Skip to content

Baladia GIS capability audit — giss.baladia.gov.kw ​

A full audit of the Kuwait Municipality (Baladia) ArcGIS server at https://giss.baladia.gov.kw/server/rest/services (ArcGIS Enterprise 10.81), done 2026-07-11 by probing every folder/service against live responses (metadata → feature queries → binary tile/PNG exports). Companion to MAPS.md, which covers what we actually integrated.

Overview ​

Baladia runs two separate ArcGIS deployments — don't confuse them:

HostVersionPath rootRole
gismaps.baladia.gov.kwArcGIS 10.4/arcgis/rest/servicesThe parcels overlay we already used (KA/ParcelLocation_MKM).
giss.baladia.gov.kwArcGIS Enterprise 10.81/server/rest/servicesThe richer estate audited here — 23 folders, ~50 services.
  • Access: everything real-estate-relevant is public (no token); only 8 folders are token-gated (§ Token-gated). Read-only is the rule — several FeatureServers wrongly allow anonymous writes (§ Security).
  • Geo-block: both hosts geo-block non-Kuwait IPs intermittently (both served real data during the audit). Route through the Kuwait reverse proxy for resilience.
  • Coordinate systems: folder services use a custom Kuwait grid KTM_KM (KUDAMS datum, GRS_1980, TM CM 48°, FE 499975 / FN 209269 — no EPSG WKID). The root composite services (KM_MapViewerNew_MIL1, KM_Paci_MIL1, kmpacikm_MIL1) are EPSG:3857 and honour outSR=4326; dynamic /export accepts bboxSR=3857 and reprojects on the fly. Utilities/Geometry (a GeometryServer) can project anything else. The GP CheckParcel tasks want wkid 31901 input.

Service catalog ​

Relevance = value for a real-estate brokerage + valuation platform.

Folder / serviceTypeWhat it isRelevance
Root KM_MapViewerNew_MIL1 /3 (297,762)MapServer (3857)Full cadastral fabric: ParcelNo, BlockNo, GISNo, PACINo, MeasuredArea, Neighborhood AR/EN, CadastalPlanNo, Subtype (land-use)High — primary parcel identify (we use it)
Root KM_MapViewer_MIL1MapServer (3857)Byte-identical mirror of the aboveHigh (fallback)
Root KM_Paci_MIL1 /1 (291,766)MapServer (3857)Parcel × PACI join: BLOCK_NO, HOUSE_NO, PARCEL_NO, PACINo, Gov_NoHigh — PACI address → parcel
Root kmpacikm_MIL1MapServer (3857)Superset: plain Parcel (id 10) + Parcel_PACI (id 3)High
POC/IssuedBuildingLicenses /0 (23,153)MapServerGeocoded building permits: gov/area/block/parcel + الرقم العقاري (= parcel GISNo) + licence type (هدم…) + use type + issue dateHigh — construction/valuation signal (we use it)
POC/BuildingUnits (236)MapServerEsri Redlands, California demo data, NOT KuwaitNone (schema reference only)
SurveyingData/Parcel /0 (318,093)MapServerRichest parcel table: adds PlanningLandUseID/ClassID/CTypeID, PACINo, cadastral-plan nos, CityHigh (KTM_KM)
projectissa/ParcelsBlocks /3MapServerUniquely carries BanParcel legal-encumbrance + street/lane/house address — but a labelled demo whose data queries time outMedium (schema ref)
test_run/KMPaci /1 (291,766)MapServerPACI-joined parcels, PBF output + a WGS84→KUDAMS transform (identify by raw lng/lat)High
test_run/tesrun (316,507)MapServerStripped parcels — no ParcelNo/PACI/cadastralLow
Basemap/* (12 services)MapServerCached satellite 2018 / 2021 / 2022 ×3 / Jan-2024 / 2024-Q2, dynamic 2024-Q3, to ~13–15 cm/px; all support /export reprojected to 3857High — basemap + change detection (we use 4 epochs)
Basemap/itsprog /0 (318,656)MapServerQueryable vector Parcel + Block/Neighborhood/GovernorateHigh
Basemap/KMBasemapMapServerCartographic reference (roads, blocks, sectors)Medium
DataBank/BlocksPoint /0 (1,746)Feature/MapServerBlock centroids keyed by gov>neighborhood>sector>block (numeric FKs, no area names)Medium — block geocoder (fragile)
DataBank/KMBuildingPermits(_NEW)GPServerInternal CAD-ingest (InputCAD .dwg on \\GISSITES1), not a query API. _NEW's ParcelInfo default documents the parcel key {gov,nbh,blk,parcelNo,gisNo,area}Low (spec reference)
DataBank/ExportWebMap, PrintQRCode*, TestQRCodeGPServerStock Esri print/QR utilitiesLow
Voxel/*CheckParcel* (8)GPServerSynchronous CheckParcel: parcel polygon (wkid 31901) → authoritative ParcelGISNumber + geodesic AREA_GEO. NOT a point geocoderMedium (parcel-area validation)
Voxel/Basemap_2024_Q3MapServer2024-Q3 dynamic imagery (/export verified)High
KMUtilities/Masterplan2020 /499 (241,339)MapServerNOT western zoning despite the name — utility-network + cadastre. Land-use only via Subtype (residential/govt-by-use/farm/common/setback); no FAR/height/zoning codesHigh (parcel + coarse land-use)
KMUtilities/paci /1 (279,983)MapServerPACI-branded parcels: pkParcelID, fkBlockID, ParcelNo, ArabicName, MeasuredAreaHigh
KMUtilities/mewMapServerFull electricity/water/gas/sanitary networks (infrastructure-availability signal)Medium
KMUtilities/moh, agr, frawania, knpcMapServerParcel+block+road cadastre slices (agr reaches the farm/desert fringe; frawania = Farwaniya)Medium/Low
Utilities/GeometryGeometryServerproject, areasAndLengths, buffer, …Medium (reprojection)
CadastralPlan/ExportWebMap, LayoutTemplatesGPServerCadastral print/layout utilitiesLow
PAAF/AgriculturalTenures /0 (42)FeatureServerAgricultural-shelter tenures ("Tashween") with PARCEL_NO, STATUSMedium (ag land only)
CleanCenters/CleanCenters (78)FeatureServerMunicipal waste-center pointsLow
Camps/Camping2024, Camping/* (7,018)FeatureServerSeasonal desert-camping permits — exposes PII (§ Security)Low (+ privacy flag)
Tashween/TashweenFeatureServerToken-gated (likely the authoritative Tashween dataset)Medium (locked)

Token-gated folders (HTTP 499) ​

Editing, MasterPlan, ParcelAllocation, SplitAndMerge, Umbrellas, ViolationBlocking, RBETS, Tashween/Tashween. Highest-value if access were granted: MasterPlan (the real zoning / land-use / structural plan — the strongest valuation driver, and the coarse Subtype is a poor substitute) and ViolationBlocking (building violations / stop-work = legality & risk signal). Pursuing these needs a formal Baladia data-sharing request (deferred under the "technical-only" decision).

Key finding — the parcel↔permit join ​

The building-licence field الرقم العقاري equals the parcel GISNo (verified: 522000019454 → the exact Block 68 / Parcel 119 / Farwaniya parcel). So licences join to parcels by GISNo, not by block (block numbers are inconsistent even within one service — 005 vs قطعة68 - قطاع 1). The parcel identify returns GISNo, so a tapped parcel maps exactly to its permits.

Security & privacy findings ​

Observed during read-only probing — not exploited. Worth recording (and, if the "technical-only" stance changes, reporting to Baladia):

  • Anonymous write is advertised (Create/Update/Delete/Editing to unauthenticated callers) on DataBank/BlocksPoint, PAAF/AgriculturalTenures, CleanCenters/CleanCenters, and Camps/Camping2024 FeatureServers. We must only ever query/export — never write.
  • PII exposure: Camps/Camping2024 exposes permit-holder name, Civil ID (national ID), phone, and a UserToken, queryable unauthenticated across ~7,018 records. Do not ingest or cache it.
  • Test DB in production: several published services back onto KMGIS_TEST.DBO.* (BuildingUnits, KMPaci, CleanCenters, Camping2024) — treat their data as non-authoritative; prefer SurveyingData/Parcel and the root KM_MapViewer* services.

What we integrated ​

See MAPS.md § Baladia has two ArcGIS deployments for the shipped integration (richer parcel identify + polygons, live per-parcel building permits, satellite basemap with year selector, the public parcel-geocoder fallback) and the bulk building-licence ingestion pipeline (baladia_building_licenses + sync-baladia-building-licenses).

Data conventions ​

  • Licence/use vocabulary stays Arabic (by design). baladia_building_licenses.license_type (نوع الرخصة) and use_type (نوع الاستعمال) store the municipality's own Arabic strings and are exempt from the English-key backend program. The list is open-ended and Baladia-controlled (new values can arrive on any weekly sync), and permits join to parcels by GISNo (property_no), never by these text values — so there is no search-correctness risk in keeping them Arabic. English display is a thin, display-only fallback map on the model (BaladiaBuildingLicense.permitTypeLabelsEn / permitLabel), covering the common values (>99% of rows) and falling back to the raw Arabic for the long tail. Consumed by both the property-detail and valuation-detail "recent permits" cards.

Parcel↔permit backfill (2026-07-12) ​

To link our paci_parcels (1.14M PACI address-points) to permits, we copied each parcel's GISNo from internal.baladia_parcels (which already carries raw_attributes->>'GISNo' + polygon geom) via a pure Postgres spatial join — zero per-parcel Baladia calls: ST_Contains (containing parcel) → 58.3%, then a <-> KNN nearest-parcel fallback at 15 m → 94.7%, then a second pass at 30 m → 95.8% (1,092,781 of 1,140,253). Stopped at 30 m: the remaining parcels sit a median ~78 m from any Baladia parcel (29% beyond 300 m — roads/gaps), and widening further only mis-assigns them to adjacent parcels for ~zero permit-linkage gain. Result: 16,240 of 23,153 permits are reachable from a parcel (the other ~6,300 permit-GISNos have no PACI address-point at all — a source-side gap the backfill can't close).

Aldilaijan & Khobara Real Estate Platform