Skip to main content
Question

Private NPM Registry Auth Token Cycling

  • July 29, 2026
  • 9 replies
  • 81 views

Jake Mauer

I would like to use the private NPM registry feature but before I do I have two quick questions:

  1. Is the auth token provided in Resources → npm registry → “View Configuration” generated per-user, as in is it specific to me or is it the same for all admins?
  2. Can I cycle or regenerate that token if necessary? If so, how?

Thank you!

 

9 replies

Jaycee Lewis
Figmate

Hey hey ​@Jake Mauer 👋 Thanks for the clear, specific questions — that makes this easy to dig into.

A couple of quick things so I can repro on the same screen you're looking at:

  • Are you set up as an org admin? The npm registry configuration lives under Admin → Resources → npm registry. I want to confirm we're both looking at the same place 👀
  • Which guide are you following for setup? If it's Bring your design system package to a Make kit, I'll repro against that exact flow
  • Just to make sure I answer the right thing: when you say "auth token," you mean the token inside the .npmrc code snippet from View configuration — not a Personal Access Token or a Plan Access Token — correct?

Once I've got those, I'll get you a clear answer on both the scope and regenerating it.

— Jaycee


Jake Mauer
  • Author
  • New Member
  • July 31, 2026
  1. I am an org admin and yeah that’s the path I’m referring to. Admin → Resources → npm registry
  2. Yes those are the instructions I was looking at and following.
  3. Yes the auth token that’s provided in the code snippet that’s prefixed with “:_authToken=”

Thank you!


Jaycee Lewis
Figmate

Thanks ​@Jake Mauer 👋 I’ll take this to my resources and get clarity for us. — Jaycee


Jake Mauer
  • Author
  • New Member
  • August 4, 2026

Hey ​@Jaycee Lewis just checking in to see if you’ve been able to get any more clarification on this. Thank you!


Jaycee Lewis
Figmate

Hey hey ​@Jake Mauer 👋 We must be on the same vibe today.

Here’s what I found out for us:

I’m waiting on additional details on the maximum number of tokens per plan. If you have any additional questions, let me know and I’ll add them to my internal query. Talk soon! — Jaycee


Jake Mauer
  • Author
  • New Member
  • August 4, 2026

Thank you! I’ll let you know if our security team needs any more info.


Jake Mauer
  • Author
  • New Member
  • August 13, 2026

Hi Jaycee, 

 

Checking in to see if you got an answer about the maximum tokens per plan. Also what are the conditions under which a token is invalidated? If I click “View Configuration”, use that token, and then click “View Configuration” again, does it invalidate the previous token I used? Finally, is there any way for an administrator on our side to manage or explicitly invalidate any or all issued tokens? 


Jaycee Lewis
Figmate

Hi, ​@Jake Mauer 👋 I’m happy to take that back to the team. Talk soon! — Jaycee


Jaycee Lewis
Figmate

Hey ​@Jake Mauer 👋 I want to make sure I get this right for us. I opened a support ticket for you. The ID is 2077602 and the subject line is Private npm registry — token scope, regeneration, and admin revocation. Please keep an eye on your email (and spam folder if needed) for the reply and any follow ups. Have a fantastic rest of your week! — Jaycee