npm ERR! code E401 — Unable to authenticate, need: Basic realm / Incorrect or missing password
The registry rejected your credentials — missing, expired or wrong auth token.
Seen on:
npm
Meaning
Private registries and npm publish need a valid token in .npmrc. Tokens expire or get revoked; env vars like ${NPM_TOKEN} may be unset in CI.
Common causes
- Expired/revoked token
- .npmrc token env var not set in CI
- Logged in to a different registry than the one used
- Old _auth/_password formats
⚡ Quick fix
- npm login (or npm login --registry <url>)
- Set NPM_TOKEN in CI
- Check which registry and .npmrc are used: npm config list
Detailed fix by platform
npm
//registry.npmjs.org/:_authToken=${NPM_TOKEN}
How to diagnose
- Registry — Which one?
- Token — Present and valid (npm whoami)?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026