Vercel Agent now installs private packages from npm and custom registries
Vercel Agent can now pull private npm packages and custom registries—credentials stay sandboxed. What this means for your deployment pipeline.

Why it matters
Vercel Agent expands its dependency-resolution capability to include private npm packages and custom registries using team-shared environment variables, with credentials isolated from the agent sandbox. Practitioner relevance: enables more realistic agent workflows in Node.js environments without exposing secrets.
The key facts
12 to knowFeature: Vercel Agent now installs private dependencies from npm and custom registries
Authentication: npm, pnpm, and classic Yarn running in Agent sessions authenticate as they do in Vercel builds
Credential scope: Agent reads only team-shared variables, not project-scoped ones
Security model: Credential values stay outside the sandbox; agent cannot read them
Configuration: NPM_TOKEN for registry.npmjs.org; NPM_RC for custom or multiple registries
Docs reference: private dependencies docs available
Published: 30 September 2026
Feature: Vercel Agent installs private packages from npm and custom registries
Credentials stored as shared environment variables on Vercel (team-scoped, not project-scoped)
Support for npm, pnpm, and classic Yarn in Agent sessions
Credential values stay outside the sandbox—agent cannot read them
NPM_TOKEN for registry.npmjs.org; NPM_RC for custom/multiple registries
Go to the source
Vercel Blogvercel.com
Publisher excerpt: Vercel Agent can install private dependencies from npm and custom registries using credentials stored as shared environment variables on Vercel. , , and classic Yarn running in Agent sessions authenticate as they do in Vercel builds.npmpnpm To get started, add a for Development or Preview:shared…