- Home
- WiFi Glossary
- OpenRoaming
What is OpenRoaming?
Definition
OpenRoaming is a federation run by the Wireless Broadband Alliance and built on Passpoint. It lets a device connect automatically and securely to any participating WiFi network worldwide, using a single trusted credential from a home identity provider such as a mobile operator, an employer or a platform account.
OpenRoaming explained
The model works like mobile roaming. Venues join the federation as access network providers. Identity providers issue credentials, held on the device as a Passpoint profile. When a device with a profile comes into range of a participating network, it authenticates in the background over 802.1X and EAP, with no captive portal and no password.
Behind the scenes, authentication requests travel between the venue and the identity provider through RADIUS federation, secured with RadSec, which wraps RADIUS in mutually authenticated TLS. Because the resulting connection uses WPA2-Enterprise or WPA3-Enterprise encryption, OpenRoaming is more secure than the open networks it replaces. It also removes the shared passwords and open SSIDs that public WiFi has relied on.
For venues with many repeat visitors, such as airports, rail stations, hotel groups and retail estates, the benefit is removing onboarding friction. Once a person has onboarded at any participating network, they connect everywhere else without doing it again. Purple acts as a free identity provider for OpenRoaming.
Guides on OpenRoaming
- Technical guideOpenRoaming architecture and authentication
- Technical guidePasspoint and OpenRoaming: complete guide
- Technical guidePasspoint and OpenRoaming explained
Where it fits
Related terms
Need more than a definition?
Talk to our team about how Purple combines guest WiFi, captive portals, RADIUS, and analytics into a single platform that runs on the access points you already own.