Consuming a feed
Install packages from a private pkgstore feed in your own projects.
1. Get your credentials
If you subscribed to a marketplace feed, your credentials are provisioned automatically. Open your dashboard and generate or view the username and password for the feed. If you were given free access, the process is the same. Copy both values from the dashboard. The username is a generated value like user-0f4b..., not your email address. Copy the password when it is shown; for security it is not displayed again.
2. The two pieces you need
- The feed URL, in the form https://www.pkgstore.io/api/nuget/{publisher}/{product}/index.json
- Your credentials: the generated restore username and password used as basic authentication.
3. Add the feed with the dotnet CLI
The quickest way is a single command:
dotnet nuget add source \
https://www.pkgstore.io/api/nuget/acme/toolkit/index.json \
--name acme-toolkit \
--username user-00000000-0000-0000-0000-000000000000 \
--password YOUR_CREDENTIAL \
--store-password-in-clear-text
On some platforms NuGet cannot encrypt stored passwords, which is why --store-password-in-clear-text is required. Because this writes the password to a config file, prefer the environment variable approach below for shared machines and CI.
4. Add the feed with nuget.config
Add a nuget.config next to your solution so everyone on the project picks up the same source:
<?xml version="1.0" encoding="utf-8"?>
<configuration>
<packageSources>
<add key="acme-toolkit"
value="https://www.pkgstore.io/api/nuget/acme/toolkit/index.json" />
</packageSources>
<packageSourceCredentials>
<acme-toolkit>
<add key="Username" value="%PKG_USER%" />
<add key="ClearTextPassword" value="%PKG_PASS%" />
</acme-toolkit>
</packageSourceCredentials>
</configuration>
NuGet expands %PKG_USER% and %PKG_PASS% from environment variables. This keeps the secret out of source control while still committing the config. Set the variables locally or as CI secrets:
# Linux and macOS
export PKG_USER="user-00000000-0000-0000-0000-000000000000"
export PKG_PASS="YOUR_CREDENTIAL"
Do not commit plaintext credentials. Keep the password in an environment variable or secret store. If a key element name contains characters that are not valid XML, the section name (here acme-toolkit) must match the source key exactly.
5. Add the feed in Visual Studio
- Go to Tools → Options → NuGet Package Manager → Package Sources.
- Click the + button, set the name and paste the feed URL, then click Update.
- The first restore prompts for credentials. Enter your username and password, and Visual Studio stores them for you.
6. Restore, search, and install
Once the source is configured, restore as usual:
dotnet restore
dotnet add package Acme.Toolkit
The public nuget.org source still works alongside your private feed, so your other dependencies resolve normally.
To list packages you can access from the feed, use the source name you configured:
dotnet package search --source acme-toolkit
dotnet package search Toolkit --source acme-toolkit
Visual Studio and NuGet-aware IDEs also use the feed search endpoint after the source is added, so package manager search only shows packages your credential can access.
7. CI/CD setup
In CI, keep the feed URL in source control and store the generated restore username and password as secrets. GitHub Actions can create a temporary source before restore:
- name: Add pkgstore feed
run: |
dotnet nuget add source "https://www.pkgstore.io/api/nuget/acme/toolkit/index.json" \
--name acme-toolkit \
--username "${{ secrets.PKGSTORE_USER }}" \
--password "${{ secrets.PKGSTORE_PASS }}" \
--store-password-in-clear-text
- name: Restore
run: dotnet restore
Azure DevOps works the same way with secret variables:
- script: |
dotnet nuget add source "https://www.pkgstore.io/api/nuget/acme/toolkit/index.json" ^
--name acme-toolkit ^
--username "$(PKGSTORE_USER)" ^
--password "$(PKGSTORE_PASS)" ^
--store-password-in-clear-text
dotnet restore
8. Symbol packages
pkgstore currently serves NuGet packages from feed endpoints and does not provide a symbol server endpoint. Do not push .snupkg files to pkgstore. Publish symbols to your usual symbol server, source-link your packages, or include portable PDBs in the package when that fits your release process.
9. Troubleshooting
- 401 Unauthorized: your generated username or password is wrong, or the variables did not expand. The username is not your email address. Regenerate your credential from the dashboard if needed.
- 403 Forbidden: your subscription is cancelled or suspended, or your trial has ended. Already-restored packages remain in your local package cache, but new restores and downloads fail until access is restored.
- Stale credentials cached: clear the HTTP cache with dotnet nuget locals http-cache --clear and restore again.
- Package not found: confirm the source URL ends in /index.json and the slugs are correct.
Want to rotate or revoke a credential, or manage team seats? See Managing access. For a deeper walkthrough across CLI, Visual Studio, and CI, read How to add a private NuGet feed.
Distribute your own packages
Run a private NuGet feed with automatic credential provisioning.
Get started free