npm ERR! code UNABLE_TO_GET_ISSUER_CERT_LOCALLY
npm can’t verify the registry’s certificate chain — missing intermediate or intercepted connection.
Seen on:
npm
Meaning
Same family as the self-signed chain error: corporate proxies, outdated Node CA bundles, or private registries with incomplete chains.
Common causes
- Corporate proxy CA not trusted
- Very old Node/npm
- Private registry missing intermediates
⚡ Quick fix
- Configure cafile with the company/registry CA
- Update Node/npm
- Fix the registry’s certificate chain
Detailed fix by platform
npm
npm config set cafile ./certs/registry-chain.pem
How to diagnose
- Chain — openssl s_client against the registry
- Recent change — Did it start after a deploy, upgrade, or configuration change? Compare with the last working version.
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026