---
title: Staged publishing for npm packages
---
Staged publishing adds an approval step before packages go live on the npm registry. Instead of publishing directly with `npm publish`, you can submit packages to a staging area with `npm stage publish`. A maintainer must then review and explicitly approve the staged package — with two-factor authentication (2FA) via the CLI or [npmjs.com](https://www.npmjs.com) — before it becomes publicly available.
Staged publishing is useful when you want an extra review step before a package version becomes available on the registry.
You can use staged publishing for both new and existing packages. When you stage a package that does not yet exist, npm publishes a placeholder version of the package with the version `0.0.0-stage`. This placeholder version is publicly available, but the staged version and its contents are not publicly available until a maintainer approves the staged package. After approval, the staged version is published to the package page.
**Note:** Staged publishing requires [npm CLI](https://docs.npmjs.com/cli/v11) version 11.15.0 or later and Node version 22.14.0 or higher.
## How staged publishing works
Staged publishing has three steps:
1. [Stage a package](#stage-a-package)
2. [Review a staged package](#review-a-staged-package)
3. [Approve a staged package](#approve-a-staged-package)
## Prerequisites
Before using staged publishing, ensure the following:
- You have **publish access** to the package
- **2FA is enabled** on your npm account
## Stage a package
1. On the command line, navigate to the root directory of your package.
```
cd /path/to/package
```
2. To stage your package, run:
```
npm stage publish
```
This submits your package to a staging area.
**Note:** `npm stage publish` does not require 2FA.
## Review a staged package
After you stage a package, you can inspect it in the CLI or on [npmjs.com](https://www.npmjs.com).
#### Using the CLI
To list staged packages you have access to:
```
npm stage list []
```
To view details for a specific staged package:
```
npm stage view
```
To download the staged package tarball for inspection:
```
npm stage download
```
#### Using npmjs.com
Open the **Staged Packages** tab to review staged packages and find the package you want to approve.
## Approve a staged package
To publish a staged package to the registry, approve it with 2FA.
#### Using the CLI
To approve a staged package and publish it to the live registry:
```
npm stage approve
```
#### Using npmjs.com
On [npmjs.com](https://www.npmjs.com), review the staged package in the **Staged Packages** tab, then click **Approve**.
**Note:** You will be prompted for 2FA verification whether you approve the package in the CLI or on [npmjs.com](https://www.npmjs.com).
## Using staged publishing with trusted publishers
If you use [trusted publishing (OIDC)](/trusted-publishers) from CI/CD, you can use staged publishing to submit a package for review before it goes live. A maintainer must still review and approve the staged package with 2FA.
For more information on configuring trusted publisher permissions, see "[Trusted publishing for npm packages](/trusted-publishers#configuring-allowed-actions)."
## Learn more
- [Trusted publishing for npm packages](./trusted-publishers)
- [Generating provenance statements](./generating-provenance-statements)