Momento is now post-quantum — v2 receipts use ML-DSA-65. Learn more →⚠️ npm delayed — recovery requested, awaiting npm support. How to use Momento meanwhile →
Momento Timestamp

OpenAPI reference

Explore Momento’s endpoints, request schemas, and responses.

Download the OpenAPI schema to import Momento into your API client or generate a client library. The API also exposes its current schema at /api/openapi.json.

The playground sends requests to the public Momento API. Stamping creates a real signed receipt. No API key is required.

For a guided walkthrough, receipt formats, and offline verification, see the API guide.

Check service health

GET
/api/health

Checks that the API responds, not signing configuration or rate-limit availability.

Response Body

application/json

curl -X GET "https://example.com/api/health"
{  "ok": true}

Check signing readiness

GET
/api/ready

Imports the signing and verification keys and performs an ML-DSA-65 self-test. Checks rate-limit bindings are configured without consuming quota. Self-test results are cached up to 30 seconds per isolate; this does not test the rate-limit backend or prove uptime.

Response Body

application/json

application/json

curl -X GET "https://example.com/api/ready"
{  "ready": true}

Get public signing keys

GET
/api/v2/keys

Response Body

application/json

curl -X GET "https://example.com/api/v2/keys"
{  "algorithm": "ML-DSA-65",  "keys": {    "property1": "string",    "property2": "string"  },  "metadata": {    "property1": {      "status": "active",      "createdAt": "string",      "fingerprint": "string",      "fingerprintAlgorithm": "sha256-ml-dsa65-raw"    },    "property2": {      "status": "active",      "createdAt": "string",      "fingerprint": "string",      "fingerprintAlgorithm": "sha256-ml-dsa65-raw"    }  }}

Create a timestamp

POST
/api/v2/stamp

Signs a SHA-256 hash with the current server time. JSON body limit: 1,024 bytes. Only hash is accepted. Rate limits: 30 requests/minute per client IP and 300 per Cloudflare location. Responses are not stored by the service.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v2/stamp" \  -H "Content-Type: application/json" \  -d '{    "hash": "string"  }'
{  "payload": {    "version": 2,    "hash": "string",    "issuedAt": "2019-08-24T14:15:22Z",    "receiptId": "string",    "keyId": "string"  },  "signature": "string"}

Verify a receipt

POST
/api/v2/verify

Checks the receipt signature and supplied file hash. JSON body limit: 8,192 bytes. Choose exactly one request format. Invalid receipts return HTTP 200 with valid: false. Rate limits: 120 requests/minute per client IP and 1,200 per Cloudflare location.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/api/v2/verify" \  -H "Content-Type: application/json" \  -d '{    "hash": "string",    "receipt": {      "payload": {        "version": 2,        "hash": "string",        "issuedAt": "2019-08-24T14:15:22Z",        "receiptId": "string",        "keyId": "string"      },      "signature": "string"    }  }'
{  "valid": true,  "hash": "string",  "issuedAt": "2019-08-24T14:15:22Z",  "receiptId": "string",  "keyId": "string"}