Skip to content

Who can install or publish my Pkg packages?

Anyone can install a public Pkg package without an Account session. An internal package requires authenticated read access within its owning Account. Publishing requires authentication and permission to publish.

Package names are unique within an Account. Your selected Account matters when a name also exists elsewhere.

Public and internal visibility

Pkg accepts internal and public visibility. New Packages and ordinary registry uploads default to internal when no visibility is supplied.

An authenticated request looks for the package name in the token's Account first, then can resolve a public package with that name. Anonymous requests resolve public packages.

Public visibility exposes the installable package metadata and artifact. Review the files before making a Package public. Changing visibility cannot retract copies that someone has already downloaded.

People and agents

The registry accepts ordinary Socra OAuth Account access tokens. Human and Agent Account sessions can read and publish packages in their Account. This registry path does not add a package-owner or per-package grant check.

An invalid supplied token is rejected even when the package could be read anonymously. Check the Account session before changing visibility to resolve an access error.

For authenticated npm access, install the Account and Pkg CLI plugins and sign in to the intended Account. Run:

socra pkg configure
export SOCRA_ACCESS_TOKEN="$(socra pkg access-token)"

The first command configures npm and Bun for @socra packages. It stores a reference to the SOCRA_ACCESS_TOKEN environment variable. The second loads your Account token into the shell. Run it again when you need a refreshed token. Keep tokens out of package files and logs.

Service accounts and CI

A service-account token needs the registry OAuth scope and the matching IAM permission on its credential Project. Reads use pkg.socra.cloud/registry.read with pkg.registry.read. Publication uses pkg.socra.cloud/registry.publish with pkg.registry.publish.

Give an installation job read access. Add publishing access only when the job publishes. Scope consent and Project IAM are separate checks.

Check the intended Package

Replace PACKAGE with the package name or pkg_… ID:

socra pkg retrieve PACKAGE

Confirm its identity and visibility, then test installation with the intended consumer identity before relying on that access in a build or deployment.

Pkg removes the private request token when it forwards public npm dependency requests to the public npm registry. Package files still need your review before publication.