# @verdaccio/auth

> Verdaccio Authentication

Latest version **8.1.3** (published 2026-08-26) · MIT license · 0 weekly downloads

## Install

```sh
npm install @verdaccio/auth
pnpm add @verdaccio/auth
yarn add @verdaccio/auth
bun add @verdaccio/auth
```

## Health

**Score 80/100 (A)** — status: active.

Positive: has types; esm support; no vulnerabilities; has provenance; recently updated; high maintenance score; high quality score; popular repo.

Warnings: low downloads.

## Facts

| | |
|---|---|
| Version | 8.1.3 |
| Published | 2026-08-26 |
| First published | 2021-09-03 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | ESM + CommonJS |
| Node | >=22 |
| Dependencies | 7 |
| Unpacked size | 162.4 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Provenance | attested (GitHub Actions) |
| GitHub stars | 17880 |
| Author | Juan Picado |
| Maintainers | sergiohgz, verdaccio.npm, jotadeveloper, verdacciopack |
| Keywords | enterprise, modules, package, private, proxy, registry, repository, server, verdaccio |

## Links

- npm: https://www.npmjs.com/package/@verdaccio/auth
- Repository: https://github.com/verdaccio/verdaccio
- Homepage: https://verdaccio.org
- Issues: https://github.com/verdaccio/verdaccio/issues
- Funding: https://opencollective.com/verdaccio
- npm.io page: https://npm.io/package/@verdaccio/auth

## Dependencies (7)

- [debug](https://npm.io/package/debug.md) 4.4.3
- [lodash](https://npm.io/package/lodash.md) 4.18.1
- [@verdaccio/core](https://npm.io/package/@verdaccio/core.md) 8.3.0
- [@verdaccio/config](https://npm.io/package/@verdaccio/config.md) 8.3.0
- [@verdaccio/loaders](https://npm.io/package/@verdaccio/loaders.md) 8.1.3
- [verdaccio-htpasswd](https://npm.io/package/verdaccio-htpasswd.md) 13.1.3
- [@verdaccio/signature](https://npm.io/package/@verdaccio/signature.md) 8.1.3

## Recent versions

- 8.1.3 (latest) — 2026-08-26
- 9.0.0-next-9.31 (next-9) — 2026-09-04
- 8.0.0-next-8.38 (next-8) — 2026-04-12
- 7.0.0-next-7.20 (next-7) — 2024-08-01
- 7.0.0-next.6 (next) — 2024-01-07
- 6.0.0-6-next.9 (6-next) — 2021-09-03
- 9.0.0-next-9.30 — 2026-08-30
- 9.0.0-next-9.29 — 2026-08-30
- 9.0.0-next-9.28 — 2026-08-26
- 9.0.0-next-9.27 — 2026-08-20
- 9.0.0-next-9.26 — 2026-08-17
- 8.1.2 — 2026-08-17
- 9.0.0-next-9.25 — 2026-08-16
- 9.0.0-next-9.24 — 2026-08-02
- 9.0.0-next-9.23 — 2026-08-02
- … 135 more at https://npm.io/package/@verdaccio/auth/versions

## README

# @verdaccio/auth - Verdaccio Authentication

[![Verdaccio Home](https://img.shields.io/badge/Homepage-Verdaccio-405236?style=flat)](https://verdaccio.org)
[![MIT License](https://img.shields.io/github/license/verdaccio/verdaccio?label=License&color=405236)](https://github.com/verdaccio/verdaccio/blob/master/LICENSE)
[![Verdaccio Latest](https://img.shields.io/npm/v/verdaccio?label=Latest%20Version&color=405236)](https://github.com/verdaccio/verdaccio)
[![This Package Latest](https://img.shields.io/npm/v/@verdaccio/auth?label=@verdaccio/auth&color=405236)](https://npmjs.com/package/@verdaccio/auth)

[![Documentation](https://img.shields.io/badge/Help-Verdaccio?style=flat&logo=Verdaccio&label=Verdaccio&color=cd4000)](https://verdaccio.org/docs)
[![Discord](https://img.shields.io/badge/Chat-Discord?style=flat&logo=Discord&label=Discord&color=cd4000)](https://discord.com/channels/388674437219745793)
[![Bluesky](https://img.shields.io/badge/Follow-Bluesky?style=flat&logo=Bluesky&label=Bluesky&color=cd4000)](https://bsky.app/profile/verdaccio.org)
[![Backers](https://img.shields.io/opencollective/backers/verdaccio?style=flat&logo=opencollective&label=Join%20Backers&color=cd4000)](https://opencollective.com/verdaccio/contribute)
[![Sponsors](https://img.shields.io/opencollective/sponsors/verdaccio?style=flat&logo=opencollective&label=Sponsor%20Us&color=cd4000)](https://opencollective.com/verdaccio/contribute)

[![Verdaccio Downloads](https://img.shields.io/npm/dm/verdaccio?style=flat&logo=npm&label=Npm%20Downloads&color=lightgrey)](https://www.npmjs.com/package/verdaccio)
[![Docker Pulls](https://img.shields.io/docker/pulls/verdaccio/verdaccio?style=flat&logo=docker&label=Docker%20Pulls&color=lightgrey)](https://hub.docker.com/r/verdaccio/verdaccio)
[![GitHub Stars](https://img.shields.io/github/stars/verdaccio?style=flat&logo=github&label=GitHub%20Stars%20%E2%AD%90&color=lightgrey)](https://github.com/verdaccio/verdaccio/stargazers)

> **Note:** This package is mostly for internal use by Verdaccio and is only intended to be used with Verdaccio 6.x.

## Overview

The `@verdaccio/auth` package provides the authentication layer for Verdaccio. It handles plugin loading, user authentication, JWT and legacy AES token management, and package-level access control (access, publish, unpublish).

## Installation

```bash
npm install @verdaccio/auth
```

## Usage

```typescript
import { Auth } from '@verdaccio/auth';
```

The `Auth` class manages:

- **Plugin Loading** - Dynamically loads authentication plugins (defaults to `verdaccio-htpasswd`)
- **User Authentication** - Validates user credentials through configured auth plugins
- **Token Management** - Supports both JWT and legacy AES token encryption/decryption
- **Access Control** - Authorizes package access, publish, and unpublish operations
- **Middleware** - Generates API and Web UI JWT middleware for Express

## Donations

Verdaccio is run by **volunteers**; nobody is working full-time on it. If you find this project to be useful and would like to support its development, consider making a donation - **your logo might end up in this readme.** 😉

**[Donate](https://opencollective.com/verdaccio)** 💵👍🏻 starting from _\$1/month_ or just one single contribution.

## Report a vulnerability

If you want to report a security vulnerability, please follow the steps which we have defined for you in our [security policy](https://github.com/verdaccio/verdaccio/security/policy).

## Open Collective Sponsors

Support this project by becoming a sponsor. Your logo will show up here with a link to your website. [[Become a sponsor](https://opencollective.com/verdaccio/contribute)]

[![sponsor](https://opencollective.com/verdaccio/sponsor/0/avatar.svg)](https://opencollective.com/verdaccio/sponsor/0/website)
[![sponsor](https://opencollective.com/verdaccio/sponsor/1/avatar.svg)](https://opencollective.com/verdaccio/sponsor/1/website)
[![sponsor](https://opencollective.com/verdaccio/sponsor/2/avatar.svg)](https://opencollective.com/verdaccio/sponsor/2/website)
[![sponsor](https://opencollective.com/verdaccio/sponsor/3/avatar.svg)](https://opencollective.com/verdaccio/sponsor/3/website)
[![sponsor](https://opencollective.com/verdaccio/sponsor/4/avatar.svg)](https://opencollective.com/verdaccio/sponsor/4/website)
[![sponsor](https://opencollective.com/verdaccio/sponsor/5/avatar.svg)](https://opencollective.com/verdaccio/sponsor/5/website)
[![sponsor](https://opencollective.com/verdaccio/sponsor/6/avatar.svg)](https://opencollective.com/verdaccio/sponsor/6/website)
[![sponsor](https://opencollective.com/verdaccio/sponsor/7/avatar.svg)](https://opencollective.com/verdaccio/sponsor/7/website)
[![sponsor](https://opencollective.com/verdaccio/sponsor/8/avatar.svg)](https://opencollective.com/verdaccio/sponsor/8/website)
[![sponsor](https://opencollective.com/verdaccio/sponsor/9/avatar.svg)](https://opencollective.com/verdaccio/sponsor/9/website)

## Open Collective Backers

Thank you to all our backers! 🙏 [[Become a backer](https://opencollective.com/verdaccio/contribute)]

[![backers](https://opencollective.com/verdaccio/backers.svg?width=890)](https://opencollective.com/verdaccio/contributes)

## Special Thanks

Thanks to the following companies to help us to achieve our goals providing free open source licenses.

[![jetbrains](https://github.com/verdaccio/verdaccio/blob/master/assets/thanks/jetbrains/logo.jpg?raw=true)](https://www.jetbrains.com/)
[![crowdin](https://github.com/verdaccio/verdaccio/blob/master/assets/thanks/crowdin/logo.png?raw=true)](https://crowdin.com/)

## Contributors

This project exists thanks to all the people who contribute. [[Contribute](https://github.com/verdaccio/verdaccio/blob/master/CONTRIBUTING.md)].

[![contributors](https://opencollective.com/verdaccio/contributors.svg?width=890&button=true)](https://github.com/verdaccio/verdaccio/graphs/contributors)

## FAQ / Contact / Troubleshoot

If you have any issue you can try the following options. Do not hesitate to ask or check our issues database. Perhaps someone has asked already what you are looking for.

- [Blog](https://verdaccio.org/blog/)
- [Donations](https://opencollective.com/verdaccio)
- [Reporting an issue](https://github.com/verdaccio/verdaccio/blob/master/CONTRIBUTING.md#reporting-a-bug)
- [Running discussions](https://github.com/orgs/verdaccio/discussions)
- [Chat](https://discord.com/channels/388674437219745793)
- [Logos](https://verdaccio.org/docs/logo)
- [Docker Examples](https://github.com/verdaccio/verdaccio/tree/master/docker-examples)
- [FAQ](https://github.com/verdaccio/verdaccio/issues?utf8=%E2%9C%93&q=is%3Aissue%20label%3Aquestion%20)

## License

Verdaccio is [MIT licensed](https://github.com/verdaccio/verdaccio/blob/master/LICENSE)

The Verdaccio documentation and logos (excluding /thanks, e.g., .md, .png, .sketch files within the /assets folder) are
[Creative Commons licensed](https://creativecommons.org/licenses/by/4.0/).

---
_Source: https://npm.io/package/@verdaccio/auth · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
