Systems / UniFi Access
UniFi Access: hubs, readers, local API and upgrade options
By Tom Jin
UniFi Access is Ubiquiti's access-control application. It runs on a UniFi console on the office network, alongside other UniFi apps, and manages Ubiquiti's own door hubs, readers and intercoms. Administrators reach it through the UniFi portal, and it supports NFC cards, PIN codes, Touch Pass mobile credentials, visitor QR codes and, in recent versions, license plates.
UniFi Access is common in small offices that buy their own network equipment or work with an IT provider, because it fits into an existing UniFi network rather than needing a separate security server. It is newer than most traditional access systems in this class. Ubiquiti publishes a local API reference openly, with remote unlock, webhooks and a WebSocket feed, which makes UniFi Access one of the more open systems for small offices.
How to recognise UniFi Access
If your office network uses Ubiquiti UniFi equipment and doors are managed in an app called Access on the same UniFi console, you have UniFi Access. Administrators sign in through the UniFi portal and open the Access application, where the version number appears in its settings. At the doors you will see Ubiquiti readers, often with a small screen, and door hubs in the closet or above the door. Many sites also have a UniFi intercom at the entrance.
- An Access application on a UniFi console, reached through the UniFi portal at account.ui.com.
- Ubiquiti door hubs: Door Hub (UA-Hub-Door), Door Hub Mini (UA-Hub-Door-Mini), Gate Hub (UA-Hub-Gate) or Enterprise Access Hub (EAH-8).
- Ubiquiti readers: G2 or G3 Reader and Reader Pro, Reader Flex, Reader Lite, Access Ultra, or fingerprint models.
- A UniFi Intercom or G3 Intercom at the front door, sometimes with an Intercom Viewer inside.
- Staff opening doors with Touch Pass on their phones, or visitors with QR codes.
Still not sure? Follow how to identify your access control system.
Versions and editions
| Name | Details | Status | Source |
|---|---|---|---|
| UniFi Access 4.x | The API reference change log includes entries for 4.0.10 (doorbell triggering on Intercom and Reader Pro) and 4.2.16 (three-button unlock and double-driveway modes for the Gate Hub). The exact current release is not confirmed here. | current | source |
| UniFi Access 3.3.x | 3.3.10 added license plates, profile pictures, visitor QR codes, third-party NFC card import and more webhook events. 3.3.21 lets the remote unlock call set the actor name shown in logs and webhooks. | current | source |
| UniFi Access 2.2.10 | Added the webhook API and API server certificates. | unconfirmed | source |
| UniFi Access 1.9.1 | Minimum version for the UniFi Access API. | unconfirmed | source |
| Identity Enterprise | Ubiquiti's API reference states that the UniFi Access API is not available after upgrading to Identity Enterprise. | unconfirmed | source |
Hardware
| Name | Details | Status | Source |
|---|---|---|---|
| Door Hub (UA-Hub-Door), Door Hub Mini (UA-Hub-Door-Mini) | Single-door hubs. | current | source |
| Enterprise Access Hub (EAH-8) | Multi-door access hub. | current | source |
| Gate Hub (UA-Hub-Gate) | Hub for gates. | current | source |
| Retrofit Hub (UA-Retrofit-Hub-2) and Retrofit Readers | Retrofit hub and readers, including a fingerprint version, listed in Ubiquiti's tech specs. | current | source |
| G3 readers (UA-G3, UA-G3-Pro, UA-G3-Flex, UA-G3-Fingerprint) | Third-generation readers, including Reader Flex and a fingerprint model. | current | source |
| G2 readers (UA-G2, UA-G2-Pro) | Second-generation readers, still listed in Ubiquiti's tech specs. | current | source |
| Access Ultra (UA-Ultra), Reader Lite | Access Ultra is a reader that the API supports for remote unlock and temporary unlock; Reader Lite is a basic reader. | current | source |
| Intercoms (UA-Intercom, UA-G3-Intercom, UA-Intercom-Viewer) | Entrance intercoms and an indoor viewer. | current | source |
What is ending, and when
We found no dated end-of-sale or end-of-support notices for UniFi Access hardware in the pages we reviewed, and Ubiquiti's tech specs still list both second-generation (G2) and third-generation (G3) readers. UniFi Access is updated as an application on the UniFi console, and many features depend on the version: the API reference marks individual functions as needing 1.9.1, 2.2.10, 3.2.20, 3.3.10 or later. Keeping the Access application current is the main lifecycle task.
One change deserves a warning. Ubiquiti's API reference states that the UniFi Access API is not available after upgrading to Identity Enterprise. If you use, or plan to use, any software that connects through the Access API, check this before moving to Identity Enterprise. Dated notices for other brands are in our end-of-life tracker.
See every dated notice in the end-of-life tracker.
What offices commonly miss
- No record of who left on most doors. Like most card systems, exits usually release through a request-to-exit button or push bar with no credential, so the log shows who came in but not who went out unless exit readers are fitted.
- Upgrading to Identity Enterprise removes the UniFi Access API, according to Ubiquiti's reference. Anything connected through the API would stop working.
- The API is local to the console (HTTPS on port 12445). A cloud service needs a connector or secure tunnel inside the office network.
- Touch Pass mobile credentials are bought, not free: the API's purchase call needs a payment method set up in Access. Ubiquiti's price is not confirmed here. Features also depend on the Access version, so older consoles may lack webhooks or license plates.
- UniFi Access manages Ubiquiti's own hubs and readers. Moving from another access system usually means replacing door hardware, not just software.
Integration options
Ubiquiti publishes the UniFi Access API reference as a public PDF. The API runs on the console itself over HTTPS on port 12445, and an administrator creates an API token in Access settings, choosing its validity period and permission scopes; the token is shown only once. It needs UniFi Access 1.9.1 or later. The API covers users and groups, visitors, access policies, schedules and holidays, credentials (NFC cards, PIN codes, Touch Pass, QR codes and license plates), doors and door groups, devices, system logs and UniFi Identity invitations.
For door control, a remote unlock call opens a door and, from 3.3.21, can record a named actor in the logs and webhook. There are also temporary locking rules and a door emergency status. Events come through registered webhook endpoints, for example access.door.unlock on every unlock, door position sensor changes and emergency status changes, or through a WebSocket notification feed. Because the API is local, keep the console patched and limit who can reach port 12445.
Upgrade paths
Keep UniFi Access and add features in software
UniFi Access has a published local API with unlock and real-time events, so the doors can stay as they are while software adds what is missing, such as exit tracking or a live list of who is inside. Check the Identity Enterprise point first, and keep the Access application current.
Refresh within UniFi
Keep the console's Access application up to date, and replace or add readers and hubs with the current G3 range as needed. Sites with gates can use the Gate Hub, and larger sites the Enterprise Access Hub. G2 readers are still listed, so there is no forced swap.
Replace the platform
Moving off UniFi Access means new hubs, readers and credentials at every door. It can make sense if the office outgrows a network-equipment-based system or needs integrations that only a dedicated access platform offers, but Ubiquiti's published material gives no lifecycle reason to do it.
Compare the routes over three years in the savings calculator.
GateStride and UniFi Access
Not yet scheduled UniFi Access is Not yet scheduled on the GateStride compatibility list. It is not on our roadmap yet, and GateStride does not work with UniFi Access today. GateStride is in early access. Ubiquiti's published local API would make an integration practical, but no work has started. If your office runs UniFi Access, tell us; demand from real sites decides what we build next.
Questions about UniFi Access
- Does UniFi Access have an API?
- Yes. Ubiquiti publishes a UniFi Access API reference. The API runs on the UniFi console over HTTPS on port 12445 and uses an API token created in Access settings. It includes remote door unlock, users and credentials, visitors, system logs, webhooks and a WebSocket notification feed. It needs UniFi Access 1.9.1 or later.
- Will the API still work if we move to Identity Enterprise?
- Ubiquiti's API reference says no: the UniFi Access API is not available after upgrading to Identity Enterprise. If you rely on any software that connects to Access through the API, check with its supplier before you upgrade, because those connections would stop working.
- Can UniFi Access tell who has left the building?
- Usually not. Like most door systems, exits typically release with a request-to-exit button or push bar, so no credential is read on the way out. The log shows entries, not exits, unless you fit exit readers. Add-on software can help, but it still depends on how people leave.
- What credentials does UniFi Access support?
- According to Ubiquiti's API reference, UniFi Access handles NFC cards, PIN codes and Touch Pass mobile credentials for staff, QR codes for visitors, and license plates from version 3.3.10. Version 3.3.10 also added importing third-party NFC card IDs, which can help when moving from an older card system.
Related systems: ProdataKey pdk.io · Brivo Access · Paxton Net2
Sources
- https://assets.identity.ui.com/unifi-access/api_reference.pdf
- https://techspecs.ui.com/unifi/door-access
Last reviewed October 2026. UniFi Access and other product names are trademarks of their respective owners. GateStride is independent and not affiliated with, endorsed by or a dealer for any manufacturer.