Guests connect once. Every visit after that is automatic.
Passpoint, also called Hotspot 2.0, replaces the splash page with a secure profile on the device. Purple's SecurePass installs it through your own app, so a guest signs in once and then joins your WiFi automatically at every venue you run, encrypted from the moment they connect, with no password to share and no form to fill in twice.


One profile install, then nothing to do
- The guest authenticates once, through your own app or your branded access journey
- SecurePass installs a network profile carrying a certificate and RADIUS authentication credentials
- The device finds your network by itself and joins with no splash page and no captive portal
- Traffic is encrypted from the moment the device connects, under WPA2-Enterprise or WPA3-Enterprise

Automatic across your estate, and beyond it
- A guest onboarded at one site connects automatically at every other site you run
- Purple runs on the OpenRoaming federation, so you can extend access to over 5 million hotspots worldwide
- No second sign-in when someone moves between buildings, terminals or stores
- Hardware agnostic: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet

Recognise the returning guests MAC randomisation hides
- iOS 18 and macOS rotate device MAC addresses, which breaks return-visit counting on a captive portal
- Passpoint authenticates the installed profile rather than the MAC address, so a returning guest is still recognised
- Return rates, dwell time and visit counts stay accurate in your reporting
- Every connection ties to a known guest, feeding first-party data through over 400 connectors

No shared password to leak
- Nobody types a passphrase, so there is nothing to write on a whiteboard or hand over when someone leaves
- Each device carries its own credentials, validated by Purple's RADIUS-as-a-Service
- Revoke one guest or one device without changing anyone else's access
- Purple is ISO 27001 certified, GDPR and CCPA compliant, and has had zero data breaches since 2012
Passpoint FAQs
What is Passpoint?
Passpoint is an industry certification programme for secure, automatic WiFi onboarding, and it is the same thing as Hotspot 2.0. Instead of sending a guest to a splash page, the venue installs a network profile on the device that holds a certificate and authentication credentials. The device then discovers the network, authenticates against RADIUS and connects on its own, with traffic encrypted from the moment it connects. Purple delivers Passpoint through SecurePass, which installs the profile through your own app.
Is Passpoint the same as Hotspot 2.0?
Yes. Hotspot 2.0 is the name of the technical specification and Passpoint is the certification programme built on it, so the two terms are used interchangeably in practice. If a vendor says a device or access point is Hotspot 2.0 capable, it will work with Passpoint.
How is Passpoint different from OpenRoaming?
Passpoint is the technology that lets a device join a network automatically. OpenRoaming is a federation that uses it, so a profile issued by one member is trusted by every other member. Passpoint on its own gets guests onto your own venues automatically. Adding OpenRoaming extends that to over 5 million hotspots worldwide. Purple runs on the OpenRoaming federation, so you can choose either.
Does Passpoint solve the MAC randomisation problem?
Largely, yes. iOS 18 and macOS rotate device MAC addresses, so a returning guest looks like a brand new visitor to a captive portal and your return rate reads low. Passpoint authenticates the profile on the device rather than the MAC address, so the guest is recognised on the next visit and return rates, dwell time and visit counts stay accurate.
Do guests need to download an app?
SecurePass installs the Passpoint profile through your own app, so it suits venues that already have one and want WiFi to be a reason to use it. If you do not have an app, the other passwordless routes are a better fit: iPSK gives each person a unique key on a single SSID, and EAP-TLS issues a client certificate through MDM. Most deployments end up using two of the four together.
Which devices support Passpoint?
Current iOS, iPadOS, macOS, Android and Windows releases all support Passpoint, which covers the overwhelming majority of guest phones and laptops. Devices without a browser or a WiFi profile store, such as games consoles and smart TVs, cannot use it. Those are handled with an iPSK instead, on the same SSID.
Does Passpoint work on our existing access points?
Yes, on any hardware that is Passpoint or Hotspot 2.0 capable, which includes current Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet kit. Purple layers on top of the infrastructure you already own, so there is no rip and replace.
How secure is Passpoint compared with a shared WiFi password?
Considerably more secure. A shared passphrase is known to everyone who has ever used it and cannot be revoked for one person, and an open guest network sends traffic unencrypted. Passpoint gives each device its own credentials under WPA2-Enterprise or WPA3-Enterprise, encrypts traffic from the moment the device connects, and lets you revoke one guest without touching anyone else. Purple is ISO 27001 certified, GDPR and CCPA compliant, and has had zero data breaches since 2012.
Get more from your WiFi
Guides and real results to help you plan a network guests join without thinking about it.
Passpoint for your industry
See how Passpoint works in venues like yours, and how Purple compares to alternatives.
Used in these industries
Compare alternatives
Get guests online before they ask for the password
Ready to get started? Speak to an expert to see how Passpoint fits your venues, your app and your existing access points.








