1 ---
2 title: npm-publish
3 section: 1
4 description: Publish a package
5 github_repo: npm/cli
6 github_branch: latest
7 github_path: docs/lib/content/commands/npm-publish.md
8 redirect_from:
9 - /cli-commands/npm-publish
10 - /cli-commands/publish
11 - /cli-documentation/cli-commands/npm-publish
12 - /cli-documentation/cli-commands/publish
13 - /cli-documentation/commands/npm-publish
14 - /cli-documentation/commands/publish
15 - /cli-documentation/npm-publish
16 - /cli-documentation/publish
17 - /cli-documentation/v11/cli-commands/npm-publish
18 - /cli-documentation/v11/cli-commands/publish
19 - /cli-documentation/v11/commands/npm-publish
20 - /cli-documentation/v11/commands/publish
21 - /cli-documentation/v11/npm-publish
22 - /cli-documentation/v11/publish
23 - /cli/cli-commands/npm-publish
24 - /cli/cli-commands/publish
25 - /cli/commands/npm-publish
26 - /cli/commands/publish
27 - /cli/npm-publish
28 - /cli/publish
29 - /cli/v11/cli-commands/npm-publish
30 - /cli/v11/cli-commands/publish
31 - /cli/v11/commands/publish
32 - /cli/v11/npm-publish
33 - /cli/v11/publish
34 - /commands/npm-publish
35 - /commands/publish
36 ---
37
38 ### Synopsis
39
40 ```bash
41 npm publish <package-spec>
42 ```
43
44 ### Description
45
46 Publishes a package to the registry so that it can be installed by name.
47
48 ### Examples
49
50 Publish the package in the current directory:
51
52 ```bash
53 npm publish
54 ```
55
56 Publish a specific workspace:
57
58 ```bash
59 npm publish --workspace=<workspace-name>
60 ```
61
62 Publish multiple workspaces:
63
64 ```bash
65 npm publish --workspace=workspace-a --workspace=workspace-b
66 ```
67
68 Publish all workspaces:
69
70 ```bash
71 npm publish --workspaces
72 ```
73
74 By default npm will publish to the public registry. This can be overridden by specifying a different default registry or using a [`scope`](/cli/v11/using-npm/scope) in the name, combined with a scope-configured registry (see [`package.json`](/cli/v11/configuring-npm/package-json)).
75
76 A `package` is interpreted the same way as other commands (like `npm install`) and can be:
77
78 - a) a folder containing a program described by a [`package.json`](/cli/v11/configuring-npm/package-json) file
79 - b) a gzipped tarball containing (a)
80 - c) a url that resolves to (b)
81 - d) a `<name>@<version>` that is published on the registry (see [`registry`](/cli/v11/using-npm/registry)) with (c)
82 - e) a `<name>@<tag>` (see [`npm dist-tag`](/cli/v11/commands/npm-dist-tag)) that points to (d)
83 - f) a `<name>` that has a "latest" tag satisfying (e)
84 - g) a `<git remote url>` that resolves to (a)
85
86 If either (a) or (b) is specified as a relative path, it should begin with an explicit `./` prefix.
87
88 The publish will fail if the package name and version combination already exists in the specified registry.
89
90 Once a package is published with a given name and version, that specific name and version combination can never be used again, even if it is removed with [`npm unpublish`](/cli/v11/commands/npm-unpublish).
91
92 As of `npm@5`, both a sha1sum and an integrity field with a sha512sum of the tarball will be submitted to the registry during publication. Subsequent installs will use the strongest supported algorithm to verify downloads.
93
94 Similar to `--dry-run` see [`npm pack`](/cli/v11/commands/npm-pack), which figures out the files to be included and packs them into a tarball to be uploaded to the registry.
95
96 ### Files included in package
97
98 To see what will be included in your package, run `npm pack --dry-run`. All files are included by default, with the following exceptions:
99
100 - Certain files that are relevant to package installation and distribution are always included. For example, `package.json`, `README.md`, `LICENSE`, and so on.
101
102 - If there is a "files" list in [`package.json`](/cli/v11/configuring-npm/package-json), then only the files specified will be included. (If directories are specified, then they will be walked recursively and their contents included, subject to the same ignore rules.)
103
104 - If there is a `.gitignore` or `.npmignore` file, then ignored files in that and all child directories will be excluded from the package. If _both_ files exist, then the `.gitignore` is ignored, and only the `.npmignore` is used.
105
106 `.npmignore` files follow the [same pattern rules](https://git-scm.com/book/en/v2/Git-Basics-Recording-Changes-to-the-Repository#_ignoring) as `.gitignore` files
107
108 - If the file matches certain patterns, then it will _never_ be included, unless explicitly added to the `"files"` list in `package.json`, or un-ignored with a `!` rule in a `.npmignore` or `.gitignore` file.
109
110 - Symbolic links are never included in npm packages.
111
112 See [`developers`](/cli/v11/using-npm/developers) for full details on what's included in the published package, as well as details on how the package is built.
113
114 See [`package.json`](/cli/v11/configuring-npm/package-json) for more info on what can and can't be ignored.
115
116 ### Configuration
117
118 #### `tag`
119
120 - Default: "latest"
121 - Type: String
122
123 If you ask npm to install a package and don't tell it a specific version, then it will install the specified tag.
124
125 It is the tag added to the package@version specified in the `npm dist-tag add` command, if no explicit tag is given.
126
127 When used by the `npm diff` command, this is the tag used to fetch the tarball that will be compared with the local files by default.
128
129 If used in the `npm publish` command, this is the tag that will be added to the package submitted to the registry.
130
131 #### `access`
132
133 - Default: 'public' for new packages, existing packages it will not change the current level
134 - Type: null, "restricted", or "public"
135
136 If you do not want your scoped package to be publicly viewable (and installable) set `--access=restricted`.
137
138 Unscoped packages cannot be set to `restricted`.
139
140 Note: This defaults to not changing the current access level for existing packages. Specifying a value of `restricted` or `public` during publish will change the access for an existing package the same way that `npm access set status` would.
141
142 #### `dry-run`
143
144 - Default: false
145 - Type: Boolean
146
147 Indicates that you don't want npm to make any changes and that it should only report what it would have done. This can be passed into any of the commands that modify your local installation, eg, `install`, `update`, `dedupe`, `uninstall`, as well as `pack` and `publish`.
148
149 Note: This is NOT honored by other network related commands, eg `dist-tags`, `owner`, etc.
150
151 #### `otp`
152
153 - Default: null
154 - Type: null or String
155
156 This is a one-time password from a two-factor authenticator. It's needed when publishing or changing package permissions with `npm access`.
157
158 If not set, and a registry response fails with a challenge for a one-time password, npm will prompt on the command line for one.
159
160 #### `workspace`
161
162 - Default:
163 - Type: String (can be set multiple times)
164
165 Enable running a command in the context of the configured workspaces of the current project while filtering by running only the workspaces defined by this configuration option.
166
167 Valid values for the `workspace` config are either:
168
169 - Workspace names
170 - Path to a workspace directory
171 - Path to a parent workspace directory (will result in selecting all workspaces within that folder)
172
173 When set for the `npm init` command, this may be set to the folder of a workspace which does not yet exist, to create the folder and set it up as a brand new workspace within the project.
174
175 This value is not exported to the environment for child processes.
176
177 #### `workspaces`
178
179 - Default: null
180 - Type: null or Boolean
181
182 Set to true to run the command in the context of **all** configured workspaces.
183
184 Explicitly setting this to false will cause commands like `install` to ignore workspaces altogether. When not set explicitly:
185
186 - Commands that operate on the `node_modules` tree (install, update, etc.) will link workspaces into the `node_modules` folder. - Commands that do other things (test, exec, publish, etc.) will operate on the root project, _unless_ one or more workspaces are specified in the `workspace` config.
187
188 This value is not exported to the environment for child processes.
189
190 #### `include-workspace-root`
191
192 - Default: false
193 - Type: Boolean
194
195 Include the workspace root when workspaces are enabled for a command.
196
197 When false, specifying individual workspaces via the `workspace` config, or all workspaces via the `workspaces` flag, will cause npm to operate only on the specified workspaces, and not on the root project.
198
199 This value is not exported to the environment for child processes.
200
201 #### `provenance`
202
203 - Default: false
204 - Type: Boolean
205
206 When publishing from a supported cloud CI/CD system, the package will be publicly linked to where it was built and published from.
207
208 This config cannot be used with: `provenance-file`
209
210 #### `provenance-file`
211
212 - Default: null
213 - Type: Path
214
215 When publishing, the provenance bundle at the given path will be used.
216
217 This config cannot be used with: `provenance`
218
219 ### See Also
220
221 - [package spec](/cli/v11/using-npm/package-spec)
222 - [npm-packlist package](http://npm.im/npm-packlist)
223 - [npm registry](/cli/v11/using-npm/registry)
224 - [npm scope](/cli/v11/using-npm/scope)
225 - [npm adduser](/cli/v11/commands/npm-adduser)
226 - [npm owner](/cli/v11/commands/npm-owner)
227 - [npm deprecate](/cli/v11/commands/npm-deprecate)
228 - [npm dist-tag](/cli/v11/commands/npm-dist-tag)
229 - [npm pack](/cli/v11/commands/npm-pack)
230 - [npm profile](/cli/v11/commands/npm-profile)