Use this API to interact with the npm package manager client.

This API is used by the npm package manager client and is not meant for manual consumption.

These endpoints do not adhere to the standard API authentication methods. See the npm package registry documentation for details on which headers and token types are supported. Undocumented authentication methods might be removed in the future.

NPM registry bulk advisory endpoint

POST /api/v4/groups/{id}/-/packages/npm/-/npm/v1/security/advisories/bulk

This feature was introduced in GitLab 15.6

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the group

Responses

CodeDescriptionSchema
200Ok—
307Temporary Redirect—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

NPM registry quick audit endpoint

POST /api/v4/groups/{id}/-/packages/npm/-/npm/v1/security/audits/quick

This feature was introduced in GitLab 15.6

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the group

Responses

CodeDescriptionSchema
200Ok—
307Temporary Redirect—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Get all tags for a given NPM package

GET /api/v4/groups/{id}/-/packages/npm/-/package/{package_name}/dist-tags

This feature was introduced in GitLab 12.7

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the group
package_name
Path, required
StringPackage name

Responses

CodeDescriptionSchema
200OKAPIEntitiesNpmPackageTag
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Create or Update the given tag for the given NPM package and version

PUT /api/v4/groups/{id}/-/packages/npm/-/package/{package_name}/dist-tags/{tag}

This feature was introduced in GitLab 12.7

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the group
package_name
Path, required
StringPackage name
tag
Path, required
StringPackage dist-tag

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Deletes the given tag

DELETE /api/v4/groups/{id}/-/packages/npm/-/package/{package_name}/dist-tags/{tag}

This feature was introduced in GitLab 12.7

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the group
package_name
Path, required
StringPackage name
tag
Path, required
StringPackage dist-tag

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

NPM registry metadata endpoint

GET /api/v4/groups/{id}/-/packages/npm/{package_name}

This feature was introduced in GitLab 11.8

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the group
package_name
Path, required
StringPackage name
Example: mypackage

Responses

CodeDescriptionSchema
200OkAPIEntitiesNpmPackage
302Found (redirect)—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

NPM registry bulk advisory endpoint

POST /api/v4/packages/npm/-/npm/v1/security/advisories/bulk

This feature was introduced in GitLab 15.6

Responses

CodeDescriptionSchema
200Ok—
307Temporary Redirect—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

NPM registry quick audit endpoint

POST /api/v4/packages/npm/-/npm/v1/security/audits/quick

This feature was introduced in GitLab 15.6

Responses

CodeDescriptionSchema
200Ok—
307Temporary Redirect—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Get all tags for a given NPM package

GET /api/v4/packages/npm/-/package/{package_name}/dist-tags

This feature was introduced in GitLab 12.7

Parameters

NameTypeDescription
package_name
Path, required
StringPackage name

Responses

CodeDescriptionSchema
200OKAPIEntitiesNpmPackageTag
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Create or Update the given tag for the given NPM package and version

PUT /api/v4/packages/npm/-/package/{package_name}/dist-tags/{tag}

This feature was introduced in GitLab 12.7

Parameters

NameTypeDescription
package_name
Path, required
StringPackage name
tag
Path, required
StringPackage dist-tag

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Deletes the given tag

DELETE /api/v4/packages/npm/-/package/{package_name}/dist-tags/{tag}

This feature was introduced in GitLab 12.7

Parameters

NameTypeDescription
package_name
Path, required
StringPackage name
tag
Path, required
StringPackage dist-tag

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

NPM registry metadata endpoint

GET /api/v4/packages/npm/{package_name}

This feature was introduced in GitLab 11.8

Parameters

NameTypeDescription
package_name
Path, required
StringPackage name
Example: mypackage

Responses

CodeDescriptionSchema
200OkAPIEntitiesNpmPackage
302Found (redirect)—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

NPM registry bulk advisory endpoint

POST /api/v4/projects/{id}/packages/npm/-/npm/v1/security/advisories/bulk

This feature was introduced in GitLab 15.6

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project

Responses

CodeDescriptionSchema
200Ok—
307Temporary Redirect—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

NPM registry quick audit endpoint

POST /api/v4/projects/{id}/packages/npm/-/npm/v1/security/audits/quick

This feature was introduced in GitLab 15.6

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project

Responses

CodeDescriptionSchema
200Ok—
307Temporary Redirect—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Get all tags for a given NPM package

GET /api/v4/projects/{id}/packages/npm/-/package/{package_name}/dist-tags

This feature was introduced in GitLab 12.7

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name

Responses

CodeDescriptionSchema
200OKAPIEntitiesNpmPackageTag
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Create or Update the given tag for the given NPM package and version

PUT /api/v4/projects/{id}/packages/npm/-/package/{package_name}/dist-tags/{tag}

This feature was introduced in GitLab 12.7

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name
tag
Path, required
StringPackage dist-tag

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Deletes the given tag

DELETE /api/v4/projects/{id}/packages/npm/-/package/{package_name}/dist-tags/{tag}

This feature was introduced in GitLab 12.7

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name
tag
Path, required
StringPackage dist-tag

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

NPM registry metadata endpoint

GET /api/v4/projects/{id}/packages/npm/{package_name}

This feature was introduced in GitLab 11.8

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name
Example: mypackage

Responses

CodeDescriptionSchema
200OkAPIEntitiesNpmPackage
302Found (redirect)—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Create or deprecate an NPM package

PUT /api/v4/projects/{id}/packages/npm/{package_name}

Creates or deprecates an NPM package for a specified project. Deprecate support was added in GitLab 16.0.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name

Request body (multipart/form-data)

PropertyTypeDescription
file
Required
String (binary)The package file to be published (generated by Multipart middleware)

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not Found—

Download the NPM tarball

GET /api/v4/projects/{id}/packages/npm/{package_name}/-/{file_name}

This feature was introduced in GitLab 11.8

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
package_name
Path, required
StringPackage name
file_name
Path, required
StringPackage file name

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
403Forbidden—
404Not Found—

Schemas

Objects returned by the operations above and objects nested in their request bodies.

APIEntitiesNpmPackage

PropertyTypeDescription
dist-tagsObjectExample: {"latest":"1.0.1"}
nameStringExample: my_package
versionsObjectExample: {"1.0.0":{"dist":{"shasum":"12345","tarball":"https://..."},"name":"my_package","version":"1.0.0"}}

APIEntitiesNpmPackageTag

PropertyTypeDescription
dist_tagsObjectExample: {"latest":"1.0.1"}