This is the acme registry. Access follows your GitHub permissions: you can use a crate if you can
read its repository on GitHub. There is no separate account.
If a project already uses this registry, you need one thing: the credential provider.
cargo binstall cargo-credential-privatecrates # without cargo-binstall, it builds from source: cargo install cargo-credential-privatecrates --locked
Then build as usual. The first time, Cargo shows a code: approve it on GitHub, and you are signed in for every project using this registry. To sign in before building (for example, before opening the project in an editor):
cargo login --registry acme
A project that does not use the registry yet needs it in .cargo/config.toml:
[registries.acme] index = "sparse+https://acme.privatecrates.dev/index/" credential-provider = ["cargo-credential-privatecrates"]
and dependencies that name it, in Cargo.toml:
my_crate = { version = "1", registry = "acme" }
Editors such as rust-analyzer run Cargo without a terminal, where there is nowhere to show a sign-in code. If you
are not signed in, the build stops at once with not signed in … run cargo login --registry acme in a
terminal. Run that once, then reload the editor.
cargo privatecrates doctor --crate NAME checks your setup and sign-in.cargo update.Cargo.lock. Commit it, and push a tag for the next version;
cargo privatecrates doctor checks this before you tag.cargo logout --registry acme, then
cargo login --registry acme.Add permissions: id-token: write to the job and install the credential provider with the step in the
workflow below, which downloads the prebuilt binary and checks it. No secrets are needed.
Crates are published from GitHub Actions, so every version has verifiable provenance. Only people who can create releases in the crate's repository (write access or above) can trigger a publish.
on:
push:
tags: ["v*"]
permissions:
id-token: write
contents: read
jobs:
publish:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- name: Install cargo-credential-privatecrates 0.2.6 (checksummed and attested)
env: { GH_TOKEN: "${{ github.token }}", VERSION: "0.2.6" }
run: |
cd "$(mktemp -d)"
name=cargo-credential-privatecrates-$(uname -m)-unknown-linux-gnu
base=https://github.com/worldbuilding-dev/privatecrates.dev/releases/download/v$VERSION
curl -fsSL --remote-name-all "$base/$name.tgz" "$base/SHA256SUMS"
sha256sum --check --ignore-missing SHA256SUMS
gh attestation verify "$name.tgz" --repo worldbuilding-dev/privatecrates.dev
tar -xzf "$name.tgz"
install -D "$name/cargo-credential-privatecrates" ~/.cargo/bin/cargo-credential-privatecrates
- run: cargo publish --registry acme
The crate's package.repository must be the repository the workflow runs in.
cargo privatecrates init sets all of this up.
More: joining a team, all documentation.