Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

npm OIDC API

OpenID Connect token exchange for trusted publishing. Exchange OIDC identity tokens from supported CI/CD providers for short-lived npm registry access tokens.

npm OIDC API is one of 10 APIs that npm publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include OIDC. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.

This API exposes 1 operation across 1 path, and defines 1 schema. It is described by OpenAPI 3.1.0, at version 1.0.0.

Requests are made against a single base URL, https://registry.npmjs.org.

1 operations 1 paths 1 schemas 1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
1.0.0
Base URL
https://registry.npmjs.org
Authentication
HTTP Bearer
Terms of Service
Resource Areas
1

Authentication & Security 1

npm OIDC API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (bearerAuth). By default, every request must be authenticated.

  • bearerAuth — npm access token provided as a Bearer token.

Paths & Operations 1

Across 1 path, the API surfaces 1 operation — 1 POST. Each is listed below with its method, path, parameters, and response codes.

OIDC 1

OpenID Connect token exchange for trusted publishing. Exchange OIDC identity tokens from supported CI/CD providers for short-lived npm registry access tokens.

POST
/-/npm/v1/security/oidc/tokens
Exchange an OIDC token for an npm token
exchangeOidcToken body → 200401403

Schemas 1

The contract defines 1 schema that model the data the API accepts and returns. The most detailed is Error (2 properties). Each schema is shown below with its type and property counts.

Error
object
An error response from the npm API.
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

npm-oidc-api-openapi.yml Raw ↑

Other APIs npm publishes across the network.

npm Registry API
npm Hooks API
npm Provenance
npm Downloads API
npm Packages API
npm Search API
npm Tokens API
npm Trusted Publishers API