One platform. One protected gateway. No root credential distribution.

The gateway runs inside this Mappls Developer Platform deployment as a server-only trust boundary. Developers receive narrow, expiring platform authorization for exact operations; provider credentials stay in the same Replit project's production server secret boundary.

Allowlisted live surfaces9No arbitrary URL or headers
Beta quota1,000/dayTwo requests/second
Browser token5 minExact-origin bound
REST root secrets in clients0Web public key is origin-restricted

A gateway subsystem—not a second product.

The public portal, console, token edge, operation router and provider adapter ship from this repository and Replit deployment. Internal modules remain separated so secret custody can later move to KMS without changing the public API.

  1. 01
    Developer application

    Authenticates with a platform client or exact browser/mobile identity.

  2. 02
    Mappls Developer Platform edge

    Checks tenant, app, entitlement, operation, region, quota, token and kill switches.

  3. 03
    Server-only gateway core

    Selects a credential alias, validates the fixed schema and redacts responses and errors.

  4. 04
    Approved Mappls endpoint

    Receives only the conformed request. Missing evidence fails closed.

9 explicit operations. Nothing adjacent is implied.

autosuggestread-only

search.autosuggest

search-places · place query

Credential alias: core-rest-current
geocoderead-only

search.geocode

search-places · place query

Credential alias: core-rest-current
reverseGeocoderead-only

search.reverse_geocode

search-places · route coordinate

Credential alias: core-rest-current
nearbyread-only

search.nearby

search-places · route coordinate

Credential alias: core-rest-current
routeread-only

routes.plan

routes-navigation · route coordinate

Credential alias: core-rest-current
matrixread-only

routes.matrix

routes-navigation · route coordinate

Credential alias: core-rest-current
webMapLoadread-only

maps.web_js_load

maps · map viewport

Credential alias: web-js-platform
assetStatusread-only

intouch.device_status

intouch-telematics · sensitive live location

Credential alias: intouch-read
assetEventsread-only

intouch.device_events

intouch-telematics · sensitive live location

Credential alias: intouch-read

Fixture first. Live only when every gate is green.

Provider credentials never enter this browser. Live mode obtains a five-minute origin-bound platform token and invokes one catalogued operation.

No sign-in or network request
Execution mode
Safe response

Run the selected operation to inspect its typed response and provenance.

1,000 requests/day · 2/second · 9 operations

Gatewaying REST does not magically make every SDK live.

Each source stays visible with an honest delivery path. Package identity, platform restrictions, account entitlement and provider-side child credentials remain independent gates.

SurfacePlatform / statePrivate-beta delivery
Mapmyindia Intouch Android SDKmapmyindia-intouch-android-sdk
Androidstateful
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
MapmyIndia Vector Map Android SDKmapmyindia-maps-vectorSDK-android
Androidstateless
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mappls Android SDKmappls-android-sdk
Androidstateless
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mappls Camera SDKmappls-camera-sdk-android
Androidstateless
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mappls Intouch Android SDKmappls-intouch-android-sdk
Androidstateful
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mappls Location Capture SDKmappls-location-capture-android-sdk
Androidhybrid
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Workmate SDK - Androidmappls-workmate-android-sdk
Androidstateful
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Flutter MapmyIndia GLflutter-mapmyindia-gl
Flutterstateless
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mappls Flutter SDKmappls-flutter-sdk
Flutterstateless
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
[Mappls Intouch SDK]()mappls-intouch-ios-sdk
iOSstateful
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
[Mappls Map SDK]()mappls-map-ios-distribution
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
[Mappls Map SDK]()mappls-map-ios-distribution-base
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
[Mappls Map SDK]()mappls-map-move-ios-distribution-base
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
[MapplsAPICore]()mappls-api-core-ios-distribution
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapmyIndia Intouch iOS SDKmapmyindia-intouch-ios-sdk
iOSstateful
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mapmyindia Maps VectorSDK IOSmapmyindia-maps-vectorSDK-iOS
iOSstateless
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mappls Annotation Extension for iOSmappls-annotation-extension-ios-distribution
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
Mappls Annotation Extension for iOSmappls-annotation-extension-ios-distribution-base
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
Mappls Intouch IOS Distributionmappls-intouch-ios-distribution
iOSstateful
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
Mappls Intouch IOS Distribution Basemappls-intouch-ios-distribution-base
iOSstateful
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
Mappls iOS SDKmappls-ios-sdk
iOSstateless
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mappls LMS IOS Distributionmappls-lms-ios-distribution
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
Mappls LMS IOS Distribution Basemappls-lms-ios-distribution-base
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
Mappls Location Capture IOS SDKmappls-location-capture-ios-sdk
iOShybrid
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mappls Location Capture SDK (iOS)mappls-location-capture-sdk-ios-distribution
iOShybrid
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
Mappls Nearby Search Widget for iOSmappls-nearby-ui-ios-distribution
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
Mappls Nearby Search Widget for iOSmappls-nearby-ui-ios-distribution-base
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsCamera SDK for iOSmappls-camera-ios-distribution
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsCamera SDK for iOSmappls-camera-sdk-ios
iOSstateless
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
MapplsDirectionUI for iOSmappls-direction-ui-ios-distribution
iOShybrid
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsDirectionUI for iOSmappls-direction-ui-ios-distribution-base
iOShybrid
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsDrivingRangePlugin for iOSmappls-drivingrange-plugin-ios-distribution
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsDrivingRangePlugin for iOSmappls-drivingrange-plugin-ios-distribution-base
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsFeedbackKit for iOSmappls-feedback-kit-ios-distribution
iOShybrid
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsFeedbackKit for iOSmappls-feedback-kit-ios-distribution-base
iOShybrid
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsFeedbackUIKit for iOSmappls-feedback-uikit-ios-distribution
iOShybrid
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsFeedbackUIKit for iOSmappls-feedback-uikit-ios-distribution-base
iOShybrid
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsGeoanalytics Plugin for iOSmappls-geoanalytics-ios-distribution
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsGeoanalytics Plugin for iOSmappls-geoanalytics-ios-distribution-base
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsGeofenceUI Plugin for iOSmappls-geofence-ui-ios-distribution
iOShybrid
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsGeofenceUI Plugin for iOSmappls-geofence-ui-ios-distribution-base
iOShybrid
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsRasterCatalogue Plugin for iOSmappls-raster-catalogue-ios-distribution
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
MapplsRasterCatalogue Plugin for iOSmappls-raster-catalogue-ios-distribution-base
iOSstateless
provider-app credentialKeep fixture-backed until Mappls issues a per-app key, package or license artifact.
Mapmyindia Intouch React Native SDKmapmyindia-intouch-react-native-sdk
React Nativestateful
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mappls Intouch React Native SDKmappls-react-native-intouch-sdk
React Nativestateful
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mappls React Native SDKmappls-react-native-sdk
React Nativestateless
gateway-adjacentREST reads may use the gateway, but the SDK itself needs separate version and credential conformance.
Mapmyindia Places N Directions Web SDKmapmyindia-places-n-directions-web-sdk
Webstateless
hosted originMay qualify on the exact platform origin; never embed the shared provider key in a download.
Mapmyindia Vector Maps JS Web SDKmapmyindia-vector-maps-js-web-SDK
Webstateless
hosted originMay qualify on the exact platform origin; never embed the shared provider key in a download.
MapmyIndia Interactive Map JS API !mapmyindia-interactive-map-js-api
Web, RESTstateless
hosted originMay qualify on the exact platform origin; never embed the shared provider key in a download.
Placesiframe
Widgetstateless-view
hosted originThe official page supplies the iframe path and Pin, token, fullscreen, position, zoom, and pitch parameters. Token issuance and production entitlement remain account-specific.
Nearbyiframe
Widgetstateless-view
hosted originThe official page supplies the iframe path and Pin, token, traffic, keyword, fullscreen, and pitch parameters. Category availability remains an acceptance test.
EarthViewiframe
Widgetstateless-view
hosted originThe official page supplies the EarthView path, BSMP5 basemap, view, controls, zoom, rotation, details, timeline, and optional token parameters.
3D Metaverseiframe
Widgetstateless-view
hosted originThe official page supplies the immersive path and Pin, optional token, place details, shadow, and rotation parameters. Venue coverage must be confirmed independently.
Post on Mapiframe
Widgetapplication-owned-state
provider-app credentialThe official page shows the postOnMap iframe path and display parameters. Submission identity, moderation, callbacks, and completion semantics are not inferred by this generator.
RealView Auth2iframe
Widgetapplication-owned-state
provider-app credentialThe official Auth2 page marks RealView as an access-controlled paid service and documents the pano iframe, required access_token, distance, control, and inset-map parameters. This lab emits only a placeholder.
Add a Placeiframe
Widgetapplication-owned-state
provider-app credentialThe official page and demo establish the addAplace iframe and display parameters. Its examples append the first option with '&'; a dated public probe confirms the conventional '?' query shape succeeds while the documented ampersand path does not. No callback, receipt, moderation-status, withdrawal, or publication contract is documented.
mGIS enterprise widgetsjavascript-wrapper
Widgetenterprise-stateful
provider-app credentialThe official page documents widgets.js and MGIS.Widget(container, options), including widgetName, widgetKey, map settings, and workViewName. Keys, work views, tenant data, and lifecycle events belong to the enterprise contract.
Native and cross-platform widgetsnative-sdk
Widgetapplication-owned-state
provider-app credentialAndroid, iOS, Flutter, and React Native publish distinct package, lifecycle, permission, and callback contracts. Select an exact platform/version guide; an iframe configuration cannot stand in for native integration.

Code is shipped; live authority is deliberately external.

The platform remains fixture-first until the owner privately enters provider values, PostgreSQL is migrated, exact live conformance passes and an administrator activates the live gate. Stateful operations stay disabled until their complete journey, idempotency and reconciliation approvals exist.