UniFi Cloud Key login: how to sign in locally and remotely
To log in to a UniFi Cloud Key, open https:// followed by its IP address in a browser on the same network. Sign in with your UI account, or with the local account you created during setup. From anywhere else, sign in at unifi.ui.com and open the Cloud Key's site.
The first-generation Cloud Key works differently. It runs the UniFi Network application directly. Ubiquiti's ports reference lists port 8443 for that application's web interface.
This guide covers each Cloud Key model, both account types, and what Ubiquiti says to do when you're locked out. Last checked against Ubiquiti's documentation on September 25, 2026.
Which address to use for your Cloud Key
| Cloud Key | What it runs | Local address | Remote access |
|---|---|---|---|
| CloudKey+ (UCK-G2-SSD, UCK-G2-PLUS) and Cloud Key Gen2 (UCK-G2) | UniFi OS | https://<IP> (port 443) |
Site Manager at unifi.ui.com |
| CloudKey Enterprise (CK-Enterprise) | UniFi OS | https://<IP> on a data port |
Site Manager at unifi.ui.com |
| Cloud Key Gen1 (UC-CK), legacy | UniFi Network application | https://<IP>, then Manage, per its quick start guide. Ubiquiti lists port 8443 for the Network application |
Not covered by Ubiquiti's current Site Manager docs |
Ubiquiti's UniFi Local Management article says self-hosted Network Servers use port 8443 and other devices use 443. Port 443 is the browser default, so on a CloudKey+ or CloudKey Enterprise the plain IP address is enough.
The Gen1 is on Ubiquiti's Legacy list, which means it no longer gets updates. UniFi Network 7.3 and newer don't support it. If you still run one, our Cloud Key vs Cloud Gateway vs UniFi controller comparison covers what to replace it with.
How to log in to a Cloud Key locally
Local login works without an internet connection. You need to be on the same local network as the Cloud Key, or connected to it through a VPN.
- Find the Cloud Key's IP address (see below).
- Open a browser and go to
https://<IP>. - Your browser shows a privacy or security warning. Ubiquiti says this is normal and to proceed anyway.
- Sign in with your UI account or your local account.
You can also use the UniFi mobile app. It lists the UniFi consoles it finds on the local network. If yours isn't listed, tap Can't Find Your Device, then Console Manual Setup, and enter the details yourself.
Find the Cloud Key's IP address
- Read it from the front display. The CloudKey+ has a small OLED screen and the CloudKey Enterprise a touchscreen, and Ubiquiti's setup guide points to the screen for the IP address.
- Use the WiFiman app. Connect your phone to the same network, open WiFiman and tap Discovery. Without a UniFi Gateway, it only finds devices on the same network or VLAN (virtual network) as your phone's WiFi.
- Check the DHCP lease list on your router. Cloud Keys use DHCP by default.
If no DHCP server hands out an address, Ubiquiti's Gen1 guide and its recovery instructions give 192.168.1.30 as the Cloud Key's fallback address.
Using a CloudKey Enterprise
The CloudKey Enterprise has three network ports: 1 GbE, 10G SFP+ and a separate management port. Sign in through one of the first two.
The management port connects to an onboard management interface that is separate from UniFi OS. Ubiquiti says UniFi OS applications can't be reached from it. Its support team may ask you to use it for diagnostics (Dedicated Management Ports).
UI account or local account
On a Cloud Key running UniFi OS, you create the web login during setup. Ubiquiti's docs describe two types.
UI account
This is the account you use at unifi.ui.com. Once Remote Management is set up, you can use the same UI account to sign in locally.
Ubiquiti has required multi-factor authentication on every UI account since July 22, 2024. Accounts without another method got email verification switched on automatically (Multi-Factor Authentication).
Local account
If Remote Management isn't enabled, setup creates a local username and password for that one Cloud Key. Ubiquiti says the default username for local-only deployments is admin.
Ubiquiti's MFA FAQ makes one exception: signing in locally with local credentials.
What about ubnt / ubnt?
That was the Gen1's default login for its Configure page, according to its quick start guide. On UniFi OS consoles, Ubiquiti lists root / ui (root / ubnt on older units) as the default SSH credentials before setup. These are for SSH, and Ubiquiti says SSH is disabled by default on consoles (Debug Tools & SSH).
How to log in to a Cloud Key remotely
Remote login goes through UniFi Site Manager:
- Go to unifi.ui.com, or open the UniFi mobile app.
- Sign in with your UI account.
- Click the site your Cloud Key runs.
Remote Management is on by default when you set up a UniFi console. If your Cloud Key doesn't appear, sign in locally and turn on Remote Management under Settings > Control Plane > Console.
The Cloud Key also needs outbound TCP 443 and 8883. You don't need to open any inbound ports (Enabling UniFi Remote Management).
Our guide to UniFi Site Manager covers the rest of the portal. For VPN access and the other remote routes, see how to access your UniFi controller.
When you're locked out of your Cloud Key
What you can do depends on the account type. Ubiquiti's Password Recovery and Ownership Transfer article sets out the options.
You forgot the password
- UI account: click Forgot Password on the login screen. The reset email goes to the address on your UI account.
- Local account: Ubiquiti can't recover it, unless you set up your own SMTP server for password emails.
- Lost all MFA methods: Ubiquiti can't reset MFA on a UI account. You'll need to create a new account.
If you're the owner and still can't get in, Ubiquiti's answer is to factory reset all your UniFi devices and set up UniFi again.
You inherited the Cloud Key
Only the owner can transfer ownership, from the Control Plane of the console. If the original owner is gone, Ubiquiti says to factory reset all UniFi devices, set up UniFi again and re-adopt the devices.
Factory reset the Cloud Key
Hold the Reset button for 5 to 10 seconds, depending on the device, until the LEDs show the reset has started. Keep the Cloud Key powered the whole time (Reset to Factory Defaults). If you can still sign in as the owner, UniFi OS also has a Factory Reset button in its system settings.
Two things to know before you reset:
- If automatic system backups were on, the Cloud Key made a cloud backup every week and before each major update. These backups are stored on the owner's UI account, at account.ui.com/backups (Backups and Migration).
- After a reset, your access points and switches may show "Managed by Another Console" ("Managed by Other" in older versions). Restore a backup in which they were managed, or factory reset and re-adopt them.
The Cloud Key won't boot
Recovery Mode is Ubiquiti's last resort for a Cloud Key that no longer responds, often after losing power during an update. For the Gen2 and Gen2 Plus (UniFi Recovery Mode):
- Download the latest firmware for your model.
- Power off the Cloud Key.
- Hold the Reset button and connect power.
- Keep holding for 10 seconds, until the LED flashes blue and white and the screen reads RECOVERY MODE.
- Open the IP address shown on the screen in a browser. If the Cloud Key got no address from DHCP, try the fallback
192.168.1.30. - Run Check Filesystem, then restore the firmware you downloaded. This also factory resets the Cloud Key.
If it fails again, Ubiquiti says that points to the storage disk and you should replace it.
For sign-in problems on other UniFi controllers and login pages, see our UniFi login guide.
Frequently asked questions
What is the default Cloud Key login?
On a CloudKey+ or CloudKey Enterprise, you create the login during setup, as a UI account or a local account. Ubiquiti gives admin as the default username for local-only setups. The old ubnt / ubnt login belongs to the Gen1.
Can I log in to my Cloud Key without internet?
Yes. Ubiquiti's local management works during an internet outage and for fully offline setups. You need to be on the same local network.
Can I use my UI account to log in locally?
Yes. Once Remote Management is set up, the same UI account works for local sign-in.
Is the Cloud Key Gen1 still supported?
No. Ubiquiti lists the UC-CK as Legacy, which means it has stopped receiving updates. UniFi Network 7.3 and newer don't support it.
Final thoughts
Most Cloud Key login problems come down to three things: the wrong address, the wrong account type, or a lost local password. Check which Cloud Key you have and which account you set up, and you'll know which route applies.
A Cloud Key works well as the controller for a single office. If you look after many client sites, we run hosted UniFi OS Server controllers for MSPs that show up in the same Site Manager.
Related guides
Keep reading
UniFi Cloud Key vs Cloud Gateway vs UniFi controller: which do you need?
Cloud Gateway, Cloud Key, UniFi OS Server or hosting? Where to run your UniFi controller, with Ubiquiti's own capacities, apps and US store prices.
Read guideHow to access a UniFi controller locally or remotely
Open your UniFi controller locally by IP and port, or remotely through Site Manager, Direct Remote Connection or a VPN such as Teleport.
Read guideUniFi Login: How to Log In to Your UniFi Controller
Step-by-step UniFi login guide: find your controller's IP address, sign in on a Cloud Key or Dream Machine, and fix the "can't reach login page" error.
Read guide