That really has nothing to do with the IAP. If you have an external captive portal, this could be coded into the HTML. The codes could be provided by hotel reception and this is all transparent to the IAP as once the 302 redirect is done, the session flow is between the client and the captive portal. That said your captive portal would need to be setup to interface with whatever provisioning system the hotel is using to generate the codes. You'd still need to POST back to the IAP for authentication upon entering the valid code.
If you are asking if the IAP can do this natively, the answer is no.
Adam