> ## Documentation Index
> Fetch the complete documentation index at: https://docs.endorlabs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure Package Firewall credentials for CI/CD

> <Badge color="green">Beta</Badge> <br /> Store your Package Firewall API key and API secret as CI/CD secrets, and configure uv, npm, pnpm, and Poetry to install from lockfiles in your pipelines.

export const YamlTable = ({children, data: propData, content}) => {
  const KV_RE = /^([A-Za-z][A-Za-z0-9_()/#\s-]+?):\s*(.+)$/;
  const INLINE_MD_RE = /(\[([^\]]+)\]\(([^)]+)\))|(`([^`]+)`)|(\*\*([^*]+)\*\*)|(\*([^*]+)\*)/g;
  const YES_RE = /^-yes-$/i;
  const NO_RE = /^-no-$/i;
  const LIMITED_RE = /^-(limited|partial)-$/i;
  const NA_RE = /^-(na|none)-$/i;
  const NA2_RE = /^-na2-$/i;
  const SIMPLE_TAG_RE = /(<br\s*\/?>)|(<p\s*\/?>)|(-note-)|(-warning-)/gi;
  const renderSuccessIcon = () => <svg viewBox="0 0 24 24" width="100%" height="100%" aria-hidden="true">
      <path d="M12 2C6.48 2 2 6.48 2 12C2 17.52 6.48 22 12 22C17.52 22 22 17.52 22 12C22 6.48 17.52 2 12 2ZM10 17L5 12L6.41 10.59L10 14.17L17.59 6.58L19 8L10 17Z" fill="currentColor" />
    </svg>;
  const renderFailureIcon = () => <svg viewBox="0 0 24 24" width="100%" height="100%" aria-hidden="true">
      <path fillRule="evenodd" clipRule="evenodd" d="M11.9902 1.98633C12.5208 1.9864 13.0426 2.12743 13.501 2.39453C13.9581 2.66107 14.3372 3.04388 14.5986 3.50391L22.5967 17.5L22.6895 17.6738C22.8921 18.0851 22.9979 18.5387 22.9981 18.999C22.9981 19.5253 22.8605 20.0431 22.5977 20.499C22.3348 20.9549 21.9555 21.3332 21.5 21.5967C21.0445 21.8601 20.5272 21.9994 20.001 22H4.00001C3.47453 22.0031 2.95699 21.868 2.50001 21.6084C2.04032 21.3471 1.65712 20.9684 1.39063 20.5117C1.12431 20.055 0.983643 19.5355 0.982429 19.0068C0.981281 18.4793 1.11967 17.9611 1.38282 17.5039L9.38184 3.50391C9.64344 3.04359 10.023 2.66111 10.4805 2.39453C10.9388 2.12755 11.4598 1.98636 11.9902 1.98633ZM12 16.9004C11.3925 16.9004 10.9004 17.3925 10.9004 18C10.9004 18.6075 11.3925 19.0996 12 19.0996H12.0098C12.6173 19.0996 13.1104 18.6075 13.1104 18C13.1104 17.3925 12.6173 16.9004 12.0098 16.9004H12ZM12 5.90039C11.3925 5.9004 10.9004 6.39249 10.9004 7V13C10.9004 13.6075 11.3925 14.0996 12 14.0996C12.6075 14.0996 13.0996 13.6075 13.0996 13V7C13.0996 6.39249 12.6075 5.90039 12 5.90039Z" fill="currentColor" />
    </svg>;
  const renderPartialSuccessIcon = () => <svg viewBox="0 0 24 24" width="100%" height="100%" aria-hidden="true">
      <path d="M12 1C18.0751 1 23 5.92487 23 12C23 18.0751 18.0751 23 12 23C5.92487 23 1 18.0751 1 12C1 5.92487 5.92487 1 12 1ZM12 3C7.02944 3 3 7.02944 3 12C3 16.9706 7.02944 21 12 21C16.9706 21 21 16.9706 21 12C21 7.02944 16.9706 3 12 3ZM12 5C13.8565 5 15.6374 5.73705 16.9502 7.0498C18.263 8.36256 19 10.1435 19 12C19 13.8565 18.263 15.6374 16.9502 16.9502C15.6374 18.263 13.8565 19 12 19C11.4477 19 11 18.5523 11 18V6C11 5.73478 11.1054 5.4805 11.293 5.29297C11.4805 5.10543 11.7348 5 12 5Z" fill="currentColor" />
    </svg>;
  const renderPendingIcon = () => <svg viewBox="0 0 24 24" width="100%" height="100%" fill="none" stroke="currentColor" strokeWidth="2" strokeLinecap="round" aria-hidden="true">
      <path d="M10.1 2.182a10 10 0 0 1 3.8 0" />
      <path d="M13.9 21.818a10 10 0 0 1-3.8 0" />
      <path d="M17.609 3.721a10 10 0 0 1 2.69 2.7" />
      <path d="M2.182 13.9a10 10 0 0 1 0-3.8" />
      <path d="M20.279 17.609a10 10 0 0 1-2.7 2.69" />
      <path d="M21.818 10.1a10 10 0 0 1 0 3.8" />
      <path d="M3.721 6.391a10 10 0 0 1 2.7-2.69" />
      <path d="M6.391 20.279a10 10 0 0 1-2.69-2.7" />
    </svg>;
  const renderRunningIcon = () => <svg className="yt-status-running-svg" viewBox="22 22 44 44" width="100%" height="100%" aria-hidden="true">
      <circle className="yt-status-running-circle" cx="44" cy="44" r="20.2" fill="none" stroke="currentColor" strokeWidth="3.6" />
    </svg>;
  const renderSkippedIcon = () => <svg viewBox="0 0 24 24" width="100%" height="100%" fill="none" stroke="currentColor" strokeWidth="2" strokeLinecap="round" strokeLinejoin="round" aria-hidden="true">
      <circle cx="12" cy="12" r="10" />
      <path d="M8 12h8" />
    </svg>;
  const STATUS_ICON_DEFS = [{
    re: /^-status-success-$/i,
    colorClass: 'yt-status-color-success',
    label: 'Success',
    render: renderSuccessIcon
  }, {
    re: /^-status-failure-$/i,
    colorClass: 'yt-status-color-failure',
    label: 'Failure',
    render: renderFailureIcon
  }, {
    re: /^-status-partial-success-$/i,
    colorClass: 'yt-status-color-partial',
    label: 'Partial success',
    render: renderPartialSuccessIcon
  }, {
    re: /^-status-pending-$/i,
    colorClass: 'yt-status-color-neutral',
    label: 'Pending',
    render: renderPendingIcon
  }, {
    re: /^-status-running-$/i,
    colorClass: 'yt-status-color-neutral',
    label: 'Running',
    render: renderRunningIcon
  }, {
    re: /^-status-skipped-$/i,
    colorClass: 'yt-status-color-neutral',
    label: 'Skipped',
    render: renderSkippedIcon
  }];
  const renderStatusBadge = def => <span className={['yt-status-icon', def.colorClass].join(' ')} role="img" aria-label={def.label} title={def.label}>
      {def.render()}
    </span>;
  const tryParseKV = trimmed => {
    const m = KV_RE.exec(trimmed);
    return m ? {
      key: m[1],
      value: m[2].trim()
    } : null;
  };
  const registerKey = (key, seenKeys, orderedKeys) => {
    if (!seenKeys.has(key)) {
      orderedKeys.push(key);
      seenKeys.add(key);
    }
  };
  const flushEntry = (currentEntry, entries) => {
    if (Object.keys(currentEntry).length > 0) entries.push(currentEntry);
  };
  const parseDashPrefixed = (lines, entries, orderedKeys, seenKeys) => {
    let currentEntry = {};
    let inEntry = false;
    for (const line of lines) {
      const trimmed = line.trim();
      if (trimmed.startsWith('- ')) {
        if (inEntry) entries.push(currentEntry);
        currentEntry = {};
        inEntry = true;
        const kv = tryParseKV(trimmed.substring(2).trim());
        if (kv) {
          registerKey(kv.key, seenKeys, orderedKeys);
          currentEntry[kv.key] = kv.value;
        }
      } else if (inEntry && trimmed !== '') {
        const kv = tryParseKV(trimmed);
        if (kv) {
          registerKey(kv.key, seenKeys, orderedKeys);
          currentEntry[kv.key] = kv.value;
        }
      }
    }
    flushEntry(currentEntry, entries);
  };
  const parseBlankSeparated = (lines, entries, orderedKeys, seenKeys) => {
    let currentEntry = {};
    let inEntry = false;
    for (const line of lines) {
      const trimmed = line.trim();
      if (trimmed === '') {
        if (inEntry) {
          flushEntry(currentEntry, entries);
          currentEntry = {};
          inEntry = false;
        }
        continue;
      }
      const kv = tryParseKV(trimmed);
      if (!kv) continue;
      const isNewEntry = !line.startsWith(' ') && !line.startsWith('\t');
      if (isNewEntry && inEntry && Object.keys(currentEntry).length > 0) {
        entries.push(currentEntry);
        currentEntry = {};
      }
      registerKey(kv.key, seenKeys, orderedKeys);
      currentEntry[kv.key] = kv.value;
      inEntry = true;
    }
    flushEntry(currentEntry, entries);
  };
  const normalizeEntries = (entries, orderedKeys) => entries.map(entry => {
    const filled = {};
    for (const key of orderedKeys) filled[key] = entry[key] || '';
    return filled;
  });
  const parseYamlTableContent = contentStr => {
    if (!contentStr) return [];
    const entries = [];
    const orderedKeys = [];
    const seenKeys = new Set();
    const lines = contentStr.split('\n');
    if (lines.some(line => line.trim().startsWith('- '))) {
      parseDashPrefixed(lines, entries, orderedKeys, seenKeys);
    } else {
      parseBlankSeparated(lines, entries, orderedKeys, seenKeys);
    }
    return normalizeEntries(entries, orderedKeys);
  };
  const processText = text => {
    if (!text) return text;
    const parts = [];
    let keyIndex = 0;
    let lastIndex = 0;
    let match;
    while ((match = INLINE_MD_RE.exec(text)) !== null) {
      if (match.index > lastIndex) parts.push(text.slice(lastIndex, match.index));
      if (match[1]) {
        parts.push(<a key={keyIndex++} href={match[3]}>{match[2]}</a>);
      } else if (match[4]) {
        parts.push(<code key={keyIndex++}>{match[5]}</code>);
      } else if (match[6]) {
        parts.push(<strong key={keyIndex++}>{match[7]}</strong>);
      } else if (match[8]) {
        parts.push(<em key={keyIndex++}>{match[9]}</em>);
      }
      lastIndex = match.index + match[0].length;
    }
    if (lastIndex < text.length) parts.push(text.slice(lastIndex));
    if (parts.length === 0) return text;
    const keyRef = {
      current: keyIndex
    };
    return expandHtmlTags(parts, keyRef);
  };
  const processBadges = text => {
    if (!text || typeof text !== 'string') return text;
    if (YES_RE.test(text)) return <span className="yt-badge-yes" role="img" aria-label="Supported" title="Supported">✓</span>;
    if (NO_RE.test(text)) return <span className="yt-badge-no" role="img" aria-label="Not supported" title="Not supported">✗</span>;
    if (LIMITED_RE.test(text)) return <span className="yt-badge-limited" role="img" aria-label="Partially supported" title="Partially supported">◐</span>;
    if (NA_RE.test(text) || NA2_RE.test(text)) return <span className="yt-sr-only" title="Not applicable">Not applicable</span>;
    const statusBadge = STATUS_ICON_DEFS.find(def => def.re.test(text));
    if (statusBadge) return renderStatusBadge(statusBadge);
    return processText(text);
  };
  const cellClassName = text => {
    if (!text || typeof text !== 'string') return undefined;
    if (NA_RE.test(text)) return 'yt-cell-na';
    if (NA2_RE.test(text)) return 'yt-cell-na2';
    return undefined;
  };
  const expandSimpleTags = (str, keyRef) => {
    const result = [];
    let last = 0;
    SIMPLE_TAG_RE.lastIndex = 0;
    let m;
    while ((m = SIMPLE_TAG_RE.exec(str)) !== null) {
      if (m.index > last) result.push(str.slice(last, m.index));
      if (m[1]) {
        result.push(<br key={keyRef.current++} />);
      } else if (m[2]) {
        result.push(<br key={keyRef.current++} />, <br key={keyRef.current++} />);
      } else if (m[3]) {
        result.push(<span key={keyRef.current++} className="yt-badge-note" style={{
          fontWeight: 600
        }}>Note: </span>);
      } else if (m[4]) {
        result.push(<span key={keyRef.current++} className="yt-badge-warning" style={{
          fontWeight: 600
        }}>Warning: </span>);
      }
      last = m.index + m[0].length;
    }
    if (last < str.length) result.push(str.slice(last));
    return result;
  };
  const expandHtmlTags = (chunks, keyRef) => {
    const out = [];
    for (const chunk of chunks) {
      if (typeof chunk === 'string') {
        out.push(...expandSimpleTags(chunk, keyRef));
      } else {
        out.push(chunk);
      }
    }
    return out;
  };
  const extractText = node => {
    if (node === null || node === undefined) return '';
    if (typeof node === 'string') return node;
    if (typeof node === 'number') return String(node);
    if (typeof node === 'boolean') return '';
    if (Array.isArray(node)) return node.map(extractText).join('');
    if (node && typeof node === 'object' && node.type) {
      const props = node.props || ({});
      if (typeof props.children === 'string') return props.children;
      if (props.children) return extractText(props.children);
      return '';
    }
    return String(node || '');
  };
  const [mounted, setMounted] = useState(false);
  const scrollWrapRef = useRef(null);
  const [isScrollable, setIsScrollable] = useState(false);
  useEffect(() => {
    setMounted(true);
  }, []);
  const data = useMemo(() => {
    if (propData) return propData;
    if (content && typeof content === 'string') return parseYamlTableContent(content);
    if (!children) return [];
    if (typeof children === 'string') return parseYamlTableContent(children);
    const childrenArray = Array.isArray(children) ? children : [children];
    return parseYamlTableContent(childrenArray.map(extractText).join('').trim());
  }, [children, propData, content]);
  const columns = useMemo(() => {
    if (!data || data.length === 0) return [];
    const firstRow = data[0];
    if (!firstRow || typeof firstRow !== 'object') return [];
    return Object.keys(firstRow);
  }, [data]);
  useEffect(() => {
    const wrap = scrollWrapRef.current;
    if (!wrap) return undefined;
    const updateScrollable = () => {
      setIsScrollable(wrap.scrollWidth > wrap.clientWidth);
    };
    updateScrollable();
    const observer = new ResizeObserver(updateScrollable);
    observer.observe(wrap);
    return () => observer.disconnect();
  }, [mounted, data]);
  if (!mounted) return null;
  if (!data || data.length === 0) return null;
  const rowKey = row => columns.map(c => row[c] || '').join('|');
  return <div ref={scrollWrapRef} style={{
    overflowX: 'auto',
    margin: '1.75rem 0'
  }} role={isScrollable ? 'region' : undefined} aria-label={isScrollable ? 'Scrollable table' : undefined} tabIndex={isScrollable ? 0 : undefined}>
      <table style={{
    display: 'table',
    width: '100%',
    minWidth: '100%',
    margin: 0
  }}>
        <thead>
          <tr>
            {columns.map(col => <th key={col}>{col.replaceAll('_', ' ')}</th>)}
          </tr>
        </thead>
        <tbody>
          {data.map(row => <tr key={rowKey(row)}>
              {columns.map(col => <td key={col} className={cellClassName(row[col])}>{processBadges(row[col])}</td>)}
            </tr>)}
        </tbody>
      </table>
    </div>;
};

export const LicenseBadge = ({sku, skus, relation = 'any'}) => {
  const DATA_URL = '/snippets/license-sku-data.json';
  const CACHE_KEY = 'license-sku-data';
  const CACHE_TTL_MS = 60 * 60 * 1000;
  const REGISTRY_KEY = '__licenseSkuRegistry';
  const FALLBACK_LICENSES_URL = '/introduction/licenses';
  const ACCENT = '#26D07C';
  const CONJUNCTION = {
    any: 'or',
    all: 'and'
  };
  const FONT_STACK = '-apple-system, BlinkMacSystemFont, "Segoe UI", Helvetica, Arial, sans-serif';
  const [isDark, setIsDark] = useState(false);
  const [data, setData] = useState(null);
  const [hasFetchError, setHasFetchError] = useState(false);
  const skuList = useMemo(() => {
    if (Array.isArray(skus) && skus.length > 0) {
      return skus.filter(code => typeof code === 'string' && code.trim()).map(c => c.trim());
    }
    if (typeof sku === 'string' && sku.trim()) {
      return [sku.trim()];
    }
    return [];
  }, [sku, skus]);
  useEffect(() => {
    const check = () => {
      const root = document.documentElement;
      setIsDark(root.dataset.theme === 'dark' || root.classList.contains('dark'));
    };
    check();
    const observer = new MutationObserver(check);
    observer.observe(document.documentElement, {
      attributes: true,
      attributeFilter: ['data-theme', 'class']
    });
    return () => observer.disconnect();
  }, []);
  useEffect(() => {
    let cancelled = false;
    const readCache = () => {
      try {
        const raw = sessionStorage.getItem(CACHE_KEY);
        if (!raw) return null;
        const parsed = JSON.parse(raw);
        if (Date.now() - parsed.ts > CACHE_TTL_MS) {
          sessionStorage.removeItem(CACHE_KEY);
          return null;
        }
        return parsed.data;
      } catch (e) {
        return null;
      }
    };
    const writeCache = value => {
      try {
        sessionStorage.setItem(CACHE_KEY, JSON.stringify({
          ts: Date.now(),
          data: value
        }));
      } catch (e) {}
    };
    const fetchSkuData = async () => {
      const cached = readCache();
      if (cached) return cached;
      if (!globalThis[REGISTRY_KEY]) {
        globalThis[REGISTRY_KEY] = {};
      }
      const registry = globalThis[REGISTRY_KEY];
      if (registry[CACHE_KEY]) return registry[CACHE_KEY];
      const promise = (async () => {
        const resp = await fetch(DATA_URL);
        if (!resp.ok) throw new Error(`HTTP ${resp.status}`);
        const json = await resp.json();
        writeCache(json);
        return json;
      })();
      registry[CACHE_KEY] = promise;
      promise.finally(() => {
        delete registry[CACHE_KEY];
      });
      return promise;
    };
    fetchSkuData().then(d => {
      if (!cancelled) setData(d);
    }).catch(() => {
      if (!cancelled) setHasFetchError(true);
    });
    return () => {
      cancelled = true;
    };
  }, []);
  const textColor = isDark ? '#e6edf3' : '#1f2937';
  const textMuted = isDark ? 'rgba(230,237,243,0.65)' : 'rgba(31,41,55,0.65)';
  const bannerBackground = isDark ? '#161b22' : '#f6f8fa';
  const borderColor = isDark ? 'rgba(38,208,124,0.35)' : 'rgba(38,208,124,0.45)';
  const linkColor = isDark ? '#4ade80' : '#047857';
  const errorBackground = isDark ? '#3b1111' : '#fef2f2';
  const errorBorder = isDark ? '#7f1d1d' : '#fecaca';
  const errorText = isDark ? '#fecaca' : '#7f1d1d';
  const licensesUrl = data?.licensesPageUrl || FALLBACK_LICENSES_URL;
  const resolveSkuName = code => {
    const entry = data?.skus?.[code];
    if (entry?.name) return entry.name;
    return null;
  };
  const formatSkuLabel = code => {
    const name = resolveSkuName(code);
    if (name) return name;
    return code;
  };
  const joinWithConjunction = (codes, conjunction) => {
    const labels = codes.map(formatSkuLabel);
    if (labels.length === 0) return '';
    if (labels.length === 1) return labels[0];
    if (labels.length === 2) return `${labels[0]} ${conjunction} ${labels[1]}`;
    const head = labels.slice(0, -1).join(', ');
    const tail = labels[labels.length - 1];
    return `${head}, ${conjunction} ${tail}`;
  };
  const buildSkuSentence = codes => {
    const conj = CONJUNCTION[relation] || CONJUNCTION.any;
    const names = joinWithConjunction(codes, conj);
    const noun = codes.length > 1 ? 'licenses' : 'license';
    return `${names} ${noun}`;
  };
  const renderLink = text => <a href={licensesUrl} className="lic-link" style={{
    color: linkColor,
    fontSize: '0.75rem',
    fontWeight: 500,
    textDecoration: 'none',
    whiteSpace: 'nowrap'
  }}>
      {text} →
    </a>;
  const renderBanner = codes => <div className="lic-banner not-prose" style={{
    margin: '1rem 0',
    padding: '0.5rem 0.85rem',
    background: bannerBackground,
    border: `1px solid ${borderColor}`,
    borderLeft: `3px solid ${ACCENT}`,
    borderRadius: '6px',
    color: textColor,
    fontSize: '0.75rem',
    display: 'flex',
    alignItems: 'center',
    gap: '0.5rem',
    flexWrap: 'wrap',
    fontFamily: FONT_STACK,
    lineHeight: 1.5
  }}>
      <span style={{
    flex: 1,
    minWidth: 0
  }}>
        <span style={{
    color: textMuted,
    marginRight: '0.3rem'
  }}>Requires</span>
        <span style={{
    fontWeight: 600
  }}>{buildSkuSentence(codes)}</span>
      </span>
      {renderLink('Licenses')}
    </div>;
  const renderLoading = () => <div className="not-prose" style={{
    margin: '1rem 0',
    padding: '0.6rem 0.9rem',
    background: bannerBackground,
    border: `1px dashed ${borderColor}`,
    borderRadius: '6px',
    color: textMuted,
    fontSize: '0.85rem',
    fontStyle: 'italic',
    fontFamily: FONT_STACK
  }} role="status" aria-live="polite">
      Loading license info…
    </div>;
  const renderInputError = message => <div className="not-prose" style={{
    margin: '1rem 0',
    padding: '0.6rem 0.9rem',
    background: errorBackground,
    border: `1px solid ${errorBorder}`,
    borderRadius: '6px',
    color: errorText,
    fontSize: '0.85rem',
    fontFamily: FONT_STACK
  }} role="alert">
      {message}
    </div>;
  if (typeof sku === 'string' && Array.isArray(skus)) {
    return renderInputError('LicenseBadge: pass either `sku` or `skus`, not both.');
  }
  if (skuList.length === 0) {
    return renderInputError('LicenseBadge: `sku` or `skus` is required.');
  }
  if (hasFetchError) return renderBanner(skuList);
  if (!data) return renderLoading();
  return renderBanner(skuList);
};

<LicenseBadge sku="EL-OSS-FWAL" />

When you resolve dependencies with Package Firewall configured as your index, your package manager writes the Package Firewall URL for your namespace into the lockfile. Every package then resolves through Endor Labs instead of the canonical registry. Installs that replay that lockfile need Package Firewall credentials, so pipeline commands such as `npm ci`, `uv sync --locked`, and `poetry install` return `401 Unauthorized` until you supply them.

Store your Package Firewall credentials as CI/CD secrets, then configure each package manager client to read them from environment variables. Your pipelines authenticate without committing credentials to your repository.

<Warning>
  Lockfiles can embed Package Firewall URLs, such as the encoded `.npmrc` authentication npm uses or the authenticated index URLs uv and Poetry write. These lockfiles break installs for anyone without credentials to your namespace, including forks and repositories shared with other organizations. Regenerate the lockfile against the canonical registry before you share the repository outside your organization.
</Warning>

## Before you begin

Make sure you have the following:

* A Package Firewall API key and API secret. See [Configure the Package Firewall with direct integration](/package-firewall/direct-integration#create-an-api-key-for-the-package-firewall) to create them.
* A package manager configuration file that points at Package Firewall. See [Configure the Package Firewall with direct integration](/package-firewall/direct-integration#configure-your-package-manager-configuration-file) to generate one with the configuration wizard.

## Store Package Firewall credentials as CI/CD secrets

Store your Package Firewall API key and API secret as secrets in your CI/CD system, such as repository or runner secrets. Expose them to pipeline jobs as environment variables. Don't write credentials directly in pipeline steps or commit them to your repository.

The following table maps each package manager configuration file to the environment variables it reads. The uv and Poetry variable names derive from the `endor-firewall` index or source name used in the following sections.

<YamlTable>
  {`
    - Configuration_file: \`.npmrc\` (npm and pnpm)
    Environment_variables: \`NPM_AUTH\`
    Value: Base64 encoding of \`<api-key>:<api-secret>\`
    Reference: [npm CI/CD documentation](https://docs.npmjs.com/using-private-packages-in-a-ci-cd-workflow#set-the-token-as-an-environment-variable-on-the-cicd-server)

    - Configuration_file: \`pyproject.toml\` or \`uv.toml\` (uv)
    Environment_variables: \`UV_INDEX_ENDOR_FIREWALL_USERNAME\` and \`UV_INDEX_ENDOR_FIREWALL_PASSWORD\`
    Value: API key and API secret
    Reference: [uv environment variable reference](https://docs.astral.sh/uv/reference/environment/#uv_index_name_password)

    - Configuration_file: \`pyproject.toml\` (Poetry)
    Environment_variables: \`POETRY_HTTP_BASIC_ENDOR_FIREWALL_USERNAME\` and \`POETRY_HTTP_BASIC_ENDOR_FIREWALL_PASSWORD\`
    Value: API key and API secret
    Reference: [Poetry repositories documentation](https://python-poetry.org/docs/repositories/)
    `}
</YamlTable>

To store secrets and map them to environment variables, refer to the documentation for your CI/CD system, for example [GitHub Actions](https://docs.github.com/en/actions/security-for-github-actions/security-guides/using-secrets-in-github-actions), [GitLab CI/CD](https://docs.gitlab.com/ci/variables/), [Azure DevOps](https://learn.microsoft.com/en-us/azure/devops/pipelines/process/set-secret-variables), [CircleCI](https://circleci.com/docs/guides/security/env-vars/), [Jenkins](https://www.jenkins.io/doc/book/using/using-credentials/), or [Harness](https://developer.harness.io/docs/platform/secrets/add-use-text-secrets/).

## Configure uv for CI/CD

When you run `uv lock` with Package Firewall configured, uv writes the firewall URL, including your namespace, into `uv.lock`. Every package resolves through Endor Labs instead of a canonical PyPI source.

Since the lockfile references authenticated firewall URLs, reproducible installs fail in CI/CD when [credentials](/package-firewall/direct-integration#create-an-api-key-for-the-package-firewall) to `factory.endorlabs.com` are absent. uv commands that require a connection to the lockfile URLs, such as `uv sync --locked` or `uv sync --frozen`, return `401 Unauthorized` unless credentials are provided.

To install from the lockfile in CI/CD without committing credentials to your repository, give your index a name and pass the credentials as environment variables.

1. In your existing uv index in `pyproject.toml` or `uv.toml`, add a name and remove the credentials from the URL. uv matches credentials to an index by this name.

   <AccordionGroup>
     <Accordion title="pyproject.toml">
       ```toml theme={null}
       [[tool.uv.index]]
       name = "endor-firewall"
       url = "https://factory.endorlabs.com/v1/namespaces/<your-namespace>/firewall/pypi/simple/"
       default = true
       ```
     </Accordion>

     <Accordion title="uv.toml">
       ```toml theme={null}
       [[index]]
       name = "endor-firewall"
       url = "https://factory.endorlabs.com/v1/namespaces/<your-namespace>/firewall/pypi/simple/"
       default = true
       ```
     </Accordion>
   </AccordionGroup>

2. In your CI/CD system, store the credentials as secrets and expose them to jobs as the following environment variables. uv derives the variable names from the index name in uppercase, so `endor-firewall` becomes `ENDOR_FIREWALL`. For more information, refer to the [uv environment variable reference](https://docs.astral.sh/uv/reference/environment/#uv_index_name_password).

   * `UV_INDEX_ENDOR_FIREWALL_USERNAME`: Your Package Firewall API key.
   * `UV_INDEX_ENDOR_FIREWALL_PASSWORD`: Your Package Firewall API secret.

## Configure npm for CI/CD

When you run `npm install` with Package Firewall configured, npm writes the firewall URL, including your namespace, into `package-lock.json`. Every package resolves through Endor Labs instead of a canonical npm registry.

Since the lockfile references firewall URLs, reproducible installs fail in CI/CD when [credentials](/package-firewall/direct-integration#create-an-api-key-for-the-package-firewall) to `factory.endorlabs.com` are absent. Commands that install from the lockfile, such as `npm ci`, return `401 Unauthorized` unless credentials are provided.

To install from the lockfile in CI/CD without committing credentials to your repository, keep the registry URL in `.npmrc` and pass the encoded credentials as an environment variable.

1. In the project `.npmrc` file, set the Package Firewall registry and read `_auth` from an environment variable.

   ```ini theme={null}
   registry=https://factory.endorlabs.com/v1/namespaces/<your-namespace>/firewall/npm/
   //factory.endorlabs.com/v1/namespaces/<your-namespace>/firewall/npm/:_auth=${NPM_AUTH}
   always-auth=true
   ```

2. Generate the Base64 encoding of `<api-key>:<api-secret>` with your Package Firewall API key and API secret. This is the same encoding as the configuration wizard.

   ```bash theme={null}
   printf '%s' "<api-key>:<api-secret>" | base64 | tr -d '\n'; echo
   ```

3. In your CI/CD system, store the encoded value as a secret and expose it to jobs as the `NPM_AUTH` environment variable. For more information, refer to the [npm CI/CD documentation](https://docs.npmjs.com/using-private-packages-in-a-ci-cd-workflow#set-the-token-as-an-environment-variable-on-the-cicd-server).

## Configure pnpm for CI/CD

pnpm reads the same `.npmrc` registry as npm. When that file points at Package Firewall, `pnpm install` and `pnpm add` go through Endor Labs. By default, `pnpm-lock.yaml` stores integrity hashes and does not store tarball URLs.

Set the same `.npmrc` credentials in CI/CD as you do for npm. See [Configure npm for CI/CD](#configure-npm-for-ci/cd) to set `NPM_AUTH`. Commands such as `pnpm install --frozen-lockfile` then resolve through Package Firewall.

If the [`lockfile-include-tarball-url`](https://pnpm.io/settings) setting is `true`, pnpm writes Firewall tarball URLs into `pnpm-lock.yaml`. Reproducible installs then return `401 Unauthorized` when credentials to `factory.endorlabs.com` are absent.

## Configure Poetry for CI/CD

When you run `poetry lock` with Package Firewall set as a source, Poetry writes the Firewall URL, including your namespace, into `poetry.lock`. Every package resolves through Endor Labs instead of a canonical PyPI source.

Since the lockfile references firewall URLs, reproducible installs fail in CI/CD when [credentials](/package-firewall/direct-integration#create-an-api-key-for-the-package-firewall) to `factory.endorlabs.com` are absent. Commands that install from the lockfile, such as `poetry install`, return `401 Unauthorized` unless credentials are provided.

To install from the lockfile in CI/CD without committing credentials to your repository, keep the source URL in `pyproject.toml` and pass the credentials as environment variables.

1. In `pyproject.toml`, add the Package Firewall source with a name and no credentials in the URL. Poetry matches credentials to a source by this name.

   ```toml theme={null}
   [[tool.poetry.source]]
   name = "endor-firewall"
   url = "https://factory.endorlabs.com/v1/namespaces/<your-namespace>/firewall/pypi/simple/"
   priority = "primary"
   ```

2. In your CI/CD system, store the credentials as secrets and expose them to jobs as the following environment variables. Poetry derives the variable names from the source name in uppercase, so `endor-firewall` becomes `ENDOR_FIREWALL`. For more information, refer to the [Poetry repositories documentation](https://python-poetry.org/docs/repositories/).

   * `POETRY_HTTP_BASIC_ENDOR_FIREWALL_USERNAME`: Your Package Firewall API key.
   * `POETRY_HTTP_BASIC_ENDOR_FIREWALL_PASSWORD`: Your Package Firewall API secret.

## Next steps

* Configure which packages the firewall flags and how it responds. See [Package Firewall policy](/package-firewall/policy) to learn more.
* Review the events the firewall records. See [View Package Firewall logs](/package-firewall/logs) to learn more.

<draft>
  ## Troubleshooting and FAQ

  <AccordionGroup>
    <Accordion title="Why does Poetry return 401 errors when my environment variables are set?">
      The variables aren't in your current shell scope. On Windows, set them with `[System.Environment]::SetEnvironmentVariable` using the `User` scope, then restart your terminal. For a single session, you can set `$env:POETRY_HTTP_BASIC_ENDOR_FIREWALL_USERNAME` and `$env:POETRY_HTTP_BASIC_ENDOR_FIREWALL_PASSWORD` in PowerShell instead.
    </Accordion>
  </AccordionGroup>
</draft>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.