This guide explains how to set up automated npm publishing for the Jay Framework monorepo without being prompted for OTP tokens.
- NPM Account: You need an npm account with publish permissions for
@jay-frameworkpackages - NPM Token: You need an npm authentication token
- OTP Token: You need a one-time password token for publishing
Set the NPM_OTP environment variable with your OTP token:
# Temporary (for current session)
export NPM_OTP=your_otp_token_here
# Permanent (add to your shell profile)
echo 'export NPM_OTP=your_otp_token_here' >> ~/.zshrc
source ~/.zshrcThen publish using:
yarn publishIf you prefer to enter the OTP manually:
yarn publish:interactiveUse the manual command with your OTP:
NPM_OTP=your_otp_token_here yarn publish:manual-
From npm website:
- Go to https://www.npmjs.com/settings/tokens
- Create a new token with "Automation" type
- Use this token as your OTP
-
From npm CLI:
npm token list
-
Generate new token:
npm token create --read-only
For automated publishing via GitHub Actions:
-
Add secrets to your repository:
NPM_TOKEN: Your npm authentication tokenNPM_OTP: Your npm OTP token
-
Trigger publishing:
- Push a tag starting with
v(e.g.,v1.0.0) - The workflow will automatically build, test, and publish
- Push a tag starting with
The project includes an .npmrc file with:
- Registry configuration
- Access level settings
- OTP environment variable reference
- Automatic confirmation settings
yarn publish: Automated publishing with OTP from environmentyarn publish:interactive: Manual publishing with promptsyarn publish:manual: Direct command with OTP
- Ensure
NPM_OTPenvironment variable is set - Verify your OTP token is valid
- Check that you have publish permissions
- Verify your npm token is correct
- Run
npm whoamito check authentication - Try
npm loginto refresh credentials
- Increment package versions before publishing
- Use
yarn version:packages:patch|minor|majorto update versions
- Never commit OTP tokens to version control
- Use environment variables or secrets management
- Rotate tokens regularly
- Use read-only tokens when possible
Before publishing, ensure all packages have the correct version:
# Patch version (1.0.0 -> 1.0.1)
yarn version:packages:patch
# Minor version (1.0.0 -> 1.1.0)
yarn version:packages:minor
# Major version (1.0.0 -> 2.0.0)
yarn version:packages:major