Blognpm

npm ci can only install packages when your package.json and package-lock.json are in sync How to fix it.

Your lock file and package.json disagree. Run npm install on your machine, commit the new lock file, and deploy again.

How the Agent API works
What you see
npm error code EUSAGE
npm error
npm error `npm ci` can only install packages when your package.json and
npm error package-lock.json or npm-shrinkwrap.json are in sync. Please update
npm error your lock file with `npm install` before continuing.
npm error
npm error Missing: express@4.19.2 from lock file
  • What it meansThe two files list different packages
  • The fixRun npm install, commit package-lock.json
  • Why it appears nownpm ci is strict, npm install is not
  • On AntideployThe build repairs its own copy and tells you

What it means

package.json lists the packages your project wants. package-lock.json records the exact versions that were installed. The command npm ci installs exactly what the lock file says, and it stops if the two files disagree. Somewhere, a package was added, removed or changed in one file and not the other.

How to fix it

  1. Run npm install on your machine

    Use the same Node.js version as your project. npm updates package-lock.json so it matches package.json.

  2. Commit the lock file

    Commit package-lock.json together with package.json. Check that the lock file is not listed in .gitignore.

  3. Deploy again

    A failed deploy never counts against your plan, so you can try as often as you need.

If you use another package manager, the same idea applies. For Yarn, run yarn install and commit yarn.lock. For pnpm, run pnpm install and commit pnpm-lock.yaml.

Why it happens

  • A coding agent edited package.json and never ran an install. This is the most common cause with AI-written code.
  • The lock file came from a different npm version. A newer or older npm can record packages in a way another version rejects.
  • The lock file is in a different folder, or not committed. The build only sees what you send.

What Antideploy does

Antideploy recognises this failure. It installs from package.json for that build, in its own copy of your source, and tells you it did. It never edits your repository. The cost is that a package can resolve to a newer version inside the range your package.json allows, which is not always the version you ran. That is why the right fix is still to commit a matching lock file.

01Questions

Lock file questions, answered.

Anything else? Write to us and a person answers.

support@antideploy.com
Should I delete package-lock.json?

Not as a first step. Run npm install so npm rebuilds it, then commit the result. Deleting it and not committing a new one removes the record of your exact versions.

Why does it work on my machine?

npm install forgives a mismatch and rewrites the lock file on your machine. npm ci is built to be strict, so it fails instead.

Does this failed deploy cost anything?

No. Failed deploys never count against your plan.

Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

Start from GitHub or a folder
Prompt copied Paste it into Claude Code, Codex or Cursor and press Enter.