Skip to main content

Your private Node.js registry.In one command.

Verdaccio is a free, open source Node.js registry that you run yourself. Publish your private packages, cache the public ones and keep using pnpm, npm or yarn. Built for local development, ready to host for your whole team.

Latest release6.xv6.10.5Oct 3, 2026Release notes →
  1. Startone command, no config
  2. Publisha private package
  3. Installprivate and public ones
my-app — your project$ pnpm config set registry http://localhost:4873/# log in once with pnpm login$ pnpm publish+ @verdaccio/ui@1.0.0$ pnpm add @verdaccio/uiProgress: resolved 1, reused 0, downloaded 1, added 1, done$ pnpm add reactProgress: resolved 1, reused 0, downloaded 1, added 1, done
verdaccio — the registry log$ pnpm dlx verdaccioinfo --- http address http://localhost:4873/http <-- 201, user: jane(127.0.0.1), req: 'PUT /@verdaccio%2fui', bytes: 4210/0http <-- 200, user: jane(127.0.0.1), req: 'GET /@verdaccio%2fui', bytes: 0/2310http <-- 200, user: jane(127.0.0.1), req: 'GET /@verdaccio/ui/-/ui-1.0.0.tgz', bytes: 0/18204http --> 200, req: 'GET https://registry.npmjs.org/react' (streaming)http <-- 200, user: jane(127.0.0.1), req: 'GET /react', bytes: 0/52184http <-- 200, user: jane(127.0.0.1), req: 'GET /react/-/react-19.2.6.tgz', bytes: 0/6411# react now lives in the cache: the next install does not leave your network
How it works

One registry in front of everything you install.

  1. Private packages are published to your registry and served from your own storage.
  2. Public packages are fetched once from npmjs.org, an uplink, and kept in the cache.
  3. Every next install comes from the cache: faster, and still available when the public registry has a bad day.
Your teampnpm · npm · yarnCI runnersverdaccio:4873PRIVATE@verdaccio/*storageCACHEemptyCACHEreacttarballUplinkregistry.npmjs.orgor any registryCACHE MISS → UPLINKCACHE HIT · NO UPLINKGET reactreact.tgzreact.tgzGET reactreact.tgz1 · First install: not in cache, fetched from the uplink2 · Tarball stored locally, then served to your client3 · Every next install: served from cache, the uplink is never touchedYour teampnpm · npm · yarn · CI runnersverdaccio:4873PRIVATE@verdaccio/*storageCACHEemptyCACHEreacttarballUplinkregistry.npmjs.org or any registryCACHE MISS → UPLINKCACHE HIT · NO UPLINKGET reactreact.tgzreact.tgzGET reactreact.tgz1 · First install: not in cache,fetched from the uplink2 · Tarball stored locally,then served to your client3 · Every next install is servedfrom cache. Uplink untouched
Two ways to run it

Built for local development. Ready to host as your registry.

Most people start on their own machine: test a publish, reproduce a CI run, try a package manager. When you need to share it, the same configuration runs as a hosted registry for your team.

START HERE

Local development

  • Test publishes and installs before they reach a real registry
  • Run end-to-end tests against real package managers
  • Zero config, no database, one command to start
  • Cached packages install without touching the network
$ pnpm dlx verdaccio → http://localhost:4873
Testing with Verdaccio →
HOSTED

Hosted registry

  • Host it on your own server, with one URL for your team and CI runners
  • Authentication with htpasswd or your own plugin
  • Storage on Amazon S3, Google Cloud Storage or a plugin of your own
  • Run it anywhere: official Docker image and Helm chart for Kubernetes
$ docker run -it -p 4873:4873 \ verdaccio/verdaccio
Run it with Docker →

A registry that stays out of your way.

No database to start: Verdaccio ships with its own small one. It proxies registries like npmjs.org, caches what you download, and plugs into storage such as Amazon S3 or Google Cloud Storage when you outgrow the disk.

01

Private packages

Keep your code private and keep using your package manager the way you already do. Scoped, access-controlled, yours.

02

Link registries

Chain several registries and fetch everything from one endpoint. One URL in every .npmrc.

03

Cache npmjs.org

Cut install latency in CI and keep limited failover when the public registry has a bad day.

04

Override public packages

Need a patched third-party dependency? Publish your fix under the same name, locally.

Discover more features →

Web interface

Browse what you publish.

Verdaccio ships with a web interface. Search your packages, read their README, copy the install command for your package manager and check versions, tags and dependencies, without leaving the browser.

  • Search and browse the packages in your registry
  • README, versions, tags, dependencies and uplinks for every package
  • Install commands for pnpm, npm and yarn, ready to copy
  • Login, dark mode and translations; your access rules apply to it too
Open source

Free, MIT licensed and built in the open.

Verdaccio is open source software. Read the code, run it anywhere, fork it, fix it. Everything happens in public on GitHub: the registry, its plugins, the Docker image and this website.

LICENSEMIT
  • MIT licensed. Use it at work and in commercial projects.
  • Public source. Registry, plugins, Docker image and docs live on GitHub.
  • Built by contributors. Issues, pull requests and plugins are welcome from anyone. Meet the contributors.
  • Community supported. Sponsors share the tools and services that keep it running. Become a sponsor.
Bring your own client

pnpm, npm, Yarn. One line to switch.

Point your package manager at Verdaccio and keep every command you already know.

$pnpm config set registry http://localhost:4873/
the whole server
storage: ./storage
auth:
  htpasswd:
    file: ./htpasswd
uplinks:
  npmjs:
    url: https://registry.npmjs.org/
packages:
  '@*/*':
    access: $all
    publish: $authenticated
    proxy: npmjs
  '**':
    access: $all
    proxy: npmjs
storage · where tarballs live
auth · htpasswd or plugins
uplinks · registries to proxy
packages · who reads, who publishes
Plugins

Verdaccio does the basics. Plugins do the rest.

Authentication, storage, middleware, the web interface and package filters can all be swapped or extended. Use one from the community or write your own.

98 plugins8 from the core team90 from the community
61

Authentication

Decide who can log in and publish.

verdaccio-htpasswdverdaccio-openid
16

Storage

Keep packages on S3, Google Cloud or your own backend.

verdaccio-aws-s3-storageverdaccio-google-cloud
15

Middleware

Add endpoints, metrics and hooks to the registry.

verdaccio-auditverdaccio-openmetrics
3

Theme UI

Replace or restyle the web interface.

@verdaccio/ui-themeverdaccio-oidc-ui
3

Filters

Hide or block versions before they are served.

verdaccio-plugin-secfilterverdaccio-plugin-delay-filter
Node API

Run Verdaccio from your own code.

Start a registry without the command line. runServer hands you a Node server that is not listening yet, so you choose the port and when to stop it. Ideal for end-to-end tests, embedded registries and tooling.

  • Typed configuration with ConfigBuilder, no YAML to keep in sync
  • A fresh storage per run, so nothing leaks between tests
  • Works with the same config you would use in production
runServer
import { runServer } from 'verdaccio';
import { ConfigBuilder } from '@verdaccio/config';

const config = ConfigBuilder.build()
  .addStorage('./storage')
  .addAuth({ htpasswd: { file: './htpasswd' } })
  .addUplink('npmjs', { url: 'https://registry.npmjs.org/' })
  .addPackageAccess('**', { access: '$all', proxy: 'npmjs' })
  .getConfig();

const app = await runServer(config);
const server = app.listen(4873); // you pick the port
// ...publish, install, assert...
server.close(); // and when to stop
DevOps, made easy

Ship it where you ship everything else.

An official Docker image and a Helm chart for Kubernetes, maintained alongside the core.

Docker

$ docker pull verdaccio/verdaccio $ docker run -it -p 4873:4873 verdaccio/verdaccio
Docker guide →

Kubernetes · Helm

$ helm repo add verdaccio https://charts.verdaccio.org $ helm install verdaccio/verdaccio
Helm chart →
Looking for a setup that already works?

The Verdaccio repository has runnable examples, including a local storage volume, nginx and Apache reverse proxies, S3 storage and GitHub OAuth.

Browse docker-examples →
Community supported

Powered by people and companies who share what they have.

Our sponsors provide the tools and free services that keep Verdaccio running, and contributors give their time. Want to be part of it?

Become a sponsor

Your own registry is one command away.