Visitor WiFi settings, field by field

Every field in a Visitor WiFi entry — the Basic page, the RADIUS settings, the OAuth Config values and the WiFi login page design — what each does and when to change it.

Updated 20 Aug 2026

Each row on the Visitor WiFi page is one guest network. Opening one shows a dialog with up to three pages, listed on the left: Basic always, then either RADIUS settings (the Cisco, Unifi, TP-Link, Ruckus and Generic brands) or OAuth Config and WiFi login page (the Ruckus Cloudpath brand).

Open Visitor WiFi

Basic

SettingWhat it doesWhen to change it
NameNames the entry in the list. Visitors never see itName it after the network or site it serves, so the right row is obvious once you have several
BuildingWhich buildings this network serves. Empty means all buildingsSet it when different offices run different guest networks — the badge prints the one for the visit’s building
Visiting purposeWhich visiting purposes may use this network. Empty means allRestrict it when only some kinds of visit should get WiFi at all
BrandThe controller vendor, picked from the Add menu and shown as the dialog’s banner. It decides how visitors sign in: every brand except Ruckus Cloudpath is a RADIUS (secured network) brand. It cannot be changed afterwardsOnly at creation. To move a network to another brand, create a new entry
Username typeWhat the visitor signs in with: Visitor email address, Registration code, Mobile number, Last name or Reference codePick something every visitor reliably has. Last name can match several visitors at once — the password then decides which
Password typeWhat proves it is them: Badge WiFi password, Registration code, Mobile number or Not requiredBadge WiFi password is the per-visit code minted at check-in — the safest default. Not required waves through anyone with a valid username
WiFi SSIDRuckus Cloudpath only. The network name shown to the visitor — on the badge and the lobby boardMatch it exactly to the SSID broadcast by your controller; Offision displays it but does not create it
WiFi passwordRuckus Cloudpath only. The network’s shared password, where the SSID is not openSet it if the network itself needs a password to join before the login page appears

The last two fields do not exist on RADIUS brands: a secured network has no shared password, and its name lives on your controller.

RADIUS settings

Everything on this page is generated by Offision for you to copy into your controller — nothing here is typed in except the UniFi MAC list.

SettingWhat it doesWhen to change it
Host IP or FQDNThe address of Offision’s RADIUS server, shown as a host name and an IPNever changed — copy whichever form your controller accepts
Auth portThe UDP port the controller sends authentication to (1812)Never changed — copy it
SecretThe shared secret between your controller and the RADIUS server. Shown masked, with show, copy and RegenerateRegenerate it if it may have leaked — then update the controller immediately, or every sign-in fails
NAS identifierThe generated identifier that tells Offision which entry an incoming request belongs to. Regenerate issues a new oneNever changed in normal use. Configure it on the access points exactly as shown
MAC addressesUnifi only, replacing the NAS identifier. Your access points’ MAC addresses, one or more, comma- or line-separatedAdd every access point that serves the guest network — a request from an unlisted one cannot be matched

The Cisco brand shows the same values arranged as a step-by-step Meraki guide.

OAuth Config

Ruckus Cloudpath only. The values to copy into the controller’s Custom OAuth 2.0 form, each with a copy button: Name (suggested), Consumer key (Client ID), Consumer secret (Client Secret), Access token endpoint URL, Authorize URL, Data URL and Scope.

SettingWhat it doesWhen to change it
Consumer secret (Client Secret)Proves the controller to Offision. The full secret is only shown at creation or after regenerationRegenerate if lost or leaked, then paste the new value into the controller
OAuth redirect URLThe callback URLs from your controller that Offision will allow during sign-in. Add one per line; each is removableAdd the redirect URL your controller’s portal documentation gives you — sign-in fails without it

WiFi login page

Ruckus Cloudpath only. What the visitor sees in their browser. All text fields can be entered per language.

SettingWhat it doesWhen to change it
LogoShown at the top of the login page. 256 × 256 recommendedSet it so the page is recognisably yours — visitors hesitate at an unbranded sign-in page
Page titleThe heading on the pageDefault is fine; change it to name the network or the site
Welcome messageA short line under the titleUse it for the one instruction visitors need — where the code is on their badge
Footer textA line at the bottom of the pageTerms of use, or a front-desk contact
Background ImageFills the page behind the sign-in card. 1920 × 1080 recommendedOptional branding

What this does not control

  • The badge layout — whether a badge prints WiFi details at all is the badge design, on Visitor label design. See Print the WiFi code on the badge.
  • When the code is valid — always check-in to check-out. There is no setting that extends a visitor’s access beyond their visit.
  • The signage Wi-Fi QR widget — its network details are typed into the widget, not read from here.