/usr/local/lib/node_modules/npm/docs/output/commands
NameSizeModeActions
npm-access.html84030644editdlrm
npm-adduser.html74460644editdlrm
npm-audit.html261680644editdlrm
npm-bugs.html87820644editdlrm
npm-cache.html93000644editdlrm
npm-ci.html178730644editdlrm
npm-completion.html56650644editdlrm
npm-config.html105610644editdlrm
npm-dedupe.html174840644editdlrm
npm-deprecate.html75800644editdlrm
npm-diff.html155510644editdlrm
npm-dist-tag.html114390644editdlrm
npm-docs.html87240644editdlrm
npm-doctor.html112160644editdlrm
npm-edit.html60520644editdlrm
npm-exec.html195910644editdlrm
npm-explain.html81260644editdlrm
npm-explore.html59570644editdlrm
npm-find-dupes.html140700644editdlrm
npm-fund.html90600644editdlrm
npm-get.html52370644editdlrm
npm-help-search.html56300644editdlrm
npm-help.html59580644editdlrm
npm-init.html187530644editdlrm
npm-install-ci-test.html157760644editdlrm
npm-install-test.html210390644editdlrm
npm-install.html432580644editdlrm
npm-link.html214200644editdlrm
npm-ll.html127840644editdlrm
npm-login.html78650644editdlrm
npm-logout.html68540644editdlrm
npm-ls.html146730644editdlrm
npm-org.html74890644editdlrm
npm-outdated.html138000644editdlrm
npm-owner.html86200644editdlrm
npm-pack.html99200644editdlrm
npm-ping.html57050644editdlrm
npm-pkg.html142800644editdlrm
npm-prefix.html63430644editdlrm
npm-profile.html87680644editdlrm
npm-prune.html124280644editdlrm
npm-publish.html155420644editdlrm
npm-query.html128210644editdlrm
npm-rebuild.html114040644editdlrm
npm-repo.html84040644editdlrm
npm-restart.html67750644editdlrm
npm-root.html60860644editdlrm
npm-run.html147050644editdlrm
npm-sbom.html138630644editdlrm
npm-search.html99380644editdlrm
npm-set.html65340644editdlrm
npm-shrinkwrap.html57030644editdlrm
npm-star.html71720644editdlrm
npm-stars.html56680644editdlrm
npm-start.html70370644editdlrm
npm-stop.html66110644editdlrm
npm-team.html100260644editdlrm
npm-test.html64910644editdlrm
npm-token.html120050644editdlrm
npm-trust.html190330644editdlrm
npm-undeprecate.html65810644editdlrm
npm-uninstall.html108500644editdlrm
npm-unpublish.html103580644editdlrm
npm-unstar.html70250644editdlrm
npm-update.html230560644editdlrm
npm-version.html155800644editdlrm
npm-view.html144980644editdlrm
npm-whoami.html57000644editdlrm
npm.html120700644editdlrm
npx.html124250644editdlrm
Edit: /usr/local/lib/node_modules/npm/docs/output/commands/npm-token.html (12005B)
npm-token

npm-token @11.12.0

Manage your authentication tokens

Table of contents

Synopsis

npm token list
npm token revoke <id|token>
npm token create

Note: This command is unaware of workspaces.

Description

This lets you list, create and revoke authentication tokens.

Listing tokens

When listing tokens, an abbreviated token will be displayed. For security purposes the full token is not displayed.

Generating tokens

When generating tokens, you will be prompted you for your password and, if you have two-factor authentication enabled, an otp.

Please refer to the docs website for more information on generating tokens for CI/CD.

Revoking tokens

When revoking a token, you can use the full token (e.g. what you get back from npm token create, or as can be found in an .npmrc file), or a truncated id. If the given truncated id is not distinct enough to differentiate between multiple existing tokens, you will need to use enough of the id to allow npm to distinguish between them. Full token ids can be found on the npm website, or in the --parseable or --json output of npm token list. This command will NOT accept the truncated token found in the normal npm token list output.

A revoked token will immediately be removed from the registry and you will no longer be able to use it.

Configuration

name

  • Default: null
  • Type: null or String

When creating a Granular Access Token with npm token create, this sets the name/description for the token.

token-description

  • Default: null
  • Type: null or String

Description text for the token when using npm token create.

expires

  • Default: null
  • Type: null or Number

When creating a Granular Access Token with npm token create, this sets the expiration in days. If not specified, the server will determine the default expiration.

packages

  • Default:
  • Type: null or String (can be set multiple times)

When creating a Granular Access Token with npm token create, this limits the token access to specific packages.

packages-all

  • Default: false
  • Type: Boolean

When creating a Granular Access Token with npm token create, grants the token access to all packages instead of limiting to specific packages.

scopes

  • Default: null
  • Type: null or String (can be set multiple times)

When creating a Granular Access Token with npm token create, this limits the token access to specific scopes. Provide a scope name (with or without @ prefix).

orgs

  • Default: null
  • Type: null or String (can be set multiple times)

When creating a Granular Access Token with npm token create, this limits the token access to specific organizations.

packages-and-scopes-permission

  • Default: null
  • Type: null, "read-only", "read-write", or "no-access"

When creating a Granular Access Token with npm token create, sets the permission level for packages and scopes. Options are "read-only", "read-write", or "no-access".

orgs-permission

  • Default: null
  • Type: null, "read-only", "read-write", or "no-access"

When creating a Granular Access Token with npm token create, sets the permission level for organizations. Options are "read-only", "read-write", or "no-access".

cidr

  • Default: null
  • Type: null or String (can be set multiple times)

This is a list of CIDR address to be used when configuring limited access tokens with the npm token create command.

bypass-2fa

  • Default: false
  • Type: Boolean

When creating a Granular Access Token with npm token create, setting this to true will allow the token to bypass two-factor authentication. This is useful for automation and CI/CD workflows.

password

  • Default: null
  • Type: null or String

Password for authentication. Can be provided via command line when creating tokens, though it's generally safer to be prompted for it.

registry

The base URL of the npm registry.

otp

  • Default: null
  • Type: null or String

This is a one-time password from a two-factor authenticator. It's needed when publishing or changing package permissions with npm access.

If not set, and a registry response fails with a challenge for a one-time password, npm will prompt on the command line for one.

read-only

  • Default: false
  • Type: Boolean

This is used to mark a token as unable to publish when configuring limited access tokens with the npm token create command.

See Also