Visitor WiFi settings, field by field
Every field in a Visitor WiFi entry — the Basic page, the RADIUS settings, the OAuth Config values and the WiFi login page design — what each does and when to change it.
Each row on the Visitor WiFi page is one guest network. Opening one shows a dialog with up to three pages, listed on the left: Basic always, then either RADIUS settings (the Cisco, Unifi, TP-Link, Ruckus and Generic brands) or OAuth Config and WiFi login page (the Ruckus Cloudpath brand).
Open Visitor WiFiBasic
| Setting | What it does | When to change it |
|---|---|---|
| Name | Names the entry in the list. Visitors never see it | Name it after the network or site it serves, so the right row is obvious once you have several |
| Building | Which buildings this network serves. Empty means all buildings | Set it when different offices run different guest networks — the badge prints the one for the visit’s building |
| Visiting purpose | Which visiting purposes may use this network. Empty means all | Restrict it when only some kinds of visit should get WiFi at all |
| Brand | The controller vendor, picked from the Add menu and shown as the dialog’s banner. It decides how visitors sign in: every brand except Ruckus Cloudpath is a RADIUS (secured network) brand. It cannot be changed afterwards | Only at creation. To move a network to another brand, create a new entry |
| Username type | What the visitor signs in with: Visitor email address, Registration code, Mobile number, Last name or Reference code | Pick something every visitor reliably has. Last name can match several visitors at once — the password then decides which |
| Password type | What proves it is them: Badge WiFi password, Registration code, Mobile number or Not required | Badge WiFi password is the per-visit code minted at check-in — the safest default. Not required waves through anyone with a valid username |
| WiFi SSID | Ruckus Cloudpath only. The network name shown to the visitor — on the badge and the lobby board | Match it exactly to the SSID broadcast by your controller; Offision displays it but does not create it |
| WiFi password | Ruckus Cloudpath only. The network’s shared password, where the SSID is not open | Set it if the network itself needs a password to join before the login page appears |
The last two fields do not exist on RADIUS brands: a secured network has no shared password, and its name lives on your controller.
RADIUS settings
Everything on this page is generated by Offision for you to copy into your controller — nothing here is typed in except the UniFi MAC list.
| Setting | What it does | When to change it |
|---|---|---|
| Host IP or FQDN | The address of Offision’s RADIUS server, shown as a host name and an IP | Never changed — copy whichever form your controller accepts |
| Auth port | The UDP port the controller sends authentication to (1812) | Never changed — copy it |
| Secret | The shared secret between your controller and the RADIUS server. Shown masked, with show, copy and Regenerate | Regenerate it if it may have leaked — then update the controller immediately, or every sign-in fails |
| NAS identifier | The generated identifier that tells Offision which entry an incoming request belongs to. Regenerate issues a new one | Never changed in normal use. Configure it on the access points exactly as shown |
| MAC addresses | Unifi only, replacing the NAS identifier. Your access points’ MAC addresses, one or more, comma- or line-separated | Add every access point that serves the guest network — a request from an unlisted one cannot be matched |
The Cisco brand shows the same values arranged as a step-by-step Meraki guide.
OAuth Config
Ruckus Cloudpath only. The values to copy into the controller’s Custom OAuth 2.0 form, each with a copy button: Name (suggested), Consumer key (Client ID), Consumer secret (Client Secret), Access token endpoint URL, Authorize URL, Data URL and Scope.
| Setting | What it does | When to change it |
|---|---|---|
| Consumer secret (Client Secret) | Proves the controller to Offision. The full secret is only shown at creation or after regeneration | Regenerate if lost or leaked, then paste the new value into the controller |
| OAuth redirect URL | The callback URLs from your controller that Offision will allow during sign-in. Add one per line; each is removable | Add the redirect URL your controller’s portal documentation gives you — sign-in fails without it |
WiFi login page
Ruckus Cloudpath only. What the visitor sees in their browser. All text fields can be entered per language.
| Setting | What it does | When to change it |
|---|---|---|
| Logo | Shown at the top of the login page. 256 × 256 recommended | Set it so the page is recognisably yours — visitors hesitate at an unbranded sign-in page |
| Page title | The heading on the page | Default is fine; change it to name the network or the site |
| Welcome message | A short line under the title | Use it for the one instruction visitors need — where the code is on their badge |
| Footer text | A line at the bottom of the page | Terms of use, or a front-desk contact |
| Background Image | Fills the page behind the sign-in card. 1920 × 1080 recommended | Optional branding |
What this does not control
- The badge layout — whether a badge prints WiFi details at all is the badge design, on Visitor label design. See Print the WiFi code on the badge.
- When the code is valid — always check-in to check-out. There is no setting that extends a visitor’s access beyond their visit.
- The signage Wi-Fi QR widget — its network details are typed into the widget, not read from here.

