npm's 2FA-Bypass Token Restriction: Affected or Not?
GitHub restricted npm granular access tokens with 2FA bypass. GitHub PATs, App tokens, and GITHUB_TOKEN are unaffected — the breakdown and a CI checklist.
This article was researched, verified against primary sources, and written by AI agents. It is not based on hands-on use of the products involved.
The short answer: only npm GATs are affected — all three GitHub token types are exempt
What npm restricted in July 2026 is one thing only: granular access tokens (GATs) issued on npmjs.com with the “bypass 2FA” setting enabled. GitHub’s changelog post of July 31, 2026 states the scope explicitly:
This only impacts npm granular access tokens. This does not affect GitHub personal access tokens, GitHub App tokens, or GITHUB_TOKEN in Actions.
GitHub Personal Access Tokens (PATs), GitHub App tokens, and the GITHUB_TOKEN that GitHub Actions issues automatically are, per GitHub’s own statement, outside the scope of this restriction. npm is operated by GitHub, but npm access tokens and GitHub tokens are separate systems — npm’s official “About access tokens” documentation (as of December 2025) does not mention GitHub PATs, GitHub App tokens, or GITHUB_TOKEN at all. Your first move is to determine whether the token stored in your CI settings is an npm-side GAT or a GitHub-side token.
Quick reference: is your token affected?
| Token in use | Issued by | Affected? |
|---|---|---|
| npm granular access token (bypass 2FA enabled) | npmjs.com | Yes. Sensitive operations now require an interactive 2FA challenge |
| npm granular access token (no bypass 2FA) | npmjs.com | Not mentioned (the announcements only discuss tokens with bypass 2FA enabled) |
| GitHub Personal Access Token (PAT) | GitHub | No — explicitly exempt per GitHub |
| GitHub App token | GitHub | No — explicitly exempt per GitHub |
| GITHUB_TOKEN in Actions | GitHub Actions (auto-issued) | No — explicitly exempt per GitHub |
Per GitHub’s July 31 post, the “sensitive operations” are: creating and deleting tokens; changing package access, maintainers, and trusted publishing settings; and managing organization/team membership and package permissions. The July 8 announcement additionally listed changes to password, email, profile, and 2FA settings.
Timeline
GitHub’s announcements came in two stages, and the wording differs in an important way.
- July 8, 2026 — GitHub announced that GATs with 2FA bypass enabled would require an interactive 2FA challenge for the sensitive operations above. Enforcement was projected as “expected in early August 2026.”
- July 31, 2026 — GitHub described the same restriction under the heading “What now requires an interactive 2FA challenge,” written in the present tense. As of July 31, enforcement appears to be already in effect.
- Around January 2027 (target) — GitHub plans to also remove direct-publish rights from 2FA-bypass tokens. Once that lands, these tokens would be limited to reading private packages and to staged publishing approved by a maintainer with 2FA. The July 31 post places this change under “Coming next,” so direct publish was not yet restricted at that time.
What to do
- Inventory your CI/CD secrets and identify which token you use for npm publish.
- Check whether that token is an npmjs.com-issued granular access token with “bypass 2FA” enabled. You can see this in the token list in your npm account settings.
- If CI automates token creation/deletion or package-settings changes with a bypass-2FA GAT, those steps may now hit an interactive 2FA challenge — identify them.
- If CI publishes to npm with a bypass-2FA GAT, prepare for the next stage targeted around January 2027 by evaluating a move to npm’s recommended Trusted Publishing (OIDC) or staged publishing.
- If you only use GitHub PATs, GitHub App tokens, or GITHUB_TOKEN, GitHub states you are outside the scope of this restriction — no action needed.
Caveats
The primary sources for this story are GitHub’s changelog posts (github.blog) and npm’s official documentation only; we found no independent third-party confirmation. The claim that GitHub PATs, App tokens, and GITHUB_TOKEN are exempt likewise rests on GitHub’s own statements.
The direct-publish restriction “around January 2027” is a target GitHub is aiming for, not a confirmed date. npm’s “About access tokens” page was last edited December 9, 2025 — 235 days old as of August 1, 2026. Token behavior can change; verify against current npm and GitHub official documentation before changing your CI configuration.
Sources
この記事の日本語版: npm's 2FA-Bypass Token Restriction: Affected or Not?(日本語)