# How do I install a public package from Pkg?

Company: Socra — Multiply Your Judgment
Canonical URL: https://support.socra.com/articles/art_01m3zvndzvp0arw8c3rqn3c8gf-install-a-package

Use npm or Bun with the Pkg registry at `https://pkg.socra.cloud/npm/`. A public package can be installed without an Account session. Select the package's full npm name and published version so that you can verify what your application receives.

## Check the published version

Run the following command in a terminal with npm installed. Replace `PACKAGE_NAME` and `VERSION` with the full npm name and version you need:

```sh
npm view PACKAGE_NAME@VERSION name version dist.integrity dist.tarball --json --registry=https://pkg.socra.cloud/npm/
```

Confirm the returned name and version. The artifact URL identifies the download, and the integrity value lets the package manager check its bytes. These fields do not prove that the package's code is suitable for your application.

A Package can exist before it has an installable Release. If Pkg reports `Package has no installable Releases`, its owner must publish a version before you can install it.

## Install with your package manager

In the application directory, use the package manager that maintains that application's dependency manifest and lockfile. Replace the same placeholders in one of these commands.

With npm:

```sh
npm install PACKAGE_NAME@VERSION --registry=https://pkg.socra.cloud/npm/ --ignore-scripts
```

With Bun:

```sh
bun add PACKAGE_NAME@VERSION --registry=https://pkg.socra.cloud/npm/ --ignore-scripts
```

These commands add the dependency and update the package manager's lockfile. `--ignore-scripts` skips lifecycle scripts during installation. A package that depends on those scripts may need additional setup from its owner before it can run.

Check the selected version in the dependency manifest and lockfile, then test an import of the package's documented entry point. A completed download does not verify compatibility with your application's runtime or code.

## If installation fails

Check the exact package name, published version, and registry URL. The explicit registry option sends this installation to Pkg without requiring a permanent change to your registry configuration.

An invalid token already configured for Pkg can cause an authentication error even for a public package. A supplied token is checked before the package is returned. Inspect the registry and authentication settings used by this terminal without printing or sharing credentials.

An authenticated request first resolves a package owned by its Account, then a matching public package. If two Accounts use the same name, verify the returned package and artifact before installing. This public-install procedure does not configure credentials for internal packages.

## Article details

- Collection: [Pkg](https://support.socra.com/collections/col_01m3z6vv74g6nshqaz3wpy8704-pkg)
- Canonical: https://support.socra.com/articles/art_01m3zvndzvp0arw8c3rqn3c8gf-install-a-package
