# npm "EUNSUPPORTEDPROTOCOL" - Fix Unsupported Dependency URL Schemes

> Fix npm "EUNSUPPORTEDPROTOCOL" in CI - a dependency uses a URL scheme (link:, portal:, catalog:, patch:) the running npm cannot resolve. Use a supported spec or the right manager.

Source: https://latchkey.dev/learn/node-js/npm-eunsupportedprotocol-dep  
Updated: 2026-06-25

npm hit a dependency specifier whose protocol it does not support - `link:`, `portal:`, `catalog:`, `patch:` and similar are pnpm/Yarn-specific. npm cannot resolve the scheme and aborts with `EUNSUPPORTEDPROTOCOL`.

## Diagnose it: reproduce the CI install locally

Install failures are usually environment drift rather than a broken lockfile: a different package-manager major, a different Node version, or a cache that is being restored from a run with different inputs. Reproduce the CI conditions before changing the lockfile, because regenerating it hides the real cause.

```Terminal
# match the runner exactly, then install from a clean slate
node --version && npm --version
rm -rf node_modules
npm ci --foreground-scripts

# if that succeeds locally but fails in CI, the difference is the cache
# or the package-manager version, not your lockfile
```

> Pin the package manager with Corepack (`"packageManager"` in package.json) so the runner and every developer machine resolve the same version. Version skew is the single most common source of lockfile errors that only appear in CI.

## Verify the fix survives a cold cache

A green run immediately after a fix often proves nothing, because it restored a cache written before the change. Force a cold install once to confirm the fix is real.

```.github/workflows/ci.yml
# temporarily bust the cache key to prove the fix on a cold runner
- uses: actions/setup-node@v4
  with:
    node-version: 22
    cache: npm
    cache-dependency-path: package-lock.json
# then bump this suffix once, run, and remove it
#   key: ${{ runner.os }}-node-${{ hashFiles('package-lock.json') }}-v2
```

## FAQ

### What causes npm "EUNSUPPORTEDPROTOCOL"?

There are 2 common causes: a dependency uses a manager-specific protocol and installing with the wrong tool. Schemes like catalog: (pnpm catalogs), portal:/link: (Yarn), or patch: are defined by pnpm/Yarn.

### How do I fix npm "EUNSUPPORTEDPROTOCOL"?

There are 2 fixes depending on which cause you have: install with the manager that defines the protocol and rewrite to a spec npm understands. Work through them in order, since the first is the most common.

### What does npm "EUNSUPPORTEDPROTOCOL" actually mean?

npm install fails with code EUNSUPPORTEDPROTOCOL, naming a dependency whose version range uses a non-npm scheme.

### How do I stop npm "EUNSUPPORTEDPROTOCOL" happening again?

Declare and pin the package manager via packageManager + Corepack. The prevention section lists 3 changes that keep it from recurring.

---

Latchkey runs CI/CD that repairs its own failures. Agent entry points: https://latchkey.dev/agent.txt, https://latchkey.dev/openapi.json, https://latchkey.dev/llms.txt
