{"schemaVersion":"mappls.authentication-catalog.v1","summary":{"paths":14,"runtimes":10,"products":10,"noCredential":1,"publicRestricted":3,"trustedOrEntitled":10,"normalizedOperationsConsidered":162},"rules":["A credential name is not an authentication contract: product, runtime, generation, host/path, transport, region, restriction, expiry, and owner must agree.","Public browser/mobile keys are observable and therefore rely on exact restrictions; server keys, client secrets, and provider bearers never enter untrusted clients.","Current core static-query, legacy core OAuth, InTouch bearer, widget values, device activation, and MCP client identity are separate generations and security planes.","Repository security signals and normalized contracts are evidence, not proof of account entitlement, supported versions, or universal issuance behavior.","Rotation is a measured overlap-and-drain journey; revocation without consumer and in-flight reconciliation creates unknown outcomes."],"lifecycle":[{"phase":"1 · Classify","proof":"Runtime, product, auth generation, region, data class, and trust boundary are explicit before a credential is requested."},{"phase":"2 · Issue","proof":"A non-production application owns the credential; one-time reveal is acknowledged and no value enters tickets, chat, screenshots, or source."},{"phase":"3 · Store","proof":"Secrets use a managed secret provider; public app keys live only in the intended client configuration and remain restricted."},{"phase":"4 · Restrict","proof":"Exact origins, server egress, Android package/signing identity, iOS bundle/team context, scope, region, and expiry are least-privilege."},{"phase":"5 · Exercise","proof":"Success, missing, denied, expired, rate-limited, revoked, offline, and release-build paths are tested without credential reflection."},{"phase":"6 · Rotate","proof":"A second version is issued, both versions are observed during a bounded overlap, consumers drain, and the prior version is revoked."},{"phase":"7 · Reconcile","proof":"Inventory, last-safe-use metadata, owner, expiry, restrictions, provider identity, and revocation state agree with the control plane."}],"options":{"runtimes":["android","browser","cross-platform","deep-link","device","enterprise","ios","mcp","trusted-server","widget"],"products":["ai-location","app-widgets-deep-links","capture-feedback","gis-analytics","intouch-telematics","maps","offline-automotive","routes-navigation","search-places","workmate"]},"paths":[{"slug":"core-rest-current-static-key","title":"Current core REST from a trusted server","runtime":"trusted-server","platforms":["REST"],"products":["maps","search-places","routes-navigation"],"visibility":"secret","summary":"Use the current restricted static-key generation only inside a trusted process for current core location requests.","generation":"Current core REST","credentialClass":"Restricted static key","transport":"Documented access_token query contract, applied internally by the trusted adapter","stateBoundary":"The request is stateless; credential inventory, rotation, quota, provenance, and any business workflow are durable application/control-plane state.","useWhen":["The issued account explicitly names the current core REST generation","The selected Search, Maps, Route, or Matrix contract uses the approved current host/path line","The caller is a server, job, gateway, or MCP service—not an untrusted client"],"allowedPlacement":["Managed secret provider injected into a trusted process","Dedicated backend-for-frontend or policy-checked tool server","Separate non-production and production application identities"],"forbiddenPlacement":["Browser JavaScript, HTML, mobile bundle, desktop package, URL returned to a user, model context, logs, analytics, screenshots, or source","Generic proxy endpoints that accept arbitrary provider paths or parameters"],"restrictions":["Exact server egress identities and subscribed products","Query-string redaction at application, proxy, WAF, APM, and support boundaries","Explicit timeout, bounded idempotent retry, input/result limits, and safe request provenance"],"rotation":["Issue a second restricted version","Deploy it behind the same adapter and observe safe success/error rates","Drain caches/workers, revoke the old version, and reconcile inventory"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."}],"sourceGuideSlugs":["mappls-rest-apis"],"contractEvidence":{"operations":13,"modes":["not-declared"],"boundary":"The normalized current-source operations do not themselves declare a security scheme; static-query behavior is separately implemented and tested in the trusted-server SDK. The issued account remains authoritative."},"samples":[{"language":"typescript","label":"Trusted server adapter","code":"const mappls = new MapplsClient({\n  tokenProvider: envToken(\"MAPPLS_STATIC_KEY\"),\n  coreAuthentication: \"static-query\",\n});\n\nconst result = await mappls.geocode({ address, region: \"IND\" });\n// The SDK owns credential placement, timeout, bounded retry, and redaction."}],"consoleHref":"/console/credentials"},{"slug":"core-rest-legacy-oauth","title":"Legacy core REST OAuth generation","runtime":"trusted-server","platforms":["REST"],"products":["maps","search-places","routes-navigation"],"visibility":"secret","summary":"Preserve the pre-current OAuth bearer generation only for an explicitly approved legacy host/path contract; do not mix it with current static-key URLs.","generation":"Legacy core REST","credentialClass":"OAuth bearer access token plus server-held client credential material","transport":"Authorization: Bearer header on the issued legacy endpoint generation","stateBoundary":"Provider token state is time-bound; the application owns refresh serialization, expiry margin, rotation, migration, and request provenance.","useWhen":["The issued application and selected operation explicitly require the legacy OAuth line","A migration cannot yet move the caller to the current core generation","The client-credential exchange occurs only in a trusted process"],"allowedPlacement":["Managed secret storage and a single-flight token provider","Trusted server SDK configured explicitly as oauth-bearer"],"forbiddenPlacement":["Client secret or bearer token in browsers, mobile apps, model prompts, source, build arguments, logs, or support packets","Legacy token with a current host/path, or a current key with legacy URLs"],"restrictions":["Exact legacy host/path and subscribed scope","Refresh before expiry with one concurrent owner and bounded failure","Migration owner, deadline, compatibility tests, and rollback evidence"],"rotation":["Rotate client material in the provider-approved sequence","Warm and prove the new token provider without exposing token text","Drain the previous issuer material and complete the migration record"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."}],"sourceGuideSlugs":["mapmyindia-rest-api"],"contractEvidence":{"operations":8,"modes":["oauth2-bearer"],"boundary":"These normalized operations preserve public OAuth bearer evidence; they do not prove that an issued account, host, path, or product still uses this generation."},"samples":[{"language":"typescript","label":"Explicit legacy mode","code":"const mappls = new MapplsClient({\n  tokenProvider: singleFlightOAuthProvider(secretStore),\n  coreAuthentication: \"oauth-bearer\",\n  // Endpoint overrides come only from the approved legacy contract.\n});"}],"consoleHref":"/console/credentials"},{"slug":"intouch-rest-bearer","title":"InTouch telematics data plane","runtime":"trusted-server","platforms":["REST","Web","Android","iOS","React Native"],"products":["intouch-telematics"],"visibility":"secret","summary":"Use a separately scoped InTouch bearer in a trusted data-plane adapter; never reuse the current core static key.","generation":"InTouch REST","credentialClass":"Time-bound InTouch bearer","transport":"Authorization: Bearer header","stateBoundary":"Reads may be request-shaped, but asset identity, consent, time windows, cursor/checkpoint, triage, retention, and audit belong to the application journey.","useWhen":["The project is subscribed to the exact InTouch asset operation","The backend applies asset, time-window, field, purpose, and principal policy","Mobile or web experiences call an application backend rather than receiving the provider bearer"],"allowedPlacement":["Trusted server or MCP live-read process under a separately named secret","Short-lived internal result cache with tenant and policy identity"],"forbiddenPlacement":["APK, IPA, browser bundle, widget URL, client-side storage, model context, or a core-location credential variable","Unbounded asset history or arbitrary project proxy"],"restrictions":["Project, asset, operation, time range, user purpose, and data minimization","Precise-location access audit and response-field allow-list","Independent expiry, rotation, and incident response from core location credentials"],"rotation":["Acquire a replacement through the approved InTouch project flow","Prove both token classification and least-scope reads in non-production","Drain, revoke, and reconcile independently of all core credentials"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."}],"sourceGuideSlugs":["mappls-intouch-rest-apis","mapmyindia-intouch-rest-apis"],"contractEvidence":{"operations":53,"modes":["bearer"],"boundary":"The normalized repository contract declares bearer transport for these InTouch operations; entitlement, token issuance, permitted assets, and production retention remain account-specific."},"samples":[{"language":"typescript","label":"Separate InTouch provider","code":"const mappls = new MapplsClient({\n  tokenProvider: envToken(\"MAPPLS_STATIC_KEY\"),\n  coreAuthentication: \"static-query\",\n  intouchTokenProvider: envToken(\"MAPPLS_INTOUCH_ACCESS_TOKEN\"),\n});\n\nconst status = await mappls.assetStatus({ assetId, region: \"IND\" });"}],"consoleHref":"/console/credentials"},{"slug":"workmate-oauth","title":"Workmate workforce APIs","runtime":"trusted-server","platforms":["REST","Web","Android"],"products":["workmate"],"visibility":"selection-required","summary":"Use the exact organization, actor, host, OAuth generation, and transition contract issued for the Workmate integration.","generation":"Workmate source generation","credentialClass":"Organization/user-scoped OAuth evidence; issuance confirmation required","transport":"Bearer transport where declared by the selected source contract","stateBoundary":"Task, assignment, acceptance, proof, review, exception, and actor history are durable workflow state; authentication never substitutes for transition authorization.","useWhen":["The organization has an approved Workmate API entitlement","Service and human actor boundaries are separately modeled","Every mutation uses an idempotency and reconciliation design"],"allowedPlacement":["Trusted workforce integration service","User session only after company identity and Workmate actor mapping are approved"],"forbiddenPlacement":["Shared organization credential in a worker client","Treating a successful token as permission for every task transition"],"restrictions":["Organization, actor, task/action, purpose, region, and least fields","Optimistic concurrency, transition invariants, audit, outbox, and reconciliation","Exact source generation and provider provisioning approval"],"rotation":["Freeze the exact actor/service mapping","Rotate through an approved non-production transition suite","Drain pending commands and reconcile unknown outcomes before revocation"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."}],"sourceGuideSlugs":["mapmyindia-workmate-apis","mappls-workmate-android-sdk"],"contractEvidence":{"operations":13,"modes":["oauth2-bearer"],"boundary":"The public Workmate contracts preserve OAuth bearer evidence, but the company-issued organization, user, host, scope, and lifecycle contract is authoritative."},"samples":[],"consoleHref":"/console/credentials"},{"slug":"web-public-key","title":"Browser Web Maps and Places","runtime":"browser","platforms":["Web"],"products":["maps","search-places","routes-navigation"],"visibility":"public-restricted","summary":"Use only the browser-supported public credential class, restricted to exact origins; privileged REST operations stay behind a backend.","generation":"Selected Web SDK generation","credentialClass":"Origin-restricted browser public key","transport":"Documented Web SDK configuration for the selected source line","stateBoundary":"Map/view state is client lifecycle state; accepted place identity, workflow state, policy, and privileged calls remain application/backend owned.","useWhen":["The selected Web SDK guide explicitly supports the issued browser credential","Every production and preview origin is known","A backend-for-frontend owns privileged or sensitive operations"],"allowedPlacement":["Documented Web SDK configuration or server-rendered public runtime configuration","Exact-origin development and production applications with separate keys"],"forbiddenPlacement":["Server secret, OAuth client secret, InTouch bearer, or unrestricted key in JavaScript","Secrets disguised by environment-variable names in a client build"],"restrictions":["Exact scheme, hostname, and port; avoid broad wildcards","CSP, dependency/version pinning, callback validation, and teardown","Separate preview, development, and production identities"],"rotation":["Register new exact origins before rollout","Deploy the replacement public key and prove every origin","Remove the old key after cache/service-worker drain"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."}],"sourceGuideSlugs":["mappls-web-maps","mappls-web-maps-js"],"contractEvidence":{"operations":0,"modes":[],"boundary":"Web SDK repository evidence identifies the client surface; the issued key configuration, supported script/package line, origins, and entitlements remain authoritative."},"samples":[{"language":"typescript","label":"Public runtime configuration","code":"type PublicMapConfig = { publicKey: string; allowedOrigin: string };\n\nconst config = readPublicConfig();\nif (location.origin !== config.allowedOrigin) throw new Error(\"Unexpected origin\");\n// Pass only the issued browser public key to the documented Web SDK adapter."}],"consoleHref":"/console/credentials"},{"slug":"android-public-key","title":"Android native application","runtime":"android","platforms":["Android"],"products":["maps","search-places","routes-navigation","capture-feedback"],"visibility":"public-restricted","summary":"Use only the Android app credential documented for the selected SDK line and restrict it to package plus signing identity.","generation":"Selected Android SDK generation","credentialClass":"Android application public credential","transport":"Documented Android application initialization","stateBoundary":"SDK/view/session lifecycle belongs to the app process; accepted domain records, user consent, and server operations remain outside the credential.","useWhen":["Package, signing certificate, build variant, SDK line, and entitlement are approved together","Release builds are tested on physical devices","Server secrets remain behind an application backend"],"allowedPlacement":["Documented Android manifest/resource/runtime configuration for a public app key","Variant-specific non-production and production configuration"],"forbiddenPlacement":["Static server key, OAuth client secret, or InTouch data-plane bearer in resources, BuildConfig, assets, native libraries, or Java/Kotlin","One fleet-wide secret baked into an APK"],"restrictions":["Exact package and signing certificate identity","SDK and toolchain compatibility plus release signing","Permission denial, recreation, background/resume, offline, and teardown tests"],"rotation":["Register the next key against every active signing identity","Ship a bounded release cohort and monitor safe initialization errors","Retire the prior key only after supported app versions drain or an overlap policy is approved"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."}],"sourceGuideSlugs":["mappls-android-sdk","mappls-android-compose-demo"],"contractEvidence":{"operations":0,"modes":[],"boundary":"Android source repositories provide SDK/sample evidence, not a universal credential field, compatibility matrix, or entitlement promise."},"samples":[{"language":"kotlin","label":"Application-owned boundary","code":"interface MapCredentialProvider {\n  fun publicAndroidKey(): String\n}\n\n// Inject only the package/signing-restricted app credential into the\n// documented SDK initialization for the approved release line."}],"consoleHref":"/console/credentials"},{"slug":"ios-public-key","title":"iOS native application","runtime":"ios","platforms":["iOS"],"products":["maps","search-places","routes-navigation","capture-feedback"],"visibility":"public-restricted","summary":"Use only the iOS app credential documented for the selected SDK release and bind approval to bundle/team context.","generation":"Selected iOS SDK generation","credentialClass":"iOS application public credential","transport":"Documented iOS application initialization","stateBoundary":"Scene/view/delegate ownership is client lifecycle state; consent, accepted business records, and privileged operations remain application/server owned.","useWhen":["Bundle, team/signing, target, package/binary set, and entitlement are approved together","Archive and physical-device behavior are proven","Extensions receive only explicitly approved capability"],"allowedPlacement":["Documented iOS public app configuration for the selected package line","Target-specific non-production and production configuration"],"forbiddenPlacement":["Server key, OAuth client secret, or provider bearer in plist, source, resources, keychain-as-distribution, or binary obfuscation","Assuming Keychain makes an embedded provider secret safe"],"restrictions":["Exact bundle/team context and approved targets","Complete Swift/Xcode/package/binary compatibility set","Scene restore, backgrounding, memory pressure, permission changes, and teardown"],"rotation":["Approve a replacement for every shipping target","Release with bounded overlap and safe initialization telemetry","Retire only after supported installed versions are accounted for"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."}],"sourceGuideSlugs":["mappls-ios-sdk","mappls-map-ios-distribution","mappls-api-kit-ios-distribution"],"contractEvidence":{"operations":0,"modes":[],"boundary":"iOS source and distribution repositories identify candidate SDK lines; account credentials, checksums, target compatibility, and entitlement require confirmation."},"samples":[{"language":"swift","label":"Application-owned boundary","code":"protocol MapCredentialProviding {\n  var publicIOSKey: String { get }\n}\n\n// Supply only the bundle/team-approved public app credential to the\n// documented SDK initializer for the resolved package set."}],"consoleHref":"/console/credentials"},{"slug":"cross-platform-native-keys","title":"React Native, Flutter, Cordova, or Xamarin","runtime":"cross-platform","platforms":["React Native","Flutter","Cordova","Xamarin"],"products":["maps","search-places","routes-navigation","intouch-telematics"],"visibility":"selection-required","summary":"Configure Android and iOS halves independently; shared JavaScript or Dart is neither a secret store nor evidence of native parity.","generation":"Wrapper plus underlying native SDK generations","credentialClass":"Separate platform app credentials; wrapper-specific confirmation required","transport":"Underlying native initialization, not a shared privileged credential","stateBoundary":"The shared layer owns normalized app state; each native bridge owns readiness, events, cancellation, teardown, and its separately approved credential.","useWhen":["Wrapper, Android, iOS, architecture mode, and toolchain versions are one approved matrix","Both native sample halves work before the shared feature","A backend owns privileged operations"],"allowedPlacement":["Android and iOS public application configuration separately","A typed bridge that never returns credential text to the shared layer"],"forbiddenPlacement":["Server secret in JavaScript, Dart, assets, compile-time constants, or a native bridge getter","One cross-platform key assumed to cover both native restriction systems"],"restrictions":["Android package/signing and iOS bundle/team independently","Wrapper/native dependency parity and release builds","Mount/unmount, late callbacks, offline, background/resume, and bridge cleanup"],"rotation":["Rotate each native platform as its installed-base policy permits","Prove both release artifacts and shared error normalization","Retire per-platform versions independently"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."}],"sourceGuideSlugs":["mappls-react-native-sdk","mappls-flutter-sdk","flutter-mapmyindia-gl"],"contractEvidence":{"operations":0,"modes":[],"boundary":"Wrapper repositories are integration evidence only. The exact wrapper/native credential methods, compatibility matrix, and supported architecture require confirmation."},"samples":[{"language":"typescript","label":"No credential bridge","code":"type NativeMapAdapter = {\n  ready(): Promise<void>;\n  selectPlace(id: string): Promise<void>;\n  dispose(): Promise<void>;\n};\n\n// The shared API exposes behavior—not Android/iOS credential values."}],"consoleHref":"/console/credentials"},{"slug":"iframe-and-app-widgets","title":"App widgets and iframe embeds","runtime":"widget","platforms":["Widgets","Web"],"products":["app-widgets-deep-links","gis-analytics"],"visibility":"entitlement-specific","summary":"Many documented app widgets are credential-free; optional or paid access remains a literal placeholder until the exact widget entitlement is issued.","generation":"Selected widget contract","credentialClass":"None, origin-restricted browser value, or paid ephemeral token—selection required","transport":"Documented iframe parameter or browser wrapper only where the selected widget requires it","stateBoundary":"Frame load is not completion. The host owns origin/schema validation, candidate/accepted state, reconciliation, accessibility fallback, and any durable contribution or review journey.","useWhen":["The exact current widget URL and event/callback contract are selected","The host can operate without the widget","Paid/optional token ownership and expiry are explicitly approved"],"allowedPlacement":["No credential for credential-free widget shapes","Only the documented browser-visible placeholder/value for an entitled widget","Exact-origin postMessage validation and narrow CSP"],"forbiddenPlacement":["Server secret in an iframe URL","Persisting or logging token-bearing URLs","Treating HTTP 200 or frame load as entitlement, coverage, publication, or business completion"],"restrictions":["Exact frame and message origins, schema, CSP, referrer policy, and fallback","Widget-specific entitlement, expiry, data purpose, and callback lifecycle","No sensitive payload in query parameters"],"rotation":["Rotate only through the selected widget entitlement contract","Update the host without logging complete URLs","Prove expired/revoked/blocked behavior and remove cached token-bearing state"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."}],"sourceGuideSlugs":["mappls-app-widgets","mappls-web-plugins"],"contractEvidence":{"operations":0,"modes":[],"boundary":"Widget evidence varies by family and generation. The widget builder emits placeholders only and does not accept, persist, or validate credentials."},"samples":[{"language":"html","label":"Credential-free host first","code":"<iframe\n  src=\"APPROVED_MAPPLS_WIDGET_URL\"\n  title=\"Mappls place experience\"\n  referrerpolicy=\"no-referrer\"\n></iframe>\n<!-- Never paste a server credential into an iframe URL. -->"}],"consoleHref":"/console/credentials"},{"slug":"deep-links-no-credential","title":"Mappls deep links","runtime":"deep-link","platforms":["Deep links","Web","Android","iOS"],"products":["app-widgets-deep-links"],"visibility":"none","summary":"Mappls app hand-off links need no credential; the URL carries only bounded, non-sensitive intent.","generation":"Current documented link shape","credentialClass":"No credential","transport":"Validated HTTPS link, with installed-app URI only where documented","stateBoundary":"The hand-off is stateless; the application owns user intent, fallback, downstream arrival evidence, consent, and any durable workflow.","useWhen":["A zero-SDK hand-off meets the experience","The exact place/navigation/link shape is documented","Browser fallback is acceptable"],"allowedPlacement":["Validated public intent with encoded Mappls Pin, coordinates, name, or travel mode as documented"],"forbiddenPlacement":["Any API key, token, private address, precise private/user payload, internal ID, or server secret in the URL","Assuming click means app-open or arrival"],"restrictions":["Allow-listed HTTPS host/path and bounded fields","Consent before sending location intent","Separate click, app open, browser fallback, recovery, and arrival evidence"],"rotation":["No credential rotation","Version and regression-test the approved link shape","Remove deprecated paths through normal application release control"],"diagnostics":[{"signal":"The app does not open","likelyCause":"The URI is undocumented, unavailable, or the app is not installed.","nextAction":"Use the documented HTTPS link as the primary hand-off and retain a visible browser fallback."},{"signal":"The destination is wrong","likelyCause":"Coordinate order, encoding, Mappls Pin, or mode differs from the selected intent contract.","nextAction":"Rebuild through the bounded deep-link tool and test the same fixture across app-installed and browser-only devices."}],"sourceGuideSlugs":["mappls-app-widgets"],"contractEvidence":{"operations":0,"modes":[],"boundary":"Deep links are documented outside the REST contract catalog and carry no credential."},"samples":[{"language":"typescript","label":"Intent only","code":"const url = buildMapplsDeepLink({\n  intent: \"share-place\",\n  mapplsPin: selectedPlace.mapplsPin,\n});\n// Never append a key, token, or private application payload."}],"consoleHref":"/tools/deep-links"},{"slug":"mgis-entitled-browser","title":"mGIS browser surfaces","runtime":"enterprise","platforms":["Web","Widgets","REST","MCP"],"products":["gis-analytics"],"visibility":"entitlement-specific","summary":"Keep the entitled widget key, Web JS access token, durable workspace API identity, and sovereign deployment identity as separate contracts.","generation":"Selected mGIS or MIGIST surface","credentialClass":"Surface-specific enterprise credential; exact issuance required","transport":"Documented browser parameter or approved trusted adapter for the selected surface","stateBoundary":"Dataset versions, styles, analysis attempts, exports, lineage, sharing, and audit are durable workspace state; a browser callback is only candidate evidence.","useWhen":["Workspace, tenant, region, dataset, surface, and method are approved","Browser and server credential classes are separated","Durable commands have idempotency, expected version, receipt, and reconciliation"],"allowedPlacement":["Browser-visible widget/Web SDK value only where explicitly documented and origin-restricted","Trusted adapter for workspace/API credentials","Deployment-specific device/workload identity for sovereign runtimes"],"forbiddenPlacement":["Server/workspace secret in browser code","Reusing an mGIS browser value for MIGIST, generic REST, or another tenant","Invented endpoint or method name where source evidence conflicts"],"restrictions":["Tenant, workspace, dataset, method, role, share/export purpose, origin, and retention","Versioned dataset/style/workview identity and immutable lineage","Exact entitlement plus naming-drift release gates"],"rotation":["Classify every consumer by surface before issuance","Rotate browser and trusted-service identities independently","Reconcile in-flight analysis/export attempts before revoking a service identity"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."}],"sourceGuideSlugs":["mapmyindia-mgis-apis","mapmyindia-mgis-libraries"],"contractEvidence":{"operations":0,"modes":[],"boundary":"mGIS evidence spans browser methods, durable workspace descriptions, and a separate sovereign distribution. It does not establish one universal authentication contract."},"samples":[{"language":"typescript","label":"Trusted workspace seam","code":"interface MgisWorkspaceAdapter {\n  publish(command: PublishDatasetCommand): Promise<ProviderReceipt>;\n  reconcile(attemptId: string): Promise<AttemptStatus>;\n}\n// Exact endpoint and auth come only from the approved workspace contract."}],"consoleHref":"/console/credentials"},{"slug":"offline-device-activation","title":"Offline and automotive activation","runtime":"device","platforms":["Automotive","Linux","Android"],"products":["offline-automotive"],"visibility":"entitlement-specific","summary":"Treat per-device activation, licensed runtime/data, signatures, and fleet release policy as a provisioning system—not as a reusable API key.","generation":"Entitled runtime and data release","credentialClass":"Per-device/workload identity plus non-secret activation evidence and licensed artifacts","transport":"Approved manufacture/fleet provisioning channel","stateBoundary":"Activation, runtime/data compatibility, slots, qualification, rollout, rollback, and retirement are durable fleet state and must survive long offline periods.","useWhen":["The exact hardware, ABI, graphics, runtime, data epoch, region, vehicle interfaces, and license are entitled","A device/fleet control plane owns manufacture through retirement","A/B activation and rollback are atomic"],"allowedPlacement":["Per-device secure hardware/workload identity","Signed manifests and separately delivered runtime/data/license material","Non-secret activation state in health evidence"],"forbiddenPlacement":["Fleet-wide shared secret or license baked into an image","Protected artifact bodies, package URLs, keys, or license files in docs, logs, model context, or support bundles","Treating copied files as successful activation"],"restrictions":["Device, fleet, region, hardware/software manifest, validity, and release cohort","Signature, compatibility, storage, power-loss, rollback, backup/restore, and retirement","Minimum offline privilege and revocation/reconciliation on reconnect"],"rotation":["Stage a signed compatible release in the inactive slot","Qualify, atomically activate, observe, and retain rollback","Retire the previous release or device identity only after fleet reconciliation"],"diagnostics":[{"signal":"Runtime starts but rendering or routing fails","likelyCause":"Runtime, data epoch, ABI, graphics, configuration, voice, region, or activation is incompatible.","nextAction":"Fail readiness, retain the prior slot, compare the signed release manifest to device facts, and obtain the exact compatibility decision."},{"signal":"Activation is unknown after interruption","likelyCause":"The process persisted partial files instead of one atomic active-slot pointer and durable receipt.","nextAction":"Boot the last qualified slot, reconcile the staged manifest and activation journal, and never guess success from file presence."}],"sourceGuideSlugs":[],"contractEvidence":{"operations":0,"modes":[],"boundary":"The public snapshot does not establish a universal offline/automotive credential or safety contract. Entitled release material is authoritative."},"samples":[{"language":"text","label":"Fleet lifecycle","code":"manufacture → provision → stage → qualify → activate → observe\n                                      ↘ rollback → reconcile → retire\n\nNo shared fleet credential belongs in the runtime image."}],"consoleHref":"/tools/automotive"},{"slug":"mcp-gateway-and-provider","title":"MCP and AI-native clients","runtime":"mcp","platforms":["MCP","REST"],"products":["ai-location","maps","search-places","routes-navigation","intouch-telematics","gis-analytics"],"visibility":"selection-required","summary":"Keep MCP client identity, tool authorization, and underlying Mappls provider credentials as independent security planes.","generation":"MCP offline or live-read profile","credentialClass":"None for offline tools; gateway/OAuth client token for remote MCP; product credential stays inside the server for approved live reads","transport":"Local stdio or authenticated stateless Streamable HTTP; provider transport is tool-specific and never exposed to the client","stateBoundary":"The MCP transport is stateless; principal, approval, execution lease, tool evidence, provenance, replay protection, and business workflows are application-owned durable state.","useWhen":["Offline discovery/configuration is preferred unless live provider data is required","Tool input/output is typed, bounded, policy-checked, and provenance-validated","Remote identity is scoped to the exact MCP resource and is independent of provider credentials"],"allowedPlacement":["Provider credentials only in the MCP service secret provider","Short-lived remote MCP access token only in the MCP client transport","No credential for local/offline catalog tools"],"forbiddenPlacement":["Provider key/token in model context, prompt, tool arguments, client configuration, structured output, errors, logs, or provenance","MCP gateway token reused as a Mappls provider credential","Write tools or arbitrary URLs in the read-only profile"],"restrictions":["Exact MCP resource, issuer, audience, principal, client, scope, expiry, origin, and profile","Tool allow-list, input/output bounds, egress allow-list, redaction, rate limit, audit, and approval","Underlying product credential restricted independently by product, region, and server egress"],"rotation":["Rotate MCP gateway/OAuth identity independently of provider credentials","Rotate each provider credential through its own path while keeping tool schemas stable","Revoke leases and reconcile in-flight executions before removing either identity"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."},{"signal":"Tool is not listed","likelyCause":"The endpoint uses the offline profile, the client lacks the required scope, or the selected capability is intentionally unavailable.","nextAction":"Use offline planning first; move to a separately deployed live-read profile only with approved product entitlement and least scope."}],"sourceGuideSlugs":[],"contractEvidence":{"operations":162,"modes":["bearer","not-declared","oauth2-bearer"],"boundary":"MCP documentation tools need no provider credential. Live-read tools delegate to exact product contracts; the MCP server is not an authorization server and exposes no writes."},"samples":[{"language":"json","label":"Remote MCP client boundary","code":"{\n  \"url\": \"https://mcp.example.com/mcp\",\n  \"headers\": { \"Authorization\": \"Bearer ${MCP_RESOURCE_TOKEN}\" }\n}\n// MAPPLS_* provider credentials exist only in the MCP server process."}],"consoleHref":"/ai"},{"slug":"contract-selection-required","title":"Entitled or source-ambiguous product","runtime":"enterprise","platforms":["REST","Web","Android","iOS","Widgets","MCP"],"products":["gis-analytics","capture-feedback","ai-location"],"visibility":"selection-required","summary":"When public evidence does not establish issuance, host/path generation, or client placement, stop at the adapter boundary and obtain the exact account contract.","generation":"Account-specific","credentialClass":"Selection required","transport":"Selection required—never inferred from an adjacent Mappls product","stateBoundary":"Authentication uncertainty is a release gate. Durable business state still requires explicit actors, commands, evidence, reconciliation, audit, and retention.","useWhen":["The selected source says entitlement, activation, token, access, or API key but does not establish the full contract","Multiple public/local generations conflict","A product or deployment is company-provisioned"],"allowedPlacement":["Typed adapter with no credential literal","Blank secret/public-key placeholders classified by intended runtime","Provisioning request that records exact evidence gaps"],"forbiddenPlacement":["Trying static key, OAuth bearer, browser token, or another product credential until one works","Copying a sample credential field into production without matching issuance and restriction evidence"],"restrictions":["Provider owner, product, generation, host/path, runtime, transport, scopes, region, restriction, expiry, rotation, and revocation must all be answered","Non-production hostile-path proof before production issuance"],"rotation":["Define the issued lifecycle before the first credential","Prove replacement, overlap/drain, revoke, and reconciliation in non-production","Attach evidence to the application—not to informal operator memory"],"diagnostics":[{"signal":"401 or authentication rejected","likelyCause":"The credential generation, transport, host/path line, expiry, or product scope does not match the selected contract.","nextAction":"Stop retries; compare the issued credential class and exact contract, retain only a safe request identity, and test a new non-production credential after reconciliation."},{"signal":"403 or entitlement rejected","likelyCause":"Authentication succeeded but the application, product, region, origin, package, bundle, asset, workspace, or operation is not allowed.","nextAction":"Keep the same credential shape and reconcile entitlement plus restrictions in the console; do not weaken restrictions blindly."},{"signal":"Works locally, fails in release","likelyCause":"Release origin, signing certificate, bundle, egress address, build configuration, or environment injection differs from development.","nextAction":"Compare safe runtime identity to the registered restriction and prove the release artifact without printing the credential."}],"sourceGuideSlugs":[],"contractEvidence":{"operations":0,"modes":[],"boundary":"This path exists specifically to prevent public source signals from being promoted into an invented authentication contract."},"samples":[{"language":"typescript","label":"Fail-closed adapter","code":"interface EntitledProviderAdapter {\n  execute(command: ApprovedCommand): Promise<ProviderReceipt>;\n}\n\nthrow new Error(\"Credential contract selection required\");"}],"consoleHref":"/console/credentials"}]}