Home
DevSecOps
Polyglot teams
Marketplace platforms
Unified registries
Supply-chain security
Self-hosted
Access control
Pricing
Docs
Blog
Registries
Compare
Terms of Service
Privacy Policy
Personal access tokens API
PATs authenticate package managers and other registry clients. Management API calls still use JWT.
Solutions
Self-hosted package registry for DevSecOps
Unified package registry for polyglot teams
Package registry for multi-vertical platforms
Product
Unified multi-ecosystem package registries
OSV vulnerability scanning for package registries
Self-hosted package registry on your infrastructure
SSO, PATs, and org RBAC for package registries
Self-hosted registries
Self-hosted package registries
Self-hosted npm registry
Self-hosted Composer registry
Self-hosted Docker registry
Self-hosted PyPI registry
Self-hosted Go module registry
Self-hosted Cargo registry
Self-hosted Maven registry
Self-hosted RubyGems registry
Self-hosted Conan registry
Self-hosted multipurpose artifact registry
Documentation
Quickstart
Install with Docker Compose
Install with Helm
Install with Ansible
Install on AWS, Azure, or DigitalOcean
Core concepts
Registries
Vulnerability scanning
Single Sign-On (SSO)
API reference
Latest from the blog
When npm audit Goes Down: Why External Security APIs Break Your CI/CD
3CX and the trust you never audited: controlling what enters your software supply chain
A package in your inventory just went malicious—what you do in the first hour
Install protection is a policy, not a scanner checkbox
Your coding agent still talks to the public registry