launch a package

six steps from a published npm package to a verified public identity. Each one reports its own state from the server, so a reload never shows a step as done when it is not.

01

what we read

from npm: the package's public record, which is the same document anyone can fetch from the registry. From GitHub: your login and avatar, your verified email addresses, and your permission on the one repository you ask us to check.

  • read-only, through the official apis
  • no private repository contents, ever
  • figures are shown as returned, or as a dash
02

what we never do

nothing is written to your repository or to the registry on your behalf. We never publish a version for you: the proof step asks you to publish one, which is exactly why it proves something.

  • no posting, committing or publishing as you
  • no npm credentials are asked for or accepted
  • revoking on GitHub ends our access immediately
03

what a claim is worth

importing a package records what npm says about it and gives you nothing. Linking its repository shows you control that repository. Only the publish proof, or npm's own attestation, makes a package verified, and the public page always shows which of those happened.

  • one verified owner per package
  • withdraw a claim at any time
  • withdrawing releases the package for anyone else to prove