Travel

VPN for hotel Wi-Fi: a network you live on for days

A hotel network is the one shared connection you do not simply pass through. You join it on arrival and you are still on it four nights later, asleep, with a laptop on the desk and a phone charging beside the bed. Almost everything about the exposure changes once a session is measured in days instead of in the minutes between a boarding call and a gate.

Terminals fail in their own particular ways, and the airport Wi-Fi page deals with those. This one is about what belongs to hotels: a sign-in page that identifies you by room rather than by person, a device allowance you will reach by the second evening, a guest segment shared with the floor above you, equipment maintained by a company whose name is not on the building, and a television in the corner that somebody else signed into last week.

Networks you will meet
Room Wi-Fi · Lobby and bar · Business centre · Conference floors · Serviced apartments

Days, not an hour: the session that has to survive the night

Duration is the whole difference. A tunnel that comes up once and then runs for four nights meets things a brief session never does: a lid closing and opening, a phone dropping into a sleep state and waking to a fresh lease, a corridor access point restarting at some quiet hour, and the property's own sign-in cycle lapsing somewhere in the middle of the stay.

The wake is the moment worth planning around, because a device wakes onto the hotel network first and into protection second. Auto-Connect on Wi-Fi, in Settings, is what closes that interval: the tunnel comes back as part of joining the network rather than when you next think to look at the app. Left off, the seconds after a lid opens are ordinary readable traffic, and a laptop that has slept all afternoon opens with mail, calendar and file sync all asking at once.

On a long stay the session timer on the main screen earns its place, because its Connected for readout counts the current session rather than the trip. A timer reading a few minutes when you left the tunnel up overnight means it re-established itself at some point, which is usually a sleep cycle or the access point rather than anything you did, and Session History is where that gets confirmed instead of guessed at.

  • Leave it connected for the length of the stay rather than switching it on per task. On a multi-day network the exposure is the sum of the gaps, and toggling is what manufactures gaps.
  • Anything left in the room while you are out of it is still on the network and still syncing: a work laptop on charge, a tablet in the safe, a camera uploading by itself.
  • Overnight is the cheapest window on a hotel connection for a large upload, which is precisely the opposite of the advice for a network you are leaving in an hour.

Your room number and your surname are the credential

Most hotel portals authenticate a room rather than a person. Surname plus room number is the usual pair, occasionally an arrival date in place of one of them, and the combination is weak in a specific way: room numbers are printed on the doors, and a surname is the single detail a stranger standing near the front desk is most likely to overhear. Another guest guessing their way onto your allowance is a mundane event rather than a sophisticated one.

The same arrangement labels the session. The operator is not looking at an anonymous device on the segment; it is looking at the device registered to a room, and the destinations that device reached can be lined up against the folio paying for the stay. A tunnel cuts the second half of that and not the first. You handed over your name at check-in, so the property still knows which room is online, but what the room did becomes a single encrypted session to one endpoint.

The portal cannot live inside the tunnel. Until the terms are accepted the gateway forwards nothing, so a handshake has nowhere to land. Join the Wi-Fi, let the sign-in page finish, watch one ordinary page load, and only then bring protection up.

Then expect to repeat it. Hotel sign-in sessions commonly lapse on a daily cycle, or when the property clears its session table, and on the third morning the page can reappear with no warning while the app still reports a live connection, because the device never actually left the network. The symptom is protection that says it is on and carries nothing. The cure is to open a plain page, re-enter the same room details, and let the tunnel come back.

  • Note at check-in exactly which detail the portal accepted. Reception can re-register a room at two in the afternoon; at two in the morning there is nobody to ask.
  • At many properties a room number and a surname are also enough to charge something to the room, which is the better reason not to leave them written on a notepad in the lobby.
  • Every device clears the portal separately, and that registration is usually the same thing the device allowance counts.

Device caps, and the premium tier at the bottom of the portal

Hotel Wi-Fi is one of the last places where the number of devices you packed is a billing question. The familiar arrangement is a deliberately slow free tier limited to one or two devices per room, a faster tier sold per device and often per night, and a separate rate for meetings and events. A family arriving with four phones, two tablets and a laptop reaches the cap before dinner.

This is where one account covering unlimited devices stops being a line on a pricing page. The hotel's allowance is a property of the room; a WrapVPN plan is not. What you negotiate at reception is how many of your devices get an address, while every device that has one is protected without buying anything further. The plan lengths fit a stay as well: $0.99 for a day, $1.99 a week, $3.99 a month, a 7-day free trial on the monthly plan, and no annual subscription to carry home afterwards. The free tier is not built for this, at 3 hours a week with a 1-hour session cap on two devices, which is a test of the app rather than cover for four nights.

One gap belongs in this section rather than in small print, because this page keeps talking about the laptop on the desk. The released apps are iPhone, iPad, Mac and Android; the Windows build is in review rather than shipped. So if the machine you intend to work from all week runs Windows, it is the one device the hotel will happily register and WrapVPN cannot yet protect, and the realistic plan for a working stay is to keep anything sensitive on the phone, tablet or Mac until that changes.

What no tunnel does is get you past the cap, and that should be said plainly. The allowance is enforced at the gateway, by device, before any of your traffic reaches a server, so protection is simply irrelevant to it. The honest ways round are dull ones: ask the desk to register the extra devices, which many properties will do for a longer stay without charging, pay the per-device rate for the one or two that genuinely need the faster tier, or put the overflow on your own phone hotspot and keep the tunnel running on that.

  • Allowances are typically counted by hardware address, so forgetting the network and rejoining can present a new one and quietly consume a second slot.
  • The lobby, the bar and the business centre are frequently separate networks with separate allowances, so a laptop registered upstairs can be asked to sign in again downstairs.
  • Conference and event floors often run their own network behind a code handed out with the badge, which expires with the event rather than with your reservation.

A flat guest segment puts the floor on your network

A terminal network is a crowd you walk through. A hotel network is a neighbourhood you sleep in, and at a good number of properties it is a flat one: guest devices sharing a segment, able to see one another, with nothing isolating one room from the next. If your laptop can discover the printer in the business centre, something in another room can discover your laptop.

That matters because the contents of a suitcase are configured for home. A laptop with file sharing left on, a tablet offering its photo library to a living-room speaker that is three hundred miles away, a media server, a development server bound to every interface because that was convenient on Tuesday: each of them announces itself to the segment on joining and keeps announcing for the length of the stay.

The division of labour is worth being exact about. The tunnel protects traffic leaving the device for the internet. It does nothing about a service the device is advertising to its neighbours, because that traffic never goes near an exit at all. That half is the operating system's job: mark the network as public rather than trusted, switch sharing off before you pack, and turn off local discovery you are not using. It is a far easier job at home than in a dark room at midnight.

  • Client isolation, where the access point refuses to carry traffic between two guests, is the thing that would prevent all of this, and from inside a room there is no way to tell whether the property bought it.
  • It cuts both ways: where isolation is switched on, your phone will not reach the room television either, and a laptop will not see your own handheld.
  • A key unique to your stay controls who gets to join the network. It does not control who can see whom once they are on it.

Old radios, an evening peak, and a contractor who does not work for the hotel

Guest Wi-Fi is capital equipment inside a building, and buildings are refurbished on a slower cycle than radios are replaced. It is ordinary to meet access points several generations behind the phone in your hand, mounted where the cabling already ran rather than where coverage would be best, with a structural wall between them and the bed. One bar in a corner room is usually the geometry of the building, not a fault anyone can clear.

Demand then arrives all at once. Backhaul is sized for an average, and the average is not the evening, when most of the house is upstairs at the same time. A connection that felt unremarkable at breakfast can be hopeless after dinner, and encryption neither causes that nor cures it, because the shared uplink is the ceiling for every room on the floor.

The third thing to know is who you are actually talking to. Guest networks are very often run under contract by a third party, which is why the desk can reset your registration but cannot explain a routing fault, and why the support number on the portal answers in a company name you have never seen. If the connection is broken rather than merely slow, the sentence that gets results at reception is a request to re-register the room on the system.

  • Choose the exit by the live latency shown in the server picker rather than by the country you recognise. A weak room signal is already costing you something, and a needlessly distant exit adds to the bill.
  • Clean Web refuses ad, tracker and malicious-host domains at the lookup, so the device never opens those connections and a heavy page fetches less of itself over a contended uplink. It is a toggle in Settings with an explainer beside it, and switching it off is the first thing to try if a page misbehaves.
  • If a room is genuinely unusable, the lobby or business centre is often on newer hardware, and asking to change rooms is a more effective fix than any setting on your device.

The television in the corner is a signed-in device you do not own

The thing that most often actually goes wrong in a hotel room has nothing to do with the network. A guest signs a video or music account into the room's smart television, watches something, checks out, and leaves the session live for whoever sleeps there next. Televisions sign out when they are asked to, and housekeeping is not asked.

Here is the honest part: a VPN does nothing about this. The television is a separate device, it is not inside your tunnel, and an account you typed into it stays signed in regardless of what your phone is doing. The fix is account hygiene, carried out from your own phone before you leave the room: sign the session out on the set itself, then use the account's own sign-out-everywhere control, which is the one that catches a television you have already walked away from.

Not signing in at all is the better habit. Playing from your own device keeps the credential on hardware you are taking home, and it is worth knowing what usually breaks that: the room network may refuse to pass traffic between your phone and the set, and a tunnel on the phone can stop the two discovering each other as well. The Pause control exists for exactly this kind of short exception: it asks how long — 1, 5, 15 or 30 minutes, beside the option of disconnecting completely — and the dashboard then reads Protection Paused with the time counting down, so it comes back by itself instead of staying off for the rest of the trip.

  • Check the set for a previous guest's session when you arrive and sign it out. It takes a minute, and it is the same favour you would like from whoever had the room before you.
  • A pairing code on a screen is a sign-in to your account on somebody else's hardware. Treat it with the care you would give the password itself.
  • Whatever you do sign in on a room device should be the account you would least mind finding still signed in next week.

What people use it for

Four nights in the room

The ordinary case, and the one the advice here is shaped around. One registration, one portal that will probably lapse before you check out, devices that sleep and wake several times a day, and an evening peak between about dinner and bedtime. Connect once, turn on Auto-Connect on Wi-Fi, and leave the rest alone.

The business centre

A shared desktop, a printer anyone on the floor can discover and a network that is often separate from the one in your room, with its own sign-in. Printing from a laptop means being discoverable on that segment for as long as the job takes, which is an argument for sending the file and then packing up rather than working there all afternoon.

A conference floor

Event networks are provisioned for a crowd that arrives on one morning and leaves on another, behind a code printed on the badge. Several hundred attendees on one uplink is the same contention as the evening peak, except it happens during the keynote, and the code stops working the day the event ends rather than the day you check out.

A serviced apartment for a few weeks

The interesting thing about a long let is how little of this page survives it. There is usually no portal to lapse, no allowance being counted, and no desk that can re-register a room at two in the morning, because there is no desk. What is left is the one problem none of those mechanisms were solving anyway: a flat home network, configured by somebody else, on a password that did not change when the last tenant left. Over weeks rather than nights the monthly plan is the unit, and Auto-Connect has nothing to interrupt it.

How to set it up

  1. 1

    Before you pack, lock the devices down

    Switch off file, printer and screen sharing, mark unknown networks as public rather than trusted, and clear saved hotspots from previous trips so a familiar chain name cannot be rejoined automatically. This is the work that protects you on a flat guest segment, and none of it is pleasant to do after a late arrival.

  2. 2

    At check-in, ask the three questions

    How many devices the room is allowed, which detail the sign-in page will want, and whether the lobby, bar or business centre is a different network. Thirty seconds at the desk while a human is in front of you saves a lot of guessing later, and the person who can re-register your room is standing right there.

  3. 3

    In the room, portal first and tunnel second

    Join the Wi-Fi, complete the sign-in page, and confirm that an ordinary web page loads. Then open WrapVPN, pick a location by the live latency in the server picker, and connect. The IP address card is the quickest confirmation that the exit you chose is the one your traffic is leaving from.

  4. 4

    Turn on Auto-Connect on Wi-Fi, then stop fiddling

    This is the setting that matters most across several nights, because it brings protection back as devices wake rather than waiting for you to notice. Check Session History after the first night to see how many times the tunnel re-established itself; on an older hotel network the answer is often more than you would have guessed.

What it costs

Short plans, priced so a week costs what a week is worth. Cancel by not renewing.

$1.99per week

$3.99per month

No annual subscription. No long-term commitment.

7-day free trial

See all plans

Common questions

Why did my hotel VPN stop working on the third night?

Usually because the property's sign-in session lapsed rather than anything in the app. Your device never left the network, so it keeps its address and everything looks connected while the gateway has quietly stopped forwarding. Open any plain web page, re-enter the room details the portal wants, and let protection re-establish. A device that has just woken from sleep produces the same symptom.

Can I bring the tunnel up before I have cleared the hotel sign-in page?

No, and nothing in the app can work around it. The gateway blocks everything except its own page until the terms are accepted, so the handshake has no path out of the building. The working order is join, sign in, load one ordinary page as proof, then connect. Keep that first unprotected stretch short and do not check your mail in it.

Does the hotel know which sites I used if the Wi-Fi is tied to my room number?

Without a tunnel it can associate the destinations your device reached with the room you registered, which is to say with your name and your folio. With one running, the property still knows the room is online, because you told it that at check-in, but what it carries is one encrypted session to a single endpoint rather than a list of the hosts you contacted. Be clear that the knowledge moves rather than disappears: the exit forwards your packets, so it is by construction the point that sees where they are addressed, and what is kept as opposed to momentarily seen is a question for the privacy policy.

The hotel charges for each device. Does one account help with that?

It helps with protection, not with the bill. A paid plan covers unlimited devices on one account, so every device that gets onto the network is protected with nothing extra to buy. The allowance itself is enforced at the gateway before your traffic reaches any server, so the options there are the desk, the per-device upgrade, or your own hotspot for the overflow.

Can other guests see my laptop on the hotel network?

On a flat guest network, where nothing isolates one room from another, they can see whatever your laptop is advertising: shared folders, a discoverable printer queue, a media library, a local development server. A tunnel protects traffic leaving the device and does nothing about this, so switch sharing off and let the operating system treat the network as public.

Will a VPN protect the streaming account I signed into the room television?

It will not. The television is not your device and is not inside your tunnel, so the session you opened on it stays open after you check out. Sign out on the set, then use the account's sign-out-everywhere control from your phone to catch it if you have already left. Better still, play from your own device and leave the credential on hardware you are taking home.

Get WrapVPN

One account covers your phone, tablet and computer. Connect in a tap, from any of our regions.