PGP verification · trust the key · 2026
Verify WeTheNorth with PGP 2026: Match the Signed Onion Fingerprint
A PGP check is the one test a clone cannot pass. The look of a page copies easily. A valid signature from the canon key does not. Here is how to import that key, check the signature that ships beside the mirror register, and read the fingerprint. Do that, and the address you finally open is the real WeTheNorth, not a look-alike dressed up to match.
hn2paw7hljeihrk7qm2toniay5bb4cfz46cav5iywnsv64klm45mypqd.onionHow a WeTheNorth signature check runs
The idea is small once you see it. You hold a key. The register ships with a signature made by the matching private key. The check asks one question. Was this exact list signed by the key you trust? Nothing about the wording of a page enters into it.
What PGP proves about a WeTheNorth link that a careful eye cannot
People try to judge a WeTheNorth link by reading it. They count characters, they squint at the middle of the string, they trust a page that looks polished. A patient WeTheNorth clone defeats all of that. It can copy the layout, the wording, and most of the address.
A signature closes that gap. The private key that signs the WeTheNorth register never leaves the people who hold it. No clone can produce a WeTheNorth list that passes the check without that key. So you stop grading the name and start reading the math. The name can lie. The signature cannot.
Run the WeTheNorth check, from import to match
- Import the canon public key once. Keep the file you imported so you can compare its fingerprint later.
- Pull the signed register and the signature that sits next to it. Both come from the canon, not from search.
- Run the verify command on the pair. The tool reads the signature and the file together.
- Read the result. A good signature names the canon key by its fingerprint. A bad or missing one means stop.
- Compare that fingerprint against the one shown on the canon. If a single block differs, the list is not ours.
gpg --import wethenorth-canon.asc
gpg --verify mirrors.json.sig mirrors.json
gpg --fingerprint wethenorth-canonHonest limit. The key that signs the WeTheNorth register publishes in Phase 0. Until it does, the fingerprint reads pending and the strongest check you have is a slow, full character compare of the WeTheNorth address against the canon.
Where a WeTheNorth warrant canary fits in
A warrant canary is a short signed note that gets refreshed on a set schedule. As long as a WeTheNorth canary keeps appearing, signed by the same key, it quietly says nothing has forced a change behind the scenes. If it goes stale or vanishes, that silence is the message.
The canary rides on the same key as the register, so the moment you can verify one you can verify the other. It is pending alongside the key in Phase 0, listed here so you know to look for it.
Why the official WeTheNorth PGP key is the anchor, not the domain
A domain can be seized, expire, or be cloned by anyone willing to register a similar-looking name. A PGP key cannot be seized the same way — it can only be compromised, and a compromise is the one thing this whole verification process is built to catch. That is why every claim on this site about an official WeTheNorth address ultimately reduces to one question: does it match this key? Nothing else on the page substitutes for that check.
How long a WeTheNorth PGP key should stay the same
A stable key that has signed the register consistently over months is a mild positive signal, the same way a long clean vendor history is on a market — evidence of continuity, not proof of anything on its own. A key rotation is not automatically suspicious either; operators rotate keys deliberately after a security review or a suspected exposure. What matters is that any new key is itself announced and signed in a traceable way, not simply swapped without explanation.
Common mistakes when verifying a WeTheNorth signature
A PGP verification failure is rarely caused by the software; it is almost always a small procedural mistake. Here are the ones we see most often.
Importing a WeTheNorth key from the wrong source
Importing a WeTheNorth key pasted into a forum post or a chat message, rather than fetched from the canon record itself, defeats the entire purpose of the check — you would just be confirming a message matches a key that could itself be fake. Always import the WeTheNorth key from the same signed source this page points to, never from a copy someone else handed you.
Trusting a signature without checking the fingerprint
GnuPG will report "Good signature" even for a key you imported from an untrustworthy source, because that message only confirms the signature matches the key you have — not that the key itself is genuine. The fingerprint comparison is the step that actually matters, and skipping it while relying on "Good signature" alone is one of the most common ways this whole process gives false confidence.
Comparing a truncated WeTheNorth fingerprint
Some interfaces display a shortened fingerprint by default. A partial match on the first and last few characters is not a verified match — grind a vanity fingerprint prefix is trivial with enough compute, so always expand to and compare the full fingerprint, not an abbreviated view.
Reading a PGP-signed WeTheNorth message, not just verifying the WeTheNorth address
Verifying the WeTheNorth onion address against the canon key is a one-time setup step. Verifying individual signed WeTheNorth messages — from staff, in a dispute, or in an announcement — is a habit that keeps paying off for as long as you use the WeTheNorth account.
Why WeTheNorth staff communication should also be signed
Any message claiming to be from WeTheNorth staff, particularly one asking you to take an action — move funds, change an address, follow a new link — should be PGP-signed and verified the same way the WeTheNorth onion address itself was. An unsigned WeTheNorth message making an urgent request is a common social-engineering pattern precisely because urgency discourages the extra step of checking a signature.
What a valid signature on a WeTheNorth message actually proves
A valid signature proves the WeTheNorth message was signed by whoever holds the private key you already verified belongs to WeTheNorth — the same continuity-of-trust argument that applies to the onion address itself. It does not prove the message's request is wise or in your interest, only that it genuinely came from the WeTheNorth key. Read the content critically even after the signature checks out.
Keeping your WeTheNorth verification habit current
A PGP setup done once and never revisited tends to decay — a key expires, a keyring gets lost during a device wipe, a habit of skipping the check creeps in after enough uneventful WeTheNorth sessions. Periodically re-confirm your imported WeTheNorth key still matches the canon fingerprint published on this register, especially after any gap of inactivity.
Why PGP verification matters for WeTheNorth vendors, not just mirrors
Everything above covers verifying the WeTheNorth onion address itself. The same PGP discipline applies once you are inside the darknet market, dealing with individual vendors and escrow — verification does not stop at the front door.
Vendor PGP keys protect order communication, not just the market's own key
A vendor with a published PGP key lets a buyer encrypt a shipping address or a dispute message so that only the vendor, not a compromised staff account or a server-side leak, can read it. Treat a vendor's own key with the same care as the market's canon key: match the fingerprint against what the vendor has posted consistently across their listings, not against a single message.
Escrow disputes are exactly where a signed message matters most
An escrow dispute is the highest-stakes WeTheNorth interaction most buyers ever have with a vendor, and it is also where impersonation does the most damage — a convincing but unsigned message claiming to be market staff, offering to resolve a dispute off-platform, is a common scam pattern. A signed message from the market's actual PGP key is verifiable; an unsigned one asking you to move a dispute outside the escrow system is not, regardless of how official it reads.
WeTheNorth verification questions people ask
I have never used PGP. Is this too much?
No. You import one key, run one command, and read one line of output. The first run takes a few minutes. Every run after that is quick, and it is the only check a clone cannot fake.
The signature check failed. What does that mean?
It means the list was not signed by the canon key, or it was changed after signing. Either way you do not use any address from it. Close the page and start again from the canon.
Is the fingerprint the same thing as the onion address?
No. The onion address is where WeTheNorth lives. The fingerprint identifies the key that vouches for that address. You check the fingerprint so you can trust the address.
A worked WeTheNorth verification example, and the mistakes it prevents
Worked example: a full verification run
Picture the sequence with real inputs instead of abstractions. You have never imported the WeTheNorth key before, so you start with an empty keyring and a browser tab showing nothing but a search bar. Close the search bar. The canon page is the only place a first-time visitor should type a WeTheNorth string, because an unverified onion address is, by definition, unverified — a name and nothing else until a signature says otherwise.
You open a terminal, paste the import command from the canon key block, and watch gpg confirm one new public key added to your keyring. That key does not vouch for any specific onion address by itself; it only lets you check whether a given list of onion addresses was signed by the people who publish the canon. So the next step matters as much as the first: you pull the signed register — the file that actually lists the current onion mirrors — and the detached signature that ships beside it, both from the canon page, never from a bookmark or a forum thread.
Run gpg --verify against the pair. Two outcomes exist. A good signature prints a line naming the fingerprint of the key you just imported, and only then do the onion addresses in that register become addresses you can act on. A failed or missing signature means the register was not signed by the canon key — maybe it was tampered with in transit, maybe it is an old copy repackaged with a different onion address slipped in. Either way, no onion address from that file gets typed into Tor Browser.
The last check is the one people skip because it feels redundant after a good signature: compare the printed fingerprint, character for character, against the fingerprint shown on the canon itself. A matching fingerprint on a valid signature is what turns a downloaded file into a trusted list of onion mirrors. Skip that comparison and you have only proven the file was signed by some key, not necessarily the one you meant to trust.
Common mistakes, expanded
Trusting a link because it “looks right.” A convincing onion address is not evidence of anything; Tor addresses are long, random-looking strings by design, and a clone operator only needs to get close enough that a tired reader stops checking character by character. The signature check exists precisely because eyeballing an onion address does not scale and does not catch a single-character substitution.
Importing a key from the wrong place. If the public key comes from a market listing, a chat forward, or a search result instead of the canon page, the entire verification collapses — you would just be checking a register against a key an attacker also controls. The key has to originate from the same canon that publishes the onion mirrors you are trying to verify.
Reusing an old signed register. Onion addresses on WeTheNorth do rotate, and a stale signed file — even one that verifies cleanly against the canon key — can point at an onion address that is no longer current. Always pull a fresh register at the time you actually intend to connect, not one saved from weeks earlier.
Skipping the fingerprint match after a passing signature. A signature can be technically valid and still not be the one you meant to check, if you somehow imported a similar-looking key from the wrong source. The fingerprint comparison is the step that closes that gap, and it takes ten seconds against the string already printed on the canon.
Treating verification as optional “if the site looks fine.” The entire reason a PGP check exists is that a well-made clone looks fine. Visual polish tells you nothing about which onion address a listing actually points to. The signature is the only part of this chain a copy of the page cannot fake, so it is also the only part worth treating as non-negotiable.
Every part of this walkthrough exists to answer a single question about a single onion address: was this specific string, and no other, signed by the canon key. Not the page it is written on, not the words used to introduce it — the onion address itself, checked against a signature that a clone cannot forge.
The PGP tools a WeTheNorth signature check actually runs on
Nothing on this page is a custom WeTheNorth tool. The commands above run on standard, independently maintained software, and reading their own documentation deepens the same WeTheNorth verification habit this page teaches.
- GnuPG — the free PGP implementation behind every
gpg --verifyandgpg --fingerprintcommand a WeTheNorth check runs. - The Tor Project — the network you open the verified WeTheNorth onion through once the signature checks out.
- KeePassXC — a reasonable place to store an exported WeTheNorth key backup and fingerprint offline.
- Electronic Frontier Foundation — background reading on why key-based verification, not domain trust, is the sound model here.
More WeTheNorth verification reading
A matched fingerprint is one step in a longer WeTheNorth session: the WeTheNorth login page covers what happens right after verification, the safety and opsec guide covers the device and identity hygiene that should already be in place before you open a signed onion, and the status grid tells you honestly whether that onion is answering at all right now. Buyers reading this from a Canada-focused search land on the same verification steps as anyone else, and the about page explains why this register trusts a signature over a forum post. For the reasoning behind signature verification generally, Privacy Guides and Whonix both document the same PGP-first habit for any Tor hidden service, not only WeTheNorth.
Next moves
Key checked and ready to connect? The access guide puts this step inside the full run over Tor.