npm

Search the npm registry for packages, versions, and metadata.

Works with: Claude DesktopClaude CodeCursor

Community server · details last checked

Quick install
npx -y npm-mcp-server

How to install the npm MCP server

Add this to your Claude Desktop MCP configuration:

{
  "mcpServers": {
    "npm": {
      "command": "npx",
      "args": [
        "-y",
        "npm-mcp-server"
      ]
    }
  }
}

Add this to your Claude Code MCP configuration:

npx -y npm-mcp-server

Add this to your Cursor MCP configuration:

{
  "mcpServers": {
    "npm": {
      "command": "npx",
      "args": [
        "-y",
        "npm-mcp-server"
      ]
    }
  }
}

Built by ContextBoltThis directory is built by ContextBolt: MCP-native memory and SEO tools that run alongside npm in the same client.

Explore ContextBolt

The npm MCP server gives an agent live access to the npm registry: package metadata, version history, dependencies and publish dates. It is a small server that fixes a specific and irritating failure mode, which is a model confidently recommending a version that does not exist.

What it actually does

The server queries the public registry and returns package information. The agent can search for packages, read the metadata for a specific one, list available versions and their publish dates, and inspect declared dependencies. No authentication is required for public packages.

Practical patterns:

  • ‘What is the current version of this package, and when was it last published?’
  • ‘This dependency has not been updated in two years. What are the maintained alternatives?’
  • ‘What does this package pull in transitively?‘

Why use it

A model’s knowledge of the npm ecosystem is a snapshot from training time, and npm changes constantly. Packages get deprecated, maintainers hand over, versions move. Advice based on a frozen snapshot is subtly wrong in ways that waste an afternoon. Giving the agent the live registry means version numbers and maintenance status are checked rather than recalled.

Gotchas

Registry metadata tells you when something was published, not whether it is any good or safe. Publish recency is a weak proxy for health and an actively malicious package looks fine in metadata, so this is not a substitute for a security tool or for reading the source of anything you are about to trust. Transitive dependency trees also get large fast; ask for the direct dependencies unless you genuinely want the whole graph in your context window.

Built by ContextBolt

This directory is built by ContextBolt

We build MCP-native tools that give your AI the context it cannot reach on its own. Bookmarks turns your saved posts into agent-queryable memory. SEO puts live keyword and ranking data inside Claude. Both run alongside npm in the same client.

Explore the products →

npm MCP server: FAQs

Does it need authentication?

Not for public registry data. Private registries are a different matter and depend on the implementation.

Why not just let the model tell me?

Because a model's package knowledge is frozen at training time and npm moves weekly. Asking the registry is the difference between the current version and a plausible old one.

Can it check for vulnerabilities?

It reads registry metadata rather than an advisory database. Use npm audit or a dedicated security tool for that.

Does it install anything?

No, it reads metadata. Installation stays with you, which is the right boundary.