npm website screenshot

npm

npm is the world's largest software registry, hosting over two million JavaScript packages for the Node.js ecosystem. Their developer platform provides APIs for searching and retrieving package metadata, managing access tokens, subscribing to registry event webhooks, and publishing packages with supply chain provenance verification.

npm publishes 8 APIs on the APIs.io network, including Registry API, Hooks API, Downloads API, and 5 more. Tagged areas include Packages, JavaScript, Node.js, Package Management, and Registry.

The npm catalog on APIs.io includes 1 event-driven AsyncAPI specification, 1 JSON-LD context, and 2 Spectral governance rulesets.

npm’s developer surface includes authentication, developer portal, documentation, engineering blog, support, and 11 more developer resources.

61.8/100 strong ▬ flat Agent 43/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serveFree trial⚡ Free to try
10 APIs
PackagesJavaScriptNode.jsPackage ManagementRegistrySecurity

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 61.8/100 · strong
Contract Quality 20.1 / 25
Developer Ergonomics 7.8 / 20
Commercial Clarity 14.7 / 20
Operational Transparency 6.8 / 13
Governance 5.7 / 12
Discoverability 6.5 / 10
Agent readiness — 43/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 6 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/npm: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 10

Individual APIs this provider publishes, each with its own machine-readable definition.

npm Registry API

The npm Registry API provides programmatic access to the npm package registry, the largest software registry in the world hosting over two million JavaScript packages. Developer...

npm Hooks API

The npm Hooks API allows developers to subscribe to notifications about changes in the npm registry. Hooks send HTTP POST payloads to a configured URI whenever a package is chan...

npm CLI

The npm CLI is the official command-line interface for the npm package manager, providing developers with tools to install, publish, and manage JavaScript packages and their dep...

npm Provenance

npm Provenance provides supply chain security for JavaScript packages by establishing a verifiable link between a published package and its source code repository and build envi...

npm Downloads API

Package tarball downloads.

npm OIDC API

OpenID Connect token exchange for trusted publishing. Exchange OIDC identity tokens from supported CI/CD providers for short-lived npm registry access tokens.

npm Packages API

Package metadata retrieval, including full packuments and version-specific documents.

npm Search API

Full-text search across the npm registry with weighted scoring.

npm Tokens API

Manage npm access tokens for authentication. Create, list, and delete tokens with customizable permissions and restrictions.

npm Trusted Publishers API

Configure trusted publisher settings for packages to enable OIDC token exchange from CI/CD providers without long-lived npm tokens.

Scroll for all 10

Postman Collections 8

Ready-to-run Postman collections for exercising this provider's APIs.

Scroll for all 8

Open Collections 3

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

npm Hooks API

OPEN COLLECTION

npm Public API

OPEN COLLECTION

npm Registry API

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Npm Plans Pricing

4 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Npm Rate Limits

4 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Npm Finops

FINOPS

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

npm Hooks Events

The npm Hooks event system delivers HTTP POST payloads to subscriber endpoints whenever changes occur in the npm registry. Hooks can be configured to watch for changes to indivi...

ASYNCAPI

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Npm Context

0 classes · 8 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

npm API Rules

6 rules · 1 errors 4 warnings 1 info

SPECTRAL

npm API Rules

6 rules · 4 warnings 2 info

SPECTRAL

JSON Schema 19

Standalone JSON Schema definitions for this provider's data models.

Distribution

6 properties

JSON SCHEMA

Error

2 properties

JSON SCHEMA

npm Hook Event Payload

8 properties

JSON SCHEMA

Hook

10 properties

JSON SCHEMA

HookCreateRequest

4 properties

JSON SCHEMA

HookUpdateRequest

2 properties

JSON SCHEMA

npm Package Document

17 properties

JSON SCHEMA

PackageDocument

16 properties

JSON SCHEMA

PackageVersion

19 properties

JSON SCHEMA

Person

3 properties

JSON SCHEMA

RegistryMetadata

11 properties

JSON SCHEMA

Repository

2 properties

JSON SCHEMA

SearchResultItem

3 properties

JSON SCHEMA

SearchResults

3 properties

JSON SCHEMA

Token

7 properties

JSON SCHEMA

TokenCreateRequest

4 properties

JSON SCHEMA

TokenWithValue

0 properties

JSON SCHEMA

TrustedPublisher

7 properties

JSON SCHEMA

TrustedPublisherRequest

5 properties

JSON SCHEMA

Scroll for all 19

JSON Structure 1

JSON Structure definitions describing this provider's data shapes.

Npm Structure

0 properties

JSON STRUCTURE

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Npm Authentication

http · 2 schemes

SECURITY

Npm Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Npm Vulnerability Disclosure

security.txt · contact published

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Npm Agentic Access

17 operations · 8 acting

17 operations · 8 acting

AGENTIC

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 3

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: npm
name: npm
description: npm is the world's largest software registry, hosting over two million JavaScript packages for the Node.js ecosystem.
  Their developer platform provides APIs for searching and retrieving package metadata, managing access tokens, subscribing
  to registry event webhooks, and publishing packages with supply chain provenance verification.
kind: contract
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: true
  try_now: true
  public: false
  label: Freemium (free trial) · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
position: Consuming
access: 3rd-Party
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/npm.png
tags:
- Packages
- JavaScript
- Node.js
- Package Management
- Registry
- Security
url: https://raw.githubusercontent.com/api-evangelist/npm/refs/heads/main/apis.yml
created: '2026-03-20'
modified: '2026-05-19'
specificationVersion: '0.19'
apis:
- aid: npm:registry
  name: npm Registry API
  description: The npm Registry API provides programmatic access to the npm package registry, the largest software registry
    in the world hosting over two million JavaScript packages. Developers can query package metadata, download tarballs, search
    for packages, and retrieve version-specific information. The API follows CouchDB-based conventions and serves package
    manifests in JSON format, enabling tools and services to integrate with the npm ecosystem for dependency resolution, package
    discovery, and automated workflows.
  humanURL: https://github.com/npm/registry/blob/main/docs/REGISTRY-API.md
  baseURL: https://registry.npmjs.org
  tags:
  - Packages
  - JavaScript
  - Registry
  - Package Management
  - Node.js
  properties:
  - type: Documentation
    url: https://github.com/npm/registry/blob/main/docs/REGISTRY-API.md
  - type: OpenAPI
    url: openapi/npm-registry-api-openapi.yml
  - type: JSONSchema
    url: json-schema/npm-package-schema.json
- aid: npm:hooks
  name: npm Hooks API
  description: The npm Hooks API allows developers to subscribe to notifications about changes in the npm registry. Hooks
    send HTTP POST payloads to a configured URI whenever a package is changed, enabling developers to build integrations that
    respond to registry events in real time. Users can add hooks to follow specific packages, track all activity of given
    npm users, or monitor all packages within an organization or user scope. The API provides endpoints for creating, listing,
    updating, and deleting hook subscriptions.
  humanURL: https://blog.npmjs.org/post/145260155635/introducing-hooks-get-notifications-of-npm
  tags:
  - Webhooks
  - Notifications
  - Events
  - Automation
  - Packages
  properties:
  - type: Documentation
    url: https://blog.npmjs.org/post/145260155635/introducing-hooks-get-notifications-of-npm
  - type: OpenAPI
    url: openapi/npm-hooks-api-openapi.yml
  - type: AsyncAPI
    url: asyncapi/npm-hooks-asyncapi.yml
  - type: JSONSchema
    url: json-schema/npm-hook-event-schema.json
- aid: npm:cli
  name: npm CLI
  description: The npm CLI is the official command-line interface for the npm package manager, providing developers with tools
    to install, publish, and manage JavaScript packages and their dependencies. It supports package publishing with provenance
    attestation via Sigstore, workspace management for monorepos, script execution, semantic versioning, and comprehensive
    dependency tree management. The CLI is bundled with Node.js and serves as the primary developer interface for interacting
    with the npm registry.
  humanURL: https://docs.npmjs.com/cli
  tags:
  - Command Line
  - Package Management
  - JavaScript
  - Node.js
  - Developer Tools
  properties:
  - type: Documentation
    url: https://docs.npmjs.com/cli
  - type: SourceCode
    url: https://github.com/npm/cli
- aid: npm:provenance
  name: npm Provenance
  description: npm Provenance provides supply chain security for JavaScript packages by establishing a verifiable link between
    a published package and its source code repository and build environment. When a package is published with provenance,
    it is signed using Sigstore public good servers and the attestation is logged in a public transparency ledger. This allows
    developers to verify where and how a package was built before downloading it, helping to protect against supply chain
    attacks and ensuring the integrity of the npm ecosystem.
  humanURL: https://docs.npmjs.com/generating-provenance-statements
  tags:
  - Security
  - Supply Chain
  - Verification
  - Sigstore
  - Transparency
  - CI/CD
  properties:
  - type: Documentation
    url: https://docs.npmjs.com/generating-provenance-statements
  - type: Documentation
    url: https://github.blog/security/supply-chain-security/introducing-npm-package-provenance/
- aid: npm:npm-downloads-api
  name: npm Downloads API
  description: Package tarball downloads.
  humanURL: https://github.com/npm/registry/blob/main/docs/REGISTRY-API.md
  baseURL: https://registry.npmjs.org
  tags:
  - Downloads
  properties:
  - type: OpenAPI
    url: openapi/npm-downloads-api-openapi.yml
  - type: Documentation
    url: https://api-docs.npmjs.com/
- aid: npm:npm-oidc-api
  name: npm OIDC API
  description: OpenID Connect token exchange for trusted publishing. Exchange OIDC identity tokens from supported CI/CD providers
    for short-lived npm registry access tokens.
  humanURL: https://github.com/npm/registry/blob/main/docs/REGISTRY-API.md
  baseURL: https://registry.npmjs.org
  tags:
  - OIDC
  properties:
  - type: OpenAPI
    url: openapi/npm-oidc-api-openapi.yml
  - type: Documentation
    url: https://api-docs.npmjs.com/
- aid: npm:npm-packages-api
  name: npm Packages API
  description: Package metadata retrieval, including full packuments and version-specific documents.
  humanURL: https://github.com/npm/registry/blob/main/docs/REGISTRY-API.md
  baseURL: https://registry.npmjs.org
  tags:
  - Packages
  properties:
  - type: OpenAPI
    url: openapi/npm-packages-api-openapi.yml
  - type: Documentation
    url: https://api-docs.npmjs.com/
- aid: npm:npm-search-api
  name: npm Search API
  description: Full-text search across the npm registry with weighted scoring.
  humanURL: https://github.com/npm/registry/blob/main/docs/REGISTRY-API.md
  baseURL: https://registry.npmjs.org
  tags:
  - Search
  properties:
  - type: OpenAPI
    url: openapi/npm-search-api-openapi.yml
  - type: Documentation
    url: https://api-docs.npmjs.com/
- aid: npm:npm-tokens-api
  name: npm Tokens API
  description: Manage npm access tokens for authentication. Create, list, and delete tokens with customizable permissions
    and restrictions.
  humanURL: https://github.com/npm/registry/blob/main/docs/REGISTRY-API.md
  baseURL: https://registry.npmjs.org
  tags:
  - Tokens
  properties:
  - type: OpenAPI
    url: openapi/npm-tokens-api-openapi.yml
  - type: Documentation
    url: https://api-docs.npmjs.com/
- aid: npm:npm-trusted-publishers-api
  name: npm Trusted Publishers API
  description: Configure trusted publisher settings for packages to enable OIDC token exchange from CI/CD providers without
    long-lived npm tokens.
  humanURL: https://github.com/npm/registry/blob/main/docs/REGISTRY-API.md
  baseURL: https://registry.npmjs.org
  tags:
  - Trusted Publishers
  properties:
  - type: OpenAPI
    url: openapi/npm-trusted-publishers-api-openapi.yml
  - type: Documentation
    url: https://api-docs.npmjs.com/
common:
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/npm/overview
- type: AgenticAccess
  url: agentic-access/npm-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/npm-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/npm-domain-security.yml
- type: Authentication
  url: authentication/npm-authentication.yml
- type: LinkedIn
  url: https://www.linkedin.com/company/npm-inc-
- url: https://www.npmjs.com/
  name: npm Portal
  type: Portal
- url: https://docs.npmjs.com/
  name: npm Documentation
  type: Documentation
- url: https://blog.npmjs.org/
  name: npm Blog
  type: Blog
- url: https://www.npmjs.com/login
  name: Login
  type: Login
- url: https://www.npmjs.com/support
  name: Support
  type: Support
- url: https://docs.npmjs.com/policies/privacy
  name: Privacy Policy
  type: PrivacyPolicy
- url: https://docs.npmjs.com/policies/terms
  name: Terms of Service
  type: TermsOfService
- url: https://www.npmjs.com/
  name: Website
  type: Website
- url: https://github.com/npm
  name: GitHub Organization
  type: GitHubOrg
- url: https://status.npmjs.org/
  name: Status
  type: StatusPage
maintainers:
- FN: API Evangelist
  email: info@apievangelist.com