
From January 2027, a granular npm token that bypasses 2FA can no longer publish on its own (npm docs). The replacement for CI is trusted publishing: GitHub signs a short-lived OIDC token for the workflow run, npm exchanges it for a publish token, and no secret is stored anywhere.
npx go-tokenless # preview: lists every change and shows a diff, writes nothing
npx go-tokenless apply # makes the changes and prints the npm trust commands
go-tokenless (MIT) edits only the lines that need changing. It refuses unsafe cases instead of guessing:
pull_request_target or issue_commentrepository pointing at another repopermissions: id-token: write.npm install -g npm@^12 first.NODE_AUTH_TOKEN / NPM_TOKEN reaches the publish step. npm falls back to a configured token.actions/setup-node has registry-url: https://registry.npmjs.org.package.json repository.url names this GitHub repo.npm trust github <pkg> --repo OWNER/REPO --file release.yml --allow-publish --yesnpm error code ENEEDAUTHnpm error 404 Not Found - PUT https://registry.npmjs.org/...npm error code E422 … repository.urlNPM_TOKEN after the migrationnpm notice npm tokens that bypass 2FA are being restrictedclaude mcp add go-tokenless -- npx -y go-tokenless mcp
It’s also a Claude Code plugin, a Gemini CLI extension and an Agent Skill. See the README.