Momento is now post-quantum — v2 receipts use ML-DSA-65. Learn more →⚠️ npm delayed — recovery requested, awaiting npm support. How to use Momento meanwhile →

Open source timestamping

A moment in time.
A proof you can keep.

Give any file a signed timestamp. Create a receipt in seconds, verify it whenever you need. Your file never leaves your device.

↳
your-file.zipStays on your device
LOCAL
SHA-256 fingerprint↓
m.Timestamp receiptMomento / ML-DSA-65✓
FILE FINGERPRINT
e3b0c44298fc1c149afbf4c8996fb924…
SIGNED AT · UTC
2026-09-25 12:34:56.789

Example receipt · Your next moment is yours.

01 Hash locally→02 Sign the fingerprint→03 Keep your proof

TIMESTAMP TOOLS

A timestamp for your file.

No account. No setup.
Just your file and a little cryptography.

Create a timestamp receipt

Submit a SHA-256 hash. The server sets the time and signs the receipt.

Local only · Any file type · Up to 100 MB

Checking Git commits? Jump to Git checks ↓ or use the Check repository tab above. How Git verification works →

Time is supplied by the signing server. What does a timestamp prove? ↗

ATTEST GIT COMMITS

Every commit, checked.

Hooks attest each commit as you create it.
Three checks prove the history is intact.

◈

Attest locally.

Git hooks link each commit to its parents' receipts and timestamp the commit bytes. Proofs live in refs/momento/proofs — a hidden ref, not a branch.

Install the hooks ↗
✓

Check before you push.

git verify checks signatures, hashes, parent links, and time ordering offline. The pre-push gate blocks unconfirmed commits.

How local checks work ↗

SIMPLE BY DESIGN

Your files. Your workflow.

Get to know Momento →
#

The file stays with you.

Your browser calculates a SHA-256 fingerprint. Only that hash reaches the signing service.

Your file→sha256→Receipt
✓

Built to be checked.

A JSON receipt, an ML-DSA-65 signature, and a public key. Verify locally, without contacting the issuer.

Understand the trust model ↗
⌘

Make it part of your process.

Timestamp from your app, a script, or your API client.

POST /api/v2/stamp
{ "hash": "<SHA-256>" }

What it proves: the issuer signed this hash and its stated time.

What it does not prove: authorship, ownership, original creation time, or independent clock accuracy.