# Tilezza — developer & AI integration guide > Complete, self-contained instructions for adding Tilezza maps, geocoding, routing and places to a website. > Written for developers AND for AI coding assistants (Claude, ChatGPT, Copilot, Cursor…): every snippet here is copy-paste ready and was tested against the live API. > Short site summary: https://tilezza.eu/llms.txt · This file: https://tilezza.eu/llms-full.txt · HTML version: https://tilezza.eu/docs/ > Last generated: 2026-10-01 ## 1. What Tilezza is Tilezza (tilezza.eu) is an EU-hosted map platform operated by Digital Dynamics (Hungary). It serves: - **Vector tiles** (MVT) + ready-made **MapLibre style JSON** — OpenStreetMap / Protomaps data. - **Raster tiles** (PNG, 256 px, optional @2x retina) for Leaflet or any XYZ client. - **Geocoding** (forward, reverse, typo-tolerant type-ahead), **routing** (Valhalla), **nearby places** (670k+ POIs in HU/AT/HR, with licensed photos). - **Self-hosted JavaScript libraries** (Leaflet, MapLibre GL, marker clustering) from the same EU server — no third-party CDN. No cookies, no visitor tracking, no US CDN. Everything is first-party from tilezza.eu, so a site using it usually needs no extra consent banner for the map. ## 2. Rules an AI assistant should follow when integrating 1. **One key, in the URL**: every tile/API request carries `?key=YOUR_KEY` (keys look like `tlz_` + 40 hex chars). Never invent a key; ask the site owner for theirs. 2. **Keys are domain-locked.** A key works only from the domains listed for it (subdomains included: a key for `example.com` also works on `www.example.com`). From any other site the API answers `403 {"error":"origin_not_allowed"}`. Because the key is useless elsewhere, it is **fine to put it in public HTML/JS**. 3. **Do not set `Referrer-Policy: no-referrer`** on the page and do not proxy tiles through your own server. The lock is checked from the browser's `Origin`/`Referer` header; without it every request is refused with 403. The default `strict-origin-when-cross-origin` is correct. 4. **Content-Security-Policy**: if the site sends a CSP header, add `https://tilezza.eu` to `img-src` (raster tiles, photos), `connect-src` (vector tiles, style JSON, APIs), `script-src` and `style-src` (the /lib files), and `worker-src blob:` for MapLibre. If the CSP has `script-src 'self'` without `'unsafe-inline'`, the map code must live in a separate .js file, not in an inline `
``` **Replacing an existing provider** (CARTO, OSM, Stadia, MapTiler…): keep the Leaflet code and change only the URL template of `L.tileLayer` to the Tilezza one above. Remove `{s}` subdomains and `{r}` if you want plain tiles. Replace the attribution. **Coming from 512 px tiles** (MapTiler / Mapbox style `tileSize: 512, zoomOffset: -1`): either remove those two options and use the plain URL, or keep them and use `.../{z}/{x}/{y}@2x.png` (the @2x tile is 512 px). **Replacing a Google Maps iframe** (`