> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wiacom.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Key Access

> Shared WPA2 passphrase delivered to registrants by email

Key Access is the base access tier in Wiacom. The venue operator sets a shared WPA2 passphrase for an SSID; Wiacom stores it securely and delivers it to each registered user with a scannable QR code.

Key Access is available for all vendors — with or without an API controller connection.

## How It Works

<Steps>
  <Step title="Admin sets the passphrase">The venue operator enters a WPA2 passphrase for the location's SSID in Wiacom.</Step>
  <Step title="Wiacom stores it securely">The passphrase is encrypted at rest. For API-connected controllers, Wiacom also pushes it to the SSID automatically.</Step>
  <Step title="User registers">A user registers through any onboarding channel — Guest Connect, portal, API, etc.</Step>
  <Step title="Network details delivered">The SSID and passphrase are delivered to the user. The QR code allows one-tap connection on supported devices. These details can optionally be shown on-screen at registration time and sent through one of the enabled communication channels. See [Messaging Services](/integrations/messaging).</Step>
  <Step title="User connects">The user connects to the SSID using the passphrase in the email.</Step>
</Steps>

## Key Access vs WiFi Pass

|                         | Key Access      | WiFi Pass                    |
| ----------------------- | --------------- | ---------------------------- |
| Credential type         | Shared WPA2 PSK | Unique personal PSK per user |
| Controller API required | Optional        | Yes for non RADIUS           |
| Individually revocable  | No              | Yes                          |
| Credential expiry       | No              | Yes (configurable)           |
| Per-user audit trail    | No              | Yes                          |

<Tip>
  Key Access is ideal for small venues, simple deployments, or as a fallback mode when API connectivity is unavailable. For individual, revocable credentials, upgrade to [WiFi Pass](/access-features/wifi-pass/overview).
</Tip>

## Resilience Mode

For API-connected controllers, Wiacom supports a **static SSID fallback** — the passphrase is stored in Wiacom and delivered by email even if the controller is temporarily unreachable. Guests receive valid credentials regardless of controller availability.

## Updating the Passphrase

Go to **Inventory → Controllers → \[controller] → \[SSID row] → Edit** and enter a new passphrase. For API-connected controllers, Wiacom pushes the change to the SSID immediately.

<Warning>
  Changing the shared passphrase disconnects all currently connected devices. All registered users with the old passphrase must reconnect using the new one.
</Warning>

## Vendor Support

Key Access works with any vendor that supports WPA2 Personal (all vendors). For API-connected controllers, Wiacom pushes the passphrase automatically. For legacy/manual deployments, the passphrase is managed in Wiacom and the admin configures the SSID on the device directly.
