npmjs.com
npm operates the public npm package registry for JavaScript packages and the npm command-line tooling used to publish, install, and manage packages. It also provides organization, access-control, security, and trusted publishing features around package distribution.
npmjs.com exposes the npm Registry HTTP API and the npm CLI; both use npm-issued bearer tokens, with support for traditional session tokens, access tokens, and OIDC-based publishing tokens.
- npm Registry APIdiscovered
- npm CLIdiscovered
Go to npm token settings after signing in, choose Generate New Token, and create a granular, automation, or legacy token as needed. The npm docs pages About access tokens and Creating and viewing access tokens describe the token types and management.
$ npm loginAcquired by the CLI — running npm login opens the auth flow and stores the credential.
Use a supported CI/CD identity provider such as GitHub Actions, GitLab CI, or CircleCI to mint an OIDC id_token with audience npm:registry.npmjs.org, then use it with npm's OIDC exchange flow. npm documents this under Trusted publishing with OIDC and the npm Registry API auth section.
First obtain a supported CI/CD OIDC id_token with audience npm:registry.npmjs.org, then call npm's OIDC token exchange endpoint to get a short-lived npm registry token. The npm Registry API documents this token type and its use for package publishing and management in the Authentication & Authorization section and OIDC endpoints.
conventions · 0/8 published
- integrations.json✗
/.well-known/integrations.json - llms.txt✗
/llms.txt - API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing