Plain language

The Wi-Fi connection arrives before permission to use the internet.

Hotels, airports, cafes, campuses, hospitals, and guest offices often let your device join the local wireless network first. The network then asks you to accept terms, enter a voucher, use room details, or pay on a web page before it grants wider internet access.

That intermediate page is the captive portal. The Wi-Fi icon can already be visible while the portal is still waiting.

Detection

Your device tests whether the network behaves like the open internet.

Operating systems and browsers make small connectivity requests. A venue portal may redirect a plain request or return content that differs from the expected response. The device can then present a sign-in window.

Modern networks can also advertise a captive portal and provide session status through standard mechanisms. Older networks commonly rely on traffic interception.

Important limit

A completed portal is not a security certificate.

Completing the venue login means the network may grant internet access. It does not prove who operates the access point, that the router is uncompromised, or that every connection is protected.

Confirm the official network name with the venue and do not ignore certificate warnings to reach a login page.

Sources

First-party references.

  1. RFC 8952: Captive Portal ArchitectureInternet Engineering Task Force
  2. RFC 8908: Captive Portal APIInternet Engineering Task Force
  3. How to modernize your captive networkApple Developer
  4. Captive portal detectionMozilla Support

Keep going

Related help.

Published Sep 4, 2026 · Updated Sep 4, 2026 · ONEKAPISCH Editorial