Neon is expanding into a backend: Object Storage, Functions, and AI Gateway now in beta
/APIs & SDKs/Credentials/Issue a scoped credential on the branch
POST/projects/{project_id}/branches/{branch_id}/credentialsbeta

Issue a scoped credential on the branch

Issues a new scoped service credential anchored to the specified branch. The response carries api_token and s3_secret_access_key exactly once — they are not stored server-side.

Note: This endpoint is currently in Private Beta.

Markdown for AI context

Quick start

REST API - curl
curl "https://console.neon.tech/api/v2/projects/$PROJECT_ID/branches/$BRANCH_ID/credentials" \
  -X POST \
  -H "Authorization: Bearer $NEON_API_KEY"
Also available in
import { createNeonClient, raw } from '@neon/sdk';

const neon = createNeonClient({ apiKey: process.env.NEON_API_KEY });
const { data } = await raw.createCredential({
  client: neon.client,
  path: {
    project_id: process.env.PROJECT_ID,
    branch_id: process.env.BRANCH_ID
  }
});

Parameters

Project ID
project_id
string

The Neon project ID

Branch ID
branch_id
string

The Neon branch ID

Request body

2 required Required: scopes, principal_type.

Scopes
scopes
array

Principal type
principal_type
string

Principal type for the credential. Only user is customer-managed and accepted here. function and system credentials are platform-internal (e.g. function-serve auto-mint, presign signer) and are never issued through the customer-facing API.

user
Name
name
string

Free-form customer label for the credential.

≤256 chars

Response

201

Credential issued — secrets shown once.

Depth
"token_id": (string),req
"token_id_short": (string),req
"api_token": (string),req
"s3_secret_access_key": (string),req
"scopes": (array),req
"branch_id": (string),req
"created_at": (string),reqdate-time
"name": (string),
"expires_at": (string),date-time

Errors

default

General error

This endpoint can return the standard Neon API error response.

Response fields

  • message Required. Human-readable error message.
  • code Required. Machine-readable error code.
  • request_id Optional. Request identifier for debugging. You can provide one with the X-Request-ID header.

Retry guidance

If no response is returned, the request may still have reached the server. This is why retry safety depends on the method and status code.

Idempotent methods (GET, HEAD, OPTIONS) are generally safe to retry after a network error or timeout. Non-idempotent methods (POST, PATCH, DELETE, PUT) can change state, so avoid automatic retries unless your workflow can tolerate duplicate effects.

Responses with 423 Locked or 503 Service Unavailable are safe to retry. 423 Locked means the resource is temporarily locked, usually because another operation is in progress.

Was this page helpful?

On this page

Copy neon init command