Replies: 3 comments 3 replies
|
This is a security feature called step-up authentication. Your initial login saves a session token locally, but npm requires 2FA again when publishing so that if your local .npmrc token ever gets stolen by malware, an attacker still can't push code without your phone.If you want to eliminate that second prompt, the quickest fix is to tweak your npm account settings: |
|
This is definitely a frustrating UX! Since this is a feature request, hopefully the maintainers streamline this in the future. In the meantime, the standard workaround to avoid double-2FA prompts in the CLI is to use a Personal Access Token (PAT) or an Automation Token instead of an interactive web login. If publishing to GitHub Packages: Generate a PAT (Classic with write:packages scope, or a Fine-grained token) and use that as your password when running npm login (or your respective package manager). Since the token itself acts as the secure credential, it bypasses the interactive 2FA prompt during publish. It doesn't fix the underlying interactive UX, but it will save you from pulling out your authenticator app twice! |
|
You are right to distinguish npm publishing from GitHub Packages. A GitHub PAT is not a credential for publishing to registry.npmjs.org, and the earlier suggestion to create a legacy npm “Automation Token” is outdated: npm’s current documentation says legacy tokens were removed in November 2025. The current publishing requirements are documented here: https://docs.npmjs.com/requiring-2fa-for-package-publishing-and-settings-modification/ — interactive publishing can require its own 2FA challenge, so being logged into the browser does not establish that the publish operation is already authorized. Changing an account-level setting should not be presented as a guaranteed way to remove that requirement. For an automated release workflow, npm trusted publishing uses OIDC rather than a long-lived publishing token: https://docs.npmjs.com/trusted-publishers/ . That is an alternative workflow, not a fix for your local CLI login/publish UX request. For local interactive publishing, your request to reuse a recently completed verification remains a valid product-feedback point; I would not weaken 2FA solely to work around it. |
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Product Feedback
Body
When you publish a package from the CLI, you always need to log in first, which requires 2FA, and then when you want to publish, you need to authenticate again.
It would be nice if the second authentication recognized that you already authenticated yourself.
This is only for the 2nd factor since I'm already logged in the browser.
All reactions