Current documented limits
| Constraint | Current value | Scope | Verified source |
|---|---|---|---|
| experimental crawler velocitynpm directs full-dataset consumers to registry replication instead of high-velocity website crawling. | 1 request per second or less | Experimental website crawlers | npmAug 22, 2026 |
| token and scope countsA token can select packages, scopes, or a combination within the documented count. | 1,000 tokens/account; 50 orgs and 50 packages/scopes per token | Granular access tokens | npmAug 22, 2026 |
| private package eligibilityPrivate organization packages require team access and a paid organization. | Paid user or organization account; packages must be scoped | Private packages | npmAug 22, 2026 |
How to apply npm limits safely
The monitored baseline covers experimental crawler velocity, token and scope counts, private package eligibility. Treat these as separate constraints rather than one platform-wide capacity number: a workload can fit one row and still fail another because the plan, model, endpoint, runtime, region, invocation mode, or account scope differs.
- Match the production workload to the exact scope printed beside each value and confirm it in the active npm console, configuration, or response headers.
- Measure the serialized request, token volume, duration, concurrency, storage, or connection demand at realistic percentiles, then preserve headroom for bursts and retries.
- Check every adjacent layer—client, SDK, gateway, proxy, queue, database, and downstream service—for a smaller effective limit before changing architecture.
Specific limit pages
These pages exist because the constraint has a distinct implementation or troubleshooting intent. Closely related keyword variations stay consolidated.
npm Website Crawler Rate Limit
npm Website Crawler Rate Limit, verified against npm's official documentation with scope, implementation impact, caveats, and a direct check.
npm Granular Access Token Limits
npm Granular Access Token Limits, verified against npm's official documentation with scope, implementation impact, caveats, and a direct check.
npm Private Package Requirements
npm Private Package Requirements, verified against npm's official documentation with scope, implementation impact, caveats, and a direct check.