Tenant dashboard

ISN Free WiFi Client

Manage branding, preview the captive portal, and track whether the router and DNS side of the deployment is ready.

Live Preview Subdomain

What's new

At a glance

Setup in progressPortal state
No custom domain yetDomain
–Active now
–This month's peak / limit
–Estimated monthly cost
–SMS credits
–Routers online
–Vouchers redeemed (7d)
–Ad views (7d)

Guest traffic — last 7 days

Peak concurrent devices — last 7 days

Router fleet

RouterLocationStatusDevicesLast seen
Loading…
Portal preview

What your end users will see

The real thing — this loads your actual captive portal with your real logo, colors, and brand name. Save a branding change and it refreshes automatically.

Portal preview live Open in new tab
Clients

My clients

Every branded location you run — your own domain, routers, and vouchers per client — all reachable from this one login. Useful if you're operating on behalf of more than one business or site.

–Clients
–Routers online
–Published portals
–Revenue (30d, all clients)
–Alerts
ClientDomainStatusRoutersRevenue (30d)AlertsPublished
Loading…
Branding

Update the tenant presentation

This uses the same onboarding API so brand changes can be re-saved later.

Home page hero
The headline, subtitle, and photo guests see first on your home page — the screen right after they unlock or check their usage.
View router check
Setup status

What still needs attention

Loadingwaiting

Tenant data will appear after the API responds.

Messaging

SMS credits

Every OTP sent to your end users (password reset, registration, birthday offers) uses 1 credit. R100 = 200 credits (R0.50/credit, excl. VAT).

–Credits remaining
Messaging

Buy SMS credits

Type either a Rand amount or a number of credits — the other side is calculated automatically. Minimum purchase: 200 credits / R100.

Messaging

Credit history

Purchases, refunds, and debits against your SMS credit balance.

DateChangeBalance afterReason
Loading…
Messaging

Sent messages

Every SMS sent using your own credits — password resets, registration codes, and birthday offers to your end users. A message over 160 characters (or 70 if it uses accented characters, emoji, or a non-Latin script) sends as more than one real SMS segment and is charged accordingly — the Credits column shows exactly how many were charged for each one.

A send starts as "Unconfirmed" and updates to "Delivered" (or "Failed", with a reason) once our SMS provider reports back what actually happened to it — this can take anywhere from a few seconds to a few minutes, so a very recent send may still show "Unconfirmed" briefly even though it will end up delivered. "Failed" here specifically means the message never left our system in the first place (insufficient credits, provider error) — any credit already debited for it is refunded automatically; that's a different, earlier failure than a message that sent but couldn't reach the handset.

DateToReasonCreditsStatus
Loading…
Messaging

Usage & history

Your SMS and email sending against the shared daily fair-use limits (see SMS balance and Email settings above for how those limits work, and how to raise or remove them). This is informational — nothing here is a per-message list; see Sent messages above for that.

Today

–SMS sent today
–Email sent today
–SMS — last 7 days
–Email — last 7 days

SMS sent per day — last 30 days

Email sent per day — last 30 days

Messaging

Email settings

Connect your own sender(s) so invites, password resets, and ad campaign notifications sent to your businesses come from you — not a shared platform address. You can connect both below — if you do, a send tries Resend first, then your SMTP sender, then falls back to the default ISN Free WiFi address only if both are unavailable. For your security, once saved a password or API key can never be viewed again here — only replaced (paste a new one) or removed.

Your own email (SMTP)

Defaults work for most Gmail/Google Workspace accounts (you'll need an "app password", not your normal login password). Using a different provider? Open Advanced and enter their mail server details instead.

Loadingwaiting

Checking…

Resend API key

The from address must be on a domain you've already verified in your Resend account, or sending will fail. For your security, create a "Sending access only" API key in Resend rather than a full-access one — this platform only ever needs to send email, never to read your domains, logs, or account settings, so a restricted key limits what could be done with it if it were ever compromised. Saving runs a real test send to your own account email to confirm the key and sender actually work together.

Loadingwaiting

Checking…

Applied the next time you save either sender above.

Billing & plan

Subscription

ISN Free WiFi's own subscription for this captive — a 14-day free trial (one per account, card-verified), then billed monthly at your plan's rate. Everything below is grouped by what it covers, so you can see at a glance what's live, what needs attention, and where to change it.

–Status
–Trial / billing date
–Card on file

Suspending takes your captive's guest-facing URL offline right away without canceling your subscription — republish any time before your next billing date at no extra cost. See "Unpublishing / suspending" in the payment terms for the full rule.

DateTypeAmountStatus
No charges yet.

Plan & pricing

R1,500/month includes 300 concurrent users. Extra users beyond that are R5/user. Unlimited routers at no extra cost.

–Active right now
–Concurrent user limit
–Peak concurrent users this month
–Estimated monthly cost

Your concurrent user limit is purely an access gate — it decides when a new guest gets turned away, and never affects your bill by itself. You're billed on your real peak concurrent usage this month alone, so raising your limit for headroom costs nothing extra unless guests actually fill it. That also means lowering your limit after a busy period doesn't retroactively lower what you're billed for the users you genuinely had.

Why is my bill this amount?
Base price (includes – concurrent users)R–
Your peak concurrent users this month–
Users beyond what's included– × R–
Estimated total this monthR–

Peak per month (recent history)

Your peak concurrent users for each of your last few billing months — the exact number driving that month's bill. Granularity is monthly only: this platform doesn't currently record which specific day or hour within a month produced the peak, only the peak itself.

MonthPeak concurrent users
Loading…

You can raise your limit any time (extra users bill at R5/user). If auto-scale raises your limit during the month, it can't be lowered below that until the next billing month — but a limit you set yourself here stays exactly as you left it, month to month.

Auto-scale settings

Controls how auto-scale behaves once it's switched on above.

Leave "Never auto-scale above" blank for no ceiling — auto-scale will keep raising your limit every time it's reached. Set a value to cap how high it can go automatically; you can always raise your limit further yourself.

Capacity monitoring

An early warning before guests actually get turned away — separate from the "at capacity" notification, which fires once the limit is actually reached.

Ad activity on your portal

Campaigns advertisers are running on your captive portal — informational only, not a revenue statement.

–Active campaigns
–Views delivered
–Total advertiser spend

Survey activity on your portal

Survey-unlock questions running on your captive, priced at your rate set under Surveys — informational only, not a revenue statement.

–Active questions
–Answers delivered
–Total spend

Voucher revenue

Counted once a voucher is redeemed, at the price you set when generating it.

–Total revenue
–Vouchers redeemed
–From dashboard sales
–From API integrations

Billing contact & tax details

Used on your invoices — leave blank if not applicable.

Payment gateways

Connect your own payment gateway account so guests can pay for vouchers/data plans by card. For your security, once saved a key can never be viewed again here — only replaced (paste a new one) or removed.

Without a public key, guests are sent to Paystack's own payment page to pay (still fully secure). With one, they pay in a popup right on your portal without leaving the page — the card details go straight into Paystack's own secure popup, never through your server or ours.

ProviderKeyStatusConnected
Loading…
Billing & plan

Invoices

Your own subscription invoices only — never another tenant's.

Invoice #DateAmountStatus
Loading…
Billing & plan

My revenue

What you've actually earned from ads, vouchers, data plans, surveys, and subscribers — separate from what you owe us (see Plan & pricing). Partner Payouts is what you separately owe OUT to any revenue-share partners hosting your routers, calculated on ALL of the above including subscriber revenue — shown for context only and not subtracted from the totals above.

–Ad revenue
–Voucher revenue
–Data plan revenue
–Survey revenue
–Subscriber revenue
–Total earned
–Partner Payouts (this range)
–Subscription cost (this range)
–Net

Revenue trend

Revenue by router

Which of your routers is actually earning its keep — flagged Underselling below half your per-router average this range, Overselling above 1.5× it. The Trend column compares each router against its OWN prior period instead, so a router can be dropping even while still above average. Reuses the Range picker above. A router shown offline explains low numbers on its own, worth checking before assuming it's a sales problem.

#RouterAd viewsVouchers redeemedData plans soldSubscriptions sold Ad revenueVoucher revenueData plan revenueSubscriber revenueTotalTrendStatus
Loading…

Revenue by department

The same revenue as the table above, rolled up by router group instead of by individual router — useful if you run more than one site, branch, or department (a city's Parks routers vs its Libraries routers, a franchise's branches) and want one number per group instead of per router. A router not yet assigned to any group shows under "Ungrouped". Reuses the Range picker above.

DepartmentRoutersAd revenueVoucher revenueData plan revenueSubscriber revenueTotal
Loading…
Billing & plan

Payment history

Every individual data-plan purchase and subscriber charge — who paid, how much, when, and whether it actually succeeded. "My revenue" above only shows totals; this is the transaction-level record behind those totals.

–Payments found
–Collected (successful)
DateTypePlan / chargeSubscriber / guestAmountStatusProviderRouter
Loading…
Page 1
Vouchers

Generate vouchers

Print or hand out codes for guests to redeem directly on your captive portal — you sell them however you like (cash, front desk), the system just tracks and redeems.

Turn this off to run voucher-only — end users will see the voucher code box as soon as they open the connect screen, with no ad/bundle step at all.

Turn this off to run ads-only — the "Have a voucher code? Use it here" link disappears from the connect screen entirely.

Only shown when ads and vouchers are BOTH off — guests pick a plan (see Data plans) and pay by card through your connected payment gateway (see Billing & Plan).

At least one of these three must stay on — unless you have surveys turned on (see Surveys below) or a verified 1Voucher or OTT Voucher gateway connected (see Payment gateways below), either of which counts as its own way for end users to connect and lets you turn all three of these off.

A guest can only redeem a code from this batch while connected to one of the ticked routers — e.g. restrict a "Durban → PMB" batch to that route's own router(s), so it can't be redeemed while sitting on a different bus. Leave unticked for an ordinary batch with no route restriction.

Max redemptions controls how many times each code in this batch can be used — 1 (default) means single-use; set higher for a shared code (e.g. a 10-use event code). "Max concurrent devices" is how many of those redemptions are allowed to pool into ONE shared balance instead of each getting its own separate grant (e.g. a phone + a Smart TV sharing one 2-device voucher) — "Allow adding extra devices" turns on automatically once that's above 1, the same way it does for Data plans.

Fair usage override (optional)

Leave blank to use your tenant-wide fair usage policy (set under "Owner & guest access") for vouchers from THIS batch. Set your own numbers to give this batch its own rule. Only takes effect while your tenant-wide policy is turned on.

Vouchers

External voucher bundles

If you're selling 1Voucher and/or OTT Voucher (see Payment gateways to connect either) instead of — or alongside — the codes you generate yourself above, this is where you set what a guest's redeemed balance actually buys. A guest never pays you directly for these: they've already paid a retailer or their own banking app for the real PIN, typed it into your captive portal, and its rand value landed here as a balance — they then pick one of the bundles below to spend it on, the same way they'd pick one paying by card. Nothing else needs to be switched on for this to work — a connected, verified 1Voucher/OTT gateway is itself a valid way for guests to connect, even with ads, your own vouchers, and card sales all switched off above.

This is the exact same bundle list as "Data plans" further down — add one here and it also shows up there (and vice versa), since both are just two different ways a guest can pay for the same bundle: by card, or from a redeemed voucher balance. No need to configure it twice.

"Max concurrent devices" is the total device count sharing one purchase — the same per-purchase device limit and balance/account tracking already enforced for card-paid data plans applies identically here, since it's the same underlying bundle. "Allow adding extra devices" turns on automatically once that's above 1.

Useful at a terminal with routers for several different routes — tick only the routers where this bundle actually applies, so a guest at a Pretoria router isn't shown a Cape Town → Pretoria ticket meant for the Cape Town terminal.

Fair usage override (optional)

Leave blank to use your tenant-wide fair usage policy (set under "Owner & guest access") for this bundle. Set your own numbers to give it its own rule — the same override either way a guest bought it (card or voucher), since it's the same bundle row. Only takes effect while your tenant-wide policy is turned on.

Promo protection

A free (R0) bundle is claimed automatically here — this is required and can't be turned off below. A paid bundle can optionally use the same protection too (e.g. a heavily-discounted promo price). Limits how often the SAME device OR account can claim this bundle — enforced by device fingerprint as well as email/phone, so signing up under a new account on the same phone won't get around it, and taking an already-used account to a different phone won't either. Not unbeatable (a guest changing networks can still get a fresh device fingerprint on this platform today), but it closes the common "just sign up again" pattern.

NamePriceDataDurationMax devicesPromoActive
Loading…
Vouchers

Voucher presets

Your own pricing menu (e.g. "500MB – R1", "1GB – R1.50"). Reference a preset's ID from your own booking system's API calls — bundle/price/duration always come from here, never from the calling system, so pricing stays under your control.

A voucher issued from this preset (dashboard or API) can only be redeemed while connected to one of the ticked routers. Leave unticked for an ordinary preset with no route restriction.

Max redemptions controls how many times a voucher issued from this preset can be used — 1 (default) means single-use; set higher for a shared code (e.g. a 10-use event code), including via the API. "Max concurrent devices" is how many of those redemptions are allowed to pool into ONE shared balance instead of each getting its own separate grant — "Allow adding extra devices" turns on automatically once that's above 1, the same way it does for Data plans.

Fair usage override (optional)

Leave blank to use your tenant-wide fair usage policy (set under "Owner & guest access") for vouchers issued from THIS preset. Set your own numbers to give this preset its own rule. Only takes effect while your tenant-wide policy is turned on.

LabelBundleDurationPriceValidityMax redemptionsStatus
Loading…
Vouchers

Journey presets

For a fleet running fixed routes (buses, taxis): a preset your guests can pick as "which route am I on" when they buy a voucher, watch an ad, answer a survey, or buy a data plan — or that your booking system passes automatically via the API when it already knows the trip. Works across every one of those, not just one.

GraphHopper is a free driving-directions calculator (like Google Maps' "time to destination", but with a free tier) — it powers the "click on a map" duration estimate below, and lets a delayed trip auto-extend a passenger's access if their router reports its live position and is still on the way to the destination, instead of cutting them off early. This is your own key, not a shared ISN one — sign up free at graphhopper.com, so the usage and any cost stays yours as your fleet grows. Leave this blank if you don't need automatic duration estimates or delay recovery; grace period above still helps with fixed delays.

Kept separate on purpose: trip duration is the real expected travel time; grace period is extra time added on top for a big terminal city where the vehicle is still navigating to the actual stop after arriving (e.g. reaching Bloemfontein's city limits well before the terminal) — access expires at trip duration + grace period, not before.

Riding the whole route costs whatever this is set to instead of the legs added up — leave blank to just sum the legs. The time window is only needed if the SAME bus also runs a return trip: it lets the system pick the right direction automatically by time of day instead of asking the passenger, or needing a manual daily switch.

LabelTripGraceRoutePriceRunsRouters
Loading…
Vouchers

All vouchers

Every voucher you've generated, and whether it's been redeemed.

CodeBundleDurationPriceUsesStatusRedeemed byRedeemed at
Loading…
Vouchers

Data plans

Sell internet access directly by card — no voucher code needed. A guest picks a plan on your captive portal's connect screen and pays with their own card via your connected payment gateway (see Billing & Plan). Default is 1 device per purchase, treated as a guest account — raise it per plan if you want to allow more. This is the exact same bundle list as "External voucher bundles" above — a plan added there also shows up here, since both are just two different ways a guest can pay for the same thing.

Shows a small banner with a "Top up now" button once a guest's active bundle drops below this percentage — catches them while they still have the portal page open. It only works while that page is actually open in their browser; it can't reach a guest who's closed the tab or moved on to browsing another site, since nothing routes their ordinary browsing back through this app once they're online.

Closes that gap: sends a text to the guest's phone at the same threshold, reaching them no matter what they're browsing at the time. Skipped for a guest who signed up with only an email (nothing to text), and a guest won't be texted again about the same low-data spell within 6 hours.

"Max concurrent devices" is the total device count sharing one purchase. "Allow adding extra devices" turns on automatically once that's above 1 — it's what lets a guest connect those extra devices themselves from the captive portal's "Add a device" menu (e.g. a family plan covering a phone + a Smart TV). It can't be set independently: a plan is one payment, so every device sharing it must be able to actually join.

Useful at a terminal with routers for several different routes — tick only the routers where this bundle actually applies, so a guest at a Pretoria router isn't shown a Cape Town → Pretoria ticket meant for the Cape Town terminal.

Fair usage override (optional)

Leave both blank to use your tenant-wide fair usage policy (set under "Owner & guest access") for THIS plan. Set your own numbers here to give this specific plan a different rule — e.g. a cheap 24-hour top-up that throttles after 5GB, while your main 30-day plan throttles after 100GB. Only takes effect while your tenant-wide policy is turned on.

Promo protection

A free (R0) plan is claimed automatically here — this is required and can't be turned off below. A paid plan can optionally use the same protection too (e.g. a heavily-discounted promo price). Limits how often the SAME device OR account can claim this plan — enforced by device fingerprint as well as email/phone, so signing up under a new account on the same phone won't get around it, and taking an already-used account to a different phone won't either. Not unbeatable (a guest changing networks can still get a fresh device fingerprint on this platform today), but it closes the common "just sign up again" pattern.

NamePriceDataDurationMax devicesPromoActive
Loading…
Subscribers

Subscriber accounts

Recurring accounts for your OWN regular customers — like a fixed ISP account, not a one-off voucher or data plan. Each subscriber logs in with a phone/email + password, keeps the same account every visit, and (optionally) always gets the same IP address on your network. Billing renews automatically each cycle once a card is on file; you can also add a subscriber manually if you've already collected payment yourself.

Plans

The recurring packages subscribers choose from — e.g. "R150/month Unlimited".

Fair usage override (optional)

Leave all three blank to use your tenant-wide fair usage policy (set under "Owner & guest access") for THIS plan. Set your own numbers here to give this specific plan a different rule — e.g. a cheap entry-level plan that throttles sooner than your main unlimited plan. Only takes effect while your tenant-wide policy is turned on.

NamePriceIntervalDataMax devicesStatic IPActive
Loading…

Subscribers

Assign a subscription to a guest who's already used your WiFi (e.g. they paid you in cash) — search for them below by phone, email or name, pick them from the results, then choose a plan. This ties the subscription to their REAL, already-recognized account instead of creating a separate login; they'll get access automatically the next time they connect, no password needed.

SubscriberPlanStatusNext billingStatic IP
Loading…
Ad revenue

Ad pricing

Set your own price per view for each ad plan advertisers pick when buying a campaign on your captive. Leave a field blank to keep the platform default. This never changes what each plan does (skip rules, how often it shows) — only what advertisers pay.

Ad revenue

Ad-unlock bundles

The "watch ads, get free data" choices shown on your captive's connect screen — up to 3 tiers, each with its own data amount, number of ads to watch, session length, and speed cap. Leave this unconfigured to keep the platform default (100MB/5 ads/1h, 250MB/10 ads/1.5h, 500MB/15 ads/2h).

Surveys

Survey pricing

Turn on survey-to-unlock and set what you pay per answer. This rate is what actually gets charged against every question's or bundle's budget — e.g. at R1.00/answer, a R50 budget stops the question after 50 answers. Question content, per-question budgets, businesses, and unlock tiers are all managed on your captive dashboard's Surveys tab.

Off by default. Once on, the survey-unlock option appears on your captive's connect screen alongside ads/vouchers/data plans.

Leave blank to use the platform default. Applies to every priced question and bundle at this location.

Marketing

QR flyer

A printable flyer for your front desk, tables, or rooms, generated right in your browser (nothing uploaded anywhere). "Join WiFi" makes a scan actually connect the phone to that network — recommended, since a guest isn't on your WiFi yet and a plain link can't get them online by itself. "Open portal page" just opens the login page in whatever network the phone is already on — only useful if guests are already connected but dismissed the login prompt.

Click Generate to preview your flyer.

Marketing

Re-engage guests

Send a one-off SMS to guests who connected recently, using your own SMS credits (see Messaging). Each guest gets at most one campaign message per 7 days, even across different campaigns.

Eligible recipients–
Marketing

Automated win-back campaign

The scheduled version of Re-engage guests above: once turned on, this checks daily for guests who used to buy vouchers or data plans regularly but have gone quiet, and texts them a comeback message automatically — no need to remember to send a campaign yourself. Off by default, since it spends SMS credits on its own once enabled.

Free access

Owner & guest access

Configure the instant, no-voucher-no-ads access grant you get when you log in with your own dashboard credentials on your captive portal — and, optionally, extend that same instant access to every guest who logs in or registers.

Turn this off if you only want pre-approved people online — e.g. a student residence with no walk-in guests. Guests without an internal account below will be unable to connect.

Strictly enforced — a guest under this age cannot sign up at all. Use this if you serve alcohol or other age-restricted goods. Always at least 13; leave blank to use the platform's own 13+ floor.

Applies to every regular guest at this location. Leave at 0 to use the platform default. Internal accounts below can still override this per account.

Fair usage policy (all guest access)

Stops any guest — on an ad-unlock, a voucher, a survey, a 1Voucher/OTT redemption, or a data plan — from turning "unlimited" into unmetered, since a guest can still move well over 100GB on a plan meant to just cover normal browsing. A still-active plan (a week, a month, even close to a year) stays monitored for its whole length, not just its first day. Once it expires, usage from the last 24 hours still counts — buying a fresh plan right after an over-the-limit one ends, or chaining several small vouchers back to back, doesn't reset the count; only genuinely letting 24 hours pass with no new usage does. Devices sharing one balance via "add device", and a guest who registers again on the same device under a different phone/email, are both tracked as one guest for this check — logging in fresh doesn't get a clean slate. Once the limit is crossed, speed drops to the throttle below, live, without waiting for a reconnect. Separate from the resident-voucher fair usage policy above, which is monthly and only covers that one feature.

Uses your own SMS credits — one text when a guest is approaching the limit, another when they're actually throttled. On by default so a guest's speed never drops with no explanation. Only reaches guests who logged in with a phone number.

An internal/SSO account often stays valid for months or years, reusing the same data allowance the whole time — without a reset, once it crosses the threshold above it stays throttled forever, since the system has no "new month" signal for a login that never expires. This only resets the FAIR USAGE throttle window; it does not add data or touch the account's real usage/expiry.

Also covers named internal accounts logging in directly (see the "Add an account" form further down this page — each account can set its own override) and roaming-partner guests visiting from another tenant's realm (set a roaming-specific override right on the Roaming Partners page) — every access type funnels through the same check.

Your own bypass (owner login)

Open access for all guests

When on, every guest gets full internet access the moment they log in or register here — no voucher, no ad-watch. Good fit for venues like student accommodations where you'd rather bill the tenant a flat rate than gate individual guests.

How often the SAME device can claim a fresh free grant. "Once ever" is enforced by device fingerprint, not just email/phone — signing up again on the same phone won't get around it.

Guest vouchers from residents

Let a resident generate a voucher for a visitor from their own My Usage panel, instead of enabling open access for everyone nearby — a stranger with no connection to a resident gets nothing. Redemptions above cover the visitor's own devices (phone + laptop), not multiple unrelated guests.

How many of the visitor's own devices can share one voucher — match your house rule (typically 1-3).

Own to this feature, separate from "Owner & guest access"'s default speed cap above — leave at 0 to just use that default instead.

Leave both times blank for no curfew. Outside these hours residents can't create vouchers, guests can't redeem them, and any device already connected via one is disconnected the instant curfew starts.

Fair usage policy

Stops a resident's guest vouchers from turning into unlimited free WiFi for a rotating cast of visitors — and stops one visitor from dodging a limit by collecting vouchers from several different residents, or by signing up fresh on the same phone. Once a resident's vouchers (or one visitor's device, across ANY resident's vouchers) move this much data in a calendar month, your chosen policy kicks in. On by default.

Soft throttles the resident's vouchers (and any already-connected visitor) to the speed below, live, without waiting for a reconnect. Hard stops the resident creating new vouchers and stops a limited visitor redeeming ANY resident's voucher, until next month.

Same heads-up as the main fair usage policy under "Owner & guest access", just for this monthly resident-voucher limit specifically. Uses your own SMS credits. Only reaches visitors who logged in with a phone number.

Internal accounts (named users)

Named accounts you provision yourself — students, staff, residents. Each bypasses ads/vouchers, with its own data cap and duration, and a device limit so one account can't be shared with everyone. An account can also be given a static IP (see the "Assign IP" action below) if its device needs to always be reachable at the same address — a security camera, a POS terminal, an office device.

Add an account

Unit/room/ward is a free label for a multi-unit site (a hospital ward, a floor, a boarding-house room) — it doesn't change access in any way, it just lets you filter the list below and Guest activity by physical unit instead of one account at a time.

Fair usage override (optional)

Leave blank to use your tenant-wide fair usage policy (set under "Owner & guest access") for this account's own direct logins. Set your own numbers to give named accounts (residents, staff) their own rule — separate from the monthly fair-usage policy that already covers vouchers THIS account issues to visitors. Only takes effect while your tenant-wide policy is turned on.

Reset throttle for internal/SSO accounts

Tenant-wide — applies to every internal/SSO account, not just the one you're adding here (same setting as on "Owner & guest access" and SSO Settings). An internal account often stays valid for months or years, reusing the same allowance the whole time — without a reset, once one crosses the threshold above it stays throttled until the account itself expires.

Generate a batch

Uses the same data/duration/device settings entered above for every account in the batch.

All internal accounts

With hundreds of accounts, editing one at a time isn't realistic — select the ones you want (or "select all") and change data cap, duration, device limit, or speed caps for all of them in a single save.

0 selected
UsernameUnitDataDurationMax devicesStatic IPStatus
Loading…
Free access

Repeat-guest rewards

Automatically grant a bonus data bundle to a guest every time they hit a visit milestone — a returning device is recognized the same way the rest of the dashboard already recognizes one, no extra setup needed. A "visit" counts once per calendar day, so watching several rounds of ads in one afternoon is still one visit.

e.g. "Reward every 5th visit" grants the bonus on visit 5, 10, 15, and so on — automatically, with no action needed from the guest or from you.

Free access

Guest satisfaction (NPS)

A free, one-tap "how was your visit?" prompt shown right as a guest logs out — three faces, plus an optional one-line comment. Nothing is bought or sold here and no guest identity is stored against a response; it's purely feedback for you. Distinct from the paid, ad-supported Survey-supported access under Free access, which pays a guest in data for answering — this pays nobody and asks nothing but a tap. Off by default; turning it on changes nothing else about how a guest logs out if they skip it.

Results

–Average (out of 3)
–Responses (last 30 days)
–Happy
–Okay
–Not great

Recent comments

No responses yet.

Free access

Google review bonus

Offer bonus data for leaving a Google review — off by default. The reward is for leaving a review, not a positive one (Google's own policies don't allow incentivizing reviews by sentiment), and the guest-facing wording reflects that. There's no realistic way for us to confirm a specific anonymous Google review actually came from a specific guest, so this runs on trust — the same honor-system approach most guest-WiFi review tools use.

Free access

Roaming Partners

Let a guest with an internal account at a PARTNER institution log in here using their own home credentials (e.g. 22222@theirschool.ac.za) — the same way mobile roaming or eduroam works. Nobody can connect to you unless you hand them a connection code yourself; there's no directory to search or be found in, and both sides must explicitly accept before any login trust exists.

Your realm

A short, unique domain-style name for your institution (e.g. yourschool.ac.za) — this is what a visiting guest types after the @. Required before you can generate or redeem a connection code. Once set, this never changes automatically, so pick something your students will actually recognize.

Connect with a partner

Generate a one-time code and share it with the partner institution yourself (email, phone — outside this platform). They enter it on their own dashboard; you'll then see a request here to accept before anything goes live. To connect the other way, ask your partner for a code and paste it below.

Your partners

InstitutionStatusTheir incoming status
Loading…

Outsider access rules

Applies uniformly to any visitor from ANY of your partners — not configurable per individual partnership. Separate from your own students' own account settings, which are untouched by this.

Fair usage override for visitors (optional)

Leave blank to apply your plain tenant-wide fair usage policy (Free access → Owner & guest access) to visitors too. Set your own numbers here to give every partner you host ONE consistent policy, distinct from your own direct guests — e.g. a stricter cap for visitors passing through. Only takes effect while that tenant-wide policy is turned on.

Outsiders on your network

Guests visiting FROM your partners — grouped by which institution they're from.

FromSessionsData used (MB)
Loading…

Your students abroad

Your own accounts, seen roaming at a partner institution — grouped by which institution they visited.

VisitedSessionsData used (MB)
Loading…
Free access

Single Sign-On

Let your students/staff log in with your institution's own identity provider instead of a username and password you provision manually. Supports OIDC (Azure AD, Google Workspace, Okta) and SAML (Shibboleth/InCommon and most enterprise IdPs). An account is created automatically the first time someone signs in this way.

OIDC settings

Give your identity provider admin this redirect URI: –

Auto-provision defaults

Applied the first time a given person signs in via SSO — same fields as adding an internal account manually. You can still edit any individual account afterward in Internal Accounts.

Fair usage default (optional)

Baked onto every account SSO auto-provisions from now on — leave blank to use your tenant-wide fair usage policy (Free access → Owner & guest access) instead. Editable per-account afterward, same as any manually-added internal account; changing this default only affects accounts SSO creates from now on, not ones already provisioned.

Reset throttle for internal/SSO accounts

This is the SAME tenant-wide setting as the one on Free access → Owner & guest access (Fair usage policy) — shown here too since an SSO account IS an internal account under the hood, and it often stays valid for a full semester/year, reusing the same allowance the whole time. Without a reset, once an SSO user crosses the threshold above they stay throttled until the account itself expires. Saving here updates the same tenant-wide setting, not a per-SSO-account override.

Security

Security Alerts

Automatic flags on suspicious usage patterns for your own accounts — alert-only, nothing here blocks a guest automatically. A country-level location change is the most precision available (no exact distance/speed data), so treat these as things worth a look, not proof.

WhenTypeIdentifierDetails
Loading…
Security

Abuse & IP complaints

Log a complaint about how your network's public IP was used (a copyright notice, an abuse report from another network, anything tied to a specific IP and time), then use "Look up" to find which of your routers actually had that IP at that moment and which of your guests were online on it then. This is an operational log and lookup tool only — it doesn't give legal advice or generate any notice/letter; for the correct legal process in your jurisdiction, consult your own advisor.

Log a new report

Reports

Reported IPWhenDescriptionStatus
Loading…
Security

Banned devices

Block a specific device's MAC address from your WiFi — enforced as a real block on the router itself (the device simply can't reach the network), not just a setting inside this dashboard. Already-connected devices are also kicked off immediately. Ban it on just one router, or across your whole fleet at once.

Ban a device

Currently banned

MAC addressScopeReasonBanned
Loading…
Security

POPIA data-retention auto-purge

Off by default. Once you set a window, this checks daily for guests who haven't logged in for at least that long and clears their name, date of birth, email, phone, and registration IP/device info — their past usage/revenue totals stay in your aggregate reporting, only who they were is cleared. Scope worth knowing: this clears the guest's main record; it doesn't yet reach into every historical row that separately stored their contact details elsewhere in this platform. A returning guest after their record was purged simply signs up again as new.

Purge history

WhenRecords purgedWindow at the time
No purges yet.
Security

Privacy requests (POPIA)

Under POPIA, a guest can ask to see the personal information you hold about them, or ask for it to be deleted. Guests can do this themselves from your captive portal's My Account panel (Download My Data / Delete My Data), including the link in your guest terms. Downloads are handled instantly and just logged here. Deletions wait here for you to action within 30 days. When you complete a deletion, the guest's name, contact details, devices and ad activity are removed. Their connection and billing records are kept for the 5 years RICA requires, but no longer point to their details. Only the account owner and IT can see this page.

Log a request for a guest

For a guest who asked you in person, by phone or by email. Confirm it's really them before logging it.

All requests

ReceivedGuestRequestFromStatusDue
Loading…
Branding

Custom domain

Every account gets a free working address the moment you sign up. Add your own domain whenever you're ready — your guests never have to see ours.

Your free address

–

Turn this off only once your own custom domain below is verified — turning it off before then takes your portal offline for anyone still using this address.

Your router's External Login URL

–

Set this in each router's Hotspot settings (UAM redirect). Once your custom domain below is verified, this updates to your own captive.yourdomain.com — you'll then need to update each router's Hotspot settings once more (or use Remote CLI) to switch it over.

Your own domain (optional)

Enter the domain you own below (e.g. yourbusiness.com) — don't include "www." or "captive.". We'll set up captive.yourbusiness.com as your guests' WiFi login page; the rest of your domain (your main website, email, etc.) is untouched and stays exactly as it is.

Network

Routers

Restart a router, update its WiFi name/password, or cap its speed directly — no more Teltonika RMS or SSH for everyday changes.

Add a router

Give it a name — router ID is auto-generated, or set your own if you'd rather match your own naming (e.g. matching a physical label).

Rotate WiFi password for all routers

One new name/password applies to every OpenWRT-family router at once (Teltonika, GL.iNet, generic OpenWRT) — no need to update each one by hand. A MikroTik or other-vendor router has no automated push for this and needs its own Hotspot settings changed directly.

Zero-touch enrollment

Pre-generate setup links/QR codes before you even have the physical routers in hand — hand a code to whoever's actually deploying them (a driver, an installer) and they set it up themselves, no ISN dashboard access needed on their end. Not fully hands-free (someone still has to paste one command into the router — a browser can't reach a router's local admin page directly, that's a real browser security limit, not something we can code around) but it means you're not the one who has to be there or walk them through it live. Print the QR codes and stick one on each router before it ships out.

Your routers

Loading…

Router groups

Tag routers into named groups (e.g. "Ground floor", "Branch A") so a bulk change applies to just that group instead of one router at a time or your whole fleet — useful once you're running more than a handful. Purely a label: a router not in any group behaves exactly as before.

Apply a speed cap to a whole group

Apply a reboot schedule to a whole group

A periodic maintenance restart, independent of any outage alerting — useful for routers that benefit from a routine clear-out. Fires sometime within the chosen hour, not necessarily on the minute.

(none checked = every day)

Bandwidth cost forecast

Optional — if your ISP line has a monthly data cap, set it here and this projects whether you're on track to hit it before your billing cycle resets, using actual usage so far this cycle. Leave blank to leave this off entirely.

Advanced: RADIUS authentication

For IT teams who already run their own RADIUS server (often tied to Active Directory) and want this router to authenticate guests against it too — not something ISN hosts for you, and not needed for a normal setup. Leave this off unless you already have a RADIUS server to point at.

Pushed automatically as part of Auto-config to OpenWRT-based routers (Teltonika, GL.iNet, generic OpenWRT) and to MikroTik routers (beta — hasn't been verified against real MikroTik hardware yet). Any other router vendor needs this configured directly on the router.

Advanced: TP-Link Omada integration Beta

Only needed if you run TP-Link Omada routers — usually set up through the Auto-config wizard on a router of that type instead, but you can review or change it here too. Not verified against real Omada hardware yet.

Network

Fleet map

Where your routers actually are, at a glance — colored by whether each one is online right now. Location comes from each router's own reported public IP, which is genuinely accurate to city/area level for a router at a fixed site. For a router on a mobile/cellular connection (an LTE dongle on a bus or taxi, for example), this only shows roughly where that connection is registered on the mobile network, not the vehicle's live GPS position — it will not move in real time as the vehicle travels. A router that has never reported a public IP yet has nowhere to show and is listed below the map instead.

Network

Network topology

For advanced sites running switches and access points behind one router — monitor the whole setup from one place: which devices are up, how much traffic is passing through, how many devices are connected, and an alert the moment something drops. A switch or access point never runs our agent itself (it's ordinary networking gear) — your router polls them over SNMP on its own network and relays what it finds, the same way it already reports its own stats.

Connect a controller BETA

Running UniFi, Omada, or Ruckus? Connect the controller once and every switch/access point it manages is discovered and kept in sync automatically, every 5 minutes — no manual SNMP entry needed for these. Newly built and not yet verified against a real controller of any of the three — a wrong credential fails as one clear error on this page, not silently.

UniFi
Omada

Separate from any hotspot-login connection above — find these under Settings → Platform Integration → Open API in your Controller.

Ruckus

For a SmartZone controller — access points only for now (switches aren't covered by this beta pass).

Add a switch or access point manually

SNMP is switched off by default on most switches/APs — enable it on the device first (most vendors call this "SNMP v2c", with a "community string" acting as its password) before adding it here, or the poll will just come back offline.

Your topology

–Devices online
–Needing attention

Loading…

Network

Remote CLI & restart

Run a command directly on one of your routers. Every command is logged below — re-enter your password to unlock this for however long you choose.

Command history

TimeRouterCommandStatusOutput
Loading…
Network

Fair Pause

If a specific router goes offline (load-shedding, an ISP blip, a power cut) and comes back later, guests who were mid-session on THAT router — and had time left — get it back: their access clock is frozen for exactly however long the router was down, then resumes right where it left off. Guests on your other routers are never affected. Data-bundle usage already can't burn down while a router is offline (no way for it to report usage), so this only matters for time-based access. Resident/internal-account vouchers are excluded — this only protects paid, ad-earned, and other revenue-generating access.

Outage history

Every time one of your routers stopped reporting in and came back, with how many guests had their access time restored.

RouterWent offlineBack onlineDurationGuests restored
Loading…
Network

Content filtering

Block specific websites on your WiFi — nothing is blocked until you add a domain below. Applies to every router listed here that supports automated push; re-enter your password to make changes.

Insights

Analytics & reports

Traffic trends, peak concurrent usage, ad performance, and downloadable monthly reports.

–Guest connections
–Peak concurrent devices
–Ad views
–Ad clicks
–Vouchers redeemed
–SMS sent
–Avg. guest download speed
–Avg. guest upload speed

Traffic trend

Ad performance by campaign

Busiest hours

When guests actually connect, by day and hour (SAST) — darker means busier. Useful for staffing up or timing a promo.

Footfall & repeat visitors

Unique guests and how many are coming back, for this range.

–Unique visitors
–New visitors
–Returning visitors
–Returning ratio
–Peak hour
Insights

Guest activity

Registered guest users, bundle transactions, and site visits for this captive only — never shared with any other tenant.

Registered users

NameEmail / phoneDOBBundle MBRemaining MBStatusRegistered
Loading…

Recent transactions

IdentifierBundle MBRouterGranted at
Loading…

Domain visits

POPIA-compliant · daily anonymised snapshots, aggregated by domain only — no per-guest browsing history is stored.

DomainVisits
Loading…
Insights

Notifications

Emailed to your own account's registered email. Only you receive these — settings and history never affect other tenants.

Loadingwaiting

Notification settings will appear after the API responds.

Low SMS credit alert & auto top-up

Choose how low your balance can go before we email you, and optionally have us prepare a top-up request automatically.

If you have a saved card on file (from starting a trial or paying your subscription), auto top-up charges it automatically the moment your balance drops — no manual step. Without a saved card, it falls back to a pending EFT request you complete manually from your dashboard's banking details.

Leave the monthly cap blank for no limit. Once auto top-ups this calendar month would cross it, auto top-up pauses itself (you still get the low-balance email, and can always top up manually) instead of continuing to spend.

Guest data-usage SMS alerts

Sent to the GUEST, not to you — an SMS letting them know their own bundle has crossed a usage point, with a link straight into their usage view. Both off by default: this uses your SMS credits, so only turn on what's actually useful to your guests.

Team & access

Team members

Invite staff with limited roles instead of sharing one login. Each role controls what they can see and do — full detail is server-enforced, not just hidden in this UI.

NameEmailRoleAll captivesStatusLast login
Loading…
Team & access

API & integrations

Let your own systems call into ISN programmatically: a booking/ticketing backend can issue and reschedule vouchers, or your till/POS system can grant a guest WiFi the instant they pay — no code for the guest to type in. See Voucher presets to define what an API key is allowed to issue or grant.

LabelKeyCreatedLast usedStatus
Loading…

Recent POS grants

IdentifierDataDurationGrantedKey
Loading…

Webhooks

The other direction: let your own systems hear about a real event the moment it happens, instead of only ever checking this dashboard. Each webhook fires an HTTPS POST, signed with a secret only you have (verify it with the X-ISN-Signature header, HMAC-SHA256 of the raw request body).

URLEventsStatusLast successLast failure
Loading…
Support

Help & contact

Guides for managing your captive portal, plus how to reach the ISN Free WiFi team directly.

Contact the ISN team

Email support

Send your tenant slug (—), domain, and router model so we can confirm what still needs attention.

Email info@isnfreewifi.co.za
Account

My profile

Your own login — shared across every captive you run, separate from any single captive's branding or "Owner name" contact field.

Account & company details

Used for billing contact and support — not shown to your Guests.

Change password

Two-factor authentication

Alternative to the emailed sign-in code — a code from an authenticator app (Google Authenticator, Authy, or similar) on your phone instead. Optional; your emailed code keeps working either way.

Checking status…

Active sessions

Every device currently logged into this dashboard. Signed into one you don't own and forgot to log out? Sign it out from here.

DeviceLocationLast active
Loading…

Security questions

Optional, but recommended — if you ever lose access to your email and can't sign in, ISN support can verify it's really you with these before changing your login email. Pick at least 3.

Account

Switch captive

Every branded location on this login, one click away — the same list as the account menu in the header, just easier to find. "Add another captive" starts a brand-new one under this same login.