Skip to content
All tool news

Tool desk · Updated daily

Tool news·Vercel·

Vercel Agent Installs Private Packages from Custom Registries.

Vercel Agent can now install private packages from npm and custom registries using shared environment variables for credentials.

CW

Create With tool desk

3 sources checked · 2 min read · 3 sections

ShareLinkedIn
Vercel Agent Installs Private Packages from Custom Registries

Vercel Agent can now install private packages from npm and custom registries. Agent sessions authenticate through credentials held in Vercel shared environment variables, bringing private dependencies into the same workflow as public packages.

According to the Vercel changelog, the update works with npm, pnpm and classic Yarn. Each package manager authenticates as it does during a Vercel build.

That means an Agent session can install an organisation’s internal component library, shared configuration package or other private dependency when working on a project. The required credentials remain outside the Agent sandbox.

How Vercel Agent installs private packages

There are two supported routes. For a private package hosted on registry.npmjs.org, add an NPM_TOKEN shared environment variable. For a custom registry, or a setup that uses several registries, add the registry configuration through NPM_RC.

The variable must be shared with the team and assigned to the Development or Preview environment. Vercel Agent does not read project-scoped environment variables.

  1. 1

    Choose the environment

    add the shared variable to Development or Preview

  2. 2

    Set npm credentials

    use NPM_TOKEN for private packages on registry.npmjs.org

  3. 3

    Configure other registries

    use NPM_RC for custom or multiple registries

  4. 4

    Start the session

    npm, pnpm or classic Yarn authenticates during installation

This setup separates the credential from the Agent’s working environment. The package manager receives the authentication it needs, while the credential value stays outside the sandbox.

Team-shared credentials are required

The distinction between team-shared and project-scoped variables affects existing Vercel projects. A token already stored against one project will not become available to Vercel Agent through this update. It needs to be added as a shared environment variable for the relevant team and environment.

Using NPM_RC also covers projects that pull dependencies from more than one registry. The configuration can describe the required registries, while Vercel supplies it to npm, pnpm or classic Yarn during the Agent session.

For teams whose applications rely on private packages, the Agent can now work with those dependencies without placing registry credentials inside its sandbox. The authentication method also matches the one used by Vercel builds, rather than introducing a separate package setup for Agent sessions.

Frequently asked questions

What is private package support in Vercel Agent?

It lets Agent sessions install private dependencies from npm or custom package registries. Credentials are supplied through team-shared environment variables and remain outside the Agent sandbox.

Which package managers support private packages in Vercel Agent?

The update supports npm, pnpm and classic Yarn. They authenticate in Agent sessions in the same way they do during Vercel builds.

Which Vercel plan includes private package support?

The changelog does not state which plans include the feature. It requires access to team-shared environment variables for Development or Preview.

Sources

3 checked

How we cover tool news: Create With's tool desk drafts these reports with AI from the sources listed above and checks them against those sources before publishing.

Worth passing on?

ShareLinkedIn

Go deeper on Vercel

Related reading, watching and going.

Everything on Vercel →

The briefing

19 May 2026

How to Migrate Your App from Lovable to Claude Code in 2025

Step-by-step guide to migrating your Lovable app to Claude Code. Learn how to move from Lovable's managed platform to a stack you own and control.

Read →

The briefing

10 Feb 2026

OpenClaw Review: 2 Weeks With This AI Agent

Honest 2-week review of OpenClaw — an autonomous AI agent powered by Claude. We test setup, safety, autonomy, and real value to see if it's worth using.

Read →
34 min

Podcast

My Daughter Built a Website Business, Claude Design First Look & Going All-In on Cloudflare

James and Kieran discuss practical AI-powered development through real-world examples, including a seven-year-old building a website business with Claude Code voice mode, Anthropic's new Claude Design tool, API security challenges in the AI agent era, and Cloudflare's expanding AI infrastructure offerings. The episode covers hands-on experiences with vibe coding, emerging design tools, and the evolving landscape of AI-assisted development.

Watch now ↗

Podcast

53. Why Your Vibe Code Needs Tests, Ditching SaaS & AI Agents That Work While You Sleep

James and Kieran discuss the practical realities of building AI-powered software, emphasizing the importance of testing in vibe-coded applications, exploring alternatives to traditional SaaS tools, and implementing autonomous AI agents for business operations. The episode covers technical topics like Convex databases, app store bottlenecks from AI-generated submissions, and using OpenClaw as a marketing automation agent.

Watch now ↗
38 min

Podcast

52. Your AI Co-Founder: OpenClaw, Manus & the Zero-Person Business

In this Create With podcast episode, James and Kieran are joined by Matt Roberts from Happy Operators for an in-depth discussion on using autonomous AI agents in production. The conversation covers practical experiences with OpenClaw, security considerations, comparison with emerging tools like Manus, and the broader shift toward AI-assisted development. They also discuss the VibeCoding Olympics results, Bubble's new AI capabilities, and research on Claude.MD file effectiveness.

Watch now ↗

Latest tool news

What else changed this week.

All tool news
MakeDigest

What Make Shipped in Early October

Make shipped a small but useful reliability update for people building automations in the editor. This one is about protecting work in progress, following broader recent changes…

The Create With Briefing

Don't watch forty changelogs. Read one email.

Every Tuesday: the tool changes worth knowing, real business use cases, and what's on near you. Free, unsubscribe any time.