MikroTik HotSpot with an external login server
RouterOS has a full captive portal built in, called HotSpot, and its login page can hand guests to a server you run. This guide explains how, from MikroTik’s own documentation.
Not supported by VoqadoWiFi. Written from MikroTik documentation read on 7 October 2026.
What RouterOS HotSpot is and who runs it
MikroTik makes routers and access points that run RouterOS, and HotSpot is the RouterOS captive portal, configured on the router itself. MikroTik also offers Cloud Hosted Router (CHR), RouterOS in a virtual machine, whose free licence runs indefinitely and is limited to 1 Mbps upload per interface, which makes it useful for testing a HotSpot setup before touching a live site.
How an external login server works with HotSpot
MikroTik’s customisation page has a worked example of making HotSpot authenticate on a remote server. You modify the HotSpot login page so it redirects the guest to the external server, posting details such as the MAC address, IP address, username, the login link, the original destination and any error message. The external server must be reachable before login, so MikroTik says to allow direct access to it in the walled garden.
To log the guest in, the external server redirects the browser back to the original HotSpot login page with the correct username and password. In MikroTik’s example HotSpot then asks a RADIUS server whether to allow the login, showing a success page if it does and sending the guest back to the external server if it does not.
RouterOS also has a command for logging in an active client from the router side, /ip hotspot active login, which takes the client IP, MAC address, user and password. Using it from outside means reaching the router over the network, which most venues do not allow.
One setting matters for a shared venue account: a user profile’s shared-users value defaults to unlimited. Whether a single account for every guest is a good idea is a design choice, not something MikroTik recommends.
Guest WiFi you can run on MikroTik RouterOS Hotspot today
| Option | What it does | Source |
|---|---|---|
| http-chap and http-pap | Username and password on the HotSpot login page; CHAP uses an MD5 challenge, PAP sends the password in plain text. | Vendor docs |
| https | Username and password, with the exchange encrypted. | Vendor docs |
| trial | Internet without a HotSpot login for a set amount of time. | Vendor docs |
| mac | The device is authenticated by MAC address without a login form. | Vendor docs |
| cookie and mac-cookie | Returning devices are recognised; both lifetimes default to 3 days. | Vendor docs |
| Walled garden | Resources reachable before login, such as provider information. | Vendor docs |
Trial login is the closest RouterOS gets to a click-through page on its own. If you only need guests to accept terms, a customised HotSpot login page with trial access may be all you need.
HTTPS and the captive portal notice on phones
MikroTik notes that RouterOS only advertises the captive portal to devices through DHCP (RFC 7710) when the router has both a DNS name and a valid SSL certificate. Without them, phones fall back to detecting the portal on their own.
Plan the router’s DNS name and certificate before the HotSpot goes live, so phones get the notice from the start.
VoqadoWiFi and MikroTik RouterOS Hotspot: the honest status
VoqadoWiFi does not support MikroTik RouterOS Hotspot today. VoqadoWiFi works with two controller platforms: TP-Link Omada and Ubiquiti UniFi. On those, the controller sends each new guest to the VoqadoWiFi login page as an external captive portal, and VoqadoWiFi asks the controller to open the network once the guest signs in.
This page describes what MikroTik documents, so you can decide what to do with the hardware you have. It is not a setup guide for VoqadoWiFi, and nothing on it means VoqadoWiFi works with MikroTik RouterOS Hotspot.
| Question | Answer |
|---|---|
| VoqadoWiFi status | Not supported by VoqadoWiFi yet |
| What the vendor calls the external portal | HotSpot, customised login.html |
| How access is granted, as documented | Form post from the guest browser. After the guest signs in, the guest browser posts a small form back to the access point or router, which then opens the network. |
Because the venue installs the login page, the hand off is fully under the integrator’s control, and CHR allows end to end testing in a virtual machine. VoqadoWiFi would still need to build and test that flow, including the account the router checks. It has not shipped, and there is no date.
If you are choosing hardware now, the TP-Link Omada setup guide and the Ubiquiti UniFi setup guide show exactly what VoqadoWiFi needs. If you are keeping your current hardware, its own options above work today without us.
MikroTik RouterOS Hotspot questions
Can MikroTik HotSpot use an external login page?
What login methods does HotSpot support?
How long do HotSpot cookies last?
http-cookie-lifetime and mac-cookie-timeout.Can I test a HotSpot without hardware?
Does VoqadoWiFi work with MikroTik?
Sources
Every MikroTik fact on this page comes from these official pages, read on 7 October 2026. Menus and features change between releases, so check them against your own version.
Keep reading
MikroTik and RouterOS are trademarks of Mikrotikls SIA. VoqadoWiFi is not affiliated with, endorsed by, or sponsored by MikroTik.