Launch yourpackage onchain.
Packages gives existing npm packages a verified public identity on Solana, connecting their publishers, source code, release history and contributors.
find any package on npm
packages
see allhow a package
gets an identity
search the registry. Importing records what npm reports and nothing more.
official oauth, read-only, revocable at any time from your GitHub settings.
we read your permission on the repository the package declares.
the step that matters. Controlling the repo is not permission to publish.
a signature, not a transaction. Optional, and nothing moves.
a deterministic address on devnet holding the verified release record.
state steps one to five work today. The sixth is written and waiting on a devnet deployment, and every surface that touches it says so rather than implying an identity already exists.
a repository link
is not a proof.
Anyone can put any repository url in a package.json, and the npm registry does not check it. So a repository link is treated as a claim about where code came from, never as permission to publish, and the difference is visible on every package page.
publish authority, proved
a package is verified only when a string we issue appears in a version its owner published, or when npm's own build attestation names a repository they control.
no figure is invented
download counts, versions, stars and contributors come from npm and GitHub as those services return them. Where there is no figure you see a dash, never an estimate.
no token, nothing for sale
Packages issues no token and runs no market. An identity is a record of who publishes a package and what they have released. That is the whole product.