Validating a map and its DOI
A validation is an author's statement that the tracing map of their paper is right: that this is where the paper's code is, at this commit, under this licence. It is the only way a map receives a DOI.
Who can validate
A verified author of the paper, with an ORCID identity linked to their account — the DOI record names its creators by their ORCID iD. The "Validate its tracing map" part of the paper's Contribute section appears only for them.
What to check first
- the repositories listed as your code are yours, and none is missing (correct them first otherwise, and wait for the correction to be applied);
- the commit recorded for each is the one that goes with the paper, or an acceptable one;
- the licence is right;
- the matches in the reader look sensible — they are part of the map.
How
Press "Validate the map". The section says what you validate — so many repositories at their verified commits, with their licences, so many scripts and matches — and shows the map's fingerprint (its SHA-256 digest). Your validation carries that fingerprint: if the map changed after the page was built, the validation stops there and you are asked to look again. Your account page shows its status.
The deposit on Zenodo
The operator's computer picks up the validation, checks the fingerprint, and deposits the map on Zenodo, the free repository run by CERN, in the registry's community:
- the record holds one file,
tracing-map.json, and a description listing the repositories; - its creators are you, with your ORCID iD, and the platform;
- it is related to the paper (
IsSupplementToits DOI) and to each repository (References, at the validated commit, or the archive's own DOI); - it is released under CC0-1.0.
The DOI comes back to your account page and to the paper's page, whose Map and Cite sections then give it.
What the DOI covers
The map: its links and metadata. Not your code, which is never deposited again and stays in your repository, nor the paper. Cite the map's DOI for "the code of this paper, as its author validated it"; cite your repository's own DOI (a Zenodo software release, for instance) for the code itself. A later correction, validated again, becomes a new version under the same concept DOI (the DOI policy).
While the platform is built
Deposits go to Zenodo's sandbox, whose DOIs are not real, until the operator switches to Zenodo itself. A validation made through ORCID's sandbox sign-in is recorded as a test: it can reach only Zenodo's sandbox and is never shown in a public output. At most 10 validations a day per account.
