npm Trusted Publishers API
Configure trusted publisher settings for packages to enable OIDC token exchange from CI/CD providers without long-lived npm tokens.
npm Trusted Publishers API is one of 10 APIs that npm publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Trusted Publishers. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.
This API exposes 3 operations across 2 paths, and defines 3 schemas. It is described by OpenAPI 3.1.0, at version 1.0.0.
Requests are made against a single base URL, https://registry.npmjs.org.
Metadata
The identity and technical contract details declared by the specification.
Authentication & Security 1
npm Trusted Publishers API declares
1 security scheme
for authenticating requests.
It accepts HTTP bearer tokens (bearerAuth).
By default, every request must be authenticated.
bearerAuth— npm access token provided as a Bearer token.
Paths & Operations 3
Across 2 paths, the API surfaces 3 operations — 1 DELETE, 1 GET, 1 POST. Each is listed below with its method, path, parameters, and response codes.
Configure trusted publisher settings for packages to enable OIDC token exchange from CI/CD providers without long-lived npm tokens.
Schemas 3
The contract defines 3 schemas that model the data the API accepts and returns. The most detailed are TrustedPublisher (7 properties), TrustedPublisherRequest (5 properties), Error (2 properties). Each schema is shown below with its type and property counts.
Specification
The full machine-readable OpenAPI contract behind this narrative.
Source
More from npm 9
Other APIs npm publishes across the network.