- Use Node.js v24. Trusted Publishing does not work on earlier versions of Node.js.
- Go to "Account > Access Tokens" and click "Generate Access Token".
- Give the new token "read and write" persmissions to "All packages".
- If you have 2FA enabled on npm (which you should), check the "Bypass 2FA" checkbox neatly hidden in the UI. Otherwise, npm will fail with an error demanding an OTP during automatic publishing.
- Create the token.