Access tokens
Make a token
A token lets npm, pip, docker and your pipelines prove who they are.
Your tools do not use your portal password. They use a token instead. A token is a long random string that stands for you. You can have many, one for each laptop or pipeline, and you can revoke one without touching the others.
- Open Tokens in the menu.
- Under New token, type what the token is for, like
laptoporstorefront-ci. - Pick how many days it lasts. Shorter is safer.
- Click Make one.
- A name that says where the token is used
- How long it lasts
- Make the token
The token is shown once. Copy it right away and keep it in a password manager or your pipeline secrets. The page also prints the exact setup commands for packages.example.com.
- The token is shown once. Copy it now
- Paste these to set up npm
- Or log docker in with it
Careful
Treat a token like a password. Never commit it to git, paste it in chat, or put it in a Dockerfile. If one leaks, revoke it and make a new one.
Keep the token out of your files
Most tools can read the token from an environment variable. The examples in this guide use NPM_TOKEN for npm and REPO_TOKEN for pip and docker. Set it once in your shell profile:
~/.bashrc or ~/.zshrc
export NPM_TOKEN="<your token>"
export REPO_TOKEN="$NPM_TOKEN"
See also: Revoke a token, or check when it was used, Set up npm, Set up pip, Sign docker in to packages.example.com