Where Are npm's Config and Cache Files?
Where npm keeps its per-user, per-project and global .npmrc files, plus the cache folder, and the command that prints the real path.
Last updated
npm reads four .npmrc files in a fixed order: one in the project you are working on, one in your home folder, a global one tied to npm's prefix, and the file bundled with npm itself. Project values win, then user, then global.
The cache is a separate folder and it gets large. Ask rather than guess: npm config get cache prints the path npm is really using on that machine, which is worth doing because Windows defaults somewhere else than macOS and Linux, and npm has moved it between major versions.
Where npm stores this, by platform
%USERPROFILE%\.npmrc
That is the per-user file, typically C:\Users\[Username]\.npmrc. The global file is %APPDATA%\npm\etc\npmrc, because npm's prefix on Windows defaults to %APPDATA%\npm. Cache lives at %LOCALAPPDATA%\npm-cache, and a project's own .npmrc sits next to its package.json.
~/.npmrc
The global config is $PREFIX/etc/npmrc, which works out to /usr/local/etc/npmrc on a standard install. The cache folder is ~/.npm. Any .npmrc at the root of a project overrides both for that project.
~/.npmrc
Global config: $PREFIX/etc/npmrc, usually /usr/local/etc/npmrc. Cache: ~/.npm. Distribution packages can pick a different prefix, so npm config get globalconfig and npm config get cache are the honest answer.
Frequently asked questions
Where does the npm cache live?
Run npm config get cache. It is %LOCALAPPDATA%\npm-cache on Windows (C:\Users\[Username]\AppData\Local\npm-cache) and ~/.npm on macOS and Linux. Deleting the folder is safe, npm just re-downloads what it needs.
Where does npm install global packages?
Into npm's prefix: %APPDATA%\npm on Windows, /usr/local/lib/node_modules elsewhere, with the executables in the matching bin folder. npm config get prefix prints yours, and the global npmrc sits in an etc folder under that same prefix.
What is the .npmrc in my project folder?
A per-project config that sits beside package.json and overrides your user file for that project: registry URLs, publish access, scoped tokens. npm ignores it in global mode (npm install -g), and it should not hold secrets if you commit it.
Notice an outdated path? Let us know.