Crawler identity
Signing keys
Every request CrawlCheck sends under its own name is signed (Web Bot Auth, HTTP Message Signatures), and so is every resolve answer. A site can allow the key instead of an IP range; anyone holding an old signature can see which key made it and when that key was valid. The history below cannot be edited quietly: each entry hashes the one before it, and the latest hash is sealed every day.
Signed key directory · Rotation record · Transparency log · Resolve protocol · Crawler policy
Current key
| Thumbprint (JWK, SHA-256) | hcIAczGf-8EFBnkunmZlvFWnD2nHHeHeC9cM4BTiBVo |
| Valid from | 2026-09-11T20:24:07.000Z |
| Signs | every request sent under our own name, and the directory |
| Overlap on rotation | 7 days: a new key is published before the old one stops signing, and the old one stays listed after |
Retired keys
| Thumbprint | Valid from | Retired | Why |
|---|---|---|---|
| 0zNVreNVKdaTFJjtRJtvcFiesmG2qgWvvIBL_zbgwko | 2026-08-21 | 2026-09-19 | moved from KV storage to a Worker secret |
Every key event
Chain: intact (checked from the genesis entry). Coverage: complete, every key the directory publishes has an entry. Head 8b9e4f47245c3324f88704d7880d7e203acec175a7873421f8680f643c9ac5d6.
| # | When (UTC) | Event | Key | Reason | Entry hash |
|---|---|---|---|---|---|
| 2 | 2026-09-18 21:17:40 | retired | 0zNVreNVKdaTFJjt… | moved from KV storage to a Worker secret | 8b9e4f47245c3324… |
| 1 | 2026-09-16 12:26:27 | publishing | 0zNVreNVKdaTFJjt… | published during overlap rotation; created 2026-08-21T03:07:11.000Z | 08d7e8ec87b75230… |
| 0 | 2026-09-12 04:42:56 | active | hcIAczGf-8EFBnku… | e092e9199a0eee49… |
Check it yourself
Each entry hashes {at, event, prev, reason, seq, storage, thumbprint} as canonical JSON with sorted keys; its prev is the hash of the entry before it, and the first entry points at 64 zeroes. Recompute the chain and it must reach head. A key that signed something last month appears here even if it no longer appears in the directory.
Daily anchor: the head hash is a leaf in that day’s sealed Merkle root, /api/seal/lookup?id=keys-head&day=YYYY-MM-DD, timestamped with OpenTimestamps.