diff --git a/docs/on_boot_config.md b/docs/on_boot_config.md
index 32f54494..08abec2a 100644
--- a/docs/on_boot_config.md
+++ b/docs/on_boot_config.md
@@ -19,7 +19,7 @@ deleted.
## Setting up Wi-Fi
!!! note
- Devices based on Raspberry Pi Zero 2 W does not support 5GHz Wi-Fi.
+ PiKVM devices based on Raspberry Pi Zero 2 W do not support 5 GHz or WPA3 Wi-Fi networks.
1. Remove the PiKVM memory card. The device must be turned off.
@@ -49,7 +49,9 @@ deleted.
6. A few things to keep in mind:
* Note that after applying the settings, the pikvm.txt file will be deleted.
- * WPA3 is not supported. Enable WPA2 on your router, while AES is supported, some aspects of it is not and you may need to disable AES for it to connect.
+ * WPA3 support is experimental, and is only supported with newer devices.
+ If WPA3 does not work for you, switch your network into WPA2/3 mixed mode
+ and see below how to configure PiKVM to use WPA2/3 mixed mode instead.
* There is a possibility that, in countries that support channel 13, the device will not connect.
You will need to configure your router to disable channels 12-14 or disable Auto scan mode.
@@ -102,6 +104,12 @@ A number of other parameters can be applied in the same way as with Wi-Fi.
Both options must be set simultaneously to avoid incorrect configuration.
Can be followed by several options:
+* `WIFI_WPA3=1`
+ Enables **experimental** support for connecting to WPA3 networks.
+
+ !!! warning
+ Available only on new images >= 2026.08.16, and only on devices based on Raspberry Pi 4.
+
* `WIFI_WPA23=1`
Allows to connect to mixed WPA2/WPA3 networks in WPA2 mode. Specifically,
this enables WPA2 PMF (protected management frame) support.
diff --git a/docs/wifi.md b/docs/wifi.md
index 0f69aa45..e112600c 100644
--- a/docs/wifi.md
+++ b/docs/wifi.md
@@ -46,6 +46,37 @@ browser) should also work.
[root@pikvm ~]# chmod 640 /etc/wpa_supplicant/wpa_supplicant-wlan0.conf
```
+ [PiKVM V3](v3.md), [PiKVM V4](v4.md), and DIY builds based on Raspberry Pi 4
+ include experimental support for connecting to WPA3 networks. To connect to
+ a WPA3 network, you need to make sure your PiKVM is up-to-date, and edit the
+ `/etc/wpa_supplicant/wpa_supplicant-wlan0.conf` file after creating it:
+
+ 1. uncomment the plain-text `psk=` line, and comment/remove the hashed `psk=` line;
+ 2. add options `key_mgmt=SAE` and `ieee80211w=2` before the closing `}` line;
+ 3. finally, add a global option `sae_pwe=2` before the `network={` line.
+
+ For instance, if your `/etc/wpa_supplicant/wpa_supplicant-wlan0.conf` looks like this:
+ ```
+ network={
+ ssid="MyNetwork"
+ #psk="P@assw0rd"
+ psk=4134d31e95e6387761d485796310894b1ac5e9bb86b3b96e0dd3473cea440014
+ }
+ ```
+
+ You need to change it as follows:
+ ```
+ sae_pwe=2
+
+ network={
+ ssid="MyNetwork"
+ psk="P@assw0rd"
+ #psk=4134d31e95e6387761d485796310894b1ac5e9bb86b3b96e0dd3473cea440014
+ key_mgmt=SAE
+ ieee80211w=2
+ }
+ ```
+
!!! note "Connecting to mixed WPA2/3 networks in WPA2 mode (older devices)"
Add options `key_mgmt=WPA-PSK-SHA256 WPA-PSK` and `ieee80211w=1`
to `/etc/wpa_supplicant/wpa_supplicant-wlan0.conf` inside the `network={` block.
@@ -94,6 +125,10 @@ while a single `>` will overwrite the entire configuration.
[root@pikvm ~]# wpa_passphrase 'Wifi3' 'P@assw0rd' >> /etc/wpa_supplicant/wpa_supplicant-wlan0.conf
```
+ If any of those networks enable or require WPA3, edit your `wpa_supplicant-wlan0.conf`
+ as described above, making changes to relevant `network={...}` blocks.
+
+
3. Restart the service: `systemctl restart wpa_supplicant@wlan0.service`.
4. Make the filesystem read-only again using `ro` command