7Maps · Verify

Check it yourself

Every day of 7Maps history is sealed and signed, and every badge is drawn from the latest check. Here you can confirm both without trusting this page: the checks run in your browser against the published key.

A day of history

Pick a day. Its signed root is fetched, recomputed from the list of files it covers, checked against the signature with the public key from /.well-known/7maps.json, and checked against the day before it in the chain.

Is this badge genuine?

Give the server address as it appears on its 7Maps page. You get what a genuine badge for that server says right now and when that was checked. A badge that says something else, or claims an owner mark or a top-10% place the server does not have, is not from 7Maps.

Machine-readable: GET https://7it.co.il/7maps/verify/badge?server=<address>&style=<style> returns {genuine, status, issued_at}.

Verify a day with your own tools

The same check, run on your machine (Node 18 or later). It needs nothing from this page.

// node verify.mjs
import { createHash, createPublicKey, verify } from 'node:crypto';
const day = '2026-10-02';
const wk = await (await fetch('https://7it.co.il/.well-known/7maps.json')).json();
const r = await (await fetch('https://7it.co.il/api/maps?a=root&day=' + day)).json();
const root = createHash('sha256').update((r.previous_root || '') + '\n' + r.files.join('\n')).digest('hex');
const ok = verify(null, Buffer.from(r.root, 'hex'), createPublicKey(wk.integrity.public_key_pem), Buffer.from(r.signature, 'base64'));
console.log(root === r.root && ok ? 'verified' : 'mismatch');

Each line of a root is sha256  id for one file of that day: the hash of the file and a stable id for it (the oldest roots show the file's path instead). Each root includes the previous day's root, so a past day cannot be changed without breaking every root after it, and a day that has a root is never signed again. The full method: methodology.

7Maps by 7IT. Also: Methodology · State of MCP uptime · Live map.