Requirements
Most communities already running UniFi Access at the gate meet the required items. The optional ones decide which self-service features residents get.
The portal talks to UniFi Access and nothing else. If your gate runs on a different system, we cannot connect to it.
A Dream Machine (UDM Pro, UDM SE, UDM Pro Max), Cloud Gateway, Cloud Key Gen2 Plus, Network Video Recorder or Enterprise Fortress Gateway running the Access application.
Ubiquiti disables the Access API when a console is upgraded to Identity Enterprise. Stay on standard UniFi Access.
Created once per console under Access → Settings → General → Advanced → API Token. The portal needs People & Groups (edit), Credentials (edit), Visitor (edit), Device (view) and System Log (view). It never needs door-unlock, policy, device-edit or webhook scopes.
Residents sign in with the email on their Access user record. A person without an email cannot sign in until the office adds one.
Create a user group per home, named with the house number first (for example “12003 Oak Ridge Ct”), and attach your gate access policy to the groups. The portal reads the group as the resident's address, which is what makes household and visitor features work.
The Access API only answers on the console's own network, on port 12445. It is not reachable through unifi.ui.com or the Site Manager cloud. The portal therefore needs a private tunnel to each site.
UniFi Network 7.3 or later can run a WireGuard server on the gateway (Settings → VPN → VPN Server). You create one client named for the portal and download its configuration; we run that tunnel from our server. One tunnel per console.
The console needs a static LAN IP or DHCP reservation so the tunnel always points at the right device.
Two sites both using 192.168.1.1 are fine for us (each tunnel runs in its own network namespace), but giving each site its own subnet makes troubleshooting with your installer much simpler.
What residents can do for themselves depends on what is installed. Everything here is optional; the portal adapts to what the console reports.
UA Hub Gate, UA Intercom, G2 or G3 readers: residents' PINs work wherever the console accepts PINs today. The portal learns the PIN length your console enforces.
A UniFi Protect AI camera with license plate recognition linked to Access, so a plate added in the portal opens the gate.
Native UniFi readers enroll cards by tap. Third-party Wiegand readers wired to a UA Hub Gate or Retrofit Hub (gate remotes, HID or Farpointe cards, TransCore toll-tag readers) work too; the portal reads the raw frame and shows residents the number printed on their credential.
If the UA Intercom's call list is organised by address, residents can set the backup phone the intercom rings when nobody answers the app. This uses the console's local administrator login, which you create for the portal with local-only access.
A few things only the community can provide.
To create the API token and the VPN client. Half an hour per console, on a video call with us if you like.
At least one person from the office or the board who will own the resident list, approve removals and answer residents' questions. They get the management console and a passkey.
An email or newsletter announcing the portal. We supply a one-page printable guide and a step-by-step walkthrough you can link to.
Tell us the console model, the Access version shown under Settings → System, and what is at the gate. We will say whether it fits and what setup would involve. No commitment.