hours or 2 days. The email code option already collects an address; whether you can use it for marketing depends on how you word the portal and your local law.
What to get right on an external Mist portal
Keep the WLAN API secret on the portal server only. It is the key that makes a signature valid, so a page that exposes it lets anyone authorize themselves.
Set authorize_min in the token to the length of access you mean to give, and use the expires timestamp to stop old authorization links from being reused.
VoqadoWiFi and Juniper Mist: the honest status
VoqadoWiFi does not support Juniper Mist today. VoqadoWiFi works with two controller platforms: TP-Link Omada and Ubiquiti UniFi. On those, the controller sends each new guest to the VoqadoWiFi login page as an external captive portal, and VoqadoWiFi asks the controller to open the network once the guest signs in.
This page describes what Juniper Networks (HPE) documents, so you can decide what to do with the hardware you have. It is not a setup guide for VoqadoWiFi, and nothing on it means VoqadoWiFi works with Juniper Mist.
| Question | Answer |
|---|---|
| VoqadoWiFi status | Not supported by VoqadoWiFi yet |
| What the vendor calls the external portal | Guest portal, external portal |
| How access is granted, as documented | Redirect grant. After the guest signs in, the portal sends the browser to a grant address the vendor provides, and the access point opens the network. |
The signed redirect is documented and the test endpoint lets the signing be checked without hardware, but end to end testing still needs a Mist access point and subscription. VoqadoWiFi has not built it, and there is no date.
If you are choosing hardware now, the TP-Link Omada setup guide and the Ubiquiti UniFi setup guide show exactly what VoqadoWiFi needs. If you are keeping your current hardware, its own options above work today without us.
Juniper Mist questions
How does a Mist external portal authorize a guest?
/authorize endpoint with a base64 token (wlan_id/ap_mac/client_mac/authorize_min/0/0/0), a SHA1 signature keyed with the WLAN API secret, and an expires timestamp.Can I test the signature without an access point?
/authorize-test, which accepts dummy example values.What can the built in Mist portal do?
Does VoqadoWiFi work with Mist?
Sources
Every Juniper Networks (HPE) fact on this page comes from these official pages, read on 7 October 2026. Menus and features change between releases, so check them against your own version.
Keep reading
Juniper and Mist are trademarks of Juniper Networks, a Hewlett Packard Enterprise company. VoqadoWiFi is not affiliated with, endorsed by, or sponsored by Juniper or HPE.