UniFi Cloud Key captive portal setup
There are two kinds of Cloud Key as far as the integration is concerned. Gen2 and later run UniFi OS and behave like a UDM. The first generation runs the older controller on port 8443 with a different login. The hotspot settings are the same on both.
www.voqadowifi.com, and allow www.voqadowifi.com and voqadowifi.com before authorization. Forward or tunnel HTTPS to the Cloud Key: port 443 for Gen2 and later, 8443 for a first generation unit. Save it in the dashboard with a local admin.At a glance
- Gen2, Gen2 Plus and later
- UniFi OS, port 443,
/api/auth/login,/proxy/network - First generation
- Older controller, port 8443,
/api/login, no prefix - Console Type in the dashboard
- Auto-detect tells them apart
- Sits behind your router
- Yes, so it needs a forwarded port or a tunnel
Checked against the VoqadoWiFi integration code on 7 October 2026. Controller menu labels move between firmware releases; the setting names above are the ones the setup wizard prints.
Step by step
- Check which Cloud Key you haveIf you reach it at an address with no port and see the UniFi OS console, it is Gen2 or later. If the controller opens on
:8443, it is the first generation. - Enable the hotspot portal on the guest SSIDIn the Network application go to Settings, WiFi, edit the guest SSID, and turn on the hotspot or guest portal. On older releases the hotspot settings sit under Guest Control.
- Point the external portal server at VoqadoWiFiIn the hotspot settings choose External Portal Server and enter the host
www.voqadowifi.com. UniFi always sends guests to the fixed path/guest/s/<site>/on that host, which is how VoqadoWiFi knows which venue they are at. If your Network version asks for an IP address, switch on Redirect using hostname and enter the host there instead. - Add the pre-authorization entries and leave HTTPS redirection offAdd
www.voqadowifi.comandvoqadowifi.comto Pre-Authorization Access. If your version shows an HTTPS Redirection toggle, leave it off: intercepting HTTPS is what produces certificate warnings on guest phones. - Create a local admin for the integrationUnder Admins and Users add an account restricted to local access, with access to the Network application and no two factor prompt. A ui.com cloud account cannot log in to the controller API, and a two factor challenge fails every automated login.
- Forward or tunnel HTTPS to the Cloud KeyThe Cloud Key is not your router, so forward the right port on the router to the Cloud Key’s LAN address, or run an outbound tunnel to it. Use 443 for UniFi OS models and 8443 for the first generation.
- Save it in the dashboardEnter the address, including
:8443for a first generation unit, the local admin, and leave Console Type on Auto-detect. Use Test Connection to pick the site id.
What breaks on this controller
Forwarding 443 to a first generation Cloud Key
The older controller answers on 8443. An address without the port reaches nothing, and Test Connection times out. Include :8443 in the dashboard address.
Auto-detect sees something in front of the Cloud Key
Detection reads the response at the root of the address: 200 means UniFi OS, a redirect to /manage means the older controller. If a proxy in front answers differently, set Console Type explicitly to UniFi OS or Legacy.
Several sites on one Cloud Key
Only the first site is called default; later sites get a generated id such as m8en8ejk. Each venue needs its own id in the dashboard, picked from the Test Connection list.
Questions
Which login does the integration use on each model?
My Cloud Key uses a self signed certificate. Is that a problem?
Should I replace a first generation Cloud Key?
Deeper reading
Longer articles from the blog that cover this controller. Where an article and this page disagree, this page is the one checked against the current integration.
- UniFi external captive portal guide. The redirect flow step by step.
- Exposing a UniFi controller with Cloudflare Tunnel
Keep reading
Sources: lib/unifi/api.ts (detectConsoleType, login) and docs/unifi-setup-guide.md, read on the date above. Ubiquiti and UniFi are trademarks of Ubiquiti Inc. VoqadoWiFi is not affiliated with or endorsed by either vendor.
Run your UniFi portal free
One location and 25 guest logins a month on the Starter plan, no card. The dashboard prints the finished portal URL for this controller.