Getting started
Signed timestamps for SHA-256 hashes.
Momento reads its server clock and signs your file’s SHA-256 hash with ML-DSA-65. No account or API key is required. The original file never leaves your device.
Use the tools
Open the tools to create, verify, or inspect a receipt. File hashing and verification happen locally in your browser. For files larger than 100 MB, use the CLI.
Keep the original file and downloaded receipt. Verifying a receipt checks its signature and the file’s hash; inspecting it checks only the signature.
Calculate a hash
Windows / PowerShell
Get-FileHash -Algorithm SHA256 "file.zip"macOS
shasum -a 256 file.zipLinux
sha256sum file.zipIntegrate
- Public API: create timestamps and verify receipts.
- Git checks and attestations: attest each commit with local hooks, then check the chain with
git verifyand the pre-push gate. - GitHub checks and badges: re-check attested history in CI (
verify-history) and publish the coverage badge. - Trust model: what signatures and server timestamps establish.
Command line
From a Momento checkout using Bun 1.3.13+ and Node.js 22.18+, install dependencies:
bun installBuild the packages, then run the CLI:
bun run build:packages
bun run --cwd packages/cli start -- stamp path/to/file.pdf
bun run --cwd packages/cli start -- verify path/to/file.pdf.momento.json path/to/file.pdfStamping uses the public API by default. To use another instance, pass its base URL after the file path or set MOMENTO_API_URL. Verification runs offline.
The first npm release is being prepared. After publication, the same commands will be available as bunx @mikthatguy/momento-timestamp stamp file.pdf and bunx @mikthatguy/momento-timestamp verify receipt.json file.pdf, without cloning this repository.