Set up and troubleshoot npm Trusted Publishing with OIDC in GitHub Actions...
This skill helps configure npm Trusted Publishing using OpenID Connect (OIDC), eliminating the need for 90-day rotating npm tokens in GitHub Actions. Instead, GitHub cryptographically proves the workflow's identity to npm.
ENEEDAUTH or 404 Not Found errors during npm publishGo to your package settings on npmjs.com:
URL: https://www.npmjs.com/package/@YOUR_SCOPE/PACKAGE_NAME/access
| Field | Value | Common Mistakes |
|---|---|---|
| Organization/User | Your GitHub org (e.g., Tasty-Maker-Studio) |
ā lowercase ā different org name |
| Repository | Repository name (e.g., Discourser-Design-System) |
ā lowercase ā wrong repo |
| Workflow | release.yml |
ā release.yml (space before)ā release.yml (space after)ā .github/workflows/release.yml |
| Environment | Leave completely empty | ā typing "blank" ā any text or spaces |
Create .github/workflows/release.yml:
name: Release
on:
push:
branches: [main]
permissions:
contents: write
pull-requests: write
id-token: write # Required for OIDC
jobs:
release:
name: Release
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: pnpm/action-setup@v4
with:
version: 9
- uses: actions/setup-node@v4
with:
node-version: 24
cache: 'pnpm'
# DO NOT set registry-url - conflicts with OIDC
- run: pnpm install --frozen-lockfile
- run: pnpm build
- name: Publish to npm with OIDC
run: npm publish --provenance --access public
env:
# No NPM_TOKEN needed - OIDC handles auth
Key Points:
id-token: write permission is requiredregistry-url in setup-node (creates .npmrc that conflicts)NODE_AUTH_TOKEN environment variable--provenance flag helps npm detect OIDCCheck for files that might interfere:
No npm tokens in GitHub Secrets:
NPM_TOKEN secretNo auth in .npmrc:
.npmrc should only have config, not authentication//registry.npmjs.org/:_authToken= linesCorrect repository URL in package.json:
{
"repository": {
"type": "git",
"url": "https://github.com/YOUR_ORG/YOUR_REPO.git"
}
}
ENEEDAUTH - need authCause: npm cannot authenticate with OIDC
Solutions:
Verify Trusted Publisher is ACTIVE (not just configured)
Check for typos in npm configuration:
Verify OIDC environment: Add debug step to workflow:
- name: Debug OIDC
run: |
npm --version
echo "OIDC URL set: ${{ env.ACTIONS_ID_TOKEN_REQUEST_URL != '' }}"
404 Not Found - PUT https://registry.npmjs.org/@scope/packageCause: npm Trusted Publisher configuration doesn't match running workflow
Solutions:
Configuration mismatch - Verify EXACT match:
release.yml (no path, no spaces)Workflow file renamed:
release.yml to something else, update npm configEnvironment field has value:
jobs:
release:
environment: production # Must match npm config
Access token expired or revokedCause: npm is trying to use token auth instead of OIDC
Solutions:
Remove registry-url from setup-node:
# ā WRONG - creates .npmrc with token
- uses: actions/setup-node@v4
with:
registry-url: 'https://registry.npmjs.org'
# ā
CORRECT - allows OIDC
- uses: actions/setup-node@v4
with:
node-version: 24
cache: 'pnpm'
Delete NPM_TOKEN from GitHub Secrets
Check for .npmrc with auth token in repository
pnpm add -D @changesets/cli @changesets/changelog-github
pnpm changeset init
Configure .changeset/config.json:
{
"changelog": ["@changesets/changelog-github", {
"repo": "YOUR_ORG/YOUR_REPO"
}],
"access": "public",
"baseBranch": "main"
}
- name: Create Release PR or Publish
uses: changesets/action@v1
with:
version: pnpm changeset version
publish: pnpm changeset publish
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# No NPM_TOKEN - using OIDC
1. Make code changes
2. Create a changeset (not a version bump!):
pnpm changeset
# Select: patch | minor | major
# Write summary of changes
3. Commit the changeset file:
git add .changeset/*.md
git commit -m "feat: add new feature"
git push
4. Workflow creates "Version Packages" PR automatically
5. Merge PR ā Auto-publishes to npm via OIDC
ā No token management - No 90-day rotation ā Better security - Short-lived, workflow-specific tokens ā No secrets - Nothing to leak or expose ā Automatic provenance - Cryptographic proof of origin ā Easier onboarding - Team members don't need npm tokens
Before asking for help, verify:
id-token: write permissionregistry-url in setup-nodeNPM_TOKEN in GitHub Secretsrelease.ymlQ: Do I still need npm tokens for local development?
A: Yes, OIDC only works in CI/CD. Local npm publish requires npm login.
Q: Can I use OIDC with private packages? A: Yes, OIDC works with both public and private packages.
Q: Does OIDC work with monorepos? A: Yes, but each package needs its own Trusted Publisher configuration.
Q: Can I have multiple workflows publish the same package? A: Yes, configure multiple Trusted Publishers (one per workflow file).