Privacy & network access
This page lists every host TMS.NET Maps talks to, so you can plan firewall rules, proxy allow-lists and privacy statements, and explains the limits of the free (keyless) map styles.
Licensing is fully offline
License validation never contacts TMS software or any other server. The license key is a
signed token that is verified locally against a public key embedded in the assembly
(TMS.Maps.Core.Licensing), with no HTTP, socket or DNS use. The only network-related input
is passive: the Date header of responses the SDK already receives from the map provider
you call is used to detect a rolled-back system clock. No license data, machine data or
telemetry is sent anywhere.
What the map controls load
The map controls (WPF, WinForms, Blazor, MAUI) render an HTML page in a web view (WebView2 on Windows, the platform web view on MAUI, an iframe in Blazor). That page loads the provider's JavaScript library from a CDN or the vendor's own host, and then map tiles/data from the provider. Nothing is bundled or proxied by TMS.
Script and stylesheet hosts
| Provider | Host | What is loaded |
|---|---|---|
| Leaflet | unpkg.com |
leaflet@1.9.4, leaflet.markercluster@1.5.3, leaflet.heat@0.2.0, leaflet-draw@1.0.4 |
| OpenLayers | cdn.jsdelivr.net |
ol@v10.3.1 (script and CSS) |
maps.googleapis.com |
Maps JavaScript API (libraries=marker,visualization,drawing) |
|
unpkg.com |
@googlemaps/markerclusterer@2 |
|
| Azure | atlas.microsoft.com |
Azure Maps Web SDK |
| HERE | js.api.here.com |
HERE Maps API for JavaScript 3.2 (core, service, ui, mapevents, data, heatmap) |
| MapKit | cdn.apple-mapkit.com |
MapKit JS 5 |
Tile hosts for the keyless styles (Leaflet and OpenLayers)
MapDisplayType |
Host | Operator / terms |
|---|---|---|
Road (default) |
tile.openstreetmap.org |
OpenStreetMap Foundation, tile usage policy |
Terrain |
a/b/c.tile.opentopomap.org |
OpenTopoMap, CC-BY-SA, terms |
Satellite, Hybrid |
server.arcgisonline.com |
Esri World Imagery, Esri terms of use |
Google, Azure, HERE and MapKit load their tiles and data from their own hosts, with your API
key, under your agreement with that vendor. Tile layers you add yourself with
AddTileLayerAsync / SetTileServerAsync go to whatever host you specify.
Service hosts
The non-visual services (geocoding, directions, elevation, places, static maps, location)
call only the REST endpoints of the provider you select: atlas.microsoft.com (Azure),
*.googleapis.com (Google), *.hereapi.com (HERE), api.tomtom.com, api.mapbox.com,
api.geoapify.com, api.openrouteservice.org, maps-api.apple.com (MapKit) and api.ipstack.com.
Limits of the free map styles
The Leaflet and OpenLayers providers need no API key, which makes them ideal for evaluation. The tile servers behind them are free community or vendor services with usage rules that you are responsible for following in production.
OpenStreetMap (Road)
- The controls use the single official URL
https://tile.openstreetmap.org/{z}/{x}/{y}.png(the olda/b/c.tile.openstreetmap.orgsubdomains are deprecated) and always show the "© OpenStreetMap contributors" attribution. Do not hide it. - The service is donation-funded and meant for light use. Heavy use, bulk downloading,
prefetching or offline caching of tiles is forbidden and may get your users blocked
without notice. For an application with many users or high traffic, use a commercial tile
provider or your own tile server via
SetTileServerAsync. - OSM requires a valid
Refererfor browser-based requests. The desktop and MAUI controls load their page withNavigateToString, which has no web origin, so the web view sends noRefererof its own:- WPF / WinForms: the WebView2 host adds a
Refererheader to requests fortile.openstreetmap.org, so OSM tiles load. - MAUI: no header is added. OSM may reject tiles or show a "blocked" tile. If that
happens, use
Terrain, a keyed provider or your own tile server. - Blazor: the map iframe inherits your site's origin, so the browser sends your
site's origin as the
Referer. Do not set aReferrer-Policy: no-referrerheader on the page hosting the map (the Leaflet tile layer requestsstrict-origin-when-cross-originitself).
- WPF / WinForms: the WebView2 host adds a
OpenTopoMap (Terrain)
- Free, keyless, commercial and app use allowed as long as the attribution "Map data: © OpenStreetMap contributors, SRTM | Map style: © OpenTopoMap (CC-BY-SA)" is shown (the controls do this).
- Tiles are only available up to zoom level 17; beyond that the controls upscale the zoom-17 tiles, so the map looks blurrier at street level.
- There is no availability guarantee and excessive downloading is not allowed. It is a volunteer-run server: for production traffic, use a commercial terrain provider.
Note
Earlier previews used Stadia Maps "Outdoors" for Terrain. Stadia requires an account
and API key for anything other than localhost, so it did not work in desktop or mobile
apps without one. If you prefer Stadia, create a key at stadiamaps.com and add it as a
tile layer with its attribution:
await map.AddTileLayerAsync(
"https://tiles.stadiamaps.com/tiles/outdoors/{z}/{x}/{y}{r}.png?api_key=YOUR_KEY",
attribution: "© <a href=\"https://stadiamaps.com/\">Stadia Maps</a> " +
"© <a href=\"https://openmaptiles.org/\">OpenMapTiles</a> " +
"© <a href=\"https://www.openstreetmap.org/copyright\">OpenStreetMap</a> contributors");
Esri World Imagery (Satellite, Hybrid)
Esri imagery is used without a key, with the Esri attribution shown. Esri's terms of use apply; check them before production or commercial use, and consider a keyed provider (Google, Azure, HERE, MapKit) for production satellite imagery.