← All docs
Captive Portal

UniFi controller reference (advanced)

Running your own UniFi controller? Point its guest hotspot at the HeidiFi captive portal — network, external portal server, and walled-garden settings.

Last updated August 13, 2026

This guide is for venues that run their own UniFi Network controller and want its guest WiFi to use the HeidiFi captive portal.

Note

Most venues don't need this page. If you bought a UniFi access point for HeidiFi, follow Setting up your UniFi access point instead — HeidiFi runs the controller for you and there's nothing below to configure.

You'll need administrator access to your controller (UniFi Network 7 or newer) and about 15 minutes.

1. Adopt your access point

If the access point is new to your controller, adopt it as usual: it appears under Devices as Pending Adoption once powered on — click Adopt.

You can also pre-register its MAC address so it's easier to spot: go to Network → Clients, click Add Client, paste the MAC address, and give it a recognizable name.

The Add Client dialog in the UniFi Network application, with fields for MAC address and device alias

2. Create the guest WiFi network

Go to Settings → WiFi → Create New:

The Settings → WiFi screen in the UniFi Network application showing the WiFi list and Create New action
  • Name — the SSID your guests will see.
  • NetworkNative Network.
  • Broadcasting APsAll, or scope it to specific access points.
  • ApplicationHotspot.
  • Hotspot TypeCaptive Portal.
The WiFi edit panel with Application set to Hotspot and Hotspot Type set to Captive Portal

Save the network — the controller confirms a Hotspot Portal has been applied to it.

3. Point the hotspot at HeidiFi

Open the hotspot you just created (usually under Clients → Hotspot, or the Hotspot Portal link in the WiFi settings). Under One Way Methods, enable External Portal Server, click Edit, and set the portal address:

External portal server

p.heidifi.ai

Then check all three of:

  • HTTPS Redirection Support
  • Encrypted URL
  • Domain — and paste p.heidifi.ai as the domain
Warning

Without HTTPS Redirection Support, guests on modern phones only get the native "Sign in to network" prompt instead of the HeidiFi splash screen.

4. Set the walled garden

Still in the hotspot editor, scroll to Authorization Access. Guests must be able to reach these before signing in — add each to Pre-Authorization Allowances:

p.heidifi.ai
api.heidifi.ai
askheidi.b-cdn.net

Also add your controller's own IP or hostname, so the access point can reach it during the sign-in flow.

Warning

askheidi.b-cdn.net serves your logo and splash images. Leave it out and the splash page still opens — but with every image broken.

To keep guests off your internal network after they sign in, add the private ranges to Post-Authorization Restrictions:

192.168.0.0/16
172.16.0.0/12
10.0.0.0/8

5. Verify

  1. Connect a phone to the new SSID.
  2. The HeidiFi splash page should open automatically.
  3. Complete the sign-in form.
  4. You should have internet access.

If you only see a native "Sign in to network" prompt, recheck HTTPS Redirection Support in step 3 and the pre-authorization allowances in step 4.

Register your controller with HeidiFi

For HeidiFi to authorize guests and show your access points' status, your controller needs to be linked to your HeidiFi account. This part is done together with our team — contact us with your venue name and we'll complete the connection with you.

Ready to get started?

Start your 14-day free trial — add a card, cancel any time before it ends and you will not be charged.

Start 14-Day Free Trial