npm Blocks 2FA-Bypass Tokens from Account and Package Management Actions
As of July 31, npm has restricted granular access tokens (GATs) configured to bypass two-factor authentication from performing account and package management tasks. These tokens can no longer create or delete other tokens, modify maintainer lists, change package access settings, or manage organisation membership without an interactive 2FA challenge. The change is designed to limit the damage from a leaked bypass token, which previously could be used to take over an account entirely. GitHub, which owns npm, recommends teams migrate automated publishing workflows to OIDC-based trusted publishing to eliminate long-lived credentials altogether. The registry has also signalled that bypass-2FA tokens will lose direct publish rights by January 2027, continuing a broader push away from bearer tokens.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in