Decentralized package infrastructure

Packages with verifiable history.

Resolve an exact package, inspect every immutable release, verify its publishers, and install the same addressed bytes from any healthy miner.

Try · Current package coordinates retain the compatibility suffix .fxn, .ark or .deadark

  • Immutable version coordinates
  • Content-addressed release bytes
  • Browser-verified publisher signatures

Package protocol

Resolve the coordinate. Verify the release. Install the bytes.

  1. 1

    Resolve a package

    An exact coordinate such as flux-toolkit.fxn@2.1.0 resolves to one immutable release record and its content CID.

  2. 2

    Verify provenance

    The release names its publisher, content type, timestamp and CID. Signatures are checked in the browser before authority is displayed.

  3. 3

    Install exact bytes

    Install latest or pin a version. Healthy miners can serve the same addressed package without changing what that version means.

Publish

Publish an immutable release.

Choose a publisher identity, package bytes, coordinate and semantic version. Current nodes authorize publisher keys through the legacy name projection; Registry does not claim or manage domains.

  1. 1Your key
  2. 2Your file
  3. 3Details
  4. 4Publish

First, who's publishing?

Your key is how the network knows it's you, like a signature that can't be forged. It stays on this page and is forgotten when you close it.

Questions

Good questions, plain answers.

What is a package coordinate?

It is the stable identifier used to resolve releases, for example flux-toolkit.fxn@2.1.0. The suffix is retained for compatibility with current miners; this Registry does not claim or configure domains.

What's a key, and why must I save it?

A publisher key signs release records without leaving your browser. There is no “forgot password” because no central registry stores a recovery copy.

Is my key sent anywhere?

No. Your key stays inside this browser tab and is forgotten when you close or reload it. Only the signature it produces is sent, and a signature can't be turned back into a key.

What's a .flx file?

It's the Flux package format: one file that holds everything a release needs. Every version published here is a single .flx file, and downloads arrive as .flx too.

Is this the same as FXN, the coin?

No. FXN is the network's coin. This registry doesn't touch coins, balances or wallets: publishing and downloading here are free, and nothing here costs FXN.

Where does the information come from?

Straight from the miners that run the network: public.defxn.com and its sister nodes st1–st4. This page selects a healthy node and verifies publisher authority in the browser instead of trusting presentation alone.

Can I change or delete a version after publishing?

No, and that's on purpose. Anyone who downloads my-tool.fxn@1.0.0 today gets the exact same file as someone who downloads it next year. To fix something, publish 1.0.1.

How do I know a download is safe?

Every release shows who signed it and which CID addresses its bytes. This proves provenance and integrity; it does not prove that the software is secure. Review the source and publisher before executing it.

Why can't I browse or search everything?

The current network exposes exact-coordinate resolution, not a complete discovery index. This is an absent capability, not an empty catalog. Package search and dependency projections require a canonical index.

How is publishing authorized today?

Current miners use the existing signed name projection as a compatibility source for package publisher keys. That is authorization plumbing, not Registry’s product boundary. Future package records should carry independent maintainer policy.

Connection

Package metadata and release bytes come straight from public miners. Nothing to set up for read-only use.

Public miners

    Publishing miner (for publishers)

    Publishing writes to one miner you have an access code for, usually your own.