Skip to main content
Table of Contents

Privacy & network access

This page lists every host TMS.NET Maps talks to, so you can plan firewall rules, proxy allow-lists and privacy statements, and explains the limits of the free (keyless) map styles.

Licensing is fully offline

License validation never contacts TMS software or any other server. The license key is a signed token that is verified locally against a public key embedded in the assembly (TMS.Maps.Core.Licensing), with no HTTP, socket or DNS use. The only network-related input is passive: the Date header of responses the SDK already receives from the map provider you call is used to detect a rolled-back system clock. No license data, machine data or telemetry is sent anywhere.

What the map controls load

The map controls (WPF, WinForms, Blazor, MAUI) render an HTML page in a web view (WebView2 on Windows, the platform web view on MAUI, an iframe in Blazor). That page loads the provider's JavaScript library from a CDN or the vendor's own host, and then map tiles/data from the provider. Nothing is bundled or proxied by TMS.

Script and stylesheet hosts

Provider Host What is loaded
Leaflet unpkg.com leaflet@1.9.4, leaflet.markercluster@1.5.3, leaflet.heat@0.2.0, leaflet-draw@1.0.4
OpenLayers cdn.jsdelivr.net ol@v10.3.1 (script and CSS)
Google maps.googleapis.com Maps JavaScript API (libraries=marker,visualization,drawing)
Google unpkg.com @googlemaps/markerclusterer@2
Azure atlas.microsoft.com Azure Maps Web SDK
HERE js.api.here.com HERE Maps API for JavaScript 3.2 (core, service, ui, mapevents, data, heatmap)
MapKit cdn.apple-mapkit.com MapKit JS 5

Tile hosts for the keyless styles (Leaflet and OpenLayers)

MapDisplayType Host Operator / terms
Road (default) tile.openstreetmap.org OpenStreetMap Foundation, tile usage policy
Terrain a/b/c.tile.opentopomap.org OpenTopoMap, CC-BY-SA, terms
Satellite, Hybrid server.arcgisonline.com Esri World Imagery, Esri terms of use

Google, Azure, HERE and MapKit load their tiles and data from their own hosts, with your API key, under your agreement with that vendor. Tile layers you add yourself with AddTileLayerAsync / SetTileServerAsync go to whatever host you specify.

Service hosts

The non-visual services (geocoding, directions, elevation, places, static maps, location) call only the REST endpoints of the provider you select: atlas.microsoft.com (Azure), *.googleapis.com (Google), *.hereapi.com (HERE), api.tomtom.com, api.mapbox.com, api.geoapify.com, api.openrouteservice.org, maps-api.apple.com (MapKit) and api.ipstack.com.

Limits of the free map styles

The Leaflet and OpenLayers providers need no API key, which makes them ideal for evaluation. The tile servers behind them are free community or vendor services with usage rules that you are responsible for following in production.

OpenStreetMap (Road)

  • The controls use the single official URL https://tile.openstreetmap.org/{z}/{x}/{y}.png (the old a/b/c.tile.openstreetmap.org subdomains are deprecated) and always show the "© OpenStreetMap contributors" attribution. Do not hide it.
  • The service is donation-funded and meant for light use. Heavy use, bulk downloading, prefetching or offline caching of tiles is forbidden and may get your users blocked without notice. For an application with many users or high traffic, use a commercial tile provider or your own tile server via SetTileServerAsync.
  • OSM requires a valid Referer for browser-based requests. The desktop and MAUI controls load their page with NavigateToString, which has no web origin, so the web view sends no Referer of its own:
    • WPF / WinForms: the WebView2 host adds a Referer header to requests for tile.openstreetmap.org, so OSM tiles load.
    • MAUI: no header is added. OSM may reject tiles or show a "blocked" tile. If that happens, use Terrain, a keyed provider or your own tile server.
    • Blazor: the map iframe inherits your site's origin, so the browser sends your site's origin as the Referer. Do not set a Referrer-Policy: no-referrer header on the page hosting the map (the Leaflet tile layer requests strict-origin-when-cross-origin itself).

OpenTopoMap (Terrain)

  • Free, keyless, commercial and app use allowed as long as the attribution "Map data: © OpenStreetMap contributors, SRTM | Map style: © OpenTopoMap (CC-BY-SA)" is shown (the controls do this).
  • Tiles are only available up to zoom level 17; beyond that the controls upscale the zoom-17 tiles, so the map looks blurrier at street level.
  • There is no availability guarantee and excessive downloading is not allowed. It is a volunteer-run server: for production traffic, use a commercial terrain provider.
Note

Earlier previews used Stadia Maps "Outdoors" for Terrain. Stadia requires an account and API key for anything other than localhost, so it did not work in desktop or mobile apps without one. If you prefer Stadia, create a key at stadiamaps.com and add it as a tile layer with its attribution:

await map.AddTileLayerAsync(
    "https://tiles.stadiamaps.com/tiles/outdoors/{z}/{x}/{y}{r}.png?api_key=YOUR_KEY",
    attribution: "&copy; <a href=\"https://stadiamaps.com/\">Stadia Maps</a> " +
                 "&copy; <a href=\"https://openmaptiles.org/\">OpenMapTiles</a> " +
                 "&copy; <a href=\"https://www.openstreetmap.org/copyright\">OpenStreetMap</a> contributors");

Esri World Imagery (Satellite, Hybrid)

Esri imagery is used without a key, with the Esri attribution shown. Esri's terms of use apply; check them before production or commercial use, and consider a keyed provider (Google, Azure, HERE, MapKit) for production satellite imagery.