N

npmjs.com

npm operates the public npm package registry for JavaScript packages and the npm command-line tooling used to publish, install, and manage packages. It also provides organization, access-control, security, and trusted publishing features around package distribution.

2 integrations · REST · CLI

npmjs.com exposes the npm Registry HTTP API and the npm CLI; both use npm-issued bearer tokens, with support for traditional session tokens, access tokens, and OIDC-based publishing tokens.

discovered 2mo ago
REST · OpenAPI1
CLI1
Credentials
npm access tokenbearerGet token ↗

Go to npm token settings after signing in, choose Generate New Token, and create a granular, automation, or legacy token as needed. The npm docs pages About access tokens and Creating and viewing access tokens describe the token types and management.

npm session tokenbearer$ npm login

Acquired by the CLI — running npm login opens the auth flow and stores the credential.

OIDC ID token for npm trusted publishingjwtGet key ↗

Use a supported CI/CD identity provider such as GitHub Actions, GitLab CI, or CircleCI to mint an OIDC id_token with audience npm:registry.npmjs.org, then use it with npm's OIDC exchange flow. npm documents this under Trusted publishing with OIDC and the npm Registry API auth section.

npm OIDC exchange tokenbearerGet token ↗

First obtain a supported CI/CD OIDC id_token with audience npm:registry.npmjs.org, then call npm's OIDC token exchange endpoint to get a short-lived npm registry token. The npm Registry API documents this token type and its use for package publishing and management in the Authentication & Authorization section and OIDC endpoints.

conventions · 0/8 published

Publish these signals → /publishing