
Vercel Agent can now install private packages from npm and custom registries. Agent sessions authenticate through credentials held in Vercel shared environment variables, bringing private dependencies into the same workflow as public packages.
According to the Vercel changelog, the update works with npm, pnpm and classic Yarn. Each package manager authenticates as it does during a Vercel build.
That means an Agent session can install an organisation’s internal component library, shared configuration package or other private dependency when working on a project. The required credentials remain outside the Agent sandbox.
How Vercel Agent installs private packages
There are two supported routes. For a private package hosted on registry.npmjs.org, add an NPM_TOKEN shared environment variable. For a custom registry, or a setup that uses several registries, add the registry configuration through NPM_RC.
The variable must be shared with the team and assigned to the Development or Preview environment. Vercel Agent does not read project-scoped environment variables.
- 1
Choose the environment
add the shared variable to Development or Preview
- 2
Set npm credentials
use NPM_TOKEN for private packages on registry.npmjs.org
- 3
Configure other registries
use NPM_RC for custom or multiple registries
- 4
Start the session
npm, pnpm or classic Yarn authenticates during installation
This setup separates the credential from the Agent’s working environment. The package manager receives the authentication it needs, while the credential value stays outside the sandbox.
Team-shared credentials are required
The distinction between team-shared and project-scoped variables affects existing Vercel projects. A token already stored against one project will not become available to Vercel Agent through this update. It needs to be added as a shared environment variable for the relevant team and environment.
Using NPM_RC also covers projects that pull dependencies from more than one registry. The configuration can describe the required registries, while Vercel supplies it to npm, pnpm or classic Yarn during the Agent session.
For teams whose applications rely on private packages, the Agent can now work with those dependencies without placing registry credentials inside its sandbox. The authentication method also matches the one used by Vercel builds, rather than introducing a separate package setup for Agent sessions.
Frequently asked questions
What is private package support in Vercel Agent?
It lets Agent sessions install private dependencies from npm or custom package registries. Credentials are supplied through team-shared environment variables and remain outside the Agent sandbox.
Which package managers support private packages in Vercel Agent?
The update supports npm, pnpm and classic Yarn. They authenticate in Agent sessions in the same way they do during Vercel builds.
Which Vercel plan includes private package support?
The changelog does not state which plans include the feature. It requires access to team-shared environment variables for Development or Preview.
Sources
3 checkedHow we cover tool news: Create With's tool desk drafts these reports with AI from the sources listed above and checks them against those sources before publishing.







