Skip to content
Troubleshooting

Portal loads but the WiFi never unlocks

This is the most common failure in an external portal, and it is never the portal page. The page did its job. The step that failed is the call from VoqadoWiFi back to your controller asking it to let the device online.

Why does the guest WiFi stay locked after the login form?
The authorization call to your controller failed. Open Portal Health in the dashboard and read the error kind: network or timeout means the controller cannot be reached, auth means a rejected login or token, controller means the controller answered with an error, ssl means a certificate problem. Each has one fix below.

Causes, in the order to check them

1. network or timeout: the controller cannot be reachedOmada and UniFi

Cause

The controller address saved in the dashboard is a LAN address, the wrong port, or behind carrier grade NAT. Each attempt waits 8 seconds before it gives up.

Check

Open the controller address from a phone on mobile data, not on your venue network. If it does not load there, VoqadoWiFi cannot reach it either.

Fix

Give the controller a public HTTPS address: a tunnel, a forwarded port, or a controller on a VPS. On Omada OC200, OC300 and software controllers it must answer on port 443.

2. auth on Omada: the token was rejected and there is no fallbackOmada

Cause

The one time token expired (-1001), or the site or MAC did not match (-1003, -1005), and the location has no OpenAPI or operator credentials to try next. Portal Health shows “Token-based auth failed and no operator/API credentials configured”.

Check

Look for the Omada error code on the failed attempt in Portal Health.

Fix

For -1001, shorten the form. For -1003 and -1005, check the portal URL has no query string of its own and the Site ID is right. See Omada error codes.

3. auth on UniFi: the controller rejected the loginUniFi

Cause

The stored account is a ui.com cloud account, has two factor on, or the password changed. Portal Health shows “login rejected (HTTP 400, 401 or 403)”.

Check

Run Test Connection on the location. It reports the same rejection.

Fix

Create a local admin without two factor, save it on the location, and test again. More in UniFi 403.

4. controller: the controller answered with an errorUniFi

Cause

Most often api.err.NoSiteContext: the site saved in the dashboard does not exist on the controller, usually because the display name was used instead of the internal id.

Check

Run Test Connection and compare the site list with what is saved.

Fix

Click the venue’s site in the Test Connection list to fill the exact id, and save.

5. ssl: a certificate problem on the way to the controllerOmada

Cause

The Omada token call checks the controller’s certificate, and a factory self signed certificate fails it. UniFi calls accept self signed certificates by default.

Check

The failed attempt shows ssl, or auth right after a token attempt on a self hosted controller.

Fix

Put a trusted certificate in front of the controller, for example with a reverse proxy or a tunnel that terminates HTTPS.

6. Omada: a query string pasted into the portal URLOmada

Cause

Omada appends clientMac, apMac, ssidName, radioId and token. A second question mark mangles them, so the portal has nothing valid to authorize.

Check

Read the portal URL in the controller. It should end in your venue slug, with nothing after it.

Fix

Paste https://www.voqadowifi.com/portal/your-venue-slug exactly as the dashboard prints it.

Reference

Error kinds recorded in Portal Health
Error kindWhat it meansWhere to look
networkThe controller address could not be reachedAddress, port, tunnel
timeoutNo answer within 8 secondsReachability, carrier grade NAT
sslCertificate or TLS failureCertificate on the controller
authLogin or token rejected, or nothing configured to tryAccount, token, Controller ID
controllerThe controller answered with an errorSite id, Site ID, error code
unknownAnything elseThe error message on the attempt

Questions

What does the guest see when this happens?
A result screen saying their details were saved, with steps to turn WiFi off and on and open a browser. Their sign up is not lost, but they are not online until the controller authorizes them.
Where is Portal Health?
In the VoqadoWiFi dashboard sidebar. It lists each authorization attempt with success or failure, the method, the error kind and code, and the device type.
It works for me but not for guests. Why?
If you tested from a phone that already had a session, the controller never needed to authorize it. Test from a device that has never joined.

Keep reading

Omada error codesUniFi authorize returns 403Omada setup hubUniFi setup hubCaptive portal not showing on iPhoneGuests see a certificate warning before the WiFi loginAll troubleshooting guides

Error kinds and codes on this page are the ones the VoqadoWiFi integration records, checked against the code on 7 October 2026.

See every authorization attempt

Portal Health in the free dashboard shows each guest login with its error kind and code. One location and 25 guest logins a month, no card.

Free forever plan. No credit card and no sales call.