go-tokenless

go-tokenless

Migrate npm publishing to trusted publishing (OIDC)

From January 2027, a granular npm token that bypasses 2FA can no longer publish on its own (npm docs). The replacement for CI is trusted publishing: GitHub signs a short-lived OIDC token for the workflow run, npm exchanges it for a publish token, and no secret is stored anywhere.

Do it in one command

npx go-tokenless          # preview: lists every change and shows a diff, writes nothing
npx go-tokenless apply    # makes the changes and prints the npm trust commands

go-tokenless (MIT) edits only the lines that need changing. It refuses unsafe cases instead of guessing:

The checklist it applies

  1. OIDC permission: the publishing job has permissions: id-token: write.
  2. npm version: npm 11.5.1 or newer runs the publish. Node 24 ships it; on Node 22, add npm install -g npm@^12 first.
  3. No token: no NODE_AUTH_TOKEN / NPM_TOKEN reaches the publish step. npm falls back to a configured token.
  4. Registry: actions/setup-node has registry-url: https://registry.npmjs.org.
  5. Repository field: package.json repository.url names this GitHub repo.
  6. Trusted publisher: one exists on npm for each package, naming the exact workflow file: npm trust github <pkg> --repo OWNER/REPO --file release.yml --allow-publish --yes
  7. Old secret: deleted after the first tokenless release.

Fix a failing publish

Use it from an AI coding agent

claude mcp add go-tokenless -- npx -y go-tokenless mcp

It’s also a Claude Code plugin, a Gemini CLI extension and an Agent Skill. See the README.