Saltar para o conteúdo principal
Trusted by venues globally
Someone moving into a new apartment, setting up their phone, laptop, speaker and printer on one WiFi identity
Identity-linked keys

A key that belongs to a person, not a place

  • Every key is bound to a named identity in Entra ID, Okta or Google Workspace, not to a room number or a socket
  • Joiners are provisioned over SCIM, so a new starter or tenant has their key without anyone raising a ticket
  • Movers keep the same identity: change room, building or role and the access follows them, with no re-issue
  • Leavers are revoked once and every device they ever registered drops off, across the whole estate
An older user in an armchair collecting their own WiFi key on a tablet, with a smart speaker and phone nearby
Self-service portal

Users get their own key, without a ticket

  • Users onboard themselves through a branded portal and pick up their own key
  • Every device they add joins that same key and their own Private Area Network, invisible to everyone else
  • Browserless kit - printers, smart TVs, consoles, sensors - joins with a key, no MDM and nothing to install
  • No shared passphrase on a welcome pack, and no helpdesk ticket for a printer or a TV
People in a shared kitchen using laptops, a tablet, a games console, smart speakers and a printer on one network
No device limits

Add every device, without counting them

  • No cap on the number of keys: they live in Purple's cloud RADIUS, not in a controller's local key store
  • No cap on devices per key, so the user with nine devices is licensed the same as the one with two
  • Licensing is per access point and per venue, with no per-device taxes and no per-authentication meter
  • One SSID carries staff, tenants, contractors and IoT, with each key landing in its own VLAN
An IT manager working at their desk in an open-plan office, with no RADIUS servers to run on site
Cloud RADIUS

The RADIUS layer, without the servers

  • RADIUS-as-a-Service with a 99.9% uptime SLA and active-active multi-region failover in seconds
  • UK, EU and US regions, and you choose yours when the service is provisioned
  • Purple never stores user passwords: authentication is proxied to your identity provider in real time
  • Replaces FreeRADIUS, Microsoft NPS or Cisco ISE, so there are no servers, no patching and no HA project

Want to see a key issued and revoked?

Book a demo and we will issue a key on a live network, show you the VLAN it lands in, then revoke it while every other device stays connected.

Book a demo

xPSK FAQs

What is xPSK?

xPSK is an umbrella term for per-user pre-shared keys: a network where every person holds their own WiFi key on a single SSID, instead of one passphrase shared by everybody. They connect every device they own to that one key. Vendors ship it under different names, but the mechanism is the same. RADIUS returns a unique passphrase for each key, along with the VLAN and policy that key should land in.

What is the difference between xPSK, iPSK, DPSK, MPSK and PPSK?

Nothing structural. They are vendor names for the same capability: iPSK and EasyPSK on Cisco Meraki, DPSK on Ruckus, MPSK on HPE Aruba, ePSK on Juniper Mist, and PPSK on Extreme Networks and Ubiquiti UniFi. The RADIUS attributes differ per vendor. Purple issues keys for all of them from one cloud RADIUS, so a mixed estate is configured once rather than per controller.

How is xPSK different from WPA2/3-Enterprise and 802.1X?

802.1X authenticates with a certificate or a directory login and is the stronger option wherever devices can support it. xPSK authenticates with a key, which is why it reaches the devices 802.1X cannot: printers, sensors, consoles, smart TVs and contractor laptops with no MDM enrolment. Most estates run both, with 802.1X for managed endpoints and xPSK for everything else.

Does xPSK work on our existing hardware?

Yes. Purple is hardware agnostic and layers on top of your existing infrastructure, including Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. No rip and replace required.

How does a user actually get their key?

Through a branded self-service portal. The user onboards themselves, collects their own key and adds their devices to their own Private Area Network, so nobody on your team is issuing credentials by hand or fielding a ticket for every printer. Keys can also be provisioned automatically from your directory, or minted through the Purple API for a system that already owns the user relationship.

What happens when someone joins, moves or leaves?

All three are automatic, because the key is bound to an identity rather than to a place. A joiner is provisioned over SCIM from Entra ID, Okta or Google Workspace and has their key without a ticket. A mover keeps the same identity, so changing room, building or role carries their access with them and no key is re-issued. A leaver is revoked once, and every device they ever registered drops off across the whole estate.

Is there a limit on how many keys or devices we can have?

No. Keys are held in Purple's cloud RADIUS rather than in an access point controller's local key store, which is where per-SSID key ceilings usually come from, so the number of keys is not the constraint it is on-box. There is no cap on devices per key either, and licensing is per access point and per venue, with no per-device taxes and no per-authentication meter, so a user with nine devices is licensed the same as one with two.

What happens if someone shares their key?

MAC binding ties a key to the device that first used it, so it cannot quietly become a second shared password. Keys can also carry an expiry date, and any single key can be revoked on its own without rotating a passphrase across the site or disconnecting anyone else.

Can each key have its own VLAN and policy?

Yes. RADIUS returns the VLAN with the key (Tunnel-Type, Tunnel-Medium-Type and Tunnel-Private-Group-ID), so each key lands in its own segment. Firewall policy, bandwidth limits and user roles are applied per key as well, which is how one SSID carries staff, tenant, contractor and IoT traffic without mixing them.

How secure and compliant is xPSK?

Every key is tied to a named identity rather than to a shared password, so each authentication is attributable and each revocation is surgical. Purple never stores user passwords, runs RADIUS regions in the UK, EU and US, is ISO 27001 certified and GDPR and CCPA compliant, and has had zero data breaches since 2012.

See how xPSK works in venues like yours, and how Purple compares to alternatives.