Some tools are needed exactly once: the generator that scaffolds a project, the migration command run on the evening of an upgrade. Installing them permanently only to forget them clutters both the machine and the dependency file.
npx handles that case by running a package on demand, then handing control back.
Definition
npx is the command shipped with npm that runs the program a package provides. It looks for that executable in the current project first, and only downloads it into a temporary cache when it is missing.
A package can expose a program through the bin field of its package.json, which maps a command name to a file.
#!/usr/bin/env node
// say-hello.js, the file named by the bin field
const name = process.argv[2] || "world";
console.log("Hello " + name + "!");The field reads "bin": { "say-hello": "./say-hello.js" }, and once the package is published, npx say-hello Marie prints the message without leaving anything installed. That very first line tells the system which program should run the file.
What npx looks for, and in which order
- The current project: if the package sits in
node_modules, that version runs, the one the project has locked. - The local cache: a package already downloaded during an earlier call is reused, with no new transfer.
- The registry: otherwise npx asks for confirmation, downloads, runs, and adds nothing to your dependencies.
Naming the version avoids unpleasant surprises. npx eslint@9 . runs a chosen version rather than the latest published one, which makes a command reproducible inside documentation or a script.
When to reach for it instead of installing
npx suits one-off commands: creating a project, generating a configuration file, trying a tool before adopting it. It saves you from installing a package machine-wide whose version will drift away from your projects.
As soon as a command comes back every day, the opposite applies: install the package as a development dependency and declare a script in package.json. The invocation gets shorter, and more importantly the whole team runs the same version.
Frequently asked questions
Does npx download the package on every call?
No. A package present in the project runs directly, and a package pulled once stays in a cache that later calls reuse. A real download only happens on the first call, or after you ask for a different version.
Why does npx ask me to confirm?
Because it is about to install a package the project does not have, and running code fetched from the registry deserves an explicit agreement. The --yes option skips the prompt, which helps inside an automated script, provided you know exactly which package is being launched.
How is it different from npm create?
npm create name is a shortcut that looks for a package called create-name and runs it, which is what makes npm create vite@latest work. Under the hood the mechanism matches npx: fetch a starter tool, run it, leave nothing behind.