Render the panorama. Keep the decision yours.

RealView Auth2 is a paid, token-bearing iframe. Its only documented parent-window result is no imagery. This guide makes entitlement, browser exposure, coverage, human observation, and review five separate contracts.

Paidentitlement required

The current Auth2 page requires enabled access and a browser-visible access token.

1documented signal

Only exact-origin { status: 204 } for no imagery enters the adapter.

0tokens accepted

The tool emits a conspicuous placeholder and never reads a secret.

10journey states

Human observation, review, rework, cancellation, and expiry remain application-owned.

Configure identity, radius, and controls

Viewer controls

Never paste a token here. The documented iframe URL makes the entitled value browser-visible.

entitlement-required

Mappls RealView Auth2 widget

Mappls Pin JQ5QN8

Non-runnable source templatehttps://pano.mappls.com/realview_widget/JQ5QN8?access_token=YOUR_ENTITLED_REALVIEW_ACCESS_TOKEN&minDistance=20&maxDistance=1000&arrow=true&map=true&zoomControls=false&controls=true&mapWidth=240&mapHeight=240

The documented iframe transports this browser-visible value in its query string. Obtain the exact entitled credential class and expiry/restriction policy; never substitute a server secret.

Iframe and exact-origin adapter
<div class="mappls-widget" aria-busy="false">
  <iframe src="https://pano.mappls.com/realview_widget/JQ5QN8?access_token=YOUR_ENTITLED_REALVIEW_ACCESS_TOKEN&amp;minDistance=20&amp;maxDistance=1000&amp;arrow=true&amp;map=true&amp;zoomControls=false&amp;controls=true&amp;mapWidth=240&amp;mapHeight=240" title="Mappls RealView Auth2 widget" loading="lazy" style="width: 100%; min-height: 420px; border: 0;" allowfullscreen></iframe>
  <p><a href="https://pano.mappls.com/realview_widget/JQ5QN8?access_token=YOUR_ENTITLED_REALVIEW_ACCESS_TOKEN&amp;minDistance=20&amp;maxDistance=1000&amp;arrow=true&amp;map=true&amp;zoomControls=false&amp;controls=true&amp;mapWidth=240&amp;mapHeight=240">Open the Mappls view directly</a></p>
</div>
Read as JSON

HTTP 200 can still mean “token required.”

On 2026-08-17 both documented iframe hosts returned an HTTP 200 shell without a token, but the shell explicitly rendered 'Required access_token.!'. HTTP success therefore proves neither entitlement nor imagery coverage.

The only documented parent-window signal is a no-imagery condition with data.status === 204. No success, panorama identity, capture date, camera pose, selected frame, measurement, annotation, export, or inspection-completion callback is established.

Open current Auth2 documentation

Four adjacent surfaces. Four different contracts.

The iframe, older host, Web Maps JS layer, and local experiment are evidence—not interchangeable implementation syntax.

Current official widget pagepano.mappls.com

Auth2 iframe

Paid, access-controlled iframe with Mappls Pin or coordinate, required access_token, radius, navigation, inset-map, zoom, and control options.

Separate official widget pagerealview.mappls.com

Earlier iframe

Similar documented shape on a different host. Do not silently swap hosts; pin the account-approved generation.

Public mappls-web-maps-js repositorymapObj.realview(boolean)

Web Maps JS layer

A map-layer toggle available from Web Maps JS v3.0, not the iframe callback or a panorama metadata API.

Local mapplsaiwebtesting implementationundocumented

Local experimental thumbnail

Uses layer introspection and an undocumented thumbnail path. It is adjacent implementation evidence only and is not published as a supported contract.

Ten states from business intent to reviewed evidence.

The Auth2 page marks RealView as paid and access controlled, requires an access_token in the iframe query, and says default OAuth access-token validity is 24 hours but configurable. The generator accepts no credential and emits only YOUR_ENTITLED_REALVIEW_ACCESS_TOKEN. Production must use the exact account-approved browser-visible credential class, expiry, origin policy, and renewal design; never substitute a server secret.

01
Host application

draft

One inspection owns external asset/site identity, purpose, selected Mappls Pin or coordinate, data classification, and version.

02
Platform administrator

entitlement pending

Account, environment, approved widget generation, browser-visible credential class, origin restrictions, expiry, quota, and permitted use are recorded.

03
Host application

ready

An unexpired entitlement reference and bounded viewer configuration exist; no token value or iframe URL has been persisted.

04
Browser lifecycle

viewing

One attempt owns the exact iframe origin, location/radius config, token-handle reference, mount, message listener, timeout, and disposal.

05
Provider adapter

coverage unavailable

An exact-origin, schema-valid status 204 message is recorded for this attempt and configuration—not generalized into permanent absence.

06
Inspector

observation recorded

A human records a bounded checklist and notes with attempt identity and time; no undocumented panorama metadata or copied imagery is claimed.

07
Inspection operations

review pending

An immutable observation set awaits a separately authorized reviewer under a declared policy.

08
Reviewer

accepted

A named reviewer accepts the observation set for its exact business purpose and policy version.

09
Reviewer

rework required

The review retains reason and prior evidence, then requires a new viewer attempt or alternate field evidence.

10
Inspector or operations

cancelled

The inspection ends with actor and reason while every prior attempt and observation remains attributable.

Persist references and decisions—not the viewer.

Inspection aggregate: external asset/site identity, purpose, Mappls Pin or coordinate, state, version, assignee, and policy

Entitlement reference: approved product/host/environment, credential class, issued/expiry metadata, restrictions, and revocation state—never the token value

Viewer attempt: exact origin, location/radius/control config, token-handle reference, opened/disposed times, and validated 204 outcome

Observation/review: bounded checklist, inspector notes, attempt link, reviewer decision, policy version, event/receipt time, and retention class

Audit/outbox: command identity, optimistic version, actor, transition, delivery state, and cleanup action

Useful visual context. Bounded business claims.

Each workflow names the proof needed after viewing and the inference that must remain outside the widget contract.

Utilities

Review poles, cabinets, trenches, and right-of-way context before dispatching a survey crew.

Asset identity, imagery availability, human observation, visible limitations, reviewer, and field-verification trigger.

Road operations

Triage a reported sign, shoulder, marking, or surface concern before scheduling inspection.

Road segment identity, observation time, bounded checklist, confidence limits, and maintenance/field escalation.

Insurance

Understand public street context around a declared incident without treating imagery as incident-time evidence.

Claim purpose, place identity, imagery-source limitation, reviewer notes, and explicit prohibition on occurrence inference.

Real estate

Review approach roads and neighborhood context for a property due-diligence queue.

Property/entrance identity, accessibility checklist, observed limitations, capture freshness unknown state, and review decision.

Retail

Screen storefront approach, visibility, and pedestrian context before an on-site feasibility visit.

Candidate-site version, human observations, no automated footfall claim, reviewer, and required field-validation items.

Telecom

Assess cabinet or tower approach constraints before dispatch and permit planning.

Asset identity, access-route observation, safety caveat, coverage result, and engineer review.

Government

Prioritize civic-asset surveys across a large inspection backlog.

Public purpose, location scope, equitable prioritization policy, observation ledger, and field confirmation.

Travel

Provide optional arrival context for a hotel or attraction with an accessible non-imagery alternative.

Stable place identity, optional viewer state, no-currentness promise, accessible text/map alternative, and handoff outcome.

Operate entitlement through review and rework.

The credential-free fixture proves exact-origin validation, status-204 handling, ephemeral handles, immutable attempts and observations, separation of duties, expiry recovery, audit, outbox, and restart recovery.

Run and download the desk Study the state machineInspect repository evidence