SECURITY WARNING: Never run commands you don't understand. Always review code before execution. Use at your own risk.
JavaScript New Added 8 September 2026

npm ERR! code E401 on a private registry

npm reached the registry but sent no usable credentials for that scope. The common causes are an .npmrc that authenticates the default registry while the scope points somewhere else, an expired token, or a CI job where the token was never written to a file npm actually reads.

Quick fix

Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.

Quick fix
# What does npm think it is talking to?
npm config get registry
npm config get @acme:registry
npm whoami --registry=https://npm.pkg.github.com

# Point the scope and its auth at the same host
@acme:registry=https://npm.pkg.github.com
//npm.pkg.github.com/:_authToken=${NODE_AUTH_TOKEN}

# CI: write it before install, never commit a real token
npm config set //registry.npmjs.org/:_authToken "$NPM_TOKEN"

How to diagnose JavaScript errors

JavaScript errors cluster into package management (resolution conflicts, lockfile drift, native build failures), asynchrony (unhandled rejections, race conditions, wrong this), and memory (the V8 heap limit, which is a fixed ceiling rather than a leak indicator on its own). Because JavaScript coerces rather than throws, many bugs surface far from their cause. undefined is not a function usually means a bad import, not a bad call.

If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.

  1. For dependency errors, read what npm actually reports as the conflicting peer requirement. Reaching for --force or --legacy-peer-deps installs a tree you have not validated.
  2. Always attach a rejection handler: process.on('unhandledRejection', …) in Node, and check that every async function called from a non-async context has a .catch().
  3. Raise the V8 heap only after confirming it is a genuine working-set problem: node --max-old-space-size=4096. If usage grows without bound, take a heap snapshot instead.
  4. Use node --inspect with Chrome DevTools to take heap snapshots and compare allocations between two points in time.
  5. For native module build failures (node-gyp), confirm Python and a C++ toolchain are present and that the Node major version matches the module's prebuilt binaries.

Tools worth reaching for

  • node --inspect
  • npm ls <pkg>
  • node --max-old-space-size
  • clinic.js
  • why-is-node-running

Authoritative references

Primary documentation for this error, worth reading before applying any fix in production.

docs.npmjs.com

Related JavaScript errors

See all 42 JavaScript errors →

Browse other categories

Something missing or wrong?

This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.