
go-tokenless
io.github.Continuous-Actionsv0.1.0Updated Oct 6, 2026
Move npm publishing in GitHub Actions from NPM_TOKEN to trusted publishing (OIDC).
Overview
Lets an assistant plan and apply changes that move npm publishing in GitHub Actions from NPM_TOKEN secrets to npm trusted publishing (OIDC).
- What it does
- Exposes two tools: plan_trusted_publishing, which is read-only and reports what would change, and apply_trusted_publishing, which writes the changes to workflow and package.json files. It removes NODE_AUTH_TOKEN and NPM_TOKEN from publish steps, grants id-token: write, adds registry-url, updates pinned publish actions, and fixes the repository field. It also prints the npm trust github commands and remaining manual steps, and refuses rather than guessing when trusted publishing cannot work.
- When to use it
- Use it when a repository publishes npm packages from GitHub Actions and you want to drop long-lived npm tokens in favour of OIDC trusted publishing, including changesets, semantic-release, release-please, Lerna, Nx, pnpm, Yarn Berry and release-it setups.
- Requirements
- Local process run via npx (npm package go-tokenless); needs Node 22.14+. No accounts, API keys, environment variables or headers are declared. It reads the local repository's workflows and package.json; the npm registry lookup can be skipped with --offline.
Installation
In SourceWeft
- Open go-tokenless in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
go-tokenless
Delete your NPM_TOKEN. One command switches your GitHub Actions release workflow to npm trusted publishing (OIDC), so no long-lived npm token has to be stored anywhere.
npm is retiring direct publishing with tokens: from January 2027 a granular token with "bypass 2FA" can no longer publish on its own (npm docs). Trusted publishing is the replacement for CI. It also adds a provenance badge to every release.
What it does
It reads your workflows and package.json files, then:
It also prints the exact npm trust github … command for every package and the remaining manual steps.
It refuses (exit code 1) rather than guessing when trusted publishing can't work: self-hosted runners, or a repository field pointing at another repo. It leaves jobs that publish to GitHub Packages alone.
Example
The default command also prints a unified diff. Your file's comments, quoting and layout are kept: only the lines that need to change are touched.
Supported release setups
Version floors are checked against your package.json where possible.
Things only you can do
The tool never touches your npm account. After applying:
- Add a trusted publisher for each package: the printed
npm trust github …commands (npm 11.15+, needs your 2FA), or npmjs.com → package → Settings → Trusted publishing. - Brand-new packages must be published once by hand first; npm can only attach a trusted publisher to a package that exists. The plan flags these.
- Delete the secret and revoke the token once a release has gone out.
Use it from an AI coding agent
Agents can run the CLI with --json (stable shape, status field, exit codes), or use the MCP server:
Tools: plan_trusted_publishing (read-only) and apply_trusted_publishing (writes files, no git or network writes). There is also an Agent Skill:
Or install the skill and MCP server together as a plugin:
Just ask: "Move our npm publishing to trusted publishing."
Options
Exit codes: 0 ok, 1 blocked (errors to fix by hand), 2 usage error, 3 unexpected error. Needs Node 22.14+.
npm version
When a publish job runs on a Node version whose bundled npm is too old, go-tokenless adds npm install -g npm@^12. It is pinned to one major on purpose: a new npm major can change how publishing behaves, and a release pipeline should not change under you. npm 12 needs Node 22.22.2+ or 24.15+; jobs pinned to an older exact Node 22 get a warning.
To use a different npm, pass --npm-version (for example --npm-version ^11.6.0). go-tokenless warns that an untested version may break the release, and refuses versions older than 11.5.1, which cannot use trusted publishing.
Troubleshooting the errors people hit
npm error code ENEEDAUTH: the job has noid-token: write, npm is older than 11.5.1, or the workflow file name doesn't match the trusted publisher exactly (case-sensitive, with.yml).npm error 404 Not Found - PUT https://registry.npmjs.org/...: usually the same causes as ENEEDAUTH, anenvironmentmismatch, or the package has no trusted publisher yet.npm error code E422…repository.url:package.jsonrepositorydoesn't match the GitHub repo.go-tokenless applyfixes the format; a different repo is reported as an error.- Publishing still uses the token: something still sets
NODE_AUTH_TOKEN,NPM_TOKEN, an.npmrc_authToken, or.yarnrc.ymlnpmAuthToken. Runnpx go-tokenlessagain; it reports leftovers.
License
MIT
Source: README.md at commit 108300f
Tools
0Version history
1- v0.1.0LatestOct 6, 2026


