Skip to main content
The managed registry gives your workspace its own private npm registry, hosted inside Vibely. You can publish packages to it without making them public, and any project in your workspace can install them.
Managed registry
Workspace owners and admins manage access tokens. Other members can see the registry’s scope, URL, and published packages.
Open the managed registry from Settings → Build & deploy → Managed registry.

Why use a managed registry

Teams often keep shared code, such as a design system, utility functions, or an internal API client, in private npm packages that shouldn’t be public. With a managed registry you can:
  • Install internal packages in Vibely projects without running your own registry.
  • Keep proprietary code private.
  • Reuse versioned internal libraries consistently across projects.

Common use cases

  • Internal component libraries: install your organization’s UI components in Vibely projects.
  • Shared utilities: reuse validation, formatting, or data-fetching code across projects.
  • Internal SDKs: install API clients that can’t be published publicly.

Prerequisites

  • The Enterprise plan.
  • The owner or admin role to issue tokens.

Your scope

Your registry publishes into one npm scope, taken from your workspace’s slug. A workspace with the slug acme publishes packages named @acme/.... The scope can’t be chosen, which is what stops one workspace from publishing into another’s namespace. If your workspace has no valid slug, the page says the registry has no scope yet. Rename the workspace in Settings → Workspace settings to create one.
Renaming your workspace changes your npm scope. Packages already published under the old scope stay there, and new ones go to the new scope. Rename before you publish, not after.

Set up the managed registry

1

Open the registry settings

Go to Settings → Managed registry. The page shows your Scope and Registry URL, with buttons to copy each.
2

Issue an access token

Under Access tokens, choose a Capability, give the token a name, and select Issue token. Copy the token right away. It’s shown once and can’t be retrieved again.
A publish token can ship code into every project in your workspace. Give publish tokens to CI only, and use read tokens everywhere else.
3

Publish a package

In your package’s own repository, add the .npmrc snippet from the settings page, set NPM_TOKEN to a publish token in your CI environment, and run npm publish. The package name must start with your scope.

View published packages

Published packages appear under Published packages on the same settings page, with how many versions each has and when it was last updated.

Use a private package in a project

To install from the registry, your projects need a read token.
1

Store a read token as a build secret

In Settings → Build secrets, add a build secret named NPM_TOKEN whose value is a read token.
2

Point your scope at the registry

In the Package registries card on the same page, select Add registry. Enter your scope, paste the Registry URL, and choose NPM_TOKEN as the token. Vibely keeps the matching .npmrc block in every project in the workspace.
3

Ask for the package

Prompt the agent with the package name, just like a public package:
The .npmrc block references the token by name, so it’s never written into your project’s files:

Rotate or revoke a token

Tokens can’t be edited in place. To rotate one:
1

Issue a replacement

Same capability, with a name that says what it’s for.
2

Update where it's used

Replace the value of the build secret, or your CI variable, that holds the old token.
3

Revoke the old token

Select Revoke next to it. Installs and publishes using it start failing immediately, which shows you anything you missed.
Each token shows its prefix and when it was last used, so you can tell which ones are still active.

Limits

FAQ

Yes, once the scope is added under Package registries with a read token. Every project in the workspace gets the same .npmrc block.
No. A version can be published once. Publish a new version instead.
You don’t need the managed registry. Add that registry’s token as a build secret and add the registry under Package registries.

Build secrets

Where your registry token lives.

npm packages

How Vibely installs packages.

Workspace settings

Everything else admins control.

Vibely for Enterprise

What the Enterprise plan includes.