Qstamp / Developers
Build with Qstamp

Install the SDK, stamp and verify.

The Qstamp SDK is open source under the Apache License 2.0 or the MIT licence. It runs on Node 20 or later and depends only on QCore, the Quantova client library for post quantum signing.

GitHubOpen source

Qstamp SDK source

Full source code, the published construction and the release history, open for independent security review.

git clone https://github.com/Quantova/QStamp.git
npmv0.1.4

@quantovainc/qstamp

Command line tool and library for Node 20 or later, with one dependency, QCore, for post quantum signing.

npm install @quantovainc/qstamp
QuantaExample

Contract templates

Open, issuer and council Quanta smart contracts. An independent third party audit is required before production deployment.

git clone https://github.com/Quantova/Qstamp-Quanta-Smart-contract-example-.git
Test networkQ-test-net-1

Endpoint and test units

Public endpoint for the Quantova test network. Claim free TQTOV test units to pay the anchoring fee.

https://rpc-testnet.quantova.org
terminalcommand line
npm install @quantovainc/qstamp fingerprint files npx qstamp hash report.pdf ledger.csv stamp them in one transaction npx qstamp stamp report.pdf ledger.csv \ --seed-file ./signer.key --index 0 --kind financial_record verify a receipt against its file npx qstamp verify report.pdf.qstamp.json --file report.pdf recover an interrupted stamp npx qstamp complete qstamp-pending-1760000000000-a1b2c3d4.json
app.jsprogrammatic
const qstamp = require('@quantovainc/qstamp'); const digest = await qstamp.digestFile('report.pdf'); const [receipt] = await qstamp.stamp({ seed, index: 0, kind: 'financial_record', records: [{ digest }], }); const result = await qstamp.verify(receipt, { file: 'report.pdf', }); result.status · result.checks · result.endpoints
API

Functions and guarantees.

FunctionPurposeBehaviour
stamp(options)Anchor up to 1048576 records in one transaction and return one receipt per recordSeed accepted only as 32 wipeable bytes and wiped after signing. Fee cap enforced before signing.
verify(receipt, options)Verify a receipt against its content and the networkNever returns valid without the content. Returns indeterminate when the network cannot be consulted.
complete(pending)Complete the receipts for a submitted batch after an interruptionRejects pending batches that do not match the anchored commitment.
digestFile, digestBytesFingerprint content with SHA3 or SHA2 at 256 bitsStreaming, so files of any size are supported.
leafHash, tree, rootFromPath, commitmentPrimitives for independent verifiersExact implementation of the published construction.
validateReceiptStrict schema validationExact keys, canonical encodings and bounded values.
Network

Test network parameters.

Chain name
Q-test-net-1
Genesis hash
ca91e093bb8de33e90db52d7c89876597d14760703793ea7211929e73e613062
Qstamp contract
Q1D6TZFRL203P3DFAFVUPZUHGUCM4EWGH6063XNS42VA5235RNQWXS7FXEWX
Endpoint
https://rpc-testnet.quantova.org
Fee per anchor
0.005 TQTOV, independent of batch size

Test network receipts carry no evidential weight. Production use will take place on the Quantova main network once it launches.

Independent verification

Verify without the SDK.

Recompute the record digest with the algorithm named in the receipt.

Compute the leaf from 0x00, QSTAMP/LEAF/V1, the algorithm identifier, the digest and the salt.

Recompute the root following RFC 9162 section 2.1.3.2.

Compute the commitment from 0x02, QSTAMP/ROOT/V1, genesis, contract, signer, kind, size and root.

Confirm that the transaction is final, is signed by the stated address and carries the commitment.

Confirm that the official contract emitted event 5a110849 with the signer, commitment and kind.

Confirm the block identifier and the block time.