npm trusted publishing now manages dist-tags via OIDC
GitHub announced on 2026-09-30 that npm trusted publishing can now manage dist-tags using the same short-lived OIDC credentials it uses to publish, removing the need for a long-lived access token. The new "Allow npm dist-tag" permission is opt-in and off by default.
- "Allow npm dist-tag" is off by default for new and existing configurations
- Dist-tag permission is independent of direct publishing permissions
- Classic token-based dist-tag management keeps working unchanged
- Authorization matches on OIDC token claims: repository, workflow, environment
Read next
Security