Requirements

What your UniFi Access setup needs

Most communities already running UniFi Access at the gate meet the required items. The optional ones decide which self-service features residents get.

RequiredRecommendedOptional

The access control system

The portal talks to UniFi Access and nothing else. If your gate runs on a different system, we cannot connect to it.

  • UniFi Access on a UniFi OS console

    Required

    A Dream Machine (UDM Pro, UDM SE, UDM Pro Max), Cloud Gateway, Cloud Key Gen2 Plus, Network Video Recorder or Enterprise Fortress Gateway running the Access application.

    • Access 4.x is what we test against. License plate support needs Access 3.3.10 or later; user search needs 3.1.30 or later.
  • Standard UniFi Access, not Identity Enterprise

    Required

    Ubiquiti disables the Access API when a console is upgraded to Identity Enterprise. Stay on standard UniFi Access.

  • An API token with limited scopes

    Required

    Created once per console under Access → Settings → General → Advanced → API Token. The portal needs People & Groups (edit), Credentials (edit), Visitor (edit), Device (view) and System Log (view). It never needs door-unlock, policy, device-edit or webhook scopes.

    • The token is shown once. You paste it into the portal, where it is stored encrypted; we never see it in email or chat.
    • Tokens expire on the schedule you pick when creating them. The portal warns the office when a console starts rejecting its token.
  • Residents' email addresses in UniFi Access

    Required

    Residents sign in with the email on their Access user record. A person without an email cannot sign in until the office adds one.

  • One user group per address

    Recommended

    Create a user group per home, named with the house number first (for example “12003 Oak Ridge Ct”), and attach your gate access policy to the groups. The portal reads the group as the resident's address, which is what makes household and visitor features work.

    • Communities that already use one flat list of users still get PIN, plates, cards and app invitations; address features switch on once groups exist.

Reaching the console

The Access API only answers on the console's own network, on port 12445. It is not reachable through unifi.ui.com or the Site Manager cloud. The portal therefore needs a private tunnel to each site.

  • A UniFi gateway with a WireGuard VPN server

    Required

    UniFi Network 7.3 or later can run a WireGuard server on the gateway (Settings → VPN → VPN Server). You create one client named for the portal and download its configuration; we run that tunnel from our server. One tunnel per console.

    • UDP port 51820 must reach the gateway from the internet. Behind another router or carrier-grade NAT, forward it or use the gateway's DDNS hostname.
    • Alternatives if WireGuard is not an option: a Tailscale subnet router at the site, or UniFi Site Magic to a site we can reach. Opening port 12445 to the internet is not something we will do.
  • A fixed address for the console

    Required

    The console needs a static LAN IP or DHCP reservation so the tunnel always points at the right device.

  • Distinct LAN subnets when you have several consoles

    Recommended

    Two sites both using 192.168.1.1 are fine for us (each tunnel runs in its own network namespace), but giving each site its own subnet makes troubleshooting with your installer much simpler.

Readers and cameras at the gate

What residents can do for themselves depends on what is installed. Everything here is optional; the portal adapts to what the console reports.

  • A UniFi reader or intercom for PIN entry

    Optional

    UA Hub Gate, UA Intercom, G2 or G3 readers: residents' PINs work wherever the console accepts PINs today. The portal learns the PIN length your console enforces.

  • License plate recognition

    Optional

    A UniFi Protect AI camera with license plate recognition linked to Access, so a plate added in the portal opens the gate.

  • Card, fob, remote and transponder readers

    Optional

    Native UniFi readers enroll cards by tap. Third-party Wiegand readers wired to a UA Hub Gate or Retrofit Hub (gate remotes, HID or Farpointe cards, TransCore toll-tag readers) work too; the portal reads the raw frame and shows residents the number printed on their credential.

    • The office picks which readers residents may enroll on and can switch self-enrollment off per gate.
    • Toll-tag style transponders are read as the car approaches; residents claim the read instead of pairing live.
  • Intercom directory

    Optional

    If the UA Intercom's call list is organised by address, residents can set the backup phone the intercom rings when nobody answers the app. This uses the console's local administrator login, which you create for the portal with local-only access.

On your side

A few things only the community can provide.

  • Someone with administrator access to the console

    Required

    To create the API token and the VPN client. Half an hour per console, on a video call with us if you like.

  • A community manager

    Required

    At least one person from the office or the board who will own the resident list, approve removals and answer residents' questions. They get the management console and a passkey.

  • A way to tell residents

    Recommended

    An email or newsletter announcing the portal. We supply a one-page printable guide and a step-by-step walkthrough you can link to.

Not sure what you have?

Tell us the console model, the Access version shown under Settings → System, and what is at the gate. We will say whether it fits and what setup would involve. No commitment.