npm ERR! code E403 — 403 Forbidden - PUT https://registry.npmjs.org/x - You do not have permission to publish
The registry refused the operation — the package name is taken, you lack publish rights, or 2FA/policies block it.
Seen on:
npm
Meaning
Publishing a name owned by someone else, a name too similar to an existing package, or an organisation policy requiring 2FA/automation tokens.
Common causes
- Package name already owned by another user
- Not a maintainer of the package
- Name too similar to an existing package
- Token type not allowed to publish
⚡ Quick fix
- Use a scoped name (@you/package)
- Ask the owner to add you as a maintainer
- Use an automation/granular token with publish rights
Detailed fix by platform
npm
npm publish --access public # for a scoped public package
How to diagnose
- Ownership — npm owner ls package
- Token — Type/permissions
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026