KioskPilot Handbuch

Einrichten. Verstehen.
Operate reliably.

The complete guide to Local Kiosk, Pro Features and Fleet Cloud - with clear platform boundaries and practical steps.

Grundlagen

So ist KioskPilot aufgebaut.

KioskPilot deliberately separates local kiosk operations from accounts and cloud. A single device can start without an account. A portal account organizes people, devices, and billing; it is not a device license itself.

Free

Permanently usable web kiosk without advertising and time limits. The visible free watermark remains active.

Pro – per device

Removes the watermark and activates professional local functions for exactly one device or a bound installation.

Fleet Cloud

Separate offering for central administration, teams, groups, health, rollouts and support. It does not replace a Pro device license.

Customer portal

Manages multiple users, devices, free and assigned license seats, billing addresses and documents.

Merksatz: Users manage devices. Licenses apply per device. Fleet manages the fleet.

In drei Schritten

First setup.

To start locally, all you need is your landing page, a sensible security limit and an admin PIN.

  1. Startseite festlegen. Use HTTPS or a private LAN HTTP address. Public HTTP destinations are not accepted.
  2. Domains erlauben. The homepage host must be included. Only add additional hosts if the website really needs them for navigation.
  3. Choose PIN and behavior. Set admin PIN, keep awake, reload, orientation and optional display times. Then test the site and start the kiosk.

Home URL

The fixed page that Home, Autopilot, and Offline Restore return to.

Domain-Allowlist

Checks main navigation, pop-ups, scanner, NFC and launcher web destinations.

Admin-PIN

Protects local settings. It should not be kept visible on publicly accessible devices.

Verbindungstest

Helps detect DNS, network, certificate and allowlist issues before kiosk launch.

Web-Inhalte

Browser & Navigation.

The Kiosk Browser is not a general browser: it shows your configured application and limits unexpected escapes.

User-Agent & Zoom

Choose mobile, desktop or your own browser profile as well as page and text zoom. Only use Custom User Agent when the target page needs it.

Pop-ups

Only after a user gesture and only for permitted hosts. Allowed targets are redirected to the main window in a controlled manner.

Datei-Uploads

Use the system file selection and can be disabled via policy.

Web-Berechtigungen

Camera, microphone and location are separate, off by default and only available to allowed hosts.

Cookies & Mixed Content

Third-party cookies and LAN mixed content are separate compatibility options, disabled by default.

Basic Auth

Username can be configured; the password is encrypted in the Android Keystore or Apple Keychain and is missing in exports.

Cannot be overridden: SSL certificate errors and safe browsing/fraud warnings are never ignored.

Gerät & Anzeige

Display, Screensaver & Launcher.

Wachhalten & Ausrichtung

Keeps the display active during kiosk operation and fixes portrait, landscape or system orientation as the platform allows.

Helligkeit & Nachtplan

Defines day and night brightness with start and end times. The operating system can specify hard minimum values.

Pixel Shift

Shifts static content minimally and reversibly to distribute sustained load more evenly.

Screensaver

Black, clock or own message after inactivity. One touch returns to the kiosk.

Universal Launcher

Shows shared websites and apps as tiles. Web targets remain bound to the allowlist.

Scanner & NFC

QR, barcodes and NDEF targets are read, validated and only then opened. Supported formats vary by device.

KioskPilot Intelligence

Autopilot, Offline Rescue & Schutz.

Kiosk Autopilot

Monitors loading, network and renderer. Escalation: Reload, Home, WebView restart, offline rescue and – for Fleet – technical diagnostic status.

Offline Rescue

Local replacement page with understandable message. As soon as the home page is accessible, the controlled return takes place.

Privacy mode

After inactivity, deletes cookies, web storage, forms and browser history and starts a fresh session.

Accessibility Check

Locally checks touch targets, captions, overflow, scaling, and basic contrast and font indicators.

Display-Schutz

Combines pixel shift, brightness plan and technical temperature and battery information as far as the device provides them.

Temporary support

One-off, short-lived code; visible consent on the device; limited rights; automatic end and audit entry.

Datensparsam: Accessibility and autopilot analysis run locally. Fleet only receives technical states and counters, not DOM content or form inputs.

Smart Home

Home Assistant & Integrationen.

KioskPilot can directly find and professionally integrate a local home assistant dashboard.

  1. Start quick setup. KioskPilot sucht `_home-assistant._tcp.local.` im lokalen Netz.
  2. Select instance. The internal address found is adopted as the home page and the host allows it.
  3. Optional Pro integrieren. Enable local API or TLS-MQTT and publish Home Assistant Discovery.

Local API · Pro

Private networks, random bearer token. Read status and trigger reload, home, privacy reset, launcher and brightness.

TLS-MQTT · Pro

Just `ssl://`/`mqtts://`. Publishes minimized status and accepts defined commands. Password is not exported.

Discovery

Can automatically make online sensors and actions such as Reload or Home known in Home Assistant.

LAN-Sicherheit

The HTTP LAN API protects via token, but does not encrypt. Use TLS-MQTT or Fleet on untrusted networks.

Lizenzierung

Free, Pro & Lizenzstatus.

Pro applies exactly to the activated device or cryptographically bound installation. The portal shows free and assigned places; it does not turn a user license into a multi-device license.

Free

  • Lokaler Web-Kiosk
  • Grundlegender Autopilot
  • Offline Rescue
  • Quick setup and accessibility check
  • Sichtbares Watermark

Pro

  • No watermark
  • Advanced autopilot/privacy features
  • Local API and TLS MQTT
  • Device Owner / Managed Policies
  • One license per device

Restore purchases

Asks the store again for active purchases and restores local entitlement.

Fully sync

Flushes conflicting local license caches and rebuilds state from store and control plane. The purchase itself will not be deleted.

Store-Grenze: Portal license seats and store purchases are technically separate. A new portal association does not automatically move a store purchase to a different installation.

Plattformen

Android and iOS/iPadOS.

Android · normal installiert

Immersive full screen mode and screen pinning, but with system limits. Depending on the device, a user can leave the system's own kiosk.

Android · Device Owner

Dedicated device operation with lock task, enterprise policies and more reliable boot behavior. Requires correct provisioning.

iPhone/iPad · privat

Guided Access is the viable single-app route. A normal app is not allowed to completely lock the device itself or start it after a restart.

iPhone/iPad · betreut

Apple Configurator or MDM can deploy Single App Mode/App Lock and Managed Configuration for supervised devices.

Funktionsgleich bedeutet gleiche Produktwirkung: Android uses Device Owner; Apple uses Guided Access or MDM. Operating system security mechanisms are not bypassed.

Central administration

Fleet Cockpit & Kundenportal.

  1. Organization and users. Owner, Admin, Operator and Read-only share clearly limited rights.
  2. Pair device. Generate a short-lived pairing code in the portal and confirm it visibly in the app.
  3. Assign license. Assign a free Pro slot to exactly one of your own devices. Release makes it available again.
  4. Organize operations. Name, group, monitor devices and roll out configuration revisions in a controlled manner.

Overview

Number of devices, online status, warnings, license occupancy and central needs for action.

Devices

Pairing, start URL, allowlist, technical details, revision, support code and revocation.

Licenses

Total, assigned and free. Every assignment remains device-specific.

Billing

Versioned billing addresses, unchangeable direct invoices and separate store receipts.

Team

Invitations are one-time and valid for 48 hours. The member chooses his or her own password.

Account

Password, TOTP MFA, recovery codes, active sessions and logout.

Safe operation

Health, Incidents & Rollouts.

Fleet Health

Evaluates heartbeat, error status and technical signals based on configurable thresholds. Alerts can be acknowledged and automatically resolved.

Device actions

Reload, home and configuration synchronization are reversible, logged actions - manual or rule-based with cooldown.

Incidents

Correlates alerts, responsible parties, comments and actions; calculates MTTD/MTTR and exports a technical report.

Schedules

One-time or weekly secure promotions with a fixed time zone.

Maintenance windows

Suppress expected organization, group, or device alerts without deleting real data.

Gestufte Rollouts

Start small, observe applied revision and health, promote controlled or roll back to previous configuration.

Noch nicht produktiv freigeschaltet: external alert webhooks, independent availability monitoring, push via APNs/FCM and Stripe live checkout remain hidden until final configuration.

Local-first

Sicherheit & Datenschutz.

Inhalte bleiben lokal

Website content, form entries and browser history are not transferred to the control plane.

Minimierte Telemetrie

For Fleet: device ID, platform, version, heartbeat, revision and technical diagnostic counters.

Portal-Sitzung

Backend token remains server side. The browser receives a Secure, HttpOnly and SameSite Strict cookie.

MFA & Recovery

TOTP secret encrypted; ten unique recovery codes only visible upon activation; Sessions can be revoked individually.

Konfigurations-Export

Does not contain PIN, API tokens, MQTT, Basic Auth or other passwords.

Support-Sitzung

Off by default, visibly confirmed, time-limited and auditable.

Diagnose

Fehler systematisch beheben.

Page doesn't load

  1. Test network and URL
  2. Check allowlist
  3. DNS/TLS kontrollieren
  4. Reload and Home
  5. Restart WebView

Device offline

  1. Check local kiosk status
  2. Check internet and system time
  3. Pairingstatus kontrollieren
  4. Check app/OS power saving
  5. Bei Bedarf neu koppeln

License is missing

  1. Check correct store account
  2. Restore purchases
  3. Check portal assignment
  4. Full sync
  5. Support mit App-Version kontaktieren

Portal-Login

  1. Check email
  2. Passwort-Reset verwenden
  3. Cookies zulassen
  4. Nach Passwortwechsel neu anmelden
  5. Rate-Limit abwarten
Helpful for a support request: Platform, device model, operating system, KioskPilot version, approximate timing and exact error message. Never send password, API token, recovery code or full billing information.

Antwort nicht gefunden?

The FAQ answers short individual questions. If there is a specific error, the platform, app version and a precise description will help you quickly isolate it.