Legal · For integrators
Badge and Attribution Terms
These terms are for the small number of people building a product that shows ModHarbor verification: a launcher, a host, a store, a dashboard. If you are just adding a badge to your own project's README, you do not need to read this; drop in the snippet and you are done. This page is about displaying ModHarbor's verification data inside a product of your own.
Start here: what is free
Independent signature verification is free and governed by nothing at all. A signed mod carries an embedded Sigstore bundle that anyone can verify against the public Fulcio and Rekor transparency logs, offline, with the open-source verifier or any Sigstore client. That needs no ModHarbor account, no license, no attribution, and no agreement, and these terms do not touch it. If we disappeared, it would keep working.
These terms apply only to enriched verification data:
the states only ModHarbor can produce
(Author verified,
Withdrawn,
Revoked)
and the
harbor
data behind them, which you obtain by calling the ModHarbor Status API.
Displaying that data means agreeing to the terms below.
The terms
These obligations attach to each badge you display, not to your product as a whole.
-
1. Show as much or as little as you want.
You may display any of the states, or none. There is no obligation to render all five states, and no obligation to integrate revocation. If you only ever show
Author verified, that is your choice. -
2. Attribution.
Where you show a state, show the ModHarbor name and mark inline, next to it, not tucked into a footer or an about page. A verification that does not say who is attesting is not worth much as a verification.
-
3. Version.
Where the data is about a specific file, show the declared version exactly as ModHarbor returns it. Do not relabel it as an attested or verified version; the honest claim is that the artifact declares itself to be that version. Do not use the version to decide which artifact to show, because it is author-authored and an attacker could set it.
-
4. Linkback.
Link the display to the ModHarbor verify page for the exact file the data describes, so a reader can check it at the source.
-
5. Accuracy.
A state you show has to be the state ModHarbor currently reports for that file, refreshed within a reasonable interval (the current interval lives in the API documentation, so it can be tuned without changing this page). The asymmetry is the point: choosing not to show
Revokedis a gap you own, but showingAuthor verifiedon a file we currently report as revoked is our mark saying something false, and is not permitted. -
6. No safety claims.
ModHarbor verification reports provenance: where a build came from and whether its author registered it. It is not a safety review.
You may never relabel or present ModHarbor data as Safe, Secure, Scanned, Malware-free, Trusted, or any equivalent.
ModHarbor runs no malware scan, by design, so a display that implies one would be false and would put that false claim on our mark.
This clause is non-negotiable and applies at every tier.
-
7. No derived verdicts.
Do not compute a score, grade, tier, or ranking from ModHarbor fields and present it as ModHarbor's. We publish facts, not verdicts, and a derived verdict shown as ours misrepresents what we said.
-
8. The easy path is a safe harbor.
If you use an unmodified ModHarbor badge and embed snippet, you are treated as compliant with the attribution, version, and linkback terms above; the safe harbor covers you.
You are welcome to build a custom display instead, and if you do, it is on you to meet those terms yourself. The branded path is the easy path, never the mandated one.
-
9. Trademark license.
The ModHarbor name and hash-seal mark are trademarks of SolrLabs LLC. Displaying enriched verification data carries a limited, revocable license to use them for that purpose only: rendering unmodified ModHarbor verification data under these terms. Breaking these terms ends the license, and continued use of the mark after that is trademark infringement.
Changes and contact
If these terms change, the date at the top changes with them. A contact address for integration questions will be published here before launch.