npm / npm/cli

Where are the trusted publisher settings on npmjs.com?

Open
#8,910 13 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
10.1k
Forks
4.7k
Avg merge
2d 2h
Merged PRs (30d)
19

Description

Good evening,

That's great, you have improved security massively. Thanks for that.
I've read github.blog/changelog/2025-12-09-npm-classic-tokens-revoked-session-based-auth-and-cli-token-management-now-available

But unfortunately, I'm still stuck because I'm unable to add a trusted publisher on npmjs.com.

I've followed your instructions from docs.npmjs.com/trusted-publishers#step-1-add-a-trusted-publisher-on-npmjscom, but still cannot find a Trusted Publisher section under my npm settings:

Image

Perhaps I missed some steps or some more information is missing in the documentation? Thanks

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the linked Trusted Publishers documentation, especially the “Step 1” instructions, and compare them with the npmjs.com settings page shown in the screenshot. Check the issue comments for any explanation of the missing section; done means the documentation accurately identifies where the setting appears or explains the relevant availability requirements.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, nodejs
Domain
authentication, documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.