npm-registry-mcp-server
Provides tools for querying the npm registry, including fetching package metadata and listing published versions and dist-tags.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@npm-registry-mcp-serverWhat are the latest versions of express?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
npm-registry-mcp-server
MCP server for npm registry package metadata lookups, powered by
package-json
A production-ready Model Context Protocol server that lets MCP clients (Claude Desktop, Claude Code, MCP Inspector, …) query the npm registry.
Registry access is delegated entirely to package-json@10.0.1, so behaviour matches npm itself:
.npmrc resolution, scoped packages, private registries, bearer/basic auth, dist-tags, and full
semver range resolution all work out of the box.
Transport: stdio (JSON-RPC over stdin/stdout)
Validation: zod on every tool input
Monitoring: Sentry initialized before the server starts
Requirements
Node.js >= 18.19.0.
package-json, @sentry/node, and @modelcontextprotocol/sdk all declare node: >=18. This
project raises the floor to 18.19.0 because ESM preloading via node --import — how Sentry is
loaded ahead of everything else — was added in 18.19.0.
Related MCP server: MCP Server for NPM Package Info
Install
git clone https://github.com/yuchen814/npm-registry-mcp-server.git
cd npm-registry-mcp-server
npm install
npm run buildConfiguration
Variable | Required | Description |
| No | Sentry DSN. When unset, Sentry is initialized in a disabled state and the server runs normally. |
| No | Falls back to |
| No | Release identifier for grouping issues. |
| No |
|
Copy .env.example as a starting point. The DSN is only ever read from the environment — it is
never hardcoded.
Registry URL and credentials are not configured here. package-json reads them from your
.npmrc exactly like npm does, which is what makes private and scoped packages work.
Usage
npm start # builds, then: node --import ./dist/instrument.js ./dist/server.js
npm run dev # tsx server.ts (no build step)
npm run typecheck # tsc --noEmitInspect it interactively
npx @modelcontextprotocol/inspector npx tsx ./server.tsRegister with an MCP client
{
"mcpServers": {
"npm-registry": {
"command": "node",
"args": [
"--import",
"/absolute/path/to/npm-registry-mcp-server/dist/instrument.js",
"/absolute/path/to/npm-registry-mcp-server/dist/server.js"
],
"env": {
"SENTRY_DSN": "https://examplePublicKey@o0.ingest.sentry.io/0"
}
}
}
}Tools
get_npm_package_metadata
Fetch metadata for a package. Arguments mirror the package-json API one-to-one.
Argument | Type | Default | Description |
|
| — | Required. npm package name. Scoped names supported ( |
|
|
| Exact version, dist-tag, or semver range: |
|
|
| Return the full metadata document rather than the abbreviated one. |
|
|
| Return the registry's main entry containing all versions. Takes precedence over |
|
| auto-detected | Registry override. Intended for internal tooling only — prefer |
|
|
| Omit deprecated versions. An explicit version or dist-tag is still returned even if deprecated. |
Structured output: packageName, requestedVersion, resolvedVersion, fullMetadata,
allVersions, omitDeprecated, registryUrl, and the raw metadata document.
// { "packageName": "package-json", "version": "10.0.1" }
// -> resolvedVersion: "10.0.1", metadata: { name, version, dependencies, dist, ... }list_npm_package_versions
List published versions and dist-tags, newest first.
Argument | Type | Default | Description |
|
| — | Required. npm package name. |
|
|
| Max versions to return (1–1000). |
|
| auto-detected | Registry override. |
Structured output: packageName, totalVersions, versions, distTags, latest, truncated.
Error handling
The two error classes from package-json are treated as expected outcomes, not defects:
PackageNotFoundError— the package name does not existVersionNotFoundError— no version satisfies the request (possibly becauseomitDeprecatedfiltered it out)
Both are returned to the client as tool errors and recorded as Sentry breadcrumbs only. Everything else — DNS/network failures, registry 5xx, auth problems, bugs — is captured to Sentry with the tool name, package name, and a local-variable-enriched stack trace, then returned as a tool error. The server never crashes on a failed lookup.
Notes for contributors
stdout is the MCP protocol channel. Never console.log from this server — all diagnostics go to
stderr, and Sentry's debug option is pinned to false for the same reason.
Sentry is loaded two ways so it is always initialized before the server:
node --import ./dist/instrument.js(used bynpm start) — preferred, lets the SDK instrument Node internalsas the first
importinserver.ts— sotsx server.tsis instrumented too
instrument.ts guards against double initialization.
License
MIT
Available Tools
2 toolsget_npm_package_metadataGet npm package metadataARead-onlyIdempotent
Fetch metadata for a package from the npm registry. Requires a package name and optionally accepts a version, dist-tag, or semver range (defaults to "latest"). By default an abbreviated metadata document is returned for performance; set fullMetadata to true for the complete document. Set allVersions to true to get the registry's main entry containing every version (this takes precedence over version). Works with scoped and private packages, honouring .npmrc registry and auth settings.
| Name | Required | Description | Default |
|---|---|---|---|
| version | No | Optional version, dist-tag, or semver range. Defaults to "latest". Examples: "1.0.0", "next", "1" (latest 1.x.x), "1.2" (latest 1.2.x), "^1.2.3", "~1.2.3". | |
| allVersions | No | Return the registry's main entry containing all versions. Overrides `version`. | |
| packageName | Yes | npm package name. Scoped packages are supported, e.g. "@sindresorhus/df". | |
| registryUrl | No | Optional registry URL override. Defaults to the registry inferred from npm defaults and .npmrc. Intended for internal tooling only. | |
| fullMetadata | No | Return the full metadata document instead of the abbreviated one. Slower but complete. | |
| omitDeprecated | No | Omit versions marked deprecated on the registry. An explicit version or dist-tag is still returned even when deprecated. |
Output Schema
| Name | Required | Description |
|---|---|---|
| metadata | Yes | Raw metadata document from the registry. |
| allVersions | Yes | |
| packageName | Yes | |
| registryUrl | No | |
| fullMetadata | Yes | |
| omitDeprecated | Yes | |
| resolvedVersion | No | |
| requestedVersion | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover read-only, open-world, and idempotent behavior. The description adds valuable non-obvious behaviors: default 'latest' version, abbreviated vs. full metadata, allVersions precedence, and .npmrc auth/registry handling. This goes beyond the structured annotations, though it doesn't cover error cases or rate limits.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is 3 sentences, front-loaded with the core purpose, then details key options and edge cases. Every sentence adds information, with no fluff or repetition of schema descriptions.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, returning values need not be explained. The description covers the tool's main behavioral facets: version selection, metadata format, allVersions precedence, and support for scoped/private packages with .npmrc. Minor gaps like error handling are not critical given the read-only nature and available schema.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with detailed parameter descriptions, so the baseline is 3. The description enriches semantics by explaining the relationship between fullMetadata and allVersions, and the performance implications of abbreviated vs. full documents. It adds value beyond the schema's per-field descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb and resource: 'Fetch metadata for a package from the npm registry.' It clearly distinguishes from the sibling tool (list_npm_package_versions) by focusing on metadata retrieval, not just version listing. The additional details about version selection and metadata formats reinforce scope.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides clear context on how to use the tool: default to 'latest', options for fullMetadata and allVersions, with precedence noted. It does not explicitly mention when to use this tool over list_npm_package_versions, but the usage context is otherwise strong. Missing explicit exclusions or alternatives drops it slightly from a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_npm_package_versionsList npm package versionsARead-onlyIdempotent
List published version numbers and dist-tags for a package from the npm registry, newest first. Useful for checking what versions exist before requesting metadata for a specific one.
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum number of versions to return, newest first. `totalVersions` always reports the untruncated count. | |
| packageName | Yes | npm package name. Scoped packages are supported, e.g. "@sindresorhus/df". | |
| registryUrl | No | Optional registry URL override. Defaults to the registry inferred from npm defaults and .npmrc. Intended for internal tooling only. |
Output Schema
| Name | Required | Description |
|---|---|---|
| latest | No | |
| distTags | Yes | Map of dist-tag to version. |
| versions | Yes | Published versions, newest first. |
| truncated | Yes | |
| packageName | Yes | |
| totalVersions | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, openWorldHint, and idempotentHint, so the safety profile is covered. The description adds 'newest first' and the inclusion of dist-tags, which are useful behavioral details, but does not disclose potential edge cases (e.g., registryUrl behavior, error conditions). This matches the baseline for a well-annotated read-only tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, front-loaded with the core action, and every clause carries meaning. There is no redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple read-only listing tool with strong annotations, a complete parameter schema, and an output schema (present but not shown), the description is sufficient. It explains the primary use case and the result ordering, while the schema and annotations cover the remainder.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema fully documents all three parameters. The description does not add parameter-level detail beyond what the schema provides; it only reinforces the 'newest first' ordering already mentioned in the limit parameter's description. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('List') and resource ('published version numbers and dist-tags for a package from the npm registry'), and adds the 'newest first' ordering. It also signals the sibling relationship by noting this is useful before requesting metadata, distinguishing it from get_npm_package_metadata.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides clear context: 'Useful for checking what versions exist before requesting metadata for a specific one.' This implies when to use the tool versus fetching metadata, though it does not explicitly name the sibling or state exclusions. It is sufficient guidance without being overly prescriptive.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
2 tool updates
v1.0.0- First observed
get_npm_package_metadata - First observed
list_npm_package_versions
TDQS
Scored across 2 tools
The two tools have clearly distinct primary purposes: fetching metadata for a package (or specific version) versus listing available versions and dist-tags. While get_npm_package_metadata with allVersions can also return version information, the descriptions make the intended use of each tool unambiguous.
Both tool names follow a consistent verb_noun pattern with snake_case: get_npm_package_metadata and list_npm_package_versions. The verbs 'get' and 'list' are appropriate for their respective operations, and the naming is predictable and uniform.
With only 2 tools, the server feels slightly thin for an npm registry surface, as it could reasonably include operations like search or package file downloads. However, the narrow read-only metadata focus makes this count defensible and not excessive.
The server covers the core read-only operations for npm package metadata: retrieving metadata (with version, tag, or range options) and listing available versions. Minor gaps exist, such as no direct search or readme retrieval, but these are not essential for the stated purpose of querying package information.
Maintenance
Related MCP Connectors
Dive into the world of npm with our NPM Package Info MCP. Access crucial metadata about any npm
npm MCP — wraps the npm Registry API (free, no auth)
PyPI MCP — wraps the Python Package Index (PyPI) JSON API (free, no auth).
Related MCP Servers
- AlicenseAqualityDmaintenanceMCP server to search npm packages, view details, compare, check downloads, and inspect dependencies.632 npmMIT
- FlicenseNot gradedqualityDmaintenanceProvides a tool to fetch npm package information via the Model Context Protocol.8-
- AlicenseAqualityBmaintenanceFetches npm package READMEs, metadata, and search results for MCP-compatible AI clients.311 npmMIT
- FlicenseNot gradedqualityCmaintenanceProvides a tool to fetch npm package information via MCP. Enables AI agents to retrieve structured package details using the getNpmPackageInfo tool.-