npm packages status (temporary)
Why the npm packages are not published yet and how to use Momento meanwhile.
Temporary notice
This page and the site banner exist only until the npm packages are published, then both are removed.
What happened
The v2 packages — @mikthatguy/momento-protocol and @mikthatguy/momento-timestamp — are built and validated but not on npm yet. The maintainer lost the npm account's two-factor authentication (no authenticator, no recovery codes), so publishing is blocked until npm support completes an account recovery. Recovery is in progress; there is no action for you to take on that front.
This means bunx @mikthatguy/momento-timestamp … does not work yet. Everything else does: the production v2 API is live, the web tools work, and the GitHub Action and CLI run from this repository.
Use Momento without npm
Web tools. Stamp, verify, and inspect receipts directly in the browser. File hashing and verification happen locally; only the SHA-256 digest is sent to the API.
API. Call the live endpoints as documented in the API reference:
curl --fail-with-body https://momento.mthatguy.workers.dev/api/v2/stamp \
-H 'Content-Type: application/json' \
--data '{"hash":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"}'On Windows Command Prompt, single quotes are not unwrapped: use double quotes around --data and escape the inner quotes. PowerShell and Bash run the command as shown.
CLI from a checkout. Clone the repository and run the compiled CLI instead of bunx. Requires Bun 1.3.13+ and Node.js 22.18+:
git clone https://github.com/MIKTHATGUY/momento.git
cd momento
bun install --frozen-lockfile
bun run build:packages
bun packages/cli/dist/index.js stamp path/to/file.pdf
bun packages/cli/dist/index.js verify path/to/file.pdf.momento.json path/to/file.pdfVerification runs offline. To stamp against another instance, pass its base URL after the file path or set MOMENTO_API_URL. The same checkout CLI installs the Git hooks (git init) and powers the GitHub Action when referenced by commit SHA.
Rate limits apply as usual while you do this — see rate limits. If you hit 429, wait out the Retry-After: 60 interval.
What happens next
Account recovery progress
Where the npm account recovery stands and what happens after access is restored. Updated by hand with each milestone.
- Publishing blocked: npm 2FA lostNo authenticator, no recovery codes, no passkeys. npm publish is impossible until account access is restored.
- Workaround publishedThis page and the site banner explain checkout-based usage while npm is unavailable.
- Recovery request sent to npm support — in progressTicket opened from the account email address. Waiting on support verification — typically a few business days.
- Prove account ownershipReply from the registered email and complete whatever verification npm support asks for.
- Regain access and reset 2FALog back in and re-enable the authenticator plus passkeys on two devices.
- Store recovery codes properlyPassword manager plus an offline copy, so this never blocks a release again.
- Publish and clean upProtocol package first, then CLI, verify a clean-room install, then delete this page, the banner and this tracker.
Once the npm account is recovered, the maintainer will publish the protocol package first and the CLI second, verify bunx @mikthatguy/momento-timestamp@2.0.0 from outside the repository, and then delete this page and the banner. The checkout commands above keep working unchanged.