N

npm Registry API

REST discovered

Details
URL
https://registry.npmjs.org
Docs
https://api-docs.npmjs.com/
Authentication
npm session token bearer discovered Get token ↗
Authorization: Bearer <credential>

Run npm login to create a logged-in npm CLI session; the registry API docs state traditional session tokens are created via npm login and are required for user account management and token creation/management. See npm login and the npm Registry API auth section.

npm access token bearer discovered Get token ↗
Authorization: Bearer <credential>

Go to npm token settings after signing in, choose Generate New Token, and create a granular, automation, or legacy token as needed. The npm docs pages About access tokens and Creating and viewing access tokens describe the token types and management.

npm OIDC exchange token bearer discovered Get token ↗
Authorization: Bearer <credential>

First obtain a supported CI/CD OIDC id_token with audience npm:registry.npmjs.org, then call npm's OIDC token exchange endpoint to get a short-lived npm registry token. The npm Registry API documents this token type and its use for package publishing and management in the Authentication & Authorization section and OIDC endpoints.

OIDC ID token for npm trusted publishing jwt discovered Get key ↗
Authorization: Bearer <credential>

Use a supported CI/CD identity provider such as GitHub Actions, GitLab CI, or CircleCI to mint an OIDC id_token with audience npm:registry.npmjs.org, then use it with npm's OIDC exchange flow. npm documents this under Trusted publishing with OIDC and the npm Registry API auth section.