npx: running a package without installing it for good

npx runs the executable a package provides, whether it is already installed in the project or downloaded for the occasion. It is the tool for one-off commands.
3 min read
Believemy logo

Some tools are needed exactly once: the generator that scaffolds a project, the migration command run on the evening of an upgrade. Installing them permanently only to forget them clutters both the machine and the dependency file.

npx handles that case by running a package on demand, then handing control back.


Definition

npx is the command shipped with npm that runs the program a package provides. It looks for that executable in the current project first, and only downloads it into a temporary cache when it is missing.

A package can expose a program through the bin field of its package.json, which maps a command name to a file.

JAVASCRIPT
#!/usr/bin/env node
// say-hello.js, the file named by the bin field

const name = process.argv[2] || "world";
console.log("Hello " + name + "!");

The field reads "bin": { "say-hello": "./say-hello.js" }, and once the package is published, npx say-hello Marie prints the message without leaving anything installed. That very first line tells the system which program should run the file.


What npx looks for, and in which order

  • The current project: if the package sits in node_modules, that version runs, the one the project has locked.
  • The local cache: a package already downloaded during an earlier call is reused, with no new transfer.
  • The registry: otherwise npx asks for confirmation, downloads, runs, and adds nothing to your dependencies.
Good to know

Naming the version avoids unpleasant surprises. npx eslint@9 . runs a chosen version rather than the latest published one, which makes a command reproducible inside documentation or a script.


When to reach for it instead of installing

npx suits one-off commands: creating a project, generating a configuration file, trying a tool before adopting it. It saves you from installing a package machine-wide whose version will drift away from your projects.

As soon as a command comes back every day, the opposite applies: install the package as a development dependency and declare a script in package.json. The invocation gets shorter, and more importantly the whole team runs the same version.


Frequently asked questions

Question

Does npx download the package on every call?

No. A package present in the project runs directly, and a package pulled once stays in a cache that later calls reuse. A real download only happens on the first call, or after you ask for a different version.


Question

Why does npx ask me to confirm?

Because it is about to install a package the project does not have, and running code fetched from the registry deserves an explicit agreement. The --yes option skips the prompt, which helps inside an automated script, provided you know exactly which package is being launched.


Question

How is it different from npm create?

npm create name is a shortcut that looks for a package called create-name and runs it, which is what makes npm create vite@latest work. Under the hood the mechanism matches npx: fetch a starter tool, run it, leave nothing behind.

Related terms

Discover our javaScript glossary

Every word of JavaScript explained simply: keywords, built-in objects, methods, errors and concepts. Clear definitions and examples that actually run, to learn and to troubleshoot.

Share this article

Want to help us? Share this article on your networks or even better: on your site, in an article or in your newsletter.