The current Auth2 page requires enabled access and a browser-visible access token.
Render the panorama. Keep the decision yours.
RealView Auth2 is a paid, token-bearing iframe. Its only documented parent-window result is no imagery. This guide makes entitlement, browser exposure, coverage, human observation, and review five separate contracts.
Only exact-origin { status: 204 } for no imagery enters the adapter.
The tool emits a conspicuous placeholder and never reads a secret.
Human observation, review, rework, cancellation, and expiry remain application-owned.
Mappls RealView Auth2 widget
Mappls Pin JQ5QN8
https://pano.mappls.com/realview_widget/JQ5QN8?access_token=YOUR_ENTITLED_REALVIEW_ACCESS_TOKEN&minDistance=20&maxDistance=1000&arrow=true&map=true&zoomControls=false&controls=true&mapWidth=240&mapHeight=240The documented iframe transports this browser-visible value in its query string. Obtain the exact entitled credential class and expiry/restriction policy; never substitute a server secret.
<div class="mappls-widget" aria-busy="false">
<iframe src="https://pano.mappls.com/realview_widget/JQ5QN8?access_token=YOUR_ENTITLED_REALVIEW_ACCESS_TOKEN&minDistance=20&maxDistance=1000&arrow=true&map=true&zoomControls=false&controls=true&mapWidth=240&mapHeight=240" title="Mappls RealView Auth2 widget" loading="lazy" style="width: 100%; min-height: 420px; border: 0;" allowfullscreen></iframe>
<p><a href="https://pano.mappls.com/realview_widget/JQ5QN8?access_token=YOUR_ENTITLED_REALVIEW_ACCESS_TOKEN&minDistance=20&maxDistance=1000&arrow=true&map=true&zoomControls=false&controls=true&mapWidth=240&mapHeight=240">Open the Mappls view directly</a></p>
</div>HTTP 200 can still mean “token required.”
On 2026-08-17 both documented iframe hosts returned an HTTP 200 shell without a token, but the shell explicitly rendered 'Required access_token.!'. HTTP success therefore proves neither entitlement nor imagery coverage.
The only documented parent-window signal is a no-imagery condition with data.status === 204. No success, panorama identity, capture date, camera pose, selected frame, measurement, annotation, export, or inspection-completion callback is established.
Open current Auth2 documentationFour adjacent surfaces. Four different contracts.
The iframe, older host, Web Maps JS layer, and local experiment are evidence—not interchangeable implementation syntax.
pano.mappls.comAuth2 iframe
Paid, access-controlled iframe with Mappls Pin or coordinate, required access_token, radius, navigation, inset-map, zoom, and control options.
realview.mappls.comEarlier iframe
Similar documented shape on a different host. Do not silently swap hosts; pin the account-approved generation.
mapObj.realview(boolean)Web Maps JS layer
A map-layer toggle available from Web Maps JS v3.0, not the iframe callback or a panorama metadata API.
undocumentedLocal experimental thumbnail
Uses layer introspection and an undocumented thumbnail path. It is adjacent implementation evidence only and is not published as a supported contract.
Ten states from business intent to reviewed evidence.
The Auth2 page marks RealView as paid and access controlled, requires an access_token in the iframe query, and says default OAuth access-token validity is 24 hours but configurable. The generator accepts no credential and emits only YOUR_ENTITLED_REALVIEW_ACCESS_TOKEN. Production must use the exact account-approved browser-visible credential class, expiry, origin policy, and renewal design; never substitute a server secret.
draft
One inspection owns external asset/site identity, purpose, selected Mappls Pin or coordinate, data classification, and version.
entitlement pending
Account, environment, approved widget generation, browser-visible credential class, origin restrictions, expiry, quota, and permitted use are recorded.
ready
An unexpired entitlement reference and bounded viewer configuration exist; no token value or iframe URL has been persisted.
viewing
One attempt owns the exact iframe origin, location/radius config, token-handle reference, mount, message listener, timeout, and disposal.
coverage unavailable
An exact-origin, schema-valid status 204 message is recorded for this attempt and configuration—not generalized into permanent absence.
observation recorded
A human records a bounded checklist and notes with attempt identity and time; no undocumented panorama metadata or copied imagery is claimed.
review pending
An immutable observation set awaits a separately authorized reviewer under a declared policy.
accepted
A named reviewer accepts the observation set for its exact business purpose and policy version.
rework required
The review retains reason and prior evidence, then requires a new viewer attempt or alternate field evidence.
cancelled
The inspection ends with actor and reason while every prior attempt and observation remains attributable.
Persist references and decisions—not the viewer.
Inspection aggregate: external asset/site identity, purpose, Mappls Pin or coordinate, state, version, assignee, and policy
Entitlement reference: approved product/host/environment, credential class, issued/expiry metadata, restrictions, and revocation state—never the token value
Viewer attempt: exact origin, location/radius/control config, token-handle reference, opened/disposed times, and validated 204 outcome
Observation/review: bounded checklist, inspector notes, attempt link, reviewer decision, policy version, event/receipt time, and retention class
Audit/outbox: command identity, optimistic version, actor, transition, delivery state, and cleanup action
Useful visual context. Bounded business claims.
Each workflow names the proof needed after viewing and the inference that must remain outside the widget contract.
Review poles, cabinets, trenches, and right-of-way context before dispatching a survey crew.
Asset identity, imagery availability, human observation, visible limitations, reviewer, and field-verification trigger.
Triage a reported sign, shoulder, marking, or surface concern before scheduling inspection.
Road segment identity, observation time, bounded checklist, confidence limits, and maintenance/field escalation.
Understand public street context around a declared incident without treating imagery as incident-time evidence.
Claim purpose, place identity, imagery-source limitation, reviewer notes, and explicit prohibition on occurrence inference.
Review approach roads and neighborhood context for a property due-diligence queue.
Property/entrance identity, accessibility checklist, observed limitations, capture freshness unknown state, and review decision.
Screen storefront approach, visibility, and pedestrian context before an on-site feasibility visit.
Candidate-site version, human observations, no automated footfall claim, reviewer, and required field-validation items.
Assess cabinet or tower approach constraints before dispatch and permit planning.
Asset identity, access-route observation, safety caveat, coverage result, and engineer review.
Prioritize civic-asset surveys across a large inspection backlog.
Public purpose, location scope, equitable prioritization policy, observation ledger, and field confirmation.
Provide optional arrival context for a hotel or attraction with an accessible non-imagery alternative.
Stable place identity, optional viewer state, no-currentness promise, accessible text/map alternative, and handoff outcome.
Operate entitlement through review and rework.
The credential-free fixture proves exact-origin validation, status-204 handling, ephemeral handles, immutable attempts and observations, separation of duties, expiry recovery, audit, outbox, and restart recovery.