Skip to content
Hardware guide: Juniper Mist

Juniper Mist external guest portal, explained

Mist lets a guest WLAN send guests to a portal you host, and documents a signed redirect to authorize them, with a test endpoint for checking the signature. Here is how it fits together.

Not supported by VoqadoWiFi. Written from Juniper Networks (HPE) documentation read on 7 October 2026.

Does VoqadoWiFi work with Juniper Mist?
No. VoqadoWiFi does not support Juniper Mist today. Mist’s own guest portal can authorize guests by passphrase, an emailed or texted code, sponsor approval, or social sign in. A guest WLAN can also use an external portal, which authorizes guests with a signed redirect built from a token and the WLAN’s API secret.

What Mist is and who runs it

Juniper Mist is Juniper’s wireless platform. Guest access is configured per WLAN, and a guest WLAN can use the portal Mist hosts, with the authorization options below, or an external portal you host.

How the external portal authorizes a guest

You set up an external portal by entering the Portal URL, starting with http:// or https://. Extra fields let you allow only certain subnets or hostnames before the guest is authorized.

When the guest has finished on your portal, the portal sends their browser to Mist’s /authorize endpoint with three values. The token is a base64 string of wlan_id/ap_mac/client_mac/authorize_min/0/0/0, so it names the WLAN, the access point, the guest device and how many minutes to allow. The signature is a base64 SHA1 hash of the request using the guest WLAN’s API secret as the key. expires is an epoch timestamp after which the authorization link stops working.

You can add guest details to the authorization in a set format: forward, name, email, company and field1 to field4, each base64 encoded. Mist also provides /authorize-test, which accepts dummy example values, so a portal can check its signing code before any access point is involved.

Guest WiFi you can run on Juniper Mist today

Guest access options Juniper Networks (HPE) documents
OptionWhat it doesSource
PassphraseGuests enter a passphrase you define.Vendor docs
Authentication code via emailGuests enter an email address and receive a code to finish signing in.Vendor docs
Authentication code via text messageGuests enter a phone number and receive a code.Vendor docs
Sponsored guest accessA sponsor approves guests before they can use the network.Vendor docs
Social sign inGuests connect with Google, Facebook, Amazon or Microsoft Azure.Vendor docs
External portalGuests are sent to a portal you host, which authorizes them with a signed redirect.Vendor docs

For each option you choose how long devices stay authorized, for example 60 minutes, 2 hours or 2 days. The email code option already collects an address; whether you can use it for marketing depends on how you word the portal and your local law.

What to get right on an external Mist portal

Keep the WLAN API secret on the portal server only. It is the key that makes a signature valid, so a page that exposes it lets anyone authorize themselves.

Set authorize_min in the token to the length of access you mean to give, and use the expires timestamp to stop old authorization links from being reused.

VoqadoWiFi and Juniper Mist: the honest status

VoqadoWiFi does not support Juniper Mist today. VoqadoWiFi works with two controller platforms: TP-Link Omada and Ubiquiti UniFi. On those, the controller sends each new guest to the VoqadoWiFi login page as an external captive portal, and VoqadoWiFi asks the controller to open the network once the guest signs in.

This page describes what Juniper Networks (HPE) documents, so you can decide what to do with the hardware you have. It is not a setup guide for VoqadoWiFi, and nothing on it means VoqadoWiFi works with Juniper Mist.

Juniper Mist at a glance
QuestionAnswer
VoqadoWiFi statusNot supported by VoqadoWiFi yet
What the vendor calls the external portalGuest portal, external portal
How access is granted, as documentedRedirect grant. After the guest signs in, the portal sends the browser to a grant address the vendor provides, and the access point opens the network.

The signed redirect is documented and the test endpoint lets the signing be checked without hardware, but end to end testing still needs a Mist access point and subscription. VoqadoWiFi has not built it, and there is no date.

If you are choosing hardware now, the TP-Link Omada setup guide and the Ubiquiti UniFi setup guide show exactly what VoqadoWiFi needs. If you are keeping your current hardware, its own options above work today without us.

Juniper Mist questions

How does a Mist external portal authorize a guest?
It sends the guest’s browser to Mist’s /authorize endpoint with a base64 token (wlan_id/ap_mac/client_mac/authorize_min/0/0/0), a SHA1 signature keyed with the WLAN API secret, and an expires timestamp.
Can I test the signature without an access point?
Yes. Mist documents /authorize-test, which accepts dummy example values.
What can the built in Mist portal do?
Passphrase, an authentication code by email or text message, sponsored guest access, and social sign in with Google, Facebook, Amazon or Microsoft Azure.
Does VoqadoWiFi work with Mist?
Not today. VoqadoWiFi supports TP-Link Omada and Ubiquiti UniFi. Leave your email below to hear if that changes.

Sources

Every Juniper Networks (HPE) fact on this page comes from these official pages, read on 7 October 2026. Menus and features change between releases, so check them against your own version.

Keep reading

Which access points support an external captive portalCheck your hardwareTP-Link Omada captive portal setupOne of the two platforms VoqadoWiFi supports today.Ubiquiti UniFi captive portal setupThe other supported platform, controller by controller.

Juniper and Mist are trademarks of Juniper Networks, a Hewlett Packard Enterprise company. VoqadoWiFi is not affiliated with, endorsed by, or sponsored by Juniper or HPE.

Notify me when Juniper Mist is supported

VoqadoWiFi does not support Juniper Mist today and we cannot promise a date. Leave your email and we will tell you if that changes. No account is created.