Your account
Passwordless: Continue with Google, or a sign-in link by e-mail — either way a session on this device. An account is what closes the upper edge of a stamp's bracket — the timestamp that says the latest your bytes can have existed. Checking a stamp is free, anonymous and needs no account; the desk, the tools and the farmer's page never needed one and still do not.
A cart is waiting on this device
A plan or a block is in the cart. Pay from checkout, or edit it first.
Sign in
Google or Microsoft, or one link to the address below. A link works once, for 15 minutes, and signs in the device that opens it. No password exists to reset.
or
An account is what closes the upper edge of a stamp's bracket: a free stamp binds a new envelope to a public beacon, and a paid timestamp adds evidence that the committed bytes existed by its stated time. Neither dates the original capture. Checking is free and anonymous forever, with or without one.
Plan and balance
—
In the United Kingdom OpenStamps is sold to businesses: Stripe's page will ask for your GB VAT number and the invoice is reverse-charged. A UK address without one is refused after payment and the money returned.
You are on a plan already, so moving up or down — and moving between monthly and yearly — happens on Stripe's pages, where the change is prorated against what you have paid.
Prices exclude VAT; Stripe adds it at checkout. Cards, Revolut Pay, invoices, receipts, VAT identifiers and cancellation are all on Stripe's own pages: this site never sees a card number or Revolut credentials. A top-up is a one-off purchase of qualified stamps that never expire.
More seats, more vault — add-ons on this plan
Changed here, prorated by Stripe on the next invoice, at this plan's cadence. Up to the stated units each. Removing one at 0 takes it off the next invoice.
This deployment cannot take payment yet, so nothing here can be bought. The account still works and the stamps it makes still seal: they close on the two free authorities, binding the new envelope to a beacon round and two independent timestamps, without the qualified token a plan adds or proof of original capture time.
Stamps by month from your journal
| Month | Stamps | Bracketed | One-sided | Browser | API |
|---|
Counted from the journal, so only stamps made while signed in or through a key are here. The balance above is the meter's own count and is what a plan is charged against; the two agree from 16 September 2026 on, and a bracketed stamp in a month with a contracted qualified authority is a qualified stamp.
Mail from us off unless you switch it on
Plain text, to the address on this account, from the same sender as the sign-in link. Nothing else is ever mailed, and nothing is mailed to anyone else.
What else the plan carries seats, mailbox, backup
| What | On this plan |
|---|
Your stamps
Every stamp this account made from a signed-in browser or through an API key, newest first — the sealed envelope itself, which is the .cts file, kept here so a cleared browser is not the end of the journey. Only a fingerprint and the authorities' tokens are stored: never the file, never a place. Opening a stamp re-checks it on this device against the pinned authorities; nothing here is graded by a server. Every night at 02:00 UTC every entry in every journal is folded into one root and that root is stamped through the same beacon and authorities — so an entry, once anchored, cannot be altered or backdated by anyone, us included; open a stamp and the proof is checked here. Stamps are renewed before their authorities' keys lapse (the switch is under Mail from us).
The vault
A stamp fixes a file's fingerprint; the file itself is what Art. 12 asks you to keep for five years. The vault keeps it beside its stamp: encrypted on this device with a passphrase only you hold, stored under the stamp's fingerprint, retained for five years, and held against deletion when you set a legal hold. We hold ciphertext and can decrypt nothing. A forgotten passphrase is a lost vault — nothing here can recover it.
Where it is held: …
The passphrase never leaves this device. Write it down where the company keeps such things: it cannot be reset, only replaced while the vault is empty.
API keys
A key stamps from a mill line, a build server or a script that has no browser session. It spends this account's balance, so treat it as you would a card: anyone holding a key can spend this balance. Only the SHA-256 of a key is stored here, which is why a key can be shown once and never again — a lost one is revoked and replaced, not recovered.
Copy this key now. It will never be shown again, and anyone holding it can spend this balance.
On a phone: install the OpenStamps app — the plot page and the checker then open without signal.
From an AI agent (MCP)
An agent that writes a report, a contract or a build can stamp it itself: openstamps-mcp.mjs is one file, Node 20 or later, no dependencies. Four tools — stamp, verify, balance, anchors. Only the SHA-256 leaves the agent's machine; the .cts is written beside the file; verify is offline. Every stamp lands in the journal above and in the next nightly anchor. Without a key the agent still seals, one-sided, and the answer says so.
{ "mcpServers": { "openstamps": {
"command": "node", "args": ["/path/to/openstamps-mcp.mjs"],
"env": { "OPENSTAMPS_API_KEY": "osk_…" } } } }
The agent signs each seal with a P-256 key it keeps at ~/.openstamps/device-key.json; its key hash is printed on every stamp and can be enrolled on the desk's reader roster like a phone's. A stamp fixes bytes and time; it never says the content is true.
Team
Several people on one balance. The owner's plan pays for every member's stamps and sets every member's allowances; each member keeps their own sign-in, keys, journal rows and vault files. A plan's seats say how many may be on it, the owner included — Studio seats five, Works fifteen, Mill forty, Plant a hundred.
Your desk, on every browser
The desk keeps its records in the browser it runs in — and, since 16 September 2026, writes them to this account by itself after every change while you are signed in: products, assessments, mitigations, statements and sealed records, up to 2 MB. Sign in on another browser and open the desk: they are there. Two browsers editing at once keep the later save per record, and the five versions before the latest write are kept here so a merge that went wrong can be undone. The bundle is stored as sent and read by nobody.
Earlier versions the five before the latest write
Restoring a version makes it the account's current desk; every signed-in browser takes it on board the next time its desk syncs. The version you replace joins this list.
Hand-off requests
The requests your desk opened for suppliers, read from the desk on this browser when it holds one, otherwise from the backup. The mailbox itself lives on this origin for 14 days per request; the desk collects the replies. A farmer answering one never sees a balance or a price: the request carries your account, so your balance closes the farmer's bracket.
Signing out clears the session on this device only. A subscription is cancelled on Stripe's own pages through Billing, invoices and cards, or ends with the account below.
Close this account everything we hold, deleted
Closing deletes the journal, the desk on the account and its kept versions, every API key and the account record itself — at once, and for good. A subscription runs to the end of the period already paid and is not renewed; Stripe keeps the invoices, as tax law obliges both of us. The records and .cts files you hold yourself are yours and are untouched. The same address may sign in again later and starts a fresh account, without a second trial.