/usr/local/lib/node_modules/npm/docs/content/commands
NameSizeModeActions
npm-access.md28880644editdlrm
npm-adduser.md20330644editdlrm
npm-audit.md162520644editdlrm
npm-bugs.md29970644editdlrm
npm-cache.md34500644editdlrm
npm-ci.md97700644editdlrm
npm-completion.md9080644editdlrm
npm-config.md40910644editdlrm
npm-dedupe.md95430644editdlrm
npm-deprecate.md21560644editdlrm
npm-diff.md89850644editdlrm
npm-dist-tag.md51700644editdlrm
npm-docs.md29750644editdlrm
npm-doctor.md50470644editdlrm
npm-edit.md10910644editdlrm
npm-exec.md113570644editdlrm
npm-explain.md27940644editdlrm
npm-explore.md10060644editdlrm
npm-find-dupes.md67910644editdlrm
npm-fund.md36740644editdlrm
npm-get.md4450644editdlrm
npm-help-search.md7550644editdlrm
npm-help.md10030644editdlrm
npm-init.md102130644editdlrm
npm-install-ci-test.md80830644editdlrm
npm-install-test.md115730644editdlrm
npm-install.md293060644editdlrm
npm-link.md123860644editdlrm
npm-ll.md56860644editdlrm
npm-login.md23540644editdlrm
npm-logout.md17490644editdlrm
npm-ls.md71480644editdlrm
npm-org.md19740644editdlrm
npm-outdated.md69780644editdlrm
npm-owner.md30820644editdlrm
npm-pack.md38320644editdlrm
npm-ping.md7690644editdlrm
npm-pkg.md80560644editdlrm
npm-prefix.md12060644editdlrm
npm-profile.md30670644editdlrm
npm-prune.md57370644editdlrm
npm-publish.md80280644editdlrm
npm-query.md69540644editdlrm
npm-rebuild.md49940644editdlrm
npm-repo.md27550644editdlrm
npm-restart.md14440644editdlrm
npm-root.md10960644editdlrm
npm-run.md75380644editdlrm
npm-sbom.md83380644editdlrm
npm-search.md35600644editdlrm
npm-set.md14330644editdlrm
npm-shrinkwrap.md9090644editdlrm
npm-star.md17120644editdlrm
npm-stars.md7430644editdlrm
npm-start.md16320644editdlrm
npm-stop.md13200644editdlrm
npm-team.md40840644editdlrm
npm-test.md12130644editdlrm
npm-token.md49050644editdlrm
npm-trust.md100730644editdlrm
npm-undeprecate.md14060644editdlrm
npm-uninstall.md44470644editdlrm
npm-unpublish.md44910644editdlrm
npm-unstar.md15740644editdlrm
npm-update.md129720644editdlrm
npm-version.md80110644editdlrm
npm-view.md74250644editdlrm
npm-whoami.md8000644editdlrm
npm.md56380644editdlrm
npx.md62870644editdlrm
Edit: /usr/local/lib/node_modules/npm/docs/content/commands/npm-token.md (4905B)
--- title: npm-token section: 1 description: Manage your authentication tokens --- ### Synopsis ```bash npm token list npm token revoke npm token create ``` Note: This command is unaware of workspaces. ### Description This lets you list, create and revoke authentication tokens. #### Listing tokens When listing tokens, an abbreviated token will be displayed. For security purposes the full token is not displayed. #### Generating tokens When generating tokens, you will be prompted you for your password and, if you have two-factor authentication enabled, an otp. Please refer to the [docs website](https://docs.npmjs.com/creating-and-viewing-access-tokens) for more information on generating tokens for CI/CD. #### Revoking tokens When revoking a token, you can use the full token (e.g. what you get back from `npm token create`, or as can be found in an `.npmrc` file), or a truncated id. If the given truncated id is not distinct enough to differentiate between multiple existing tokens, you will need to use enough of the id to allow npm to distinguish between them. Full token ids can be found on the [npm website](https://www.npmjs.com), or in the `--parseable` or `--json` output of `npm token list`. This command will NOT accept the truncated token found in the normal `npm token list` output. A revoked token will immediately be removed from the registry and you will no longer be able to use it. ### Configuration #### `name` * Default: null * Type: null or String When creating a Granular Access Token with `npm token create`, this sets the name/description for the token. #### `token-description` * Default: null * Type: null or String Description text for the token when using `npm token create`. #### `expires` * Default: null * Type: null or Number When creating a Granular Access Token with `npm token create`, this sets the expiration in days. If not specified, the server will determine the default expiration. #### `packages` * Default: * Type: null or String (can be set multiple times) When creating a Granular Access Token with `npm token create`, this limits the token access to specific packages. #### `packages-all` * Default: false * Type: Boolean When creating a Granular Access Token with `npm token create`, grants the token access to all packages instead of limiting to specific packages. #### `scopes` * Default: null * Type: null or String (can be set multiple times) When creating a Granular Access Token with `npm token create`, this limits the token access to specific scopes. Provide a scope name (with or without @ prefix). #### `orgs` * Default: null * Type: null or String (can be set multiple times) When creating a Granular Access Token with `npm token create`, this limits the token access to specific organizations. #### `packages-and-scopes-permission` * Default: null * Type: null, "read-only", "read-write", or "no-access" When creating a Granular Access Token with `npm token create`, sets the permission level for packages and scopes. Options are "read-only", "read-write", or "no-access". #### `orgs-permission` * Default: null * Type: null, "read-only", "read-write", or "no-access" When creating a Granular Access Token with `npm token create`, sets the permission level for organizations. Options are "read-only", "read-write", or "no-access". #### `cidr` * Default: null * Type: null or String (can be set multiple times) This is a list of CIDR address to be used when configuring limited access tokens with the `npm token create` command. #### `bypass-2fa` * Default: false * Type: Boolean When creating a Granular Access Token with `npm token create`, setting this to true will allow the token to bypass two-factor authentication. This is useful for automation and CI/CD workflows. #### `password` * Default: null * Type: null or String Password for authentication. Can be provided via command line when creating tokens, though it's generally safer to be prompted for it. #### `registry` * Default: "https://registry.npmjs.org/" * Type: URL The base URL of the npm registry. #### `otp` * Default: null * Type: null or String This is a one-time password from a two-factor authenticator. It's needed when publishing or changing package permissions with `npm access`. If not set, and a registry response fails with a challenge for a one-time password, npm will prompt on the command line for one. #### `read-only` * Default: false * Type: Boolean This is used to mark a token as unable to publish when configuring limited access tokens with the `npm token create` command. ### See Also * [npm adduser](/commands/npm-adduser) * [npm registry](/using-npm/registry) * [npm config](/commands/npm-config) * [npmrc](/configuring-npm/npmrc) * [npm owner](/commands/npm-owner) * [npm whoami](/commands/npm-whoami) * [npm profile](/commands/npm-profile)