npm Trusted Publishers API
Configure trusted publisher settings for packages to enable OIDC token exchange from CI/CD providers without long-lived npm tokens.
Configure trusted publisher settings for packages to enable OIDC token exchange from CI/CD providers without long-lived npm tokens.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/npm-trusted-publishers-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: npm Public Trusted Publishers API
description: The npm Public API provides authenticated endpoints for managing npm access tokens, configuring trusted publishers, and exchanging OIDC tokens for short-lived registry access.
version: 1.0.0
contact:
name: npm Support
url: https://www.npmjs.com/support
termsOfService: https://docs.npmjs.com/policies/terms
servers:
- url: https://registry.npmjs.org
description: npm Public Registry
security:
- bearerAuth: []
tags:
- name: Trusted Publishers
description: Configure trusted publisher settings for packages to enable OIDC token exchange from CI/CD providers without long-lived npm tokens.
paths:
/-/npm/v1/security/trusted-publishers/packages/{package}:
get:
operationId: listTrustedPublishers
summary: List trusted publishers for a package
description: Retrieves the trusted publisher configurations for a given package. Each configuration specifies a CI/CD provider and the conditions under which it is trusted to publish.
tags:
- Trusted Publishers
parameters:
- $ref: '#/components/parameters/encodedPackageName'
responses:
'200':
description: Trusted publishers retrieved successfully.
content:
application/json:
schema:
type: object
properties:
objects:
type: array
description: List of trusted publisher configurations.
items:
$ref: '#/components/schemas/TrustedPublisher'
'401':
description: Authentication required.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'404':
description: Package not found.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
post:
operationId: addTrustedPublisher
summary: Add a trusted publisher for a package
description: Configures a new trusted publisher for a package. This allows the specified CI/CD provider to publish the package using OIDC token exchange without requiring long-lived npm tokens. Only users with write permissions on the package can configure trusted publishers.
tags:
- Trusted Publishers
parameters:
- $ref: '#/components/parameters/encodedPackageName'
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/TrustedPublisherRequest'
responses:
'201':
description: Trusted publisher added successfully.
content:
application/json:
schema:
$ref: '#/components/schemas/TrustedPublisher'
'400':
description: Invalid request parameters.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'401':
description: Authentication required.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'403':
description: Insufficient permissions to manage trusted publishers.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
/-/npm/v1/security/trusted-publishers/packages/{package}/{publisher_id}:
delete:
operationId: removeTrustedPublisher
summary: Remove a trusted publisher from a package
description: Removes a trusted publisher configuration from a package, revoking the CI/CD provider's ability to publish via OIDC token exchange.
tags:
- Trusted Publishers
parameters:
- $ref: '#/components/parameters/encodedPackageName'
- name: publisher_id
in: path
description: The identifier of the trusted publisher configuration to remove.
required: true
schema:
type: string
responses:
'204':
description: Trusted publisher removed successfully.
'401':
description: Authentication required.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
'404':
description: Trusted publisher configuration not found.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
components:
schemas:
Error:
type: object
description: An error response from the npm API.
properties:
error:
type: string
description: The error type or code.
message:
type: string
description: A human-readable description of the error.
TrustedPublisherRequest:
type: object
description: Request body for adding a trusted publisher configuration.
required:
- provider
- repository_owner
- repository
properties:
provider:
type: string
description: The CI/CD provider name.
enum:
- github-actions
- gitlab-ci
- circleci
repository_owner:
type: string
description: The owner or namespace of the source repository.
repository:
type: string
description: The name of the source repository.
workflow_filename:
type: string
description: The workflow file that is trusted to publish. Required for GitHub Actions.
environment:
type: string
description: The deployment environment name to restrict publishing to.
TrustedPublisher:
type: object
description: A trusted publisher configuration that allows a CI/CD provider to publish a package using OIDC token exchange.
properties:
id:
type: string
description: The unique identifier for this trusted publisher configuration.
provider:
type: string
description: The CI/CD provider name.
enum:
- github-actions
- gitlab-ci
- circleci
repository_owner:
type: string
description: The owner or namespace of the source repository.
repository:
type: string
description: The name of the source repository.
workflow_filename:
type: string
description: The workflow file that is trusted to publish, applicable to GitHub Actions.
environment:
type: string
description: The deployment environment name, if restricted.
created:
type: string
format: date-time
description: The date and time the trusted publisher was configured.
parameters:
encodedPackageName:
name: package
in: path
description: The name of the package, URL-encoded for scoped packages (e.g., @scope%2Fpackage).
required: true
schema:
type: string
securitySchemes:
bearerAuth:
type: http
scheme: bearer
description: npm access token provided as a Bearer token. Supports both classic tokens and granular access tokens.
basicAuth:
type: http
scheme: basic
description: Basic authentication using npm username and password.
oidcBearerAuth:
type: http
scheme: bearer
description: OIDC identity token from a supported CI/CD provider, provided as a Bearer token for token exchange.
externalDocs:
description: npm Public API Documentation
url: https://api-docs.npmjs.com/