What's new
GuestPass Cloud is currently v2.9.2 on the alpha channel ยท bridge agent v2.1.1.
Release channels
AlphaBleeding edge โ features are built here first. Opt in only to test the latest.
BetaStabilizing โ proven โฅ1 week in alpha, seasons โฅ1 month before production.
ProductionStable โ the default channel for everyone.
Features are built in alpha, promoted to beta after a clean week, seasoned a month, then released to production. Version numbers: alpha = major.incr.minor; beta = 26.major.incr.minor; production = 26.month.incr.minor. You'll be able to opt into an earlier channel and roll back up to two revisions.
v2.9.2 alpha
2026-09-07 โ Google Workspace sync stops crying wolf
- Fixed: whenever Google's sign-in service had a brief hiccup, the Logs tab recorded it as โtoken refresh failed โ reconnect in Domain consoleโ, which read like the Workspace connection had broken when nothing was wrong and the next check fifteen minutes later worked fine. Now a real, permanent problem (the connection was revoked or expired) still says reconnect and names the reason, while a temporary outage is logged separately as a retry so it can be ignored.
v2.9.1 alpha
2026-08-24 โ Public pages answer link checkers and uptime monitors properly
- Fixed: tools that ask a page โare you there?โ without downloading it โ uptime monitors, link checkers, search engines, and scripted bridge downloads โ were being bounced to the sign-in page on every public page, including the home page, pricing, and the bridge installer download. They now get the same answer a browser does.
v2.9.0 alpha
2026-08-12 โ Simple Portals is live โ your own guest sign-in page
- The captive portal works. Point a UniFi guest network at your portal address and guests land on your page instead of UniFi's: they enter an access code or tap through free WiFi, and GuestPass authorizes their device on the controller.
- New Guest portal tab on every site โ switch it on, choose your address, pick how guests sign in, write the headline and terms, and copy the exact values to paste into UniFi. Step-by-step controller instructions are on the tab, including which hostname to allow in the walled garden.
- Sign-in methods: access code, free/accept-terms, and (on Portal Pro) site number + last name โ no code for the guest to lose, matched against the vouchers the front desk already issued. Self-pay is next.
- Every sign-in attempt is recorded โ device, method, package, guest, and whether it worked โ so a property can see who was on their network and why someone couldn't get on.
- Works in front of other controllers too, not just UniFi: the client MAC is read from whichever parameter the vendor sends.
- Professional now includes white-label branding, so a company can present GuestPass as their own tool to their staff.
- Portal add-ons for extra portals, and a Custom tier for properties that need integrations built around how they actually work.
- The entry Portal plan carries GuestPass branding and a โpowered by Simple Technologiesโ footer; Portal Plus and above put your own logo and colors on the page.
v2.8.0 alpha
2026-08-12 โ Simple Portals becomes a product ยท new pricing page ยท pricing controls
- Simple Portals โ the guest-facing captive portal โ is now a real product line with its own plans, bought alongside GuestPass rather than inside it. A company carries a portal plan independently of its voucher plan, so either can move a tier, be added, or be dropped without disturbing the other. MSP partners can resell both.
- Rebuilt the pricing page around the two products: what staff use, and what guests see. Every plan now spells out its limits and features in a full comparison, instead of a bare count.
- Bridge check-in speed is now a plan benefit. The agent's interval is set by the cloud from the plan โ 20s on Local down to 2s on Professional โ so how quickly a voucher reaches the controller (and how fast a guest gets online at the portal) is a real difference between tiers rather than a constant baked into the agent.
- Domain console: pricing policy card for annual, MSP wholesale, and both-products bundle discounts, and the plan editor now covers Simple Portals plans too.
- The thermal receipt now prints the paired PPSK WiFi password alongside the code. It was on the browser receipt but missing from the printed slip โ which is the copy the guest actually walks away with.
- Bridge agent v2.1.1: the agent checks whether it can reach the controller and reports it on every check-in, so a bridge that can no longer see UniFi turns red on its own instead of waiting for someone to press a test button.
- New "Unpair bridge" control: rotates a site's pairing token so a machine that's no longer the bridge stops connecting โ for when the agent moves to a different PC.
v2.7.0 alpha
2026-08-12 โ Install GuestPass as an app + internal tools split out
- GuestPass installs like a desktop app. Chrome and Edge now show an install button in the address bar; iPads use Add to Home Screen. Installed, it gets its own taskbar icon and a clean window with no browser chrome โ a real improvement for a front desk that lives in this all day.
- Introduced internal tools: capabilities Simple Technologies builds for its own operations, granted per organization rather than sold in a plan. Technician WiFi credentials is the first, and it's now off for everyone by default โ including MSP partners, who get it on request.
- Removed POS integrations entirely. The capability was retired months ago but was still listed on pricing, still sold as a $10 add-on, and โ worse โ ePOS receipt printing was gated behind it, so the wrong plans could and couldn't print for reasons nobody could have guessed.
- Swept customer-facing copy for references to internal vendor tooling.
v2.6.1 alpha
2026-08-12 โ Bridge agent catches up + honest connection status
- Bridge agent v2.1.0: the installed Windows agent now supports the client manager, device bypass, and PPSK. These features shipped to the cloud app but the installed agent had never been taught the commands โ anyone running the MSI or EXE would have seen them fail. The PowerShell script had them; the real agent did not.
- "Test both paths" now actually contacts the controller instead of only confirming the agent answered. It reported success without ever making a controller call, so a site could pass its own test while being completely unable to reach UniFi.
- Bridge status now separates the two hops it was conflating: "agent checking in" (the agent reached us) and "controller reachable" (that PC can reach UniFi). An agent running on a laptop that left the property was showing a green light.
- Tech WiFi credentials are now only offered to MSP partners and Simple Technologies staff. Direct customers were being shown a card built for deploying a service provider's technician logins across many properties โ nothing they have any use for.
- Trials are now per plan rather than one per organization. Trying Remote no longer blocks trying Business, so there's no need to subscribe blind to evaluate a higher tier.
- Plan cards list what each tier actually includes, marking what's new versus the tier below, instead of an unhelpful feature count.
- Site Settings now explains that Cloud API is a paid capability when a plan doesn't include it, instead of describing failover options next to fields that were never there.
v2.6.0 alpha
2026-08-12 โ Guest credential modes โ vouchers, PPSK, or both together
- Each site now chooses what the front desk hands a guest: voucher codes only, PPSK WiFi passwords only, vouchers paired with a matching password, or both issued separately.
- Paired mode is the headline: create a voucher and the guest also gets a private WiFi password on the same package. Both print on the receipt, so a guest who can't work the captive portal just joins the network and types the password instead.
- A paired password lives and dies with its voucher โ revoke the voucher (individually or in bulk) or let it reach its printed expiration, and the password comes off the controller automatically.
- PPSK keys now require a package, and the package's duration is the key's expiration. Expired keys are swept off the controller every 15 minutes, with a "Clean up expired" button for doing it on demand. This keeps a busy property clear of UniFi's per-network key ceiling without anyone tracking it by hand.
- Free WiFi is now just a package with a long duration rather than a special case โ build a complimentary package at whatever speed and duration suits the property, and it works for both vouchers and PPSK.
- The PPSK list shows each key's expiration, flags expired and paired keys, and sorts what needs attention to the top.
- Fixed: the device-bypass "require a package" toggle saved the wrong value and always read as off.
v2.5.0 alpha
2026-08-11 โ PPSK per-guest WiFi passwords + MAC bypass improvements
- PPSK (Private Pre-Shared Keys): each guest or device can now get a unique WiFi password โ no portal, no browser needed. The tech generates a readable passphrase (e.g. pine-lake-4821), and the guest just connects. Perfect for long-stay guests and smart devices that can't handle a captive portal.
- PPSK keys are pushed directly to the UniFi WLAN via the bridge, so they appear instantly on the controller. Each key is revealed on demand (click to show) and removed in one click.
- Configure which SSID(s) support PPSK in site Settings โ GuestPass fetches all WLANs from the controller and shows which ones are in IPSK mode (the requirement for per-guest passwords).
- Plan-gated: Standard plan gets 1 PPSK SSID; Pro gets unlimited; Starter and Free do not include PPSK.
- MAC bypass now defaults to requiring a speed package โ no-package 'unlimited/complimentary' bypass must be explicitly enabled in site Settings. Prevents accidental unmetered bypasses.
- Fixed: site action routes with dashes in the path segment (mac-bypass, ppsk-ssid) were silently unreachable due to a regex mismatch โ all those routes now work correctly.
v2.4.1 alpha
2026-07-27 โ Security hardening
- Changing your password now signs out every other device โ a stolen session can no longer survive the fix.
- Added browser security headers across the app: clickjacking protection, MIME-sniffing protection, a content security policy, and a referrer policy that stops password-reset and invite links from leaking to other sites.
v2.4.0 alpha
2026-07-27 โ New public website
- The marketing site people land on has been rebuilt to match the product: a proper hero, a live preview of the voucher screen, how-it-works, features, an MSP section, pricing at a glance, and an FAQ.
- Pricing on the homepage reads live plan data, so it can never drift from what we actually charge.
- White-labelled customer domains show a short branded sign-in page instead of GuestPass marketing.
v2.3.0 alpha
2026-07-27 โ Three billing paths + move companies between organizations
- Billing is now organized around how money actually travels: MSP partners are invoiced the wholesale sum of their managed companies, direct customers are charged retail through Stripe, and Simple Technologies' own managed customers are tracked but never billed here.
- The MSP wholesale rate (% off retail) is configurable, and each MSP's margin is shown alongside what we invoice them.
- Companies can be moved between organizations โ a direct customer into an MSP, out of an MSP, or in and out of Simple Technologies. Access, tech WiFi credentials, and billing responsibility all follow the move.
- An MSP can no longer be converted into a direct customer โ move its companies out first.
- Fixed: saving an organization could silently change its account type.
v2.2.1 alpha
2026-07-27 โ Scheduler hardening โ one failing sweep can no longer stop the rest
- The 15-minute background job runs three sweeps (voucher expiry, Google account sync, monthly licensing digest). The voucher sweep wasn't error-guarded, so a single database hiccup there could silently stop the other two for that run.
- Each sweep is now independently guarded, and any failure is recorded in the Health tab's error log instead of disappearing.
- Health tab now distinguishes a scheduler that starts from one that finishes: a run that begins but doesn't complete shows "starting but not finishing" instead of a green "alive".
v2.2.0 alpha
2026-07-20 โ Domain console: unified Organizations, drill-down in the shell, org types & Settings
- The organization drill-down now lives inside the sidebar shell โ no more old-design page when you open a company or organization.
- Org tree is merged into Organizations: one view with the table on top and the full hierarchy below.
- Creating an organization now offers three account types โ Managed by ST (billed off-platform), Direct customer (Stripe), and MSP (wholesale) โ the foundation for the three billing paths.
- New Settings section in the domain console (platform info, your account, team, branding).
- Seeded technician and front-desk accounts across the test organizations so every role can be explored.
v2.1.0 alpha
2026-07-20 โ Sidebar everywhere โ the whole customer app matches the console
- The entire logged-in customer app now wears the GuestPass Platform sidebar shell โ same left navigation, gold accents, and circuit texture as the domain console. No more old top-nav design.
- The sidebar is sticky and collapsible: a รขหยฐ button shows/hides it (remembered per browser).
- Company plan & billing are set from the domain console's organization drill-down (fixes 'where do I bill this company').
- Cleaned out the junk test data and seeded a realistic set: two MSPs with managed companies and two direct-signup customers, so every billing scenario can be explored.
v2.0.0 alpha
2026-07-20 โ GuestPass Platform redesign + release-channel model
- Adopted a three-channel release model: alpha โ beta โ production. Alpha uses 3-number versions (major.incremental.minor); this redesign resets the line to 2.0.0 in alpha. Beta and production add a leading year/month.
- Promotion path: build in alpha, promote to beta after a clean week, season a month, then production. Customers will be able to opt into alpha/beta, and roll back up to two revisions.
- Domain console rebuilt as the GuestPass Platform sidebar shell (gold + Medula One + circuit texture); the same shell will roll out across the rest of the app next.
- Company plan & billing are now set directly from the domain console's organization drill-down.
- New hexagon favicon, a context switcher, and a bolder circuit background.
v1.12.0 production
2026-07-20 โ Domain console redesign โ GuestPass Platform shell
- The Domain console is rebuilt as a full sidebar console: grouped navigation (Platform / Commerce / Governance), a context switcher, breadcrumb, and an in-view filter search.
- New "premium" visual layer โ gold accents, the Medula One display typeface for headings and figures, and a subtle circuit-board texture โ over the existing dark/light themes.
- Sidebar badges surface what needs attention at a glance: new feedback, offline bridges, org count.
- All existing console data and tools are unchanged โ this is the chrome and theme around them. (Designed by Chase in Claude Design.)
v1.11.0 production
2026-07-20 โ Bridge 2.0: Windows Service + MSI installer
- The bridge agent is now a real Windows Service: starts with the PC before anyone logs in, and Windows restarts it automatically on failure โ the recurring 'bridge quietly died' problem is over.
- One-click MSI installer (also silent-deployable via RMM: msiexec /i GuestPassBridge.msi /qn) โ built for NinjaOne rollouts.
- Config now lives in C:\ProgramData\GuestPassBridge\ and survives upgrades; the service waits patiently for config.json instead of exiting, so RMM can install first and configure second.
- The agent keeps a local troubleshooting log (ProgramData\GuestPassBridge\bridge.log, self-rotating).
- Same binary still runs as a plain portable app on Windows, Mac, and Linux.
v1.10.0 production
2026-07-20 โ Health tab: full backend observability
- Domain console โ Health: scheduler heartbeat (with a loud STALLED warning if the cron stops), bridge fleet table (version, last poll, queued & errored commands), server error log, 7-day activity pulse, and data-volume counts.
- Every unhandled server error โ web request or cron โ is now captured to the error log. A 500 nobody screenshots is still a 500 we see.
- Silent cron failures (Google puller, licensing digest) now surface in the error log instead of vanishing.
v1.9.0 production
2026-07-20 โ In-app feedback, bug reports & crash capture
- Every signed-in page now has a รฐลธโยฌ button: report a bug, a problem, or an idea in two clicks โ the page you're on rides along so we can reproduce it.
- Browser errors are captured automatically (once per session) as crash reports.
- Domain console โ Feedback tab: full triage queue with statuses and resolution notes.
- Reports are reviewed โ and bugs fixed โ on a weekly automated maintenance pass.
v1.8.0 production
2026-07-19 โ Licensing snapshots + monthly digest into Odoo CRM
- The Licensing tab now archives dated snapshots (CSV + JSON) and shows the full history with downloads.
- Monthly digest: on the 1st, the scheduler snapshots licensing, computes what changed since last month (new companies, plan moves, tech WiFi flips, revenue delta), and emails it โ CSV attached โ to a configurable address.
- Pointed at an Odoo CRM email alias, every month becomes a pipeline entry to work MSP subscription updates from.
- Snapshot + send-now button for on-demand runs.
v1.7.0 production
2026-07-19 โ Licensing report, all-company auto-join, tech WiFi on company pages
- Domain console โ Licensing tab: live rollup of every organization โ each company's plan, retail price, sites, bridges, users, and tech WiFi status, with per-org totals and a CSV export. The foundation for MSP wholesale billing.
- Auto-join by email domain can now target "All companies" โ new sign-ups with your domain land in every company you manage, including ones you add later.
- Tech WiFi credentials can be enabled, VLAN-tuned, or disabled right on each company's own page (not just the Organization page).
v1.6.0 production
2026-07-19 โ Org security policy: bring your own Duo, Google-only sign-in
- New Security policy card on the Organization page: require 2FA, require Google sign-in (passwords off), session length โ no more digging for these.
- Bring-your-own Duo: organizations can connect their Duo account (Web SDK app) and every team sign-in โ password or Google โ gets the Duo push. Credentials are health-checked before saving and stored encrypted.
- An org running Duo automatically satisfies its own 2FA requirement โ no double enrollment in authenticator apps.
- Fixed: the domain console's "require 2FA" toggle was saving under a key the enforcement never read โ org-enforced 2FA now actually enforces.
- MSP plan pricing is now sales-assisted everywhere: "Let's talk" + contact Simple Technologies instead of a public price.
v1.5.1 production
2026-07-19 โ Per-company technician VLAN
- Each company's Tech WiFi card now has a Technician VLAN setting โ one VLAN applied to every tech credential deployed at that property (RADIUS-assigned), for networks that don't put staff on the default LAN.
- Changing the VLAN and hitting Update re-pushes every credential with the new assignment.
v1.5.0 production
2026-07-19 โ Versioning, changelog & help center overhaul
- Version number and release channel now shown in the footer and Domain console, with this public changelog.
- Help & Support completely rebuilt: system overview, UniFi API key walkthrough, bridge deep-dive, tech WiFi credential setup (WPA-Enterprise/RADIUS), troubleshooting.
- Bridge v1.2: the agent now reports its version, shown on the site's connection panel.
- New bridge sites in a company with Tech WiFi enabled receive the whole team's credentials automatically on first check-in.
v1.4.0 production
2026-07-19 โ Tech Network Credentials + Google Workspace sync
- Personal technician WiFi credentials (RADIUS): each team member generates a 5-word passphrase in My Account; it deploys to every enabled property automatically.
- Per-company Tech WiFi toggle on the Organization page โ enabling a property pushes the whole team's credentials to its controllers.
- Leaving the team (or being removed) deprovisions the credential from every site.
- Google Workspace sync: suspend someone in Google Admin and within 15 minutes they're signed out, locked out, and their WiFi credential is removed everywhere.
- SSO-only policy now enforced: orgs can require Google sign-in (passwords refused).
- Bridge v1.1: sync_radius / remove_radius_by_name commands.
v1.3.0 production
2026-07-16 โ Voucher expiration modes & Active-tab overhaul
- Two voucher modes per site: Simple Technologies fixed-date mode (printed expiration, enforced by auto-revoke every 15 minutes) and UniFi classic mode (timer starts at first connection).
- Active vouchers: In-use/Unused filters, select-all + bulk revoke, bulk print with printer picker and cut choice, 'hide unused older than N days'.
- Receipts say exactly what happens: a real expiration date, or 'timer starts at first connection'.
- Bridge install guide rewritten with a field-by-field config.json explanation.
v1.2.0 production
2026-07-15 โ Local plan on-site lock & deep org auditing
- Free (Local) plan is now genuinely local: voucher actions work only from the site's own network; Remote unlocks anywhere-access.
- Domain console: per-organization drill-down with team, sites, voucher stats, billing events, and a 100-entry audit trail.
v1.1.0 production
2026-07-14 โ Admin portal split, Duo 2FA & help center
- Simple Technologies Domain console moved to its own address (admin-gpc), Google sign-in only, Duo two-factor for staff.
- Domain Team management with permission scopes (owner/admin/billing/support).
- Stripe promo codes, in-app Help & Support, theme accent customization, user manual.
v1.0.0 production
2026-07-13 โ Production launch รฐลธลกโฌ
- guestpass.simple-technologies.net goes live with real Stripe billing, trials, and email (verification, resets, invites).
- Bridge agent v1.0: native Windows/Mac/Linux builds replace the PowerShell script, with autostart.
- MSP demo booking, pricing page, legal pages.
v0.9 beta
2026-07-04 โ Beta: the whole foundation
- Companies โ sites โ team model, voucher packages with editable form fields, cloud API + local bridge with automatic failover, ePOS receipt printing, RADIUS user management, entitlements engine, white-label branding, 2FA, custom roles, backup/restore, reporting.
Questions about a release? support@simple-technologies.com