public-data-apis · prepared

npm registry API boundary

Official-source access, authentication, request-shaping, freshness, legal, and interpretation boundaries for npm registry API.

version 1.0.0freshness currentobserved 2026-08-28T18:03:05Z

resource.public-data.npm-registry-api
sha256:99aaf2b2b29844d4701aa124d21608f30ce6bec85c333cb3f65846acc5163976

Open canonical machine JSON →

Evidence-backed facts

  1. npm, Inc. documents package manifests, versions, distribution metadata, tarballs, tags, access rules, and registry configuration. informative
  2. Public reads are separate from token-protected publish, unpublish, owner, or private-package operations; credentials must remain secret and access does not grant package ownership. informative
  3. Clients must bind registry base URL, scoped package encoding, version or tag, manifest, tarball integrity, authentication, cache, and client configuration. informative
  4. Registry metadata and package presence can change or be publisher-controlled and do not prove author identity, code safety, maintenance, licensing, or compatibility. informative