How it works

A self-service layer on top of the UniFi Access console you already run

The portal never replaces the console or its policies. It reads the directory, lets each person change the things that are theirs, and writes every change back through the official API with an audit trail.

  1. Step 1

    We connect to your console

    You create an API token in UniFi Access with the minimum scopes and a WireGuard client on your UniFi gateway. We bring up the tunnel, pin the console's certificate and test the connection. Nothing on the console changes.

  2. Step 2

    We read your directory

    The portal pulls the user list every few minutes: names, emails, which address group each person belongs to, and what credentials are on file. PINs and card secrets are never copied; only whether they exist.

  3. Step 3

    Residents sign in with their email

    A resident types the email the office has on file and gets a 6-digit code. If the email is a user at one of your gates, they see that gate. No passwords, no accounts to create.

  4. Step 4

    Changes go straight to the console

    When a resident sets a PIN or adds a plate, the portal writes it to UniFi Access through the official API, confirms the result, and records who did what in the audit log.

  5. Step 5

    The office keeps control

    Community managers decide whether residents may pair their own cards and on which readers, cap plates per household, and can see and change everything a resident can.

Architecture

Where things live

  • Your console keeps everything that matters. Users, PINs, cards, plates, policies and schedules stay on UniFi Access. If the portal disappeared tomorrow the gate would not notice.
  • The portal holds a directory copy and an audit log. Names, emails, address group and which credentials exist, refreshed every few minutes. Never a PIN value, a card secret or a sign-in code. Console API tokens are stored encrypted.
  • One private tunnel per console. A WireGuard client on your UniFi gateway; no inbound ports at the site. The console's TLS certificate is pinned on first contact.
  • Hosted in Google Cloud, United States, with nightly encrypted backups, automatic security updates and uptime monitoring. Several communities share the service; each only ever sees its own.

Three roles

Who can do what

Resident

Anyone whose email is on a user record at one of the community's gates.

Can

  • Sign in with an emailed code
  • Set or change their personal PIN
  • Add and remove their license plates
  • Pair or claim cards, fobs, remotes and transponders where enabled
  • Add people at their own address
  • Set the visitor PIN and visitor plates for their address
  • Resend their mobile app invitation and see linked phones
  • Set the intercom backup phone for their address

Cannot

  • See or change anyone outside their address
  • Remove a person (that is the office's call)
  • Open the gate from the portal
  • Assign a card that belongs to someone else

Community manager

Office staff or board members the community names. A manager can run more than one community.

Can

  • Everything a resident can, for any resident of their community
  • Search every address and person
  • Add, disable and remove people; resend invitations
  • Edit plates, relabel cards, revoke a lost phone
  • Set vendor PINs at every gate of the community at once
  • Choose which readers allow self-enrollment and cap plates
  • Test each console's connection, sync the directory, release a stuck reader
  • Read the community's audit log
  • Invite other managers and keep the office contact details current

Cannot

  • See another community
  • Create communities or change the plan
  • Change the console's access policies (done at the console, as today)

Platform administrator

The people who run My Community Gates.

Can

  • Create communities, add their consoles and invite the first manager
  • Support any community with the same view its managers have
  • See every console's health and the platform-wide audit log
  • Answer inquiries from this website

Cannot

  • Read a PIN, a card secret or a sign-in code: none is ever stored
  • Open a gate

Check whether your setup fits

The requirements page lists what the console, the network and the gate hardware need.

Get started