Hotel WiFi login by room number and surname: how PMS login works
A hotel WiFi sign-in page that asks for a room number and the guest's surname is checking the guest against the property management system (PMS), the software that holds the hotel's reservations. The method is known as PMS login or reservation login. It ties each WiFi session to a stay, and it only works with an interface between the captive portal and the PMS.
This guide explains how the check works, how a portal connects to a PMS, what the method does well and where it falls short, and the alternatives a hotel can use without a PMS interface. CaptiFi does not integrate with any PMS, and the last sections set out what it offers hotels instead. The PMS facts come from Oracle's interface specification and the Mews developer documentation, listed at the end.
How room number and surname login works
- The guest joins the hotel's guest network and the captive portal page opens.
- The page asks for a room number and the surname on the booking, with the hotel's WiFi terms.
- The portal sends both to the PMS, directly or through an interface server, and asks whether a checked-in reservation matches.
- If one does, the portal tells the WiFi controller to let the device online, for a session that can run to the departure date on the reservation.
- If none does, the page shows an error, and the guest tries again or asks at reception.
- When the PMS records the check-out, the portal ends the session or stops renewing it, and that room number and surname stop working.
On the PMS side, the trigger is the stay changing state. Oracle's FIAS specification, which third-party systems use to exchange data with Oracle Hospitality property management systems such as OPERA, defines a Guest Check-in record (GI), a Guest Check-out record (GO) and a Guest data change record (GC). A check-in record can carry the room number, the reservation number, the guest's name and first name, and the arrival and departure dates. The Mews developer documentation puts internet access among its guest technology use cases and says these integrations need to know about reservation changes, "especially when a reservation is checked-in and checked-out". It recommends subscribing to webhooks or WebSockets "rather than polling the API for state changes".
How the portal talks to the PMS
A portal reaches a PMS in one of two ways.
With an on-premises PMS, the connection runs through the PMS vendor's interface. FIAS lists "In-Room Internet Systems" among its interface types, and the specification says the link "is designed to be contained within a local area network infrastructure and not for transmission through active components over the internet". A cloud-hosted portal therefore needs something on the hotel's network to hold that link, such as an interface server. Ask the PMS provider who supplies it, who supports it and what it costs before choosing a WiFi platform.
With a cloud PMS, the portal calls the PMS provider's API over the internet with credentials issued for the property. The Mews Connector API covers reservations and customers, and the portal can follow check-ins and check-outs through Mews's notification events.
Checking a booking only needs read access. Charging WiFi to the room bill is a different job: FIAS includes posting records that the external system sends to the PMS against a room number, so a portal that bills a premium tier to the room needs an interface allowed to post charges. Agree with the PMS provider which records the WiFi system may send before it goes live.
A platform that offers PMS login should name the systems it supports. Spotipo's guide, published in August 2026, names Cloudbeds and Zonal and says further systems can be added. Check that your PMS is on a platform's list before you choose it for reservation login.
What PMS login does well
- Access follows the stay. A guest gets online with details they already know, and the check-out ends it, so former guests and people outside the building stop using the network.
- There is no shared password to print on key card wallets, change and reprint.
- Each session links to a reservation, which matters when a hotel sells faster WiFi charged to the room or wants to know which stays used the network.
Where PMS login falls short
Names are the first problem. FIAS notes that "the format of the name is configurable in the PMS", so what the portal compares against depends on the hotel's settings. A guest who types an accent, a hyphen or a second surname differently from the booking, or whose room was booked by a colleague, a travel agent or a company, fails the check and goes to reception.
Shared rooms add another failure. Where an interface supports several guests per room, the specification requires a reservation number and a share flag "to prevent overwriting current guest data". A portal that checks one room against one surname may let the booker in and turn away the person travelling with them, unless the integration handles sharers.
Non-residents are left out. Restaurant diners, spa visitors, conference delegates and people meeting a guest in the bar have no booking to match, so the hotel needs a second sign-in method for them on the same network or on another one.
The credential is weak. Room numbers follow a pattern, and a surname can be overheard at reception or read off a luggage label. Limit failed attempts per device, and keep reservation details off the portal page.
The login adds no contact details. The PMS holds whatever details came with the booking, and a room number login collects no email address, mobile number or marketing consent from anyone in the party. A hotel that wants a guest list still needs a form, with the marketing opt-in kept separate from the WiFi terms. The hotel WiFi marketing guide covers what to do with that list.
Device addresses change, whatever the login. An iPhone joins each network with a private address. Apple says it chooses a Fixed address by default on networks with WPA2 or stronger security and a Rotating one on networks with weak or no security, and that a Rotating address changes every 2 weeks. Android 10 and later use a randomised address per network by default, which stays the same until a factory reset. On an open guest network, a guest staying longer than two weeks may be asked to sign in again partway through.
The alternatives a hotel can use
| Method | What the guest does | How long access lasts | Contact details for the hotel | Needs a PMS interface |
|---|---|---|---|---|
| Room number and surname | Types both | Until check-out | None | Yes |
| Voucher code from reception | Types a code handed over at check-in | The code's duration | None, unless the page also asks | No |
| Email or phone form | Enters an email address or mobile number | A session length the hotel sets | Yes, with consent recorded | No |
| Paid pass | Picks a pass and pays | The pass length | Yes, from the payment | No |
| Click-through terms | Ticks a box | A session length the hotel sets | None | No |
| Password on the key card wallet | Types the password | Until the password changes | None | No |
A hotel can combine them: a voucher or room login for residents, a form for restaurant and spa visitors, and a paid pass for faster speeds. The guide to guest WiFi login options compares each method in more depth.
What CaptiFi offers hotels instead
CaptiFi has no PMS integration. It cannot check a room number and surname against OPERA, Mews, Cloudbeds or any other property management system, and it cannot post a WiFi charge to a room bill. If reservation login is a requirement, choose a platform that names your PMS; the comparison of guest WiFi platforms for hotels sets out the options.
Without a PMS link, a hotel on CaptiFi has these tools:
- Guests sign in with an email address or a phone number on a branded form, and marketing consent is asked separately from getting online: on the standard sign-in page it is its own question after the guest taps Connect, with Accept and Reject buttons. Each guest in a party can sign in with their own details, and returning devices are recognised and let straight through.
- The session length is set per venue in minutes, hours or days, so the hotel decides how long a sign-in lasts before the page appears again.
- WiFi vouchers put a code between the guest and the network, which suits a code handed over at check-in. Codes are eight characters, generated up to 100 at a time, and each batch has its own access duration, so reception can keep a one-night batch and a two-night batch side by side. A code that is being shared can be revoked, and a till can create codes through the voucher API, up to 50 per request.
- Paid WiFi sells timed passes on the splash page: up to 8 per venue, from 30 minutes to 7 days, paid by card, Apple Pay or Google Pay into the hotel's own Stripe account with no CaptiFi commission. Passes can carry speed tiers from 1 to 500 Mbps, enforced on UniFi, with a free taster of 50 MB to 1 GB first. The guide to paid WiFi speed tiers for hotels and coworking spaces covers how to price them.
- On Growth and above, the Revinate integration sends WiFi guests who opted in to the hotel's Revinate list, including restaurant, bar and spa guests who never appear in the PMS, and automated review requests go out after a visit.
- On Pro, the multi-site dashboard shows every property together, with combined figures.
Vouchers and paid WiFi are included from Essentials, which starts from $69/mo on the pricing page.
Choosing a login method for your property
PMS login suits a property that already runs a PMS with a WiFi interface, sells a premium tier charged to rooms, and has someone to support the link. A voucher handed over at check-in gives a small hotel, B&B or serviced apartment block similar control over who gets online, with no interface to buy or maintain. Whichever method controls access, a property that wants a guest list for direct bookings needs an email or phone form, and one with a busy restaurant or spa needs a way in for people who are not staying.
To try the sign-in form, vouchers and paid passes on your own network, start a 30-day free trial.
Sources: Oracle, Oracle Hospitality Hotel Property Interface IFC8 FIAS Specification, Release 2.20.25 (May 2022); Mews, Connector API: Guest technology; Apple Support, Use private Wi-Fi addresses on Apple devices; Android Open Source Project, MAC randomization behavior; Spotipo, Guest WiFi and your PMS: how reservation login works (August 2026); CaptiFi's customer documentation, including its Revinate setup guide, October 2026. Oracle, OPERA, Mews, Cloudbeds, Zonal, Spotipo, Revinate, Apple, iPhone, Android, UniFi and Stripe are trade marks of their owners; CaptiFi is not affiliated with or endorsed by them.
Frequently asked questions
Quick answers to the most common questions about this topic.
How does hotel WiFi login with a room number and surname work?
Does CaptiFi integrate with hotel property management systems?
What happens to hotel WiFi access at check-out?
What if a hotel booking is in someone else's name?
Can hotel WiFi be charged to the guest's room bill?
Is a room number and surname a secure WiFi login?
How can a hotel offer WiFi to restaurant and spa visitors who are not staying?
The CaptiFi Editorial Team writes about guest WiFi marketing, captive portals, GDPR-compliant data capture, and local SEO for venue operators. We base our recommendations on real customer outcomes and verified third-party reviews from G2.com.
Ready to turn your guest WiFi into a marketing engine?
CaptiFi captures customer data from every WiFi login, automates Google reviews and email follow-ups, and plugs into the tools you already use. Hardware included (refundable deposit), transparent pricing, 30-day free trial.