JavaScript / Node.js

CloudRepo supports the npm registry protocol for hosting private Node.js packages.

Hosted at CloudRepo. See private npm registry hosting for plans and pricing.

Overview

CloudRepo provides private npm registry hosting with support for all major JavaScript package managers. Whether you’re using npm, Yarn, pnpm, or Bun, CloudRepo integrates seamlessly with your workflow.

Supported Package Formats

  • Tarballs (.tgz) - Standard npm package format

  • Scoped packages - @scope/package-name fully supported

  • Unscoped packages - Standard package-name format

Supported Tools

  • npm - The default Node.js package manager

  • Yarn (v1 and v2+) - Facebook’s package manager

  • pnpm - Fast, disk-efficient package manager

  • Bun - All-in-one JavaScript runtime with built-in package manager

Repository Types

Local Repositories

Host your private npm packages:

https://[org-id].mycloudrepo.io/repositories/npm-repo

Features:

  • Full npm publish and install support

  • Scoped and unscoped packages

  • Bearer token authentication (via npm login)

  • Basic authentication support

  • HTML directory browsing

  • 210 MB maximum package size

Quick Configuration Examples

npm

; .npmrc
registry=https://[org-id].mycloudrepo.io/repositories/npm-repo/
//[org-id].mycloudrepo.io/repositories/npm-repo/:_authToken=YOUR_TOKEN
always-auth=true

Yarn (v2+)

# .yarnrc.yml
npmRegistryServer: "https://[org-id].mycloudrepo.io/repositories/npm-repo/"
npmRegistries:
  "https://[org-id].mycloudrepo.io/repositories/npm-repo/":
    npmAuthToken: "YOUR_TOKEN"

pnpm

; .npmrc (pnpm uses .npmrc)
registry=https://[org-id].mycloudrepo.io/repositories/npm-repo/
//[org-id].mycloudrepo.io/repositories/npm-repo/:_authToken=YOUR_TOKEN
always-auth=true

Bun

; .npmrc (Bun falls back to .npmrc)
registry=https://[org-id].mycloudrepo.io/repositories/npm-repo/
//[org-id].mycloudrepo.io/repositories/npm-repo/:_authToken=YOUR_TOKEN
always-auth=true

Authentication Methods

Basic Authentication (legacy _auth)

For older CI tooling that requires Basic auth, _auth=base64(user:pass) is still supported:

echo -n 'username:password' | base64
registry=https://[org-id].mycloudrepo.io/repositories/npm-repo/
//[org-id].mycloudrepo.io/repositories/npm-repo/:_auth=BASE64_ENCODED
always-auth=true

Prefer the API Token pattern. It scopes the credential to one repo and rotates independently from your portal password.

Best Practices

  • Always include always-auth=true in .npmrc for private registries

  • Mint a bearer token with npm token create --registry=<your-repository-url> and use it as _authToken for CI/CD pipelines; it is revocable on its own, unlike a password in _auth

  • Revoke tokens you no longer need with npm token list / npm token revoke <id> against the same --registry

  • The interactive npm login web flow (/-/v1/login) is not supported, and modern npm also rejects email-shaped usernames, which CloudRepo uses. Configure .npmrc directly instead

  • Include a trailing slash on registry URLs

  • Use scoped packages (@yourorg/package) to avoid name conflicts

Next Steps