Launch yourpackage onchain.

Packages gives existing npm packages a verified public identity on Solana, connecting their publishers, source code, release history and contributors.

every figure here is read from the npm registry and the GitHub api
find → prove → publish → identity
search the registry

find any package on npm

packages

see all

how a package
gets an identity

find
find your package

search the registry. Importing records what npm reports and nothing more.

sign in
sign in with GitHub

official oauth, read-only, revocable at any time from your GitHub settings.

link
link the repository

we read your permission on the repository the package declares.

prove
prove publish authority

the step that matters. Controlling the repo is not permission to publish.

wallet
connect a wallet

a signature, not a transaction. Optional, and nothing moves.

identity
launch the identity

a deterministic address on devnet holding the verified release record.

state steps one to five work today. The sixth is written and waiting on a devnet deployment, and every surface that touches it says so rather than implying an identity already exists.

what a check mark means here

a repository link
is not a proof.

Anyone can put any repository url in a package.json, and the npm registry does not check it. So a repository link is treated as a claim about where code came from, never as permission to publish, and the difference is visible on every package page.

publish authority, proved

a package is verified only when a string we issue appears in a version its owner published, or when npm's own build attestation names a repository they control.

no figure is invented

download counts, versions, stars and contributors come from npm and GitHub as those services return them. Where there is no figure you see a dash, never an estimate.

no token, nothing for sale

Packages issues no token and runs no market. An identity is a record of who publishes a package and what they have released. That is the whole product.