Baladia GIS capability audit — giss.baladia.gov.kw
A full audit of the Kuwait Municipality (Baladia) ArcGIS server at https://giss.baladia.gov.kw/server/rest/services (ArcGIS Enterprise 10.81), done 2026-07-11 by probing every folder/service against live responses (metadata → feature queries → binary tile/PNG exports). Companion to MAPS.md, which covers what we actually integrated.
Overview
Baladia runs two separate ArcGIS deployments — don't confuse them:
| Host | Version | Path root | Role |
|---|---|---|---|
gismaps.baladia.gov.kw | ArcGIS 10.4 | /arcgis/rest/services | The parcels overlay we already used (KA/ParcelLocation_MKM). |
giss.baladia.gov.kw | ArcGIS Enterprise 10.81 | /server/rest/services | The richer estate audited here — 23 folders, ~50 services. |
- Access: everything real-estate-relevant is public (no token); only 8 folders are token-gated (§ Token-gated). Read-only is the rule — several FeatureServers wrongly allow anonymous writes (§ Security).
- Geo-block: both hosts geo-block non-Kuwait IPs intermittently (both served real data during the audit). Route through the Kuwait reverse proxy for resilience.
- Coordinate systems: folder services use a custom Kuwait grid
KTM_KM(KUDAMS datum, GRS_1980, TM CM 48°, FE 499975 / FN 209269 — no EPSG WKID). The root composite services (KM_MapViewerNew_MIL1,KM_Paci_MIL1,kmpacikm_MIL1) are EPSG:3857 and honouroutSR=4326; dynamic/exportacceptsbboxSR=3857and reprojects on the fly.Utilities/Geometry(a GeometryServer) canprojectanything else. The GPCheckParceltasks want wkid 31901 input.
Service catalog
Relevance = value for a real-estate brokerage + valuation platform.
| Folder / service | Type | What it is | Relevance |
|---|---|---|---|
Root KM_MapViewerNew_MIL1 /3 (297,762) | MapServer (3857) | Full cadastral fabric: ParcelNo, BlockNo, GISNo, PACINo, MeasuredArea, Neighborhood AR/EN, CadastalPlanNo, Subtype (land-use) | High — primary parcel identify (we use it) |
Root KM_MapViewer_MIL1 | MapServer (3857) | Byte-identical mirror of the above | High (fallback) |
Root KM_Paci_MIL1 /1 (291,766) | MapServer (3857) | Parcel × PACI join: BLOCK_NO, HOUSE_NO, PARCEL_NO, PACINo, Gov_No | High — PACI address → parcel |
Root kmpacikm_MIL1 | MapServer (3857) | Superset: plain Parcel (id 10) + Parcel_PACI (id 3) | High |
POC/IssuedBuildingLicenses /0 (23,153) | MapServer | Geocoded building permits: gov/area/block/parcel + الرقم العقاري (= parcel GISNo) + licence type (هدم…) + use type + issue date | High — construction/valuation signal (we use it) |
POC/BuildingUnits (236) | MapServer | Esri Redlands, California demo data, NOT Kuwait | None (schema reference only) |
SurveyingData/Parcel /0 (318,093) | MapServer | Richest parcel table: adds PlanningLandUseID/ClassID/CTypeID, PACINo, cadastral-plan nos, City | High (KTM_KM) |
projectissa/ParcelsBlocks /3 | MapServer | Uniquely carries BanParcel legal-encumbrance + street/lane/house address — but a labelled demo whose data queries time out | Medium (schema ref) |
test_run/KMPaci /1 (291,766) | MapServer | PACI-joined parcels, PBF output + a WGS84→KUDAMS transform (identify by raw lng/lat) | High |
test_run/tesrun (316,507) | MapServer | Stripped parcels — no ParcelNo/PACI/cadastral | Low |
Basemap/* (12 services) | MapServer | Cached satellite 2018 / 2021 / 2022 ×3 / Jan-2024 / 2024-Q2, dynamic 2024-Q3, to ~13–15 cm/px; all support /export reprojected to 3857 | High — basemap + change detection (we use 4 epochs) |
Basemap/itsprog /0 (318,656) | MapServer | Queryable vector Parcel + Block/Neighborhood/Governorate | High |
Basemap/KMBasemap | MapServer | Cartographic reference (roads, blocks, sectors) | Medium |
DataBank/BlocksPoint /0 (1,746) | Feature/MapServer | Block centroids keyed by gov>neighborhood>sector>block (numeric FKs, no area names) | Medium — block geocoder (fragile) |
DataBank/KMBuildingPermits(_NEW) | GPServer | Internal CAD-ingest (InputCAD .dwg on \\GISSITES1), not a query API. _NEW's ParcelInfo default documents the parcel key {gov,nbh,blk,parcelNo,gisNo,area} | Low (spec reference) |
DataBank/ExportWebMap, PrintQRCode*, TestQRCode | GPServer | Stock Esri print/QR utilities | Low |
Voxel/*CheckParcel* (8) | GPServer | Synchronous CheckParcel: parcel polygon (wkid 31901) → authoritative ParcelGISNumber + geodesic AREA_GEO. NOT a point geocoder | Medium (parcel-area validation) |
Voxel/Basemap_2024_Q3 | MapServer | 2024-Q3 dynamic imagery (/export verified) | High |
KMUtilities/Masterplan2020 /499 (241,339) | MapServer | NOT western zoning despite the name — utility-network + cadastre. Land-use only via Subtype (residential/govt-by-use/farm/common/setback); no FAR/height/zoning codes | High (parcel + coarse land-use) |
KMUtilities/paci /1 (279,983) | MapServer | PACI-branded parcels: pkParcelID, fkBlockID, ParcelNo, ArabicName, MeasuredArea | High |
KMUtilities/mew | MapServer | Full electricity/water/gas/sanitary networks (infrastructure-availability signal) | Medium |
KMUtilities/moh, agr, frawania, knpc | MapServer | Parcel+block+road cadastre slices (agr reaches the farm/desert fringe; frawania = Farwaniya) | Medium/Low |
Utilities/Geometry | GeometryServer | project, areasAndLengths, buffer, … | Medium (reprojection) |
CadastralPlan/ExportWebMap, LayoutTemplates | GPServer | Cadastral print/layout utilities | Low |
PAAF/AgriculturalTenures /0 (42) | FeatureServer | Agricultural-shelter tenures ("Tashween") with PARCEL_NO, STATUS | Medium (ag land only) |
CleanCenters/CleanCenters (78) | FeatureServer | Municipal waste-center points | Low |
Camps/Camping2024, Camping/* (7,018) | FeatureServer | Seasonal desert-camping permits — exposes PII (§ Security) | Low (+ privacy flag) |
Tashween/Tashween | FeatureServer | Token-gated (likely the authoritative Tashween dataset) | Medium (locked) |
Token-gated folders (HTTP 499)
Editing, MasterPlan, ParcelAllocation, SplitAndMerge, Umbrellas, ViolationBlocking, RBETS, Tashween/Tashween. Highest-value if access were granted: MasterPlan (the real zoning / land-use / structural plan — the strongest valuation driver, and the coarse Subtype is a poor substitute) and ViolationBlocking (building violations / stop-work = legality & risk signal). Pursuing these needs a formal Baladia data-sharing request (deferred under the "technical-only" decision).
Key finding — the parcel↔permit join
The building-licence field الرقم العقاري equals the parcel GISNo (verified: 522000019454 → the exact Block 68 / Parcel 119 / Farwaniya parcel). So licences join to parcels by GISNo, not by block (block numbers are inconsistent even within one service — 005 vs قطعة68 - قطاع 1). The parcel identify returns GISNo, so a tapped parcel maps exactly to its permits.
Security & privacy findings
Observed during read-only probing — not exploited. Worth recording (and, if the "technical-only" stance changes, reporting to Baladia):
- Anonymous write is advertised (Create/Update/Delete/Editing to unauthenticated callers) on
DataBank/BlocksPoint,PAAF/AgriculturalTenures,CleanCenters/CleanCenters, andCamps/Camping2024FeatureServers. We must only everquery/export— never write. - PII exposure:
Camps/Camping2024exposes permit-holder name, Civil ID (national ID), phone, and aUserToken, queryable unauthenticated across ~7,018 records. Do not ingest or cache it. - Test DB in production: several published services back onto
KMGIS_TEST.DBO.*(BuildingUnits,KMPaci,CleanCenters,Camping2024) — treat their data as non-authoritative; preferSurveyingData/Parceland the rootKM_MapViewer*services.
What we integrated
See MAPS.md § Baladia has two ArcGIS deployments for the shipped integration (richer parcel identify + polygons, live per-parcel building permits, satellite basemap with year selector, the public parcel-geocoder fallback) and the bulk building-licence ingestion pipeline (baladia_building_licenses + sync-baladia-building-licenses).
Data conventions
- Licence/use vocabulary stays Arabic (by design).
baladia_building_licenses.license_type(نوع الرخصة) anduse_type(نوع الاستعمال) store the municipality's own Arabic strings and are exempt from the English-key backend program. The list is open-ended and Baladia-controlled (new values can arrive on any weekly sync), and permits join to parcels by GISNo (property_no), never by these text values — so there is no search-correctness risk in keeping them Arabic. English display is a thin, display-only fallback map on the model (BaladiaBuildingLicense.permitTypeLabelsEn/permitLabel), covering the common values (>99% of rows) and falling back to the raw Arabic for the long tail. Consumed by both the property-detail and valuation-detail "recent permits" cards.
Parcel↔permit backfill (2026-07-12)
To link our paci_parcels (1.14M PACI address-points) to permits, we copied each parcel's GISNo from internal.baladia_parcels (which already carries raw_attributes->>'GISNo' + polygon geom) via a pure Postgres spatial join — zero per-parcel Baladia calls: ST_Contains (containing parcel) → 58.3%, then a <-> KNN nearest-parcel fallback at 15 m → 94.7%, then a second pass at 30 m → 95.8% (1,092,781 of 1,140,253). Stopped at 30 m: the remaining parcels sit a median ~78 m from any Baladia parcel (29% beyond 300 m — roads/gaps), and widening further only mis-assigns them to adjacent parcels for ~zero permit-linkage gain. Result: 16,240 of 23,153 permits are reachable from a parcel (the other ~6,300 permit-GISNos have no PACI address-point at all — a source-side gap the backfill can't close).
