Skip to content
Ubiquiti UniFi, Cloud Key

UniFi Cloud Key captive portal setup

There are two kinds of Cloud Key as far as the integration is concerned. Gen2 and later run UniFi OS and behave like a UDM. The first generation runs the older controller on port 8443 with a different login. The hotspot settings are the same on both.

How do I set up an external portal on a UniFi Cloud Key?
In the Network application on the Cloud Key, enable the hotspot portal on the guest SSID, choose External Portal Server with www.voqadowifi.com, and allow www.voqadowifi.com and voqadowifi.com before authorization. Forward or tunnel HTTPS to the Cloud Key: port 443 for Gen2 and later, 8443 for a first generation unit. Save it in the dashboard with a local admin.

At a glance

Gen2, Gen2 Plus and later
UniFi OS, port 443, /api/auth/login, /proxy/network
First generation
Older controller, port 8443, /api/login, no prefix
Console Type in the dashboard
Auto-detect tells them apart
Sits behind your router
Yes, so it needs a forwarded port or a tunnel

Checked against the VoqadoWiFi integration code on 7 October 2026. Controller menu labels move between firmware releases; the setting names above are the ones the setup wizard prints.

Step by step

  1. Check which Cloud Key you have
    If you reach it at an address with no port and see the UniFi OS console, it is Gen2 or later. If the controller opens on :8443, it is the first generation.
  2. Enable the hotspot portal on the guest SSID
    In the Network application go to Settings, WiFi, edit the guest SSID, and turn on the hotspot or guest portal. On older releases the hotspot settings sit under Guest Control.
  3. Point the external portal server at VoqadoWiFi
    In the hotspot settings choose External Portal Server and enter the host www.voqadowifi.com. UniFi always sends guests to the fixed path /guest/s/<site>/ on that host, which is how VoqadoWiFi knows which venue they are at. If your Network version asks for an IP address, switch on Redirect using hostname and enter the host there instead.
  4. Add the pre-authorization entries and leave HTTPS redirection off
    Add www.voqadowifi.com and voqadowifi.com to Pre-Authorization Access. If your version shows an HTTPS Redirection toggle, leave it off: intercepting HTTPS is what produces certificate warnings on guest phones.
  5. Create a local admin for the integration
    Under Admins and Users add an account restricted to local access, with access to the Network application and no two factor prompt. A ui.com cloud account cannot log in to the controller API, and a two factor challenge fails every automated login.
  6. Forward or tunnel HTTPS to the Cloud Key
    The Cloud Key is not your router, so forward the right port on the router to the Cloud Key’s LAN address, or run an outbound tunnel to it. Use 443 for UniFi OS models and 8443 for the first generation.
  7. Save it in the dashboard
    Enter the address, including :8443 for a first generation unit, the local admin, and leave Console Type on Auto-detect. Use Test Connection to pick the site id.

What breaks on this controller

Forwarding 443 to a first generation Cloud Key

The older controller answers on 8443. An address without the port reaches nothing, and Test Connection times out. Include :8443 in the dashboard address.

Auto-detect sees something in front of the Cloud Key

Detection reads the response at the root of the address: 200 means UniFi OS, a redirect to /manage means the older controller. If a proxy in front answers differently, set Console Type explicitly to UniFi OS or Legacy.

Several sites on one Cloud Key

Only the first site is called default; later sites get a generated id such as m8en8ejk. Each venue needs its own id in the dashboard, picked from the Test Connection list.

Questions

Which login does the integration use on each model?
UniFi OS models: /api/auth/login, with the CSRF token from the header or the TOKEN cookie. The first generation: /api/login, with the csrf_token cookie.
My Cloud Key uses a self signed certificate. Is that a problem?
Not for the UniFi integration. It accepts the factory self signed certificate unless strict certificate checking has been switched on for the platform.
Should I replace a first generation Cloud Key?
It works with the integration. Whether to replace it is a question of Ubiquiti’s support for that hardware, not of the portal.

Deeper reading

Longer articles from the blog that cover this controller. Where an article and this page disagree, this page is the one checked against the current integration.

Keep reading

UniFi setup hubSelf hosted UniFi Network ServerUniFi authorize returns 403Walled garden domains

Sources: lib/unifi/api.ts (detectConsoleType, login) and docs/unifi-setup-guide.md, read on the date above. Ubiquiti and UniFi are trademarks of Ubiquiti Inc. VoqadoWiFi is not affiliated with or endorsed by either vendor.

Run your UniFi portal free

One location and 25 guest logins a month on the Starter plan, no card. The dashboard prints the finished portal URL for this controller.

Free forever plan. No credit card and no sales call.