CrawlCheck

Crawler identity

Signing keys

Every request CrawlCheck sends under its own name is signed (Web Bot Auth, HTTP Message Signatures), and so is every resolve answer. A site can allow the key instead of an IP range; anyone holding an old signature can see which key made it and when that key was valid. The history below cannot be edited quietly: each entry hashes the one before it, and the latest hash is sealed every day.

Signed key directory · Rotation record · Transparency log · Resolve protocol · Crawler policy

Current key

Thumbprint (JWK, SHA-256)hcIAczGf-8EFBnkunmZlvFWnD2nHHeHeC9cM4BTiBVo
Valid from2026-09-11T20:24:07.000Z
Signsevery request sent under our own name, and the directory
Overlap on rotation7 days: a new key is published before the old one stops signing, and the old one stays listed after

Retired keys

ThumbprintValid fromRetiredWhy
0zNVreNVKdaTFJjtRJtvcFiesmG2qgWvvIBL_zbgwko2026-08-212026-09-19moved from KV storage to a Worker secret

Every key event

Chain: intact (checked from the genesis entry). Coverage: complete, every key the directory publishes has an entry. Head 8b9e4f47245c3324f88704d7880d7e203acec175a7873421f8680f643c9ac5d6.

#When (UTC)EventKeyReasonEntry hash
22026-09-18 21:17:40retired0zNVreNVKdaTFJjt…moved from KV storage to a Worker secret8b9e4f47245c3324…
12026-09-16 12:26:27publishing0zNVreNVKdaTFJjt…published during overlap rotation; created 2026-08-21T03:07:11.000Z08d7e8ec87b75230…
02026-09-12 04:42:56activehcIAczGf-8EFBnku…e092e9199a0eee49…

Check it yourself

Each entry hashes {at, event, prev, reason, seq, storage, thumbprint} as canonical JSON with sorted keys; its prev is the hash of the entry before it, and the first entry points at 64 zeroes. Recompute the chain and it must reach head. A key that signed something last month appears here even if it no longer appears in the directory.

Daily anchor: the head hash is a leaf in that day’s sealed Merkle root, /api/seal/lookup?id=keys-head&day=YYYY-MM-DD, timestamped with OpenTimestamps.