When you have two-factor access enabled on your account, and you lose access to your 2FA device, you may be able to recover your account using the following methods.
When you use a recovery code to log in, npm places a temporary 72-hour security hold on your account. The hold expires automatically 72 hours after it begins and is not extended if you use another recovery code during that period.
While the security hold is active, you can:
You cannot:
The security hold cannot be lifted early and expires automatically after 72 hours, with no action required. If you did not use a recovery code, contact npm Support immediately because your account may have been compromised.
If you have misplaced the device that provided second-factor authentication, you can use the recovery codes generated when you enabled 2FA to access your account.
Locate the recovery codes generated that you have saved.
Enter an unused recovery code in the "Use a Recovery Code" prompt.
You are now logged into npm.
Note: Once you regenerate a set of code, all previous recovery codes become invalid. Each code can be used only once.
On the account settings page, under "Two-Factor Authentication", click Modify 2FA.
Click "Manage Recovery Codes" to view your recovery codes.
Click "Regenerate Code" to generate a new set of codes.
If you have misplaced both your 2FA device and your recovery codes, you can contact our support team to attempt to recover your account. Provide as much information as possible to help us expedite the request faster.
Under the "Use a Recovery Code" form, click Try recovering your account.
If you have access to your registered email, enter the one-time password sent to your email in the One-Time Password field, then click Verify Email Address. If you do not have access to your registered email, select Skip email verification at the bottom of the form.
In the How can we help? section, select Reset my two-factor authentication (2FA).