Skip to content

Features

SpherAAA is a cloud RADIUS and Diameter platform for Wi-Fi, wired, VPN and mobile/SIM authentication. Instead of a fixed set of rules, your access policy is a script you write and control, and you test it in separate environments before it goes live.

At a glance

  • Authentication: EAP-TLS, EAP-TTLS, PEAP, MAC Authentication Bypass, private PSK, and EAP-AKA for SIM devices.
  • Certificates: a built-in CA, with self-service enrollment over SCEP and EST.
  • Policy: PolicyLogic scripts, with test tools, debug traces and call-flow diagrams.
  • Integrations: Microsoft Entra ID and Intune, partner AAA servers, OpenRoaming and eduroam, and a REST API.
  • Security: RADSEC, Blast-RADIUS protection, field-level encryption, and a vault for secrets.
  • Providers: multi-tenant MSP accounts and isolated environments.

The rest of this page lists every feature by area. Where a feature has its own page, it's linked so you can go straight to the details.

Core RADIUS & AAA

Feature Description
RADIUS server Access-Request/Accept/Reject and Accounting, over plain UDP, TCP, or RADSEC (RADIUS over TLS).
RADIUS proxy / relay Forward requests to an upstream AAA server, with load balancing and failover. See Federation & proxying.
Disconnect-Message (DM) and Change-of-Authorization (CoA) Push session changes or disconnects to a NAS from PolicyLogic, or via the API.
Blast-RADIUS mitigation Require the Message-Authenticator attribute on incoming requests, per NAS.
Custom RADIUS attribute dictionary Define your own Vendor-Specific Attributes (VSAs) alongside the built-in, shared attribute dictionary.
RFC5580 location data Read and act on NAS-supplied location attributes (civic location, geo-coordinates) in PolicyLogic.
Environment-based traffic isolation Every NAS, Diameter peer, and PolicyLogic script is scoped to an environment (Dev/Test/Stage/Prod, or a configured Proxy environment), so you can build and test changes without touching production traffic.

Diameter & mobile (3GPP)

Full details: Diameter

Feature Description
Diameter peer connections Dial out to a carrier/HSS (Server role), or accept inbound Diameter connections matched by source Host/IP (Client role).
EAP-AKA / EAP-AKA' authentication Authenticate mobile/SIM subscribers against a carrier's HSS over Diameter/SWx, covering identity decryption, vector fetch, and challenge/response in one flow.
EAP-AKA identity privacy Decrypt RSA-encrypted permanent identities (IMSI) sent by clients that use identity privacy, for both EAP-AKA and EAP-AKA', detected automatically.
EAP-AKA proxying Forward a decrypted subscriber identity on to their home 3GPP-AAA instead of authenticating locally.
Diameter peer groups & load balancing Share a group name across multiple peers to load-balance EAP-AKA/SWx traffic, round-robin or random.
Diameter Peer TLS Mutual TLS for outbound Diameter connections, with existing-certificate or generate-new-certificate options and TLS 1.2/1.3 version control.
Diameter Certificates management A dedicated page for importing and tracking the certificates used by outbound Diameter connections, separate from RADIUS/RADSEC certificates.
Diameter-RADIUS-HTTP bridging Combine Diameter, RADIUS, and HTTP calls within a single PolicyLogic script to route or bridge between them, rather than needing a separate proxy/bridge product.

Authentication methods

Feature Description
EAP-TLS Certificate-based mutual authentication, with per-request control over which server certificate, TLS versions, and cipher suites are used.
EAP-TTLS Tunneled authentication with PAP, EAP-GTC, or MSCHAPv2 inner methods, no client certificate required.
EAP-PEAP Tunneled authentication protecting inner credentials inside a TLS tunnel.
MAC Authentication Bypass (MAB) Authenticate devices that can't run 802.1X (printers, cameras, IoT) by their MAC address against a pre-registered device list.
Raw/PAP RADIUS authentication Authenticate directly against attributes in the request (username/password, pre-shared key, etc.) without an EAP exchange, including Private PSK / DPSK flows that assign a dynamic VLAN per device.
Fast-Reauth (TLS session resumption) Let a previously-authenticated EAP-TLS/TTLS/PEAP client reconnect without repeating credential or certificate checks, with PolicyLogic staying in control of the accept/reject decision every time.
OCSP checking Query an OCSP responder for EAP-TLS client certificate status and act on the result in PolicyLogic (SpherAAA surfaces the status; your script decides whether to reject).
Configurable TLS versions & cipher suites Restrict or permit specific TLS protocol versions and cipher suites per EAP method, per request.
Access-control patterns Account lockout after repeated failures, device-count caps per user, concurrent session limits, and MAC-to-username binding. These are implemented as PolicyLogic scripts, not hardcoded product settings, so you can adapt them to your own policy.

Identity provider integrations

Feature Description
Microsoft Entra ID credential check Validate a username/password directly against Entra ID (ROPC flow) from within PolicyLogic, for RADIUS logins backed by Entra ID accounts.
Microsoft Entra ID user lookup Confirm a user still exists and is active in Entra ID (via Microsoft Graph), useful for revalidating certificate-based logins against a live directory.
Microsoft Entra ID / Intune device compliance check Validate an Intune-issued device certificate's identity against Entra ID, and optionally require the device to be Intune-compliant, for device (machine) EAP-TLS authentication.
Worked examples for both cert-based and password-based Entra ID 802.1X See PolicyLogic Examples and the dedicated EAP-TLS + Entra ID walkthrough.

Certificate management (PKI)

Full details: 802.1x, PKI and RADSEC

Feature Description
EAP server certificates Generate or import server certificates for EAP-TLS/TTLS/PEAP, with automatic ECDSA/RSA selection matching the client's cipher suite.
EAP-TLS client certificates Generate client certificates from the dashboard or the API, delivered as PEM, PKCS12, an Apple .mobileconfig profile, an email attachment, or a one-time download URL.
SCEP (Simple Certificate Enrollment Protocol) Automated certificate enrollment for devices and MDM platforms, with a per-CA challenge password, an option to allow challenge-password-less enrollment for platforms that can't supply one (e.g. Intune's built-in SCEP profile), and a 48-hour request log (SCEP/EST Logs) for troubleshooting.
EST (Enrollment over Secure Transport) HTTPS-only automated enrollment (RFC 7030) on the same CAs as SCEP, protected by a per-CA EST password. Supports enrollment, renewal, and server-side key generation for devices that can't create their own keys.
MDM enrollment profile (Apple) One .mobileconfig per CA for Jamf, Kandji, Intune or another MDM. Each device creates its own key, enrolls its certificate over SCEP and joins the Wi-Fi with EAP-TLS.
Certificate revocation Mark a certificate good or revoked, from the dashboard or the API.
Certificate expiration tracking List certificates expiring within a given number of days; certificate tables flag entries already expired or expiring within 30 days.
EAP-AKA/SIM privacy keys Import the private key used to decrypt RSA-encrypted permanent identities (IMSI) sent by privacy-enabled EAP-AKA/SIM clients, scoped per environment.
Programmatic certificate issuance Generate and deliver an EAP-TLS client certificate directly from PolicyLogic (pkiGenCert) or the REST API, for self-service or automated enrollment flows.

Secure transport (RADSEC)

Feature Description
SpherAAA as a RADSEC server Accept RADIUS over TLS from NAS clients, proxies, or gateways, each with its own client certificate.
Client identification by certificate, not IP A RADSEC client using a SpherAAA-generated certificate is recognized by that certificate, so it keeps working through IP address changes (dynamic ISP connections, DHCP) with nothing to update.
SpherAAA as a RADSEC client Connect out to third-party AAA servers over RADSEC, importing their trust chain (client key, client certificate, root/intermediate CA).
Dynamic Peer Discovery (OpenRoaming, eduroam) Resolve a partner AAA server's address at request time via DNS NAPTR/SRV/A records keyed on the EAP realm (RFC 7585), instead of hardcoding every partner as a static NAS entry.
Alternative/custom CA import Trust certificates from your own CA for RADSEC clients, instead of generating client certificates in SpherAAA. These clients are matched to an environment by their IP address.

PolicyLogic (scripting engine)

Full details: PolicyLogic

Feature Description
JavaScript-based call-flow scripting Write authentication and accounting logic as JavaScript, with full access to the request, reply, session, user, EAP, Diameter, and config data for every request.
Four isolated environments Dev/Test/Stage/Prod, plus optional Proxy environments, each with separate Auth and Accounting script sets, so changes can be built and validated without affecting live traffic.
Draft/Apply workflow Save changes as a draft and validate them before publishing; a script only goes live when you explicitly Apply it, and every save/delete is auto-backed-up and restorable.
Built-in test/validate tool Send a real test request (raw attributes, or a full EAP-TTLS/PEAP/TLS/AKA handshake) through a script or the full global flow, without touching production traffic.
Saved test cases Save test requests with an expected result and required reply attributes, run them all against the draft with one click, and have them run automatically before Apply.
Debug Trace & Debug History A step-by-step table of each test round: function calls and their results, true/false conditions, built-in service calls and the final decision. Keep all rounds or only the deciding one. Traces are saved to Debug History for 7 days.
Live debug tracing on real traffic A per-script switch to trace live traffic in non-production environments while troubleshooting. Traces aren't redacted, so the dashboard warns you to turn it off when you're done.
Call-flow visualization An auto-generated flowchart of a script's branches, and an animated ladder diagram (Client/NAS/SpherAAA) of any request path through it, exportable as PNG or GIF.
Environment promotion (Sync/Deploy) Copy a category's scripts from one environment to another, either live immediately or as a review-first draft.
Editor tooling Autocomplete for PolicyLogic functions and attributes, auto-formatting, and inline script metadata (filename, description).
Parallel/async execution (runParallel) Run follow-up work (logging, collection updates) after a response is already sent, without delaying the client.
A large built-in function library covering RADIUS/Diameter requests and proxying, EAP state machines, collection CRUD, MAC vendor lookup, HMAC, Base64, X.509 DN parsing, certificate status checks, HTTP calls, and secret storage See PolicyLogic functions for the full reference.

Federation & proxying

Feature Description
Realm-based proxy routing Route a request to a specific partner AAA server based on the user's realm, configured centrally instead of per-NAS.
Failover between partner servers Fall back to a secondary AAA server if the primary doesn't respond.
Load balancing across a peer/proxy group Round-robin or random distribution across multiple endpoints, with EAP session persistence.
Dynamic Peer Discovery Find RADIUS/RADSEC and Diameter partners at request time, for roaming federations that don't publish a fixed endpoint list.
Cross-protocol bridging A single PolicyLogic script can proxy a RADIUS request out to Diameter, HTTP, or another RADIUS backend, and vice versa.

NAS & device management

Full details: NAS

Feature Description
NAS Role selection Client entries matched by source Host/IP, outbound Server/proxy targets, and RadSec Clients matched purely by TLS certificate.
Inline RADSEC client certificate generation Generate a RadSec client certificate directly from the Add NAS flow, without a separate trip to the certificates page.
Environment routing rules Override a NAS's default environment on a per-request basis (matching on attributes like Calling-Station-Id or User-Name), without standing up a duplicate NAS entry.
Per-NAS health checks A live status column showing whether SpherAAA can currently reach each configured NAS/AAA server.
MSP AAA server sharing Managed Service Provider accounts can share a read-only set of upstream AAA servers, with realm-based routing, across their managed sub-accounts.
NAS-Type grouping Classify NAS entries into custom types (AP, router, BRAS, etc.) for use in PolicyLogic routing/policy decisions.

Data, storage & secrets

Full details: Collections

Feature Description
Collections Schema-less JSON document storage for provisioned data, cached lookups, entity mappings, authentication/accounting records, or anything else a policy script needs to read or write, with configurable unique/sortable indexes.
Per-field encryption Mark specific fields within a collection (e.g. a password) as encrypted; values display masked and write-only in the dashboard, while PolicyLogic still receives the real value at runtime.
Bulk import/export Upload JSON files to seed or update a collection in bulk, and export search results as a dataset.
Vault Encrypted key/value storage for secrets (API credentials, shared keys) referenced from PolicyLogic, kept out of scripts and regular collections, with an optional TTL.
config collection Centrally managed platform configuration and defaults, available to every script as radius.config.

Monitoring, logging & diagnostics

Feature Description
Authentication logs & active sessions Queryable from the dashboard and the Reports API.
PolicyLogic Debug Trace & Debug History See PolicyLogic above.
SCEP and EST request logs Every SCEP and EST enrollment attempt, with result and failure reason, kept for 48 hours.
log() from PolicyLogic Write arbitrary debug messages from a script to the dashboard's log viewer.
Categorized troubleshooting guidance Fixes for PolicyLogic, RADIUS/NAS, session/state, EAP-TLS/certificate, Fast-Reauth, and authentication errors. See Troubleshooting.

API & automation

Full details: API

Feature Description
REST API Covering certificate issuance and status, Collections CRUD, NAS management, authentication logs/active sessions, and invoking PolicyLogic scripts directly.
OAuth2 Client Credentials authentication Scoped API keys (ClientID/ClientSecret) exchanged for short-lived bearer tokens.
Fine-grained scopes Grant a key access to only the resources it needs (PKI, Collections, NAS, Reports, PolicyLogic), or full access.
Swagger/OpenAPI documentation A live, browsable API reference alongside the platform.

Multi-tenancy

Feature Description
Managed Service Provider (MSP) accounts Share AAA server endpoints and realm-routing rules across managed sub-accounts, read-only from the sub-account side.
Per-environment isolation Doubles as a way to separate traffic between customers, sites, or stages within a single account when a full MSP setup isn't needed.
Back to top