GitHub announced on Jul 31, 2026 that npm is restricting granular access tokens that previously bypassed two-factor authentication requirements. This is a small change with an outsized blast radius for agentic workflows: any pipeline where an agent publishes packages non-interactively was likely leaning on exactly this token class. Check publish automation before the restriction bites, not after a release fails.