← Operator library Hotspot

ISPbills Premium Hotspot: Bilingual Self-Signup, OTP, Passkeys and Identity Capture

Meet the ISPbills Premium Hotspot: English and Bangla self-signup with OTP, passkeys, social login, live identity capture, RADIUS access, and MikroTik automation.

What this note covers

Meet the ISPbills Premium Hotspot: English and Bangla self-signup with OTP, passkeys, social login, live identity capture, RADIUS access, and MikroTik automation.

Public Wi-Fi should not require staff to issue every voucher, manually identify every guest, or repair access whenever a phone changes its private MAC address. The new ISPbills Premium Hotspot experience gives MikroTik operators a guided self-signup journey that connects customer identity, access control, billing, and RADIUS in one workflow.

A premium captive portal in English and Bangla

The redesigned captive portal is responsive across phones, tablets, and laptops. Guests can switch between English and বাংলা at any point, and their choice follows them through mobile verification, passkey registration, and identity capture.

The first screen keeps the choices clear: enter a mobile number or voucher code, continue with Google or Facebook when the operator has enabled those providers, or return with a passkey. ISPbills branding is kept discreetly in the footer so the venue remains the focus.

Mobile or voucher

Existing customers can identify their account, while new guests begin self-registration using a mobile number.

Social sign-in

Configured Google and Facebook providers offer familiar sign-in choices without mixing customer identities with administrator accounts.

Passkey access

A device passkey provides phishing-resistant return verification when a phone changes devices or rotates its private MAC address.

বাংলা support

The sign-in and onboarding journey can be completed in Bangla, with a persistent language switch on every required page.

How self-signup works

  1. Connect to the venue Wi-Fi. MikroTik detects the unauthenticated device and presents the captive portal.
  2. Enter a mobile number. ISPbills sends a one-time PIN through the operator’s configured WhatsApp or SMS channel.
  3. Verify the PIN. Resend is available if the first message does not arrive, with safeguards against uncontrolled retries.
  4. Create a passkey. The customer registers a passkey using the phone’s screen lock, fingerprint, face unlock, or supported security key.
  5. Add the required identity record. The customer enters their full name and captures a live photo with the built-in camera.
  6. Complete access. ISPbills validates the onboarding state, links the device context, and completes the MikroTik Hotspot login through RADIUS.

For operators using the onboarding reward, a customer who completes the required flow can receive three hours of unlimited Wi-Fi. Normal package, payment, expiry, and suspension rules continue after the reward period.

Passkeys solve private-MAC and device-change friction

Modern Android and iOS devices frequently use randomized MAC addresses. That is good for user privacy, but a Hotspot service that trusts only the MAC address can mistake a returning customer for a new device.

ISPbills now requires a passkey as part of Hotspot onboarding. When the MAC changes, the customer can prove control of the registered account with the passkey before ISPbills updates the network identity. This reduces support calls while keeping device recovery stronger than an automatic MAC replacement.

Passkeys require HTTPS and a supported full browser. When an Android captive-portal mini-window cannot use passkeys, the page provides an Open in Chrome action and a copyable secure link while preserving the original MikroTik login context.

Android behavior varies by device. Android and the device manufacturer decide whether a captive portal opens automatically or first appears as a “Sign in to Wi-Fi” notification. A web page cannot force Chrome to launch. ISPbills provides reliable captive detection and a one-tap full-browser handoff after the user opens the notification.

Clear live-photo checks for operator-required records

Where an operator must retain a subscriber identity image, the onboarding screen can require a full legal name and one live camera photo before Hotspot access is granted. The check runs through a private, local validation process and fails closed if verification is unavailable.

Images are rejected when they are too small, too dark, overexposed, blurry, contain no detectable face, or contain multiple faces. The resulting photo and validation details are stored as a private subscriber identity record, not published as a profile photo.

Operators remain responsible for presenting the correct privacy notice, defining retention and deletion periods, restricting staff access, and confirming that their use of identity images meets applicable law and licence conditions.

Built for MikroTik and RADIUS operations

The portal keeps the RouterOS session identity, client IP, client MAC, login endpoint, and logout endpoint together through OTP, social authentication, passkey, and external-browser transitions. After successful onboarding, ISPbills completes access against the correct MikroTik Hotspot session.

The deployment also supports the practical pre-login requirements: local Hotspot DNS, router DNS forwarding, and walled-garden access to the secure ISPbills portal and configured identity providers. The downloadable template can be installed in the active RouterOS Hotspot HTML directory and retained alongside a rollback copy.

What operators gain

  • Self-service registration without staff distributing every credential
  • English and Bangla onboarding for a broader customer base
  • OTP ownership checks through configured WhatsApp or SMS delivery
  • Passkey-based recovery for private-MAC rotation and device replacement
  • Optional Google and Facebook customer sign-in
  • Operator-required name and live-photo collection with automatic quality checks
  • RADIUS-backed package, expiry, usage, and suspension enforcement
  • A premium captive experience suitable for cafés, hotels, campuses, offices, and public Wi-Fi zones

Deployment and availability

The Premium Hotspot experience is available through ISPbills for managed MikroTik Hotspot deployments. Operators can configure their verification channels, identity requirements, social providers, packages, and access policies according to their own network and compliance needs.

Product basis: ISPbills Premium Hotspot functionality available on 5 September 2026. Final behavior depends on the operator’s MikroTik, RADIUS, messaging, identity-provider, package, and privacy configuration.