UniFi Cloud Key setup: step by step for CloudKey+ and CloudKey Enterprise
You set up a UniFi Cloud Key in the UniFi mobile app over Bluetooth, or in a browser at the Cloud Key's IP address. Both routes take you through a setup wizard. Afterwards you can manage the Cloud Key from the app and the web alike.
This guide covers the two Cloud Keys in Ubiquiti's US store today, the CloudKey+ and the CloudKey Enterprise. Both run UniFi OS. Last checked against Ubiquiti's documentation, quick start guides and store on September 25, 2026.
Which Cloud Key you have
| Model | Status in Ubiquiti's US store | UniFi apps in tech specs | Capacity in tech specs |
|---|---|---|---|
| CloudKey+ SSD (UCK-G2-SSD) | Available, $249 ($268 incl. surcharge) | Network, Protect, Access, Talk, Connect | 24 HD, 14 2K or 8 4K cameras; 80 Access hubs. No UniFi device count listed |
| CloudKey Enterprise (CK-Enterprise) | Available, $4,999 ($5,393 incl. surcharge) | Network | 1,000 UniFi devices, 10,000 connected users |
| CloudKey+ HDD (UCK-G2-PLUS) | Sold out | Network, Protect, Access, Talk, Connect | 24 HD, 14 2K or 8 4K cameras; 50 Access hubs |
| Cloud Key Gen2 (UCK-G2) | Sold out | Not listed | Not listed |
| Cloud Key Gen1 (UC-CK) | Legacy, no more updates | UniFi Network 7.2 or older | Not listed |
The CloudKey+ is a small box powered over PoE. It suits a site that wants cameras or door access next to its network. The CloudKey Enterprise is a 1U rack unit with two hot-swappable power supplies, built for large networks. It runs UniFi Network only.
Ubiquiti's own figures for the CloudKey+ differ. Its Choosing the Right UniFi Control Plane guide says the CloudKey+ supports up to 12 cameras, half the tech specs figure. That guide also leaves Connect out of the app list.
The Gen2 models still get UniFi OS updates. The Gen1 doesn't. UniFi Network 7.3 dropped support for it. Not sure a Cloud Key is the right controller? Our Cloud Key vs Cloud Gateway vs UniFi controller comparison covers the options.
Before you start
- A switch port for the Cloud Key. The CloudKey+ takes PoE from the switch. Without PoE, Ubiquiti's quick start guide shows a USB-C Quick Charge 2.0/3.0 adapter for power plus a network cable.
- For the CloudKey Enterprise: 1U of rack space, mains power, and a 10G SFP+ or 1 GbE connection to your switch. Its separate management port is for diagnostics and doesn't give access to UniFi OS.
- Internet access for the Cloud Key. Ubiquiti warns that a CloudKey Gen2 Plus is sometimes placed on a network or VLAN with restricted internet, which breaks setup.
- A phone with the UniFi app (iOS or Android) and Bluetooth, if you use the app.
- A UI account, if you want remote management. You can create one during setup.
If a firewall or ISP modem sits between the Cloud Key and the internet, check the ports Ubiquiti lists as needed for setup (How to Set Up UniFi). They are TCP and UDP 443, TCP 8883, TCP and UDP 53, UDP 123 and port 3478.
Set up the Cloud Key with the UniFi app
Ubiquiti recommends the app. Its quick start guides for the CloudKey+ and CloudKey Enterprise both show this route.
- Connect the Cloud Key to your switch and power it on.
- Install the UniFi app on your phone.
- Open the app and connect to the Cloud Key over Bluetooth, or over WiFi on the same network. For Bluetooth, stay within 3 meters (10 feet).
- Follow the setup wizard.
- Sign in with your UI account, or create one. Ubiquiti calls this optional but strongly recommends it.
When the wizard finishes, you can adopt your access points, switches and cameras.
Set up the Cloud Key in a browser
- Connect a laptop to the same network as the Cloud Key, over WiFi or a cable.
- Find the Cloud Key's IP address. It's on the Cloud Key's screen, or use the WiFiman app's Discovery tab.
- Open
https://<IP>in your browser. - You'll see a privacy or security warning. Ubiquiti says this is normal and to proceed anyway.
- Follow the setup wizard.
Ubiquiti's setup guide gives the unifi/ shortcut for Cloud Gateways. For a Cloud Key, use the IP address.
UI account or local account
The account you set up during the wizard decides how you sign in later.
A UI account gives you, according to Ubiquiti:
- Remote management through UniFi Site Manager at unifi.ui.com and in the UniFi app.
- Automatic system backups linked to your UI account.
- Email notifications, set up for you.
Ubiquiti turns Remote Management on by default during setup. UI accounts require multi-factor authentication.
Without Remote Management, setup creates a local username and password for that Cloud Key only. Ubiquiti can't recover those credentials for you, unless you configured your own SMTP server. Store them somewhere safe.
Our guide to logging into your UniFi Cloud Key covers both account types after setup, and what to do when you're locked out.
After the setup wizard
Update UniFi OS
Ubiquiti recommends updating to the latest version and turning on automatic updates. The current release for Cloud Keys is UniFi OS 5.1.33, published September 9, 2026, with UniFi Network 10.5.67 bundled.
Turn on automatic backups
Go to Settings > Control Plane > Backups and check System Backups. The Cloud Key then makes a cloud backup every week and before each major update. The backups are stored on the owner's UI account (Backups and Migration).
Adopt your UniFi devices
Plug in your access points and switches on the same network as the Cloud Key. They show up as Pending Adoption in the app or web interface.
A Cloud Key only discovers devices on its own network or VLAN. Cloud Gateways find devices across VLANs (ZTP and Device Replacement).
If a device doesn't appear:
- Check that TCP 8080 and UDP 10001 are open between the device and the Cloud Key, on every gateway, firewall and antivirus in between.
- For devices on another VLAN, follow Ubiquiti's Layer 3 adoption steps. You can hand the Cloud Key's address out from your DHCP server, or make the hostname
unifiresolve to the Cloud Key in your DNS. - As a last resort, factory reset the device and try again.
For a device at another site, TCP 8080 on the Cloud Key must be reachable from that site. If the Cloud Key sits behind a router, that means forwarding TCP 8080 to it. Then SSH into the device and run:
set-inform http://<public-ip-or-hostname>:8080/inform
In its steps for devices on another VLAN, Ubiquiti notes you may need to repeat the command after the device appears (Device Adoption).
Choose a router
A Cloud Key doesn't route traffic. It works next to any router. If you want a UniFi router, Ubiquiti notes that most people pair a Cloud Key with a UniFi Independent Gateway (UXG).
Troubleshooting Cloud Key setup
Ubiquiti's checklist for setup that fails:
- Check the power and network cables.
- Check that the Cloud Key has internet access and isn't on a restricted VLAN.
- Update to the latest UniFi OS.
- Check that no firewall or ISP modem blocks the ports listed above.
- Ask your ISP whether it restricts your connection.
If the Cloud Key stops responding altogether, for example after losing power during an update, Ubiquiti's Recovery Mode can reinstall the firmware. Our Cloud Key login guide walks through it. Once the Cloud Key is running, see how to access your UniFi controller for the ways to reach it.
Frequently asked questions
Do I need the UniFi app to set up a Cloud Key?
No. You can run the setup wizard in a browser at the Cloud Key's IP address. Ubiquiti recommends the app, and its quick start guides use it.
Do I need a UI account?
No. Ubiquiti calls it optional. Without one you lose remote management through Site Manager and automatic cloud backups.
Can a Cloud Key manage devices at other sites?
Yes. Devices at another site need to reach the Cloud Key on TCP 8080. You then adopt them with Ubiquiti's Layer 3 methods, such as set-inform.
Does a Cloud Key replace my router?
No. A Cloud Key runs UniFi applications and leaves routing to a separate router. Your router stays, whether it's a UniFi Independent Gateway or another brand.
Final thoughts
Setting up a Cloud Key comes down to power, the wizard and one account decision. Turn on backups and automatic updates before you adopt the first device.
For one office, a Cloud Key on site is a sensible controller. For MSPs, a Cloud Key at every client site means one more box per site to power, update, back up and replace. We run hosted UniFi OS Server for MSPs, so the controller doesn't sit on hardware at the client's site. Paid plans include daily backups, tested updates and monitoring.
Related guides
Keep reading
UniFi Cloud Key vs Cloud Gateway vs UniFi controller: which do you need?
Cloud Gateway, Cloud Key, UniFi OS Server or hosting? Where to run your UniFi controller, with Ubiquiti's own capacities, apps and US store prices.
Read guideUniFi Cloud Key login: how to sign in locally and remotely
Sign in to a UniFi Cloud Key by IP on your local network or through Site Manager, with a UI account or a local account, and what to do when locked out.
Read guideUniFi Site Manager: what it is and how to use it (2026)
UniFi Site Manager is Ubiquiti's free portal at unifi.ui.com for managing all your UniFi sites in one place. What it does, how to open it and where it stops.
Read guide