← Selected work

Momento / Timestamping · developer tools

A signed timestamp
you can keep.

Momento issues portable signed timestamp receipts for file hashes. You verify them locally, and integrations cover Git history and CI.

Status
Live service · CLI publication pending
Stack
TypeScript / Cloudflare Workers / ML-DSA-65
Implemented receipt workflow
  1. 01 / LOCALHash the file

    Only the SHA-256 digest leaves your device.

  2. 02 / WORKERIssue a receipt

    The issuer signs the digest and timestamp with ML-DSA-65.

  3. 03 / VERIFIERCheck it offline

    Verify the signature and compare the original file's hash.

Trust boundary: the issuer's signing key and clock.

01 / Problem

You keep the file
and share only its hash.

I wanted a timestamping primitive that fits into existing workflows. The client hashes the file and sends the SHA-256 digest; the service returns a signed receipt. The original file stays on the device.

02 / My build

One protocol
across several workflows.

I built a Cloudflare Worker API, web tools, a shared receipt protocol, a CLI, Git hooks and a GitHub Action. The v2 receipt format uses ML-DSA-65 signatures and validates the payload, key identity and encoding.

Momento stores Git receipts in a dedicated proof ref. History verification checks receipt signatures and links between commits, including merge history.

03 / Decisions and verification

Explicit trust assumptions.

Signing and offline verification share the protocol implementation. The repository includes protocol test vectors, API and CLI tests, Git-history scenarios, and cross-platform CI configuration.

A verified receipt depends on the issuer's clock and signing key. It does not establish who created the file or when it was first written. The service does not currently provide an independent witness or transparency log.

Read the threat model ↗

04 / Current status

The tools are live;
distribution comes next.

You can use the hosted tools and the local verifier now. Publication of the CLI and protocol packages is pending; the repository documents how to run them from a checkout.

Next: finish distribution, align release documentation with deployment, and make independent verification easier to reproduce.

Tell me what you're working on.

Let's talk ↗Next case study: N2Banking →More work →