← Back to Spot Social for Business Hardware Guide

Supported Hardware

The Spot Social Captive Portal runs on OpenWrt. Your router doesn't need to be replaced — in many cases you just add one small device to your existing network.

Three common setups — pick yours

🏢 Scenario A: You already have pro-grade gear

You run a UniFi (UDM/UDM Pro/CloudKey), TP-Link Omada, Ruckus, Aruba Instant On, Cisco Meraki, or similar business Wi-Fi with multiple APs.

The right move is not to replace any of it. You add one tiny OpenWrt device that sits on your guest VLAN and handles just the captive portal. Your existing APs still broadcast the Wi-Fi and route traffic — the OpenWrt box is only there to serve the portal page and check MAC authorizations against the Spot Social API.

How it works in practice:

  1. Configure a guest VLAN on your network (one-time setup). Your existing APs broadcast a "Guest" SSID — guests get DHCP on the guest VLAN, isolated from your business network.
  2. Plug the OpenWrt device into the guest VLAN (or a port tagged for it). It runs our portal software. That's its only job.
  3. When a guest joins the SSID, the portal page appears. They check in via the app. The device OKs their MAC with our API, and traffic flows through your existing APs and router as normal.

Recommended for this setup:

DevicePriceWhy it fits
GL.iNet GL-MT1300 (Beryl)$60256 MB RAM, rock-stable, OpenWrt pre-installed. Just disable its Wi-Fi radios and wire it to your guest VLAN. The radios in your UniFi/Omada gear are infinitely better anyway — this box is only the "portal brain."
GL.iNet GL-AXT1800 (Slate AX)$130512 MB RAM, Wi-Fi 6. Same approach — wire to guest VLAN, let it run the portal. More headroom if you have high check-in volume.
Raspberry Pi 4/5 (2 GB+)$35–55Run OpenWrt on a Pi. Overkill in CPU, fine for a 50+ client venue. Add a case and an SD card. Perfect for the tinkerer who already has one in a drawer.
📌 The short version: your UDM Pro + 5 APs are still great. You're not replacing them. You're adding a $60 dedicated box that handles one job (portal auth), which your existing gear doesn't natively support. The GL.iNet Beryl is the sweet spot here — just plug it into your guest network port, run the installer, and you're done.

☕ Scenario B: Small venue buying new (cafe, barbershop, boutique, small bar)

You need one device that does it all: guest Wi-Fi, captive portal, and maybe a basic firewall. These devices are the all-in-one option.

DevicePriceMax clientsNotes
GL.iNet GL-MT1300 (Beryl)$6030–40Our top pick. 256 MB RAM, OpenWrt pre-installed, dual-band AC. No flashing required. Enough for a busy cafe.
GL.iNet GL-AXT1800 (Slate AX)$13050–70Wi-Fi 6, 512 MB RAM. Great for a louder venue with more devices. Also comes with OpenWrt pre-installed.
MikroTik hAP ac²$5540+Rock-solid, 128 MB RAM, excellent stability, dual-band. Flashes to OpenWrt easily. More configuration required but very reliable.
TP-Link Archer C7 v5$60–8030–40Massive OpenWrt community. Budget-friendly, well-tested. Needs manual firmware flash.

🏪 Scenario C: Larger venue or commercial deployment (busy bar, restaurant, coworking, hotel)

You need dedicated portal hardware that handles high client counts 24/7, or you want a purpose-built commercial router that runs OpenWrt natively. You'll typically pair one of these with your existing APs (see Scenario A) or use it as the main router for the guest network.

DevicePriceMax clientsNotes
MikroTik RB5009UG+S+IN$180100+Our top commercial pick. 1 GB RAM, 7-port, 10 GbE SFP+. Run OpenWrt or RouterOS with our portal. This is a real routing platform, not a toy. Handles a venue of any size when paired with your existing APs.
MikroTik hAP ax³$13070+Wi-Fi 6, 1 GB RAM. Great standalone option for a larger venue. OpenWrt 23.05+ support.
GL.iNet GL-MT6000 (Flint 2)$19080+Wi-Fi 6, 1 GB RAM, dual 2.5 GbE ports. OpenWrt pre-installed. Excellent for a busy venue with a wired backhaul.
x86 / PC (anything Celeron or better)$100–200200+Need maximum performance? Run OpenWrt on any x86 box (or a VM). The ultimate scalability — use your own hardware, install OpenWrt, plug it in. Popular choices include Protectli, Topton, Dell Wyse thin clients, or any old PC with two NICs.
📌 If you already have a server closet with a hypervisor, you can run OpenWrt in a VM or LXC container. Give it a virtual NIC on the guest VLAN, install the portal — zero rack space. This is the most practical path for existing managed networks.

Quick-reference table

DevicePriceRAMBest forOpenWrt pre-installed?
GL.iNet Beryl (MT1300)$60256 MBAdd-on portal box for pro networks, or SOHO all-in-one✅ Yes
GL.iNet Slate AX (AXT1800)$130512 MBHigher-traffic SOHO or portal box✅ Yes
GL.iNet Flint 2 (MT6000)$1901 GBLarger standalone venue✅ Yes
MikroTik hAP ac²$55128 MBBudget SOHO with reliabilityNeed to flash
MikroTik hAP ax³$1301 GBLarge venue standaloneNeed to flash
MikroTik RB5009$1801 GBCommercial routing + portalNeed to flash
Raspberry Pi 4/5$35–552–8 GBDIY portal boxNeed to flash
x86 PC or VM$100+AnyMaximum scale, managed networksNeed to install

If you already have none of this equipment and need the simplest possible path

A GL.iNet Mango ($22) really is enough for a very small venue (cafe, food truck, small shop). It runs OpenWrt out of the box, our installer takes 15 minutes, and it handles ~15–20 concurrent devices fine. But if you expect more than that, start with the Beryl ($60) instead — the extra RAM makes a real difference.

⚠️ Important: Flash-ability varies by hardware revision. A TP-Link Archer C7 v5 is well-supported; a v2 is not. Always look up your exact model + version on the OpenWrt Table of Hardware before buying used gear. GL.iNet and MikroTik are the safest bets because their support is known and consistent.

The architecture in one diagram

Your network → your APs (UniFi/Omada/etc.) → guest VLAN → Spot Social portal box (OpenWrt) → outbound to api.spotsocial.link. That's it. The portal box never accepts inbound traffic and never touches your business network. The device sits on the guest VLAN, serves the portal page, checks MACs against our API, and lets guests through. Everything else — routing, switching, APs — stays exactly as-is.

Minimum requirements

Don't forget: you can test with nothing at all

You can claim your venue and start seeing check-in analytics immediately on the limited dashboard — no hardware needed. The portal just unlocks the deeper data (dwell, bandwidth, live). If you want to see what the full dashboard feels like with simulated data (150+ sessions, devices, peak hours), upgrade to Verified and we'll walk you through setup on whatever hardware you pick. No commitment on the hardware side until you're ready.