We use cookies for analytics and advertising to understand traffic and improve EarthGuessr. You can accept or reject — essential cookies always stay on. Privacy & cookies

All posts
Behind the ScenesFebruary 7, 20262 min readEarthGuessr Team

How EarthGuessr Validates Guesses and Scores

Scores are calculated in database functions. That protects result records, but a browser-based map still has limits on what it can conceal.

EarthGuessr sends guessed coordinates to a database function and displays the score returned by that function. The browser does not submit an arbitrary score as the result of a standard round.

That distinction protects the score calculation. It does not make a location game cheat-proof. The browser must receive enough geographic information to display imagery, and client-side restrictions cannot make that information secret.

The server calculates the result

The standard submit_guess call identifies the session and round, then supplies the player's latitude and longitude. The database checks the round state and calculates the result against the stored answer.

The migrations include checks for previously submitted rounds and rules controlling access to session data. Keeping this validation on the server prevents changing a displayed number in the browser from changing the recorded result.

Access rules need to match each game mode

Database access policies determine which rows a client can read or change. Game functions also enforce conditions before updating a round. Solo play, daily challenges, and multiplayer use different state, so a rule that protects one path must not be assumed to protect every path.

An accurate description of these controls needs to distinguish the migrations in the repository from the configuration actually deployed. This article describes the implementation, not the result of an independent security audit.

Map controls are gameplay rules

Limits on zooming or panning define a round's difficulty. They guide normal interaction with the interface, but browser code can be inspected and modified. They should not be presented as a security boundary against a determined player.

Coordinate offsets cannot guarantee that a player will be unable to infer a displayed location. Geographic imagery and the mapping data needed to display it can reveal where the view is centred.

Interpreting a leaderboard

A very accurate guess is not enough evidence to accuse someone of cheating. A player may recognise the location or have seen it before. Conversely, server-calculated scores alone do not establish that a player followed every rule while finding the answer.

The useful distinction is between validating a submitted result and establishing how the player arrived at it. They require different evidence.

More in Behind the Scenes

Related reading

Ready to explore?

See the world from above and test your geography skills on a 3D globe.