API_KEY
npm_api_key
Developer setup
No fields declared in this snapshot.
User connection
- NPM Access Tokengeneric_api_key · stringRequired
NPM
npm is the default package manager for JavaScript and Node.js, facilitating the sharing and reuse of code, managing dependencies, and streamlining project workflows.
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
12
Action summaries
Display-only definitions
0
Trigger types
Not installed instances
1
Auth modes
Field names, never values
No
Execution
No runtime adapter
Authentication map
API_KEY
No fields declared in this snapshot.
Capability index
Showing 1–12 of 12 actions
NPM_DELETE_USER_TOKEN_LEGACY
Tool to delete a user authentication token using the legacy endpoint. Use when you need to revoke or remove a specific token from the npm registry.
Untrusted display-only summary
NPM_GET_ALL_PACKAGES_DOWNLOAD_POINT
Get total npm registry download statistics for all packages for a specified time period. Returns aggregate download counts across the entire npm registry with start/end dates. Supports preset periods (last-day, last-week, last-month, last-year) or custom date ranges (YYYY-MM-DD:YYYY-MM-DD).
Untrusted display-only summary
NPM_GET_DOWNLOAD_COUNTS_POINT
Get npm package download statistics for a specified time period. Returns total download counts with start/end dates for single packages, scoped packages, or bulk queries (up to 128 packages). Supports preset periods (last-day, last-week, last-month, last-year) or custom date ranges (YYYY-MM-DD:YYYY-MM-DD).
Untrusted display-only summary
NPM_GET_DOWNLOAD_COUNTS_RANGE_PACKAGE
Tool to get download counts for an npm package over a specified date range. Use when you need historical daily download data.
Untrusted display-only summary
NPM_GET_DOWNLOAD_RANGE_ALL
Tool to get daily download counts for all npm packages over a specified period. Use when you need aggregate download statistics across the entire npm registry.
Untrusted display-only summary
NPM_GET_REGISTRY_CHANGES
Tool to get a stream of registry changes for replication purposes. Returns CouchDB-style change feed for following registry updates.
Untrusted display-only summary
NPM_GET_REGISTRY_META
Retrieves npm registry metadata via meta endpoints. Use 'ping' to verify registry connectivity or 'whoami' to get the authenticated username.
Untrusted display-only summary
NPM_GET_VERSION_DOWNLOADS
Tool to get download counts for specific versions of a package over the last 7 days. Use when you need to understand which versions are most popular.
Untrusted display-only summary
NPM_QUERY_BULK_SECURITY_ADVISORIES
Tool to bulk query security advisories for multiple npm packages. Use when you need to check vulnerability information for multiple packages and versions at once.
Untrusted display-only summary
NPM_REGISTRY_GET_PACKAGE
Tool to fetch metadata for a specified npm package. Use after confirming the exact package name, including scope. Responses can be large; prefer reading top-level fields like 'dist-tags', 'description', and 'license' rather than scanning the entire object.
Untrusted display-only summary
NPM_REGISTRY_GET_ROOT
Fetches npm registry root metadata including total package count and update sequence. Returns database statistics from the npm replication service. No parameters required. Use this to get current registry statistics like the total number of packages available.
Untrusted display-only summary
NPM_REGISTRY_SEARCH_PACKAGES
Tool to search for packages in the npm registry. Use when you need to find packages matching a search term. Results are returned in an 'objects' array; each element contains package metadata under a 'package' field and weekly download estimates under 'downloads.weekly'.
Untrusted display-only summary
Provenance
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.
Remote text is plain display metadata only. It must never become an agent prompt, execution policy, OAuth grant, or executable instruction.