What npm install does and why you need it
npm is the package manager for JavaScript — it downloads code libraries that other developers have written and puts them in your project so you can use them. When you run npm install, you're telling npm to read a file called package.json in your project folder, find all the packages listed there, download them from npm's servers, and store them in a folder called node_modules.
Without npm, you'd have to manually download each library, figure out where to put it, and manage updates yourself. npm handles all of that. Most JavaScript projects use it — whether you're building a website with React, a server with Express, or a simple script that needs a utility library.
Key Takeaways
- npm install reads your package.json file and downloads all listed packages into a node_modules folder in your project.
- You need Node.js installed on your computer first, which includes npm automatically.
- To add a new package to your project, use npm install package-name, which updates both node_modules and your package.json file.
- The package-lock.json file ensures everyone working on the project installs the exact same versions of packages.
Installing Node.js so npm works on your computer
npm comes bundled with Node.js, so you install them together. Go to nodejs.org, download the LTS (Long Term Support) version for your operating system — Windows, macOS, or Linux — and run the installer. Follow the prompts and accept the defaults. When it finishes, npm is already there.
To check that both installed correctly, open your terminal or command prompt and type node --version and npm --version. You should see version numbers for both. If you see an error instead, the installation didn't complete — try running the installer again or restart your computer.
Running npm install in an existing project
If you've downloaded a project that already has a package.json file — whether from GitHub, a tutorial, or a colleague — you install its dependencies by opening your terminal in that project's folder and typing npm install with no package name. npm reads package.json, downloads every package listed there, and puts them all in node_modules.
This step is always your first move with a new project. The node_modules folder is usually huge and not included when projects are shared, so you always run npm install before you start working. If you see an error, the most common cause is that you're not in the right folder — make sure your terminal is showing the path to your project's root directory, where package.json lives.
Adding a new package to your project
To add a package you don't have yet, type npm install package-name where package-name is the actual name of the package. For example, npm install lodash downloads the lodash utility library. npm downloads the package, puts it in node_modules, and automatically adds it to your package.json file under a section called dependencies.
You can install multiple packages at once by listing them: npm install lodash axios moment. If you want a package only for development — like a testing tool or a code formatter that you don't need when your project runs in production — use npm install --save-dev package-name. This puts it in devDependencies instead, which tells other developers it's not needed to run the project, only to work on it.
Understanding package.json and package-lock.json
package.json is a text file that lists your project's metadata and its dependencies. It looks like this: it has a name, version, description, and a list of packages your project needs. When you run npm install package-name, npm adds that package to the list. You can also edit package.json by hand, but it's safer to use the command line.
package-lock.json is created automatically the first time you install a package. It records the exact version of every package and every package that those packages depend on. If you commit both files to version control (like Git), everyone who clones your project and runs npm install gets the exact same versions you have. This prevents the "it works on my machine" problem. Never edit package-lock.json by hand — let npm manage it.
Troubleshooting common npm install problems
If npm install fails with a permissions error on macOS or Linux, you may have installed Node.js in a way that requires sudo. The fix is to reinstall Node.js using a version manager like nvm (Node Version Manager) instead of the installer. This avoids permission issues and makes it easier to switch between Node versions later.
If you see a message about missing peer dependencies, it usually means a package expects another package to be installed, but it's not. Read the message carefully — it often tells you exactly what to install. If npm install hangs or takes a very long time, your internet connection may be slow, or npm's servers may be temporarily overloaded. Wait a minute and try again, or check your internet connection.
If node_modules becomes corrupted or you're seeing strange errors, delete the node_modules folder and package-lock.json, then run npm install again. This forces npm to download everything fresh. It takes longer but usually fixes mysterious problems.
Frequently Asked Questions
Do I have to commit node_modules to Git?
No — in fact, you should not. node_modules is huge and changes often. Instead, commit package.json and package-lock.json. Anyone who clones your project runs npm install and gets the same packages you have. Add node_modules/ to your .gitignore file to prevent it from being tracked.
What's the difference between npm install and npm ci?
npm install is for development — it installs what's in package.json and updates package-lock.json if needed. npm ci (ci stands for "continuous integration") installs exactly what's in package-lock.json without changing it. Use npm ci in automated environments like build servers to ensure reproducible builds.
Can I install a package from a GitHub URL instead of npm?
Yes. Use npm install github-username/repo-name or the full URL. This is useful for packages not published to npm or for testing a fork. The package still goes in node_modules and is added to package.json the same way.
How do I update packages to newer versions?
Run npm update to upgrade all packages to their latest allowed versions based on what's written in package.json. To update a single package, use npm install package-name@latest. To see which packages have newer versions available, run npm outdated.