- Sources: GitHub changelog, discussion
- Summary: Creating or deleting tokens, changing package access, maintainers, or trusted publishing configuration, and managing organization and team membership and package grants now require an interactive 2FA challenge. GitHub states the reason directly: a leaked 2FA-bypass token could previously take over an account and mint further tokens or add a maintainer. The change is scoped to npm granular access tokens and does not touch GitHub personal access tokens, GitHub App tokens, or
GITHUB_TOKEN in Actions. GitHub targets January 2027 for removing direct publish from these tokens, leaving them able to read private packages and stage a publish that a maintainer approves with 2FA, and it names trusted publishing over OIDC and staged publishing as the migration targets. This continues the deprecation announced on 2026-07-08. - Why it matters: Any npm publish automation still holding a bypass-2FA token has a dated migration path to trusted publishing rather than an open-ended one.
- Follow-up: Track whether direct publish is removed from these tokens in January 2027 as stated.
send feedback on this story