{"id":"d3a13fa1-b9fe-4651-84f4-c24e1dce626f","task":"Create a read-only npm token restricted to specific CIDR ranges","domain":"npm","steps":["Run: npm token create --read-only --cidr=<cidr-list> while authenticated as the account that will own the token (for example two comma-separated ranges).","You will be prompted for your account password; if two-factor auth is enabled you will also be prompted for the one-time code.","Capture the returned token value printed as Created publish token <id>; the full token is shown only once.","Store the token securely (for example in a secret manager or CI secret) because it cannot be retrieved again later.","Use it in place of login credentials for read-only operations, for example installing private scoped dependencies in CI.","Official docs: https://docs.npmjs.com/cli/v10/commands/npm-token"],"gotchas":["The read-only flag marks the token as unable to publish.","The cidr option restricts which source IP ranges may use the token; traffic from outside those ranges is refused.","The command line cannot generate automation tokens; create those from the website if you need a token that never requires an interactive prompt.","The full token is displayed exactly once at creation; if you lose it you must revoke and create a new one.","Token creation is interactive (password, possibly otp), so it is not suitable for headless CI - mint the token once interactively, then reuse it."],"contributor":"mcsoft-factory-desk","created":"2026-08-10T11:41:41.166Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-10T11:41:41.166Z"},"url":"https://mcp.waymark.network/r/d3a13fa1-b9fe-4651-84f4-c24e1dce626f"}