npm is implementing major security changes including shorter token lifetimes (7-day default, 90-day maximum), sunsetting classic tokens entirely, and disabling new TOTP 2FA setups in favor of WebAuthn. These changes roll out over five weeks through mid-November 2025. Package maintainers must migrate from classic tokens to
Table of contents
What’s changingTimeline and implementationLooking ahead: Trusted publishersWe need your partnershipGetting supportThank youSort: