ISP Hotspot & Billing System Development

Job ID: 40111666

Budget: $750 – $1,500 USD

Here is the clean version of your project requirements with all emojis and special characters removed.

PROJECT: Cloud-Managed ISP Hotspot & Billing Platform (MikroTik + RADIUS + M-Pesa)

Project Overview
We are building a cloud-managed, multi-tenant ISP hotspot platform to power Paystore Kenya and to be resold to over 100 ISPs.

The system will provide:

Captive Wi-Fi portal (voucher + phone payment)

Centralized FreeRADIUS (primary in cloud)

M-Pesa STK Push integration

SMS voucher delivery (TextSMS)

MikroTik RouterOS v7 integration (Hotspot + API)

Admin dashboard for ISPs, sites, routers, plans, vouchers, and reports

This is a serious production system, not a basic hotspot script.

Core Functional Requirements
1. Captive Portal (Customer Side)
Mobile-friendly Wi-Fi login page.

User can buy internet using phone number + M-Pesa STK Push or login using a voucher code.

After successful payment: System generates a voucher, sends it via SMS, and automatically logs the user in.

Voucher rules: Can be reused on different devices; only one device online at a time; if logged in on a new device, the old session is disconnected.

Display: Expiry time, data remaining or unlimited status, connection status, and history.

2. Admin Dashboard (Multi-Tenant / Reseller Ready)
Support multiple ISPs (tenants) on one platform.

Each ISP has its own branding, plans, routers, and SMS credentials.

Admin features: ISP/tenant management, sites and routers (NAS), internet plans (time + speed + data OR unlimited), voucher management, live active users, sales and usage reports, SMS logs, and M-Pesa transaction logs.

Role-based access: Admin, support, and agent (Phase 2).

3. RADIUS (FreeRADIUS – Cloud Primary)
Central FreeRADIUS server with SQL backend.

Responsibilities: Authentication (voucher/phone accounts), authorization (speed, session time, data limits), and accounting (start, interim, stop).

Enforce: Single active session per voucher, data caps, and session expiry.

MikroTik RADIUS attributes (RouterOS v7): Mikrotik-Rate-Limit, Session-Timeout, and Simultaneous-Use = 1.

4. MikroTik Integration (RouterOS v7)
Hotspot authentication via RADIUS.

API integration for: Viewing active hotspot users, disconnecting sessions, and monitoring router health (CPU, RAM, uptime).

Support for multiple routers per ISP.

VPN-based connectivity (WireGuard preferred).

5. Payments – M-Pesa (Mandatory)
Safaricom Daraja STK Push with secure callback handling.

Rules: Voucher is created only after successful callback; idempotent callbacks to prevent duplicate vouchers; storage of full transaction data for audits.

Automation: Payment must auto-trigger voucher creation, SMS delivery, and auto-login.

6. SMS Integration
Provider: TextSMS (sms.textsms.co.ke).

SMS credentials stored per ISP.

Content must include: Voucher code, plan name, expiry date/time, data remaining/unlimited, and support contact.

SMS must be logged (sent/failed) with a rate-limited resend option.

Technical Stack (Required)
Backend: FastAPI (Python)

Database: PostgreSQL

RADIUS: FreeRADIUS

Cache / Queues: Redis

Frontend: Captive portal (HTML/JS), Admin UI (React or FastAPI templates)

Deployment: Linux (Ubuntu), Cloud-managed PostgreSQL and Redis

Routers: MikroTik RouterOS v7

Non-Functional Requirements
Multi-tenant isolation for 100+ ISPs.

Secure storage of API keys and secrets.

Scalable architecture and clean, documented code.

Logging, monitoring, and clear deployment documentation.

Deliverables
Working cloud-hosted platform.

Admin dashboard and captive portal.

FreeRADIUS, M-Pesa, and SMS integration.

MikroTik RouterOS v7 compatibility.

Database schema, API documentation, and handover documentation.

Project Engagement & Application
This is a long-term project with phased delivery and clear milestones.

Relevant projects (ISP, RADIUS, MikroTik, billing, payments).
PLATFORM LICENSING & BILLING ENFORCEMENT (MANDATORY)
Licensing Objective

The platform must include a built-in licensing system that:

Controls ISP (tenant) access to the platform

Enforces monthly or annual subscription payments

Automatically restricts or suspends services if payment is overdue

Cannot be bypassed by tenants (ISPs)

This license system applies per ISP, not per end-user.

Your proposed approach and architecture.

Estimated timeline and milestones.

Team composition (if applicable).