Free
Permanently usable web kiosk without advertising and time limits. The visible free watermark remains active.
Grundlagen
KioskPilot deliberately separates local kiosk operations from accounts and cloud. A single device can start without an account. A portal account organizes people, devices, and billing; it is not a device license itself.
Permanently usable web kiosk without advertising and time limits. The visible free watermark remains active.
Removes the watermark and activates professional local functions for exactly one device or a bound installation.
Separate offering for central administration, teams, groups, health, rollouts and support. It does not replace a Pro device license.
Manages multiple users, devices, free and assigned license seats, billing addresses and documents.
In drei Schritten
To start locally, all you need is your landing page, a sensible security limit and an admin PIN.
The fixed page that Home, Autopilot, and Offline Restore return to.
Checks main navigation, pop-ups, scanner, NFC and launcher web destinations.
Protects local settings. It should not be kept visible on publicly accessible devices.
Helps detect DNS, network, certificate and allowlist issues before kiosk launch.
Web-Inhalte
The Kiosk Browser is not a general browser: it shows your configured application and limits unexpected escapes.
Choose mobile, desktop or your own browser profile as well as page and text zoom. Only use Custom User Agent when the target page needs it.
Only after a user gesture and only for permitted hosts. Allowed targets are redirected to the main window in a controlled manner.
Use the system file selection and can be disabled via policy.
Camera, microphone and location are separate, off by default and only available to allowed hosts.
Third-party cookies and LAN mixed content are separate compatibility options, disabled by default.
Username can be configured; the password is encrypted in the Android Keystore or Apple Keychain and is missing in exports.
Gerät & Anzeige
Keeps the display active during kiosk operation and fixes portrait, landscape or system orientation as the platform allows.
Defines day and night brightness with start and end times. The operating system can specify hard minimum values.
Shifts static content minimally and reversibly to distribute sustained load more evenly.
Black, clock or own message after inactivity. One touch returns to the kiosk.
Shows shared websites and apps as tiles. Web targets remain bound to the allowlist.
QR, barcodes and NDEF targets are read, validated and only then opened. Supported formats vary by device.
KioskPilot Intelligence
Monitors loading, network and renderer. Escalation: Reload, Home, WebView restart, offline rescue and – for Fleet – technical diagnostic status.
Local replacement page with understandable message. As soon as the home page is accessible, the controlled return takes place.
After inactivity, deletes cookies, web storage, forms and browser history and starts a fresh session.
Locally checks touch targets, captions, overflow, scaling, and basic contrast and font indicators.
Combines pixel shift, brightness plan and technical temperature and battery information as far as the device provides them.
One-off, short-lived code; visible consent on the device; limited rights; automatic end and audit entry.
Smart Home
KioskPilot can directly find and professionally integrate a local home assistant dashboard.
Private networks, random bearer token. Read status and trigger reload, home, privacy reset, launcher and brightness.
Just `ssl://`/`mqtts://`. Publishes minimized status and accepts defined commands. Password is not exported.
Can automatically make online sensors and actions such as Reload or Home known in Home Assistant.
The HTTP LAN API protects via token, but does not encrypt. Use TLS-MQTT or Fleet on untrusted networks.
Lizenzierung
Pro applies exactly to the activated device or cryptographically bound installation. The portal shows free and assigned places; it does not turn a user license into a multi-device license.
Asks the store again for active purchases and restores local entitlement.
Flushes conflicting local license caches and rebuilds state from store and control plane. The purchase itself will not be deleted.
Plattformen
Immersive full screen mode and screen pinning, but with system limits. Depending on the device, a user can leave the system's own kiosk.
Dedicated device operation with lock task, enterprise policies and more reliable boot behavior. Requires correct provisioning.
Guided Access is the viable single-app route. A normal app is not allowed to completely lock the device itself or start it after a restart.
Apple Configurator or MDM can deploy Single App Mode/App Lock and Managed Configuration for supervised devices.
Central administration
Number of devices, online status, warnings, license occupancy and central needs for action.
Pairing, start URL, allowlist, technical details, revision, support code and revocation.
Total, assigned and free. Every assignment remains device-specific.
Versioned billing addresses, unchangeable direct invoices and separate store receipts.
Invitations are one-time and valid for 48 hours. The member chooses his or her own password.
Password, TOTP MFA, recovery codes, active sessions and logout.
Safe operation
Evaluates heartbeat, error status and technical signals based on configurable thresholds. Alerts can be acknowledged and automatically resolved.
Reload, home and configuration synchronization are reversible, logged actions - manual or rule-based with cooldown.
Correlates alerts, responsible parties, comments and actions; calculates MTTD/MTTR and exports a technical report.
One-time or weekly secure promotions with a fixed time zone.
Suppress expected organization, group, or device alerts without deleting real data.
Start small, observe applied revision and health, promote controlled or roll back to previous configuration.
Local-first
Website content, form entries and browser history are not transferred to the control plane.
For Fleet: device ID, platform, version, heartbeat, revision and technical diagnostic counters.
Backend token remains server side. The browser receives a Secure, HttpOnly and SameSite Strict cookie.
TOTP secret encrypted; ten unique recovery codes only visible upon activation; Sessions can be revoked individually.
Does not contain PIN, API tokens, MQTT, Basic Auth or other passwords.
Off by default, visibly confirmed, time-limited and auditable.
Diagnose
The FAQ answers short individual questions. If there is a specific error, the platform, app version and a precise description will help you quickly isolate it.
Fundamentals
KioskPilot deliberately separates local kiosk operation from accounts and cloud services. A device can start without an account. A portal account organizes people, devices, and billing; it is not itself a device license.
A permanent web kiosk with no ads or time limit. The visible Free watermark remains active.
Removes the watermark and enables professional local features for exactly one device or bound installation.
A separate offering for central management, teams, groups, health, rollouts, and support. It does not replace a Pro device license.
Manages users, devices, available and assigned license seats, billing addresses, and documents.
Three steps
To start locally, you only need a target page, a sensible security boundary, and an admin PIN.
The fixed page used by Home, Autopilot, and offline recovery.
Checks main navigation, pop-ups, scanner, NFC, and launcher web targets.
Protects local settings. Never display it near a publicly accessible device.
Finds DNS, network, certificate, and allowlist issues before kiosk start.
Web content
The kiosk browser is not a general-purpose browser: it displays your configured application and limits unexpected exits.
Choose mobile, desktop, or custom profiles plus page and text zoom. Use a custom user agent only when required.
Only after a user gesture and for allowed hosts. Valid targets are redirected into the checked main window.
Use the system file picker and can be disabled by policy.
Camera, microphone, and location are separate, off by default, and limited to allowed hosts.
Third-party cookies and LAN mixed content are separate compatibility options, disabled by default.
The password is encrypted in Android Keystore or Apple Keychain and omitted from exports.
Device & screen
Keeps the display active and selects portrait, landscape, or system orientation where supported.
Defines day/night brightness and times. The OS may enforce hard minimums.
Moves static content minimally and reversibly to distribute long-term load.
Black, clock, or message after inactivity. A touch returns to the kiosk.
Shows approved websites and apps as tiles. Web targets remain allowlist-bound.
QR, barcode, and NDEF targets are read, validated, then opened. Formats vary by device.
KioskPilot Intelligence
Monitors loading, network, and renderer. Escalation: reload, home, rebuild web view, Offline Rescue, and technical Fleet diagnostics.
A local fallback with a clear message and controlled return when the home page recovers.
Clears cookies, web storage, forms, and history after inactivity and starts a fresh session.
Locally checks touch targets, labels, overflow, scaling, and basic contrast/font indicators.
Combines pixel shift, brightness plans, and technical thermal/battery signals where available.
Single-use short-lived code, visible consent, limited rights, automatic end, and audit entry.
Smart home
KioskPilot can discover a local Home Assistant dashboard and integrate it professionally.
Private networks, random bearer token. Read status and trigger reload, home, privacy reset, launcher, or brightness.
Only `ssl://`/`mqtts://`. Publishes minimized state and accepts defined commands. Passwords are never exported.
Can register online sensors and actions such as Reload or Home in Home Assistant.
The HTTP LAN API uses a token but not encryption. Use TLS MQTT or Fleet on untrusted networks.
Licensing
Pro applies to the activated device or cryptographically bound installation. The portal shows available and assigned seats; a user account never becomes a multi-device license.
Asks the store again for active purchases and restores the local entitlement.
Clears inconsistent local license caches and rebuilds state from store and control plane. The purchase is not deleted.
Platforms
Immersive full screen and screen pinning with OS limits.
Dedicated Device with Lock Task, enterprise policies, and more reliable startup. Requires proper provisioning.
Guided Access is the practical single-app option. A regular app cannot fully lock the device or auto-start.
Apple Configurator or MDM can provide Single App Mode and managed configuration.
Central management
Device count, online state, alerts, license use, and key actions.
Pairing, home URL, allowlist, technical details, revision, support code, and revoke.
Total, assigned, and available. Every assignment remains device-bound.
Versioned billing addresses, immutable direct invoices, and separate store receipts.
Invitations are single-use and valid for 48 hours. Members choose their own passwords.
Password, TOTP MFA, recovery codes, active sessions, and sign-out.
Safe operations
Evaluates heartbeat, errors, and technical signals against configurable thresholds.
Reload, Home, and config sync are reversible, audited actions with optional cooldown.
Correlates alerts, owners, comments, and actions; calculates MTTD/MTTR and exports reports.
One-time or weekly safe actions in a fixed time zone.
Suppress expected alerts for organization, group, or device without deleting data.
Start small, observe revision and health, promote safely, or roll back.
Local-first
Website content, form entries, and browsing history are not sent to the control plane.
Fleet receives device ID, platform, version, heartbeat, revision, and technical counters.
The backend token stays server-side; the browser gets a Secure, HttpOnly, SameSite-Strict cookie.
Encrypted TOTP secret, ten one-time recovery codes, and revocable sessions.
Never includes PIN, API token, MQTT, Basic Auth, or other passwords.
Off by default, visibly approved, time-limited, and audited.
Diagnostics
The FAQ covers short questions. For a specific issue, platform, app version, and an exact description help us narrow it down quickly.