1 ---
2 title: Creating and publishing scoped public packages
3 ---
4
5 import shared from '~/shared.js'
6
7 To share your code publicly in a user or organization namespace, you can publish public user-scoped or organization-scoped packages to the npm registry.
8
9 For more information on scopes, see "[About scopes][scopes]".
10
11 <Note>
12
13 **Note:** Before you can publish user-scoped npm packages, you must [sign up](https://www.npmjs.com/signup) for an npm user account.
14
15 Additionally, to publish organization-scoped packages, you must [create an npm user account](https://www.npmjs.com/signup), then [create an npm organization](https://www.npmjs.com/signup?next=/org/create).
16
17 </Note>
18
19 ## Creating a scoped public package
20
21 1. If you are using npmrc to [manage accounts on multiple registries][reg-config], on the command line, switch to the appropriate profile:
22
23 ```
24 npmrc <profile-name>
25 ```
26
27 2. On the command line, create a directory for your package:
28
29 ```
30 mkdir my-test-package
31 ```
32
33 3. Navigate to the root directory of your package:
34
35 ```
36 cd my-test-package
37 ```
38
39 4. If you are using git to manage your package code, in the package root directory, run the following commands, replacing `git-remote-url` with the git remote URL for your package:
40
41 ```
42 git init
43 git remote add origin git://git-remote-url
44 ```
45
46 5. In the package root directory, run the `npm init` command and pass the scope to the `scope` flag:
47 - For an organization-scoped package, replace `my-org` with the name of your organization:
48
49 ```
50 npm init --scope=@my-org
51 ```
52
53 - For a user-scoped package, replace `my-username` with your username:
54 ```
55 npm init --scope=@my-username
56 ```
57
58 6. Respond to the prompts to generate a [`package.json`](https://docs.npmjs.com/about-package-json-and-package-lock-json-files) file. For help naming your package, see "[Package name guidelines][pkg-name]".
59 7. Create a [README file][readme-file] that explains what your package code is and how to use it.
60 8. In your preferred text editor, write the code for your package.
61
62 ## Reviewing package contents for sensitive or unnecessary information
63
64 Publishing sensitive information to the registry can harm your users, compromise your development infrastructure, be expensive to fix, and put you at risk of legal action. **We strongly recommend removing sensitive information, such as private keys, passwords, [personally identifiable information][pii] (PII), and credit card data before publishing your package to the registry.**
65
66 For less sensitive information, such as testing data, use a `.npmignore` or `.gitignore` file to prevent publishing to the registry. For more information, see [this article][developers].
67
68 ## Testing your package
69
70 To reduce the chances of publishing bugs, we recommend testing your package before publishing it to the npm registry. To test your package, run `npm install` with the full path to your package directory:
71
72 ```
73 npm install /path/to/my-test-package
74 ```
75
76 ## Publishing scoped public packages
77
78 By default, scoped packages are published with private visibility. To publish a scoped package with public visibility, use `npm publish --access public`.
79
80 <Note variant="warning">
81
82 **Important:** Publishing to npm requires either:
83
84 - Two-factor authentication (2FA) enabled on your account, OR
85 - A granular access token with bypass 2FA enabled
86
87 For more information, see the npm documentation on [requiring 2FA for package publishing](/requiring-2fa-for-package-publishing-and-settings-modification).
88
89 </Note>
90
91 1. On the command line, navigate to the root directory of your package.
92
93 ```
94 cd /path/to/my-test-package
95 ```
96
97 2. To publish your scoped public package to the npm registry, run:
98
99 ```
100 npm publish --access public
101 ```
102
103 <Note>
104
105 **Note:** If you use GitHub Actions to publish your packages, you can generate provenance information for each package you publish. For more information, see "[Generating provenance statements][provenance-how-to]."
106
107 </Note>
108
109 3. To see your public package page, visit https://npmjs.com/package/\*package-name\*, replacing \*package-name\* with the name of your package. Public packages will say `public` below the package name on the npm website.
110
111 <>{shared['organization-package-public'].image}</>
112
113 For more information on the `publish` command, see the [CLI documentation][cli-publish].
114
115 [scopes]: /about-scopes
116 [user-signup]: https://www.npmjs.com/signup
117 [create-org]: https://www.npmjs.com/signup?next=/org/create
118 [reg-config]: configuring-your-registry-settings-as-an-npm-enterprise-user
119 [pkg-name]: package-name-guidelines
120 [readme-file]: about-package-readme-files
121 [developers]: /misc/developers#keeping-files-out-of-your-package
122 [cli-publish]: /cli/publish
123 [pii]: https://en.wikipedia.org/wiki/Personally_identifiable_information
124 [provenance-how-to]: /generating-provenance-statements
125 [config-2fa]: /configuring-two-factor-authentication
126 [creating-token]: /creating-and-viewing-access-tokens
127 [requiring-2fa]: /requiring-2fa-for-package-publishing-and-settings-modification