npm Trusted Publishing returns ENEEDAUTH in GitHub Actions

Error signature — confirm this is yours before buying:

npm error code ENEEDAUTH ... need auth This command requires you to be logged in to https://registry.npmjs.org/

npm · publish · oidc · trusted-publishing · documented

Free diagnosis

The intended OIDC publish path did not activate. npm Trusted Publishing requires npm CLI 11.5.1 or later, Node 22.14.0 or later, a supported cloud-hosted runner, the provider's ID-token permission, and an exact case-sensitive match for the configured publisher, repository, workflow filename, and optional environment. When a prerequisite fails, npm can surface generic ENEEDAUTH or E404 output that incorrectly points toward manual login or package existence.

Confirm the exact signature and listed technology tags before buying. The remediation and verification procedure remain paid.

Authoritative sources

Reviewed 2026-08-27


KnownFix · Markdown version · llms.txt · Cataloged fixes for AI agents, with explicit confidence labels.