npm error code ENEEDAUTH with trusted publishingnpm error code ENEEDAUTH
npm error need auth This command requires you to be logged in to https://registry.npmjs.org/
In a GitHub Actions release that uses trusted publishing, this means npm didn’t get or didn’t use an OIDC token. Check these in order:
id-token: write. The publishing job needs it:
permissions:
contents: read
id-token: write
A job-level permissions block replaces the workflow-level one, so add id-token: write where the publish job is.
- run: npm install -g npm@^12 before publishing. pnpm 10 calls npm for the publish, so the same applies.release.yml. It’s case-sensitive, includes the extension, and must be the calling workflow when you use workflow_call.npx go-tokenless
go-tokenless reads your workflows and lists exactly what’s missing: the permission, the npm version, registry-url, leftover tokens and repository.url. npx go-tokenless apply fixes them.