# libnpmaccess

> programmatic library for `npm access` commands

Latest version **11.0.0** (published 2026-07-08) · ISC license · 0 weekly downloads

## Install

```sh
npm install libnpmaccess
pnpm add libnpmaccess
yarn add libnpmaccess
bun add libnpmaccess
```

## Health

**Score 60/100 (C)** — status: active.

Positive: no vulnerabilities; recently updated; high maintenance score; popular repo.

Warnings: low downloads; no types; no esm support.

## Facts

| | |
|---|---|
| Version | 11.0.0 |
| Published | 2026-07-08 |
| First published | 2018-08-17 |
| Weekly downloads | 0 |
| License | ISC |
| TypeScript types | none |
| Module format | CommonJS |
| Node | ^22.22.2 \|\| ^24.15.0 \|\| >=26.0.0 |
| Dependencies | 2 |
| Unpacked size | 8.4 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 10104 |
| Author | GitHub Inc. |
| Maintainers | saquibkhan, npm-cli-ops, reggi |

## Links

- npm: https://www.npmjs.com/package/libnpmaccess
- Repository: https://github.com/npm/cli
- Homepage: https://npmjs.com/package/libnpmaccess
- Issues: https://github.com/npm/libnpmaccess/issues
- npm.io page: https://npm.io/package/libnpmaccess

## Dependencies (2)

- [npm-package-arg](https://npm.io/package/npm-package-arg.md) ^14.0.0
- [npm-registry-fetch](https://npm.io/package/npm-registry-fetch.md) ^20.0.1

## Recent versions

- 11.0.0 (latest) — 2026-07-08
- 11.0.0-pre.0 (prerelease) — 2026-06-19
- 7.0.3 (backport) — 2024-02-28
- 10.0.3 — 2025-10-08
- 10.0.2 — 2025-09-24
- 10.0.1 — 2025-05-15
- 10.0.0 — 2024-12-16
- 10.0.0-pre.0 — 2024-11-26
- 9.0.0 — 2024-10-03
- 8.0.6 — 2024-05-15
- 8.0.5 — 2024-04-30
- 8.0.4 — 2024-04-25
- 8.0.3 — 2024-04-03
- 8.0.2 — 2023-12-06
- 8.0.1 — 2023-10-03
- … 29 more at https://npm.io/package/libnpmaccess/versions

## README

# libnpmaccess

[![npm version](https://img.shields.io/npm/v/libnpmaccess.svg)](https://npm.im/libnpmaccess)
[![license](https://img.shields.io/npm/l/libnpmaccess.svg)](https://npm.im/libnpmaccess)
[![CI - libnpmaccess](https://github.com/npm/cli/actions/workflows/ci-libnpmaccess.yml/badge.svg)](https://github.com/npm/cli/actions/workflows/ci-libnpmaccess.yml)

[`libnpmaccess`](https://github.com/npm/libnpmaccess) is a Node.js
library that provides programmatic access to the guts of the npm CLI's `npm
access` command. This includes managing account mfa settings, listing
packages and permissions, looking at package collaborators, and defining
package permissions for users, orgs, and teams.

## Example

```javascript
const access = require('libnpmaccess')
const opts = { '//registry.npmjs.org/:_authToken: 'npm_token }

// List all packages @zkat has access to on the npm registry.
console.log(Object.keys(await access.getPackages('zkat', opts)))
```

### API

#### `opts` for all `libnpmaccess` commands

`libnpmaccess` uses [`npm-registry-fetch`](https://npm.im/npm-registry-fetch).

All options are passed through directly to that library, so please refer
to [its own `opts`
documentation](https://www.npmjs.com/package/npm-registry-fetch#fetch-options)
for options that can be passed in.

#### `spec` parameter for all `libnpmaccess` commands

`spec` must be an [`npm-package-arg`](https://npm.im/npm-package-arg)-compatible
registry spec.

#### `access.getCollaborators(spec, opts) -> Promise<Object>`

Gets collaborators for a given package

#### `access.getPackages(user|scope|team, opts) -> Promise<Object>`

Gets all packages for a given user, scope, or team.

Teams should be in the format `scope:team` or `@scope:team`

Users and scopes can be in the format `@scope` or `scope`

#### `access.getVisibility(spec, opts) -> Promise<Object>`

Gets the visibility of a given package

#### `access.removePermissions(team, spec, opts) -> Promise<Boolean>`

Removes the access for a given team to a package.

Teams should be in the format `scope:team` or `@scope:team`

#### `access.setAccess(package, access, opts) -> Promise<Boolean>`

Sets access level for package described by `spec`.

The npm registry accepts the following `access` levels:

- `public`: package is public
- `private`: package is private

The npm registry also only allows scoped packages to have their access
level set.

#### access.setMfa(spec, level, opts) -> Promise<Boolean>`

Sets the publishing mfa requirements for a given package.  Level must be one of the
following:

- `none`: mfa is not required to publish this package.
- `publish`: mfa is required to publish this package, automation tokens
cannot be used to publish.
- `automation`: mfa is required to publish this package, automation tokens
may also be used for publishing from continuous integration workflows.

#### access.setPermissions(team, spec, permissions, opts) -> Promise<Boolean>`

Sets permissions levels for a given team to a package.

Teams should be in the format `scope:team` or `@scope:team`

The npm registry accepts the following `permissions`:

- `read-only`: Read only permissions
- `read-write`: Read and write (aka publish) permissions

---
_Source: https://npm.io/package/libnpmaccess · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
