PaySpot Docs
MikroTik guided setupBack to PaySpot

PaySpot Setup App

Set up MikroTik without exposing it to the internet

The Android app talks to RouterOS on the local network, then installs a secure outbound connection to PaySpot. It works with Starlink and does not require a public IP or additional hardware.

Download PaySpot Setup

Before you start

  • An Android phone connected to the MikroTik's local Wi-Fi or LAN.
  • The router address and a RouterOS administrator username and password.
  • The ISP or Starlink connection already plugged into the MikroTik WAN.
  • The correct PaySpot location selected as MikroTik during website onboarding.

What the app configures

  • Creates a private WireGuard path to PaySpot RADIUS that works behind Starlink CGNAT.
  • Installs the PaySpot captive-portal files and keeps a backup of replaced portal files.
  • Configures RADIUS authentication, accounting, session updates, and the correct NAS identity.
  • Adds the portal access required for customers to buy or recover vouchers before internet login.
  • Preserves unrelated WAN, main Wi-Fi, LAN, DHCP, and firewall settings.
  • Maps location → router → WAN → bridges/VLANs → APs → SSIDs/BSSIDs → captive portal.
  • Verifies WAN link/method, default route, DNS, external traffic and NAT before customer acceptance.
  • Discovers downstream APs/switches from bridge hosts, MAC fan-out, DHCP and LLDP/MNDP evidence, then confirms where Wi-Fi is actually broadcast.
  • Verifies association, guest IP, portal, voucher/trial, Internet, accounting and multi-AP roaming before reporting fully ready.

Complete setup flow

  1. 01Download and install the PaySpot Setup app from the website onboarding screen.
  2. 02Sign in with the same PaySpot tenant email and password used on the website.
  3. 03Choose the exact MikroTik location. Omada locations are protected and cannot be changed by the app.
  4. 04Enter the local router address and RouterOS credentials, then let the app inspect the real router configuration.
  5. 05Choose an existing HotSpot, or create a separate customer Wi-Fi name (SSID) on a supported local radio.
  6. 06Review the detected network and run configuration. Keep the phone connected until all seven stages finish.
  7. 07Return to website onboarding and select ‘I finished — check status’ before launching the storefront.

Customer acceptance ladder

  1. 1Associated: the real phone MAC/BSSID is observed on the intended AP path.
  2. 2Guest IP: its lease belongs to the selected guest bridge/VLAN and DHCP network.
  3. 3Portal: unauthenticated HTTP reaches the exact router/location commissioning marker.
  4. 4Authenticated or trial: a current RADIUS request/reply creates the expected HotSpot session.
  5. 5Internet: an HTTP 204 probe bound to Wi-Fi passes; mobile data cannot supply the result.
  6. 6Accounting: Start, Class correlation and an interim update reach PaySpot.
  7. 7Roaming: AP2 uses the same voucher, the old session is gone, one allowed session remains, and Internet resumes.

Voucher device policy

Latest login wins

PaySpot enforces each plan's maxDevices and sends Disconnect-Requests for replaced sessions. RouterOS shared-users remains a ceiling of 32. A person holding the voucher can replace its currently connected user.

Strict device limit

PaySpot rejects the incoming device when maxDevices is reached. This protects the current user, but stale sessions or randomized-MAC changes can temporarily make a valid voucher look used.

Safety and access lifecycle

Review the dry-run diff and download both rollback files before changes. Temporary setup rules carry an expiry and are removed after commissioning. Support access is tracked separately: keep it tunnel-only, never expose WebFig on WAN, and remove it only after the venue confirms the installation. AP management on a separate management VLAN is reported as a warning, not as a customer-connectivity failure.

If something stops the setup

Router cannot be reached

Confirm the phone is still connected to that router and try its local address, commonly http://192.168.88.1.

Sign-in is rejected

Use a RouterOS account with permission to inspect and configure HotSpot, interfaces, files, firewall, RADIUS, and WireGuard.

Create Wi-Fi is unavailable

The router may use an external access point, CAPsMAN, or have no locally managed radio. Configure the SSID on the access point, then choose an existing HotSpot.

Website is still waiting

Finish every app stage, keep the router online, then use ‘I finished — check status’ again.