@verdaccio/auth - Verdaccio Authentication
Note: This package is mostly for internal use by Verdaccio and is only intended to be used with Verdaccio 6.x.
Overview
The @verdaccio/auth package provides the authentication layer for Verdaccio. It handles plugin loading, user authentication, JWT and legacy AES token management, and package-level access control (access, publish, unpublish).
Installation
npm install @verdaccio/auth
Usage
import { Auth } from '@verdaccio/auth';
The Auth class manages:
- Plugin Loading - Dynamically loads authentication plugins (defaults to
verdaccio-htpasswd) - User Authentication - Validates user credentials through configured auth plugins
- Token Management - Supports both JWT and legacy AES token encryption/decryption
- Access Control - Authorizes package access, publish, and unpublish operations
- Middleware - Generates API and Web UI JWT middleware for Express
Donations
Verdaccio is run by volunteers; nobody is working full-time on it. If you find this project to be useful and would like to support its development, consider making a donation - your logo might end up in this readme.
Donate starting from $1/month or just one single contribution.
Report a vulnerability
If you want to report a security vulnerability, please follow the steps which we have defined for you in our security policy.
Open Collective Sponsors
Support this project by becoming a sponsor. Your logo will show up here with a link to your website. [Become a sponsor]
Open Collective Backers
Thank you to all our backers! [Become a backer]
Special Thanks
Thanks to the following companies to help us to achieve our goals providing free open source licenses.
Contributors
This project exists thanks to all the people who contribute. [Contribute].
FAQ / Contact / Troubleshoot
If you have any issue you can try the following options. Do not hesitate to ask or check our issues database. Perhaps someone has asked already what you are looking for.
License
Verdaccio is MIT licensed
The Verdaccio documentation and logos (excluding /thanks, e.g., .md, .png, .sketch files within the /assets folder) are Creative Commons licensed.

