Start with a private registry
Public npm caching is available on Growth and higher plans. Open a registry under Registry → Registries, then its Public packages settings. Caching is off until you enable it. A hosted package name or any claimed scope stays private; a missing package there never falls through to npmjs.org.
Choose which external names to serve
Public mode allows external names except your block patterns. Allowlist mode permits only names matching an allow pattern. Patterns are one glob per line, such as react or @types/*. Block patterns apply in either mode. Use the page's package-name preview to check classification before saving a policy.
Set a minimum release age from 0 to 720 hours to hide newly published upstream versions. The page also lets you decide whether npm audit requests for external names are forwarded. A download key can reach cached public packages only when its access policy permits it.
Check installs and usage
Point the npm CLI at the registry as described in the .npmrc guide. Install an external name you explicitly allow, then try a name you block and a missing name inside your claimed scope. The latter two should remain unavailable. Cached content downloads count toward monthly transfer, but cached bytes do not use your storage allowance.
Use the registry's upstream activity panel to review cache hits and misses. If upstream authorization or classification fails, the request must fail closed; the client should not silently install from the public registry.