Before you act
- Confirm that the scope matches your case.
- Keep recommendations, enforced limits, exceptions, and unstated details distinct.
- Open the official source before relying on the rule for a consequential decision.
Source-backed platform rule
npm caps one granular token at a combined 50 packages and scopes and binds the token to its user's permissions.
RuleRoster is independent and is not affiliated with or endorsed by npm.
Direct answer
One granular access token can access up to 50 packages and scopes combined—packages, scopes, or a mixture totaling 50—and cannot exceed its user's permissions. The reviewed source does not state an over-limit response or exception.
Published evidence
One granular access token can access a combined total of up to 50 packages and scopes: packages, scopes, or a mixture totaling 50. Its permissions cannot exceed the user's permissions. The reviewed source does not state an over-limit response or exception.
Service: npm. Rule group: access-token quotas. Scope: package and scope access for one granular access token. Policy version and effective dates: not stated.
Evidence trail
npm · verified August 14, 2026
npm product documentation by GitHub, Copyright 2020 GitHub. Source: https://github.com/npm/documentation/tree/26eacbbb613ca0a6c68798b8754595f8e6019164. Licensed under Creative Commons Attribution 4.0 International: https://github.com/npm/documentation/blob/26eacbbb613ca0a6c68798b8754595f8e6019164/LICENSE. Modified by RuleRoster: RuleRoster extracted and restructured facts into typed rule fields and concise answers. Verified 2026-08-14. No endorsement by npm or GitHub is implied. The Creative Commons license does not license trademark or patent rights.
Interpretation and accountability
If the source or summary appears wrong, submit precise evidence for human review.