Autoscaling Report: Production databases on Neon use 2.4x less compute and 50% less cost than if they were running on a provisioned platform.
/API reference/Authentication/Update phone number plugin configuration
PATCH/projects/{project_id}/branches/{branch_id}/auth/plugins/phone-number

Update phone number plugin configuration

Updates the phone number plugin configuration for Neon Auth. Only the fields provided in the request body are updated; omitted fields retain their current values. The phone number plugin enables phone-based OTP authentication. OTP codes are delivered via the send.otp webhook event with delivery_preference: "sms". A webhook must be configured with the send.otp event enabled for SMS delivery to work.

Markdown for AI context

Quick start

REST API - curl
curl "https://console.neon.tech/api/v2/projects/$PROJECT_ID/branches/$BRANCH_ID/auth/plugins/phone-number" \
  -X PATCH \
  -H "Authorization: Bearer $NEON_API_KEY"
Also available in
import { createApiClient } from '@neondatabase/api-client';

const api = createApiClient({ apiKey: process.env.NEON_API_KEY });
const { data } = await api.updateNeonAuthPhoneNumberPlugin(process.env.PROJECT_ID, process.env.BRANCH_ID);

Parameters

Project ID
project_id
string

The Neon project ID

Branch ID
branch_id
string

The Neon branch ID

Request body

No field is required.

Enabled
enabled
boolean

Whether the phone number plugin is enabled

Otp expires in
otp_expires_in
integer

Time in seconds before the OTP expires

min: 60, max: 600

Response

200

The phone number plugin configuration has been updated

Depth
"enabled": false,req
"otp_expires_in": 300,min: 60, max: 600

Errors

default

General error

This endpoint can return the standard Neon API error response.

Response fields

  • message Required. Human-readable error message.
  • code Required. Machine-readable error code.
  • request_id Optional. Request identifier for debugging. You can provide one with the X-Request-ID header.

Retry guidance

If no response is returned, the request may still have reached the server. This is why retry safety depends on the method and status code.

Idempotent methods (GET, HEAD, OPTIONS) are generally safe to retry after a network error or timeout. Non-idempotent methods (POST, PATCH, DELETE, PUT) can change state, so avoid automatic retries unless your workflow can tolerate duplicate effects.

Responses with 423 Locked or 503 Service Unavailable are safe to retry. 423 Locked means the resource is temporarily locked, usually because another operation is in progress.

Was this page helpful?

On this page

Copy neon init command