Features
SpherAAA is a cloud RADIUS and Diameter platform for Wi-Fi, wired, VPN and mobile/SIM authentication. Instead of a fixed set of rules, your access policy is a script you write and control, and you test it in separate environments before it goes live.
At a glance
- Authentication: EAP-TLS, EAP-TTLS, PEAP, MAC Authentication Bypass, private PSK, and EAP-AKA for SIM devices.
- Certificates: a built-in CA, with self-service enrollment over SCEP and EST.
- Policy: PolicyLogic scripts, with test tools, debug traces and call-flow diagrams.
- Integrations: Microsoft Entra ID and Intune, partner AAA servers, OpenRoaming and eduroam, and a REST API.
- Security: RADSEC, Blast-RADIUS protection, field-level encryption, and a vault for secrets.
- Providers: multi-tenant MSP accounts and isolated environments.
The rest of this page lists every feature by area. Where a feature has its own page, it's linked so you can go straight to the details.
Core RADIUS & AAA
| Feature |
Description |
| RADIUS server |
Access-Request/Accept/Reject and Accounting, over plain UDP, TCP, or RADSEC (RADIUS over TLS). |
| RADIUS proxy / relay |
Forward requests to an upstream AAA server, with load balancing and failover. See Federation & proxying. |
| Disconnect-Message (DM) and Change-of-Authorization (CoA) |
Push session changes or disconnects to a NAS from PolicyLogic, or via the API. |
| Blast-RADIUS mitigation |
Require the Message-Authenticator attribute on incoming requests, per NAS. |
| Custom RADIUS attribute dictionary |
Define your own Vendor-Specific Attributes (VSAs) alongside the built-in, shared attribute dictionary. |
| RFC5580 location data |
Read and act on NAS-supplied location attributes (civic location, geo-coordinates) in PolicyLogic. |
| Environment-based traffic isolation |
Every NAS, Diameter peer, and PolicyLogic script is scoped to an environment (Dev/Test/Stage/Prod, or a configured Proxy environment), so you can build and test changes without touching production traffic. |
Diameter & mobile (3GPP)
Full details: Diameter
| Feature |
Description |
| Diameter peer connections |
Dial out to a carrier/HSS (Server role), or accept inbound Diameter connections matched by source Host/IP (Client role). |
| EAP-AKA / EAP-AKA' authentication |
Authenticate mobile/SIM subscribers against a carrier's HSS over Diameter/SWx, covering identity decryption, vector fetch, and challenge/response in one flow. |
| EAP-AKA identity privacy |
Decrypt RSA-encrypted permanent identities (IMSI) sent by clients that use identity privacy, for both EAP-AKA and EAP-AKA', detected automatically. |
| EAP-AKA proxying |
Forward a decrypted subscriber identity on to their home 3GPP-AAA instead of authenticating locally. |
| Diameter peer groups & load balancing |
Share a group name across multiple peers to load-balance EAP-AKA/SWx traffic, round-robin or random. |
| Diameter Peer TLS |
Mutual TLS for outbound Diameter connections, with existing-certificate or generate-new-certificate options and TLS 1.2/1.3 version control. |
| Diameter Certificates management |
A dedicated page for importing and tracking the certificates used by outbound Diameter connections, separate from RADIUS/RADSEC certificates. |
| Diameter-RADIUS-HTTP bridging |
Combine Diameter, RADIUS, and HTTP calls within a single PolicyLogic script to route or bridge between them, rather than needing a separate proxy/bridge product. |
Authentication methods
| Feature |
Description |
| EAP-TLS |
Certificate-based mutual authentication, with per-request control over which server certificate, TLS versions, and cipher suites are used. |
| EAP-TTLS |
Tunneled authentication with PAP, EAP-GTC, or MSCHAPv2 inner methods, no client certificate required. |
| EAP-PEAP |
Tunneled authentication protecting inner credentials inside a TLS tunnel. |
| MAC Authentication Bypass (MAB) |
Authenticate devices that can't run 802.1X (printers, cameras, IoT) by their MAC address against a pre-registered device list. |
| Raw/PAP RADIUS authentication |
Authenticate directly against attributes in the request (username/password, pre-shared key, etc.) without an EAP exchange, including Private PSK / DPSK flows that assign a dynamic VLAN per device. |
| Fast-Reauth (TLS session resumption) |
Let a previously-authenticated EAP-TLS/TTLS/PEAP client reconnect without repeating credential or certificate checks, with PolicyLogic staying in control of the accept/reject decision every time. |
| OCSP checking |
Query an OCSP responder for EAP-TLS client certificate status and act on the result in PolicyLogic (SpherAAA surfaces the status; your script decides whether to reject). |
| Configurable TLS versions & cipher suites |
Restrict or permit specific TLS protocol versions and cipher suites per EAP method, per request. |
| Access-control patterns |
Account lockout after repeated failures, device-count caps per user, concurrent session limits, and MAC-to-username binding. These are implemented as PolicyLogic scripts, not hardcoded product settings, so you can adapt them to your own policy. |
Identity provider integrations
| Feature |
Description |
| Microsoft Entra ID credential check |
Validate a username/password directly against Entra ID (ROPC flow) from within PolicyLogic, for RADIUS logins backed by Entra ID accounts. |
| Microsoft Entra ID user lookup |
Confirm a user still exists and is active in Entra ID (via Microsoft Graph), useful for revalidating certificate-based logins against a live directory. |
| Microsoft Entra ID / Intune device compliance check |
Validate an Intune-issued device certificate's identity against Entra ID, and optionally require the device to be Intune-compliant, for device (machine) EAP-TLS authentication. |
| Worked examples for both cert-based and password-based Entra ID 802.1X |
See PolicyLogic Examples and the dedicated EAP-TLS + Entra ID walkthrough. |
Certificate management (PKI)
Full details: 802.1x, PKI and RADSEC
| Feature |
Description |
| EAP server certificates |
Generate or import server certificates for EAP-TLS/TTLS/PEAP, with automatic ECDSA/RSA selection matching the client's cipher suite. |
| EAP-TLS client certificates |
Generate client certificates from the dashboard or the API, delivered as PEM, PKCS12, an Apple .mobileconfig profile, an email attachment, or a one-time download URL. |
| SCEP (Simple Certificate Enrollment Protocol) |
Automated certificate enrollment for devices and MDM platforms, with a per-CA challenge password, an option to allow challenge-password-less enrollment for platforms that can't supply one (e.g. Intune's built-in SCEP profile), and a 48-hour request log (SCEP/EST Logs) for troubleshooting. |
| EST (Enrollment over Secure Transport) |
HTTPS-only automated enrollment (RFC 7030) on the same CAs as SCEP, protected by a per-CA EST password. Supports enrollment, renewal, and server-side key generation for devices that can't create their own keys. |
| MDM enrollment profile (Apple) |
One .mobileconfig per CA for Jamf, Kandji, Intune or another MDM. Each device creates its own key, enrolls its certificate over SCEP and joins the Wi-Fi with EAP-TLS. |
| Certificate revocation |
Mark a certificate good or revoked, from the dashboard or the API. |
| Certificate expiration tracking |
List certificates expiring within a given number of days; certificate tables flag entries already expired or expiring within 30 days. |
| EAP-AKA/SIM privacy keys |
Import the private key used to decrypt RSA-encrypted permanent identities (IMSI) sent by privacy-enabled EAP-AKA/SIM clients, scoped per environment. |
| Programmatic certificate issuance |
Generate and deliver an EAP-TLS client certificate directly from PolicyLogic (pkiGenCert) or the REST API, for self-service or automated enrollment flows. |
Secure transport (RADSEC)
| Feature |
Description |
| SpherAAA as a RADSEC server |
Accept RADIUS over TLS from NAS clients, proxies, or gateways, each with its own client certificate. |
| Client identification by certificate, not IP |
A RADSEC client using a SpherAAA-generated certificate is recognized by that certificate, so it keeps working through IP address changes (dynamic ISP connections, DHCP) with nothing to update. |
| SpherAAA as a RADSEC client |
Connect out to third-party AAA servers over RADSEC, importing their trust chain (client key, client certificate, root/intermediate CA). |
| Dynamic Peer Discovery (OpenRoaming, eduroam) |
Resolve a partner AAA server's address at request time via DNS NAPTR/SRV/A records keyed on the EAP realm (RFC 7585), instead of hardcoding every partner as a static NAS entry. |
| Alternative/custom CA import |
Trust certificates from your own CA for RADSEC clients, instead of generating client certificates in SpherAAA. These clients are matched to an environment by their IP address. |
PolicyLogic (scripting engine)
Full details: PolicyLogic
| Feature |
Description |
| JavaScript-based call-flow scripting |
Write authentication and accounting logic as JavaScript, with full access to the request, reply, session, user, EAP, Diameter, and config data for every request. |
| Four isolated environments |
Dev/Test/Stage/Prod, plus optional Proxy environments, each with separate Auth and Accounting script sets, so changes can be built and validated without affecting live traffic. |
| Draft/Apply workflow |
Save changes as a draft and validate them before publishing; a script only goes live when you explicitly Apply it, and every save/delete is auto-backed-up and restorable. |
| Built-in test/validate tool |
Send a real test request (raw attributes, or a full EAP-TTLS/PEAP/TLS/AKA handshake) through a script or the full global flow, without touching production traffic. |
| Saved test cases |
Save test requests with an expected result and required reply attributes, run them all against the draft with one click, and have them run automatically before Apply. |
| Debug Trace & Debug History |
A step-by-step table of each test round: function calls and their results, true/false conditions, built-in service calls and the final decision. Keep all rounds or only the deciding one. Traces are saved to Debug History for 7 days. |
| Live debug tracing on real traffic |
A per-script switch to trace live traffic in non-production environments while troubleshooting. Traces aren't redacted, so the dashboard warns you to turn it off when you're done. |
| Call-flow visualization |
An auto-generated flowchart of a script's branches, and an animated ladder diagram (Client/NAS/SpherAAA) of any request path through it, exportable as PNG or GIF. |
| Environment promotion (Sync/Deploy) |
Copy a category's scripts from one environment to another, either live immediately or as a review-first draft. |
| Editor tooling |
Autocomplete for PolicyLogic functions and attributes, auto-formatting, and inline script metadata (filename, description). |
Parallel/async execution (runParallel) |
Run follow-up work (logging, collection updates) after a response is already sent, without delaying the client. |
| A large built-in function library covering RADIUS/Diameter requests and proxying, EAP state machines, collection CRUD, MAC vendor lookup, HMAC, Base64, X.509 DN parsing, certificate status checks, HTTP calls, and secret storage |
See PolicyLogic functions for the full reference. |
Federation & proxying
| Feature |
Description |
| Realm-based proxy routing |
Route a request to a specific partner AAA server based on the user's realm, configured centrally instead of per-NAS. |
| Failover between partner servers |
Fall back to a secondary AAA server if the primary doesn't respond. |
| Load balancing across a peer/proxy group |
Round-robin or random distribution across multiple endpoints, with EAP session persistence. |
| Dynamic Peer Discovery |
Find RADIUS/RADSEC and Diameter partners at request time, for roaming federations that don't publish a fixed endpoint list. |
| Cross-protocol bridging |
A single PolicyLogic script can proxy a RADIUS request out to Diameter, HTTP, or another RADIUS backend, and vice versa. |
NAS & device management
Full details: NAS
| Feature |
Description |
| NAS Role selection |
Client entries matched by source Host/IP, outbound Server/proxy targets, and RadSec Clients matched purely by TLS certificate. |
| Inline RADSEC client certificate generation |
Generate a RadSec client certificate directly from the Add NAS flow, without a separate trip to the certificates page. |
| Environment routing rules |
Override a NAS's default environment on a per-request basis (matching on attributes like Calling-Station-Id or User-Name), without standing up a duplicate NAS entry. |
| Per-NAS health checks |
A live status column showing whether SpherAAA can currently reach each configured NAS/AAA server. |
| MSP AAA server sharing |
Managed Service Provider accounts can share a read-only set of upstream AAA servers, with realm-based routing, across their managed sub-accounts. |
| NAS-Type grouping |
Classify NAS entries into custom types (AP, router, BRAS, etc.) for use in PolicyLogic routing/policy decisions. |
Data, storage & secrets
Full details: Collections
| Feature |
Description |
| Collections |
Schema-less JSON document storage for provisioned data, cached lookups, entity mappings, authentication/accounting records, or anything else a policy script needs to read or write, with configurable unique/sortable indexes. |
| Per-field encryption |
Mark specific fields within a collection (e.g. a password) as encrypted; values display masked and write-only in the dashboard, while PolicyLogic still receives the real value at runtime. |
| Bulk import/export |
Upload JSON files to seed or update a collection in bulk, and export search results as a dataset. |
| Vault |
Encrypted key/value storage for secrets (API credentials, shared keys) referenced from PolicyLogic, kept out of scripts and regular collections, with an optional TTL. |
config collection |
Centrally managed platform configuration and defaults, available to every script as radius.config. |
Monitoring, logging & diagnostics
| Feature |
Description |
| Authentication logs & active sessions |
Queryable from the dashboard and the Reports API. |
| PolicyLogic Debug Trace & Debug History |
See PolicyLogic above. |
| SCEP and EST request logs |
Every SCEP and EST enrollment attempt, with result and failure reason, kept for 48 hours. |
log() from PolicyLogic |
Write arbitrary debug messages from a script to the dashboard's log viewer. |
| Categorized troubleshooting guidance |
Fixes for PolicyLogic, RADIUS/NAS, session/state, EAP-TLS/certificate, Fast-Reauth, and authentication errors. See Troubleshooting. |
API & automation
Full details: API
| Feature |
Description |
| REST API |
Covering certificate issuance and status, Collections CRUD, NAS management, authentication logs/active sessions, and invoking PolicyLogic scripts directly. |
| OAuth2 Client Credentials authentication |
Scoped API keys (ClientID/ClientSecret) exchanged for short-lived bearer tokens. |
| Fine-grained scopes |
Grant a key access to only the resources it needs (PKI, Collections, NAS, Reports, PolicyLogic), or full access. |
| Swagger/OpenAPI documentation |
A live, browsable API reference alongside the platform. |
Multi-tenancy
| Feature |
Description |
| Managed Service Provider (MSP) accounts |
Share AAA server endpoints and realm-routing rules across managed sub-accounts, read-only from the sub-account side. |
| Per-environment isolation |
Doubles as a way to separate traffic between customers, sites, or stages within a single account when a full MSP setup isn't needed. |