1 ---
2 title: npm-publish
3 section: 1
4 description: Publish a package
5 github_repo: npm/cli
6 github_branch: release/v8
7 github_path: docs/lib/content/commands/npm-publish.md
8 redirect_from:
9 - /cli-documentation/v8/cli-commands/npm-publish
10 - /cli-documentation/v8/cli-commands/publish
11 - /cli-documentation/v8/commands/npm-publish
12 - /cli-documentation/v8/commands/publish
13 - /cli-documentation/v8/npm-publish
14 - /cli-documentation/v8/publish
15 - /cli/v8/cli-commands/npm-publish
16 - /cli/v8/cli-commands/publish
17 - /cli/v8/commands/publish
18 - /cli/v8/npm-publish
19 - /cli/v8/publish
20 ---
21
22 ### Synopsis
23
24 ```bash
25 npm publish <package-spec>
26 ```
27
28 ### Description
29
30 Publishes a package to the registry so that it can be installed by name.
31
32 By default npm will publish to the public registry. This can be overridden by specifying a different default registry or using a [`scope`](/cli/v8/using-npm/scope) in the name, combined with a scope-configured registry (see [`package.json`](/cli/v8/configuring-npm/package-json)).
33
34 A `package` is interpreted the same way as other commands (like `npm install` and can be:
35
36 - a) a folder containing a program described by a [`package.json`](/cli/v8/configuring-npm/package-json) file
37 - b) a gzipped tarball containing (a)
38 - c) a url that resolves to (b)
39 - d) a `<name>@<version>` that is published on the registry (see [`registry`](/cli/v8/using-npm/registry)) with (c)
40 - e) a `<name>@<tag>` (see [`npm dist-tag`](/cli/v8/commands/npm-dist-tag)) that points to (d)
41 - f) a `<name>` that has a "latest" tag satisfying (e)
42 - g) a `<git remote url>` that resolves to (a)
43
44 The publish will fail if the package name and version combination already exists in the specified registry.
45
46 Once a package is published with a given name and version, that specific name and version combination can never be used again, even if it is removed with [`npm unpublish`](/cli/v8/commands/npm-unpublish).
47
48 As of `npm@5`, both a sha1sum and an integrity field with a sha512sum of the tarball will be submitted to the registry during publication. Subsequent installs will use the strongest supported algorithm to verify downloads.
49
50 Similar to `--dry-run` see [`npm pack`](/cli/v8/commands/npm-pack), which figures out the files to be included and packs them into a tarball to be uploaded to the registry.
51
52 ### Files included in package
53
54 To see what will be included in your package, run `npx npm-packlist`. All files are included by default, with the following exceptions:
55
56 - Certain files that are relevant to package installation and distribution are always included. For example, `package.json`, `README.md`, `LICENSE`, and so on.
57
58 - If there is a "files" list in [`package.json`](/cli/v8/configuring-npm/package-json), then only the files specified will be included. (If directories are specified, then they will be walked recursively and their contents included, subject to the same ignore rules.)
59
60 - If there is a `.gitignore` or `.npmignore` file, then ignored files in that and all child directories will be excluded from the package. If _both_ files exist, then the `.gitignore` is ignored, and only the `.npmignore` is used.
61
62 `.npmignore` files follow the [same pattern rules](https://git-scm.com/book/en/v2/Git-Basics-Recording-Changes-to-the-Repository#_ignoring) as `.gitignore` files
63
64 - If the file matches certain patterns, then it will _never_ be included, unless explicitly added to the `"files"` list in `package.json`, or un-ignored with a `!` rule in a `.npmignore` or `.gitignore` file.
65
66 - Symbolic links are never included in npm packages.
67
68 See [`developers`](/cli/v8/using-npm/developers) for full details on what's included in the published package, as well as details on how the package is built.
69
70 ### Configuration
71
72 #### `tag`
73
74 - Default: "latest"
75 - Type: String
76
77 If you ask npm to install a package and don't tell it a specific version, then it will install the specified tag.
78
79 Also the tag that is added to the package@version specified by the `npm tag` command, if no explicit tag is given.
80
81 When used by the `npm diff` command, this is the tag used to fetch the tarball that will be compared with the local files by default.
82
83 #### `access`
84
85 - Default: 'restricted' for scoped packages, 'public' for unscoped packages
86 - Type: null, "restricted", or "public"
87
88 When publishing scoped packages, the access level defaults to `restricted`. If you want your scoped package to be publicly viewable (and installable) set `--access=public`. The only valid values for `access` are `public` and `restricted`. Unscoped packages _always_ have an access level of `public`.
89
90 Note: Using the `--access` flag on the `npm publish` command will only set the package access level on the initial publish of the package. Any subsequent `npm publish` commands using the `--access` flag will not have an effect to the access level. To make changes to the access level after the initial publish use `npm access`.
91
92 #### `dry-run`
93
94 - Default: false
95 - Type: Boolean
96
97 Indicates that you don't want npm to make any changes and that it should only report what it would have done. This can be passed into any of the commands that modify your local installation, eg, `install`, `update`, `dedupe`, `uninstall`, as well as `pack` and `publish`.
98
99 Note: This is NOT honored by other network related commands, eg `dist-tags`, `owner`, etc.
100
101 #### `otp`
102
103 - Default: null
104 - Type: null or String
105
106 This is a one-time password from a two-factor authenticator. It's needed when publishing or changing package permissions with `npm access`.
107
108 If not set, and a registry response fails with a challenge for a one-time password, npm will prompt on the command line for one.
109
110 #### `workspace`
111
112 - Default:
113 - Type: String (can be set multiple times)
114
115 Enable running a command in the context of the configured workspaces of the current project while filtering by running only the workspaces defined by this configuration option.
116
117 Valid values for the `workspace` config are either:
118
119 - Workspace names
120 - Path to a workspace directory
121 - Path to a parent workspace directory (will result in selecting all workspaces within that folder)
122
123 When set for the `npm init` command, this may be set to the folder of a workspace which does not yet exist, to create the folder and set it up as a brand new workspace within the project.
124
125 This value is not exported to the environment for child processes.
126
127 #### `workspaces`
128
129 - Default: null
130 - Type: null or Boolean
131
132 Set to true to run the command in the context of **all** configured workspaces.
133
134 Explicitly setting this to false will cause commands like `install` to ignore workspaces altogether. When not set explicitly:
135
136 - Commands that operate on the `node_modules` tree (install, update, etc.) will link workspaces into the `node_modules` folder. - Commands that do other things (test, exec, publish, etc.) will operate on the root project, _unless_ one or more workspaces are specified in the `workspace` config.
137
138 This value is not exported to the environment for child processes.
139
140 #### `include-workspace-root`
141
142 - Default: false
143 - Type: Boolean
144
145 Include the workspace root when workspaces are enabled for a command.
146
147 When false, specifying individual workspaces via the `workspace` config, or all workspaces via the `workspaces` flag, will cause npm to operate only on the specified workspaces, and not on the root project.
148
149 This value is not exported to the environment for child processes.
150
151 ### See Also
152
153 - [package spec](/cli/v8/using-npm/package-spec)
154 - [npm-packlist package](http://npm.im/npm-packlist)
155 - [npm registry](/cli/v8/using-npm/registry)
156 - [npm scope](/cli/v8/using-npm/scope)
157 - [npm adduser](/cli/v8/commands/npm-adduser)
158 - [npm owner](/cli/v8/commands/npm-owner)
159 - [npm deprecate](/cli/v8/commands/npm-deprecate)
160 - [npm dist-tag](/cli/v8/commands/npm-dist-tag)
161 - [npm pack](/cli/v8/commands/npm-pack)
162 - [npm profile](/cli/v8/commands/npm-profile)