Use rrepo

Private packages

Install your team's packages with an API key.

To install private packages, ask your repository owner for the repository address and a key with packages:read permission. The key must belong to the organization that owns the repository.

Use https://rrepo.dev/acme/internal with rpx, or https://cran.rrepo.dev/acme/internal with R and renv. Replace acme/internal and internalpkg below with your repository and package name.

rpx

From your project directory:

sh
rpx repo add https://rrepo.dev/acme/internal
rpx add internalpkg

rpx prompts for the API key when it needs access and saves it in your operating system keyring. Repositories on https://rrepo.dev share that stored credential.

For unattended rpx sync runs, the runner needs a credential already stored in its keyring. For CI using an environment-variable secret, use the renv setup below.

renv

Set RREPO_API_KEY in your local environment or CI secrets. In your renv project, configure the repository and its authentication:

r
options(
  repos = c(
    rrepo = "https://cran.rrepo.dev/acme/internal",
    CRAN = "https://cloud.r-project.org"
  ),
  renv.download.headers = function(url) {
    if (startsWith(url, "https://cran.rrepo.dev/acme/internal/")) {
      return(c(Authorization = paste("Bearer", Sys.getenv("RREPO_API_KEY"))))
    }
    NULL
  }
)

renv::install("internalpkg")

The header configuration covers both the package index and package downloads, while requests to CRAN remain unauthenticated. Apply it in each session that installs or restores private packages. You can put this configuration in your project's .Rprofile after the existing renv activation line; keep the key itself in your environment. The same setup works with renv::restore() in CI.

R

Set RREPO_API_KEY in your environment, then pass it when installing from your private repository:

r
install.packages(
  "internalpkg",
  repos = "https://cran.rrepo.dev/acme/internal",
  type = "source",
  method = "libcurl",
  headers = c(Authorization = paste("Bearer", Sys.getenv("RREPO_API_KEY")))
)

Install any CRAN dependencies separately without the authentication header, or use the renv setup above to work with both repositories together.

Set up a private repository

In the dashboard, select your organization, create a private repository, and publish your package. In your organization's API keys section, create read keys for people or jobs that install packages, and separate write keys for publishing workflows. The key value is shown once; store it in your package manager's credential store or CI secrets.

Private repositories require an active Team or Business plan. See pricing for details.