canonical: https://jentic.com/apis/registry.npmjs.org/registry-npmjs

# Registry Npmjs npm Registry API

The npm public registry API. Provides endpoints for package publishing, retrieval, searching, user management, organization management, token management, and dist-tag operations. The API exposes 20 endpoints secured with bearer authentication.

## For AI agents

Programmatically get package metadata (packument), publish a package. Covers 20 operations with bearer authentication.

## Scope

Does not handle payments, communications, or crm - use for developer tools only.

## Capabilities

- Get package metadata (packument)
- Publish a package
- Search packages
- Unpublish a package version
- Download package tarball
- Update user profile

## Use cases

### Developer Tools Operations

Use the npm Registry API to perform developer tools operations programmatically. The API provides 20 endpoints covering core functionality including get package metadata (packument), publish a package, get specific package version.

Example prompt: Call GET /{package} to get package metadata (packument)

### Automated Package Management

Automate package operations by combining multiple npm Registry API endpoints. Agents can publish a package and then get specific package version in a single workflow.

Example prompt: Call PUT /{package} to publish a package, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call npm Registry API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle bearer tokens manually.

Example prompt: Search Jentic for 'get package metadata (packument)', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| GET | /{package} | Get package metadata (packument) |
| PUT | /{package} | Publish a package |
| GET | /{package}/{version} | Get specific package version |
| GET | /-/v1/search | Search packages |
| DELETE | /{package}/-/{tarball}/{revision} | Unpublish a package version |
| GET | /{package}/-/{tarball} | Download package tarball |
| POST | /-/npm/v1/user | Update user profile |
| GET | /-/npm/v1/user | Get user profile |

## Key resources

- **Package** — Package metadata retrieval, publishing, and unpublishing
- **Search** — Package search
- **DistTags** — Distribution tag management
- **Download** — Tarball downloads
- **User** — User profile and authentication

## Why Jentic

- **Setup:** Wiring the npm Registry API by hand means setting its bearer token on every call and building your own retry handling against the registry.npmjs.org host. Through Jentic you install once, import the npm Registry API from the API Directory, store the token once, and your agent calls it.
- **Permission scoping:** The npm Registry API puts the package name and version in the URL path (/{package}/{version} and /{package}/-/{tarball}), so a rule can pin your agent to one package: it can read that package's metadata and versions and nothing else. You choose the operations it may call, so destructive ones like publishing a package or deleting a tarball revision are not included unless you add them.
- **Credential handling:** Your npm Registry API bearer token is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'get package metadata' or 'search for packages', and Jentic returns the matching npm Registry API operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Github** — Alternative developer tools API
- **Gitlab** — Alternative developer tools API

## FAQ

### What authentication does the npm Registry API use?

The npm Registry API uses a Bearer token in the Authorization header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I get package metadata (packument) with the npm Registry API?

Yes. Use the GET /{package} endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the npm Registry API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I get package metadata (packument) through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'get package metadata (packument)'. Jentic returns the matching npm Registry API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the npm Registry API have?

The npm Registry API exposes 20 endpoints covering package, search, disttags operations.

### Can I limit what my agent is allowed to do with the npm Registry API?

Yes. Jentic One is self-hosted by you, so your own rules decide which npm Registry operations and credentials the agent may use. Because the package name and version sit in the URL path, such as GET /{package} and GET /{package}/{version}, you can pin the agent to a single package so it only reads that package's metadata and versions. You choose the operations it may call, so destructive ones like PUT /{package} to publish a package or DELETE /{package}/-/{tarball}/{revision} to remove a version stay off unless you add them.
