For signing to work you need a default GPG key configured. You can turn it on or off as follows:
npm config set sign-git-tag <true or false>