Skip to main content

npm

Shanone’s npm integration gives your agent 52 tools for managing packages, organizations, teams, tokens, and security across the npm registry.

Getting Started

1

Generate an npm access token

Run npm token create or go to npmjs.com Access Tokens settings and create a Granular Access Token scoped to the packages/orgs you need.
2

Add the token in Shanone

Go to Integrations > npm in the Shanone dashboard and paste the access token in.
3

Retry your request

Once saved, shanone_execute_tool calls for npm_* tools will succeed.

Available Tools

Shanone provides 52 tools for npm, organized into these categories:
npm_get_package, npm_get_package_version, npm_get_package_abbreviated, npm_search_packages, npm_search_packages_advanced, npm_get_dist_tags, npm_get_latest_version, npm_get_registry_info
npm_get_package_visibility, npm_set_package_access, npm_list_package_collaborators, npm_add_package_collaborator, npm_remove_package_collaborator, npm_add_dist_tag, npm_remove_dist_tag, npm_list_dist_tags_auth
npm_get_download_point, npm_get_download_point_all, npm_get_download_range, npm_get_download_range_all, npm_get_download_bulk, npm_get_download_versions
npm_list_org_members, npm_add_org_member, npm_remove_org_member, npm_list_org_teams, npm_list_org_packages, npm_get_org
npm_create_team, npm_delete_team, npm_list_team_members, npm_add_team_member, npm_remove_team_member, npm_list_team_packages, npm_grant_team_package_access, npm_revoke_team_package_access
npm_list_tokens, npm_create_token, npm_delete_token, npm_whoami, npm_validate_token
npm_get_user_profile, npm_update_user_profile, npm_deprecate_package, npm_undeprecate_package, npm_list_trusted_publishers, npm_add_trusted_publisher, npm_remove_trusted_publisher, npm_star_package
npm_audit_bulk, npm_get_advisory, npm_search_advisories

Common Use Cases

Dependency security review

Bulk-audit a package.json’s dependencies and surface known advisories

Package hygiene

Deprecate old package versions and check download trends before removing them

Access management

Add a new team member and grant them access to the right packages

Publish monitoring

Track download counts after a release to gauge adoption

Troubleshooting

Organization and team management requires the token to belong to an npm org owner or admin — a token scoped to a single package won’t work for these calls.
Bulk audit matches against exact package name + version ranges; ensure you’re passing the resolved versions from a lockfile rather than the semver ranges in package.json.
Setting visibility (public/restricted) on scoped packages requires a paid npm org plan for private packages — free accounts can only publish scoped packages as public.