/projects/{project_id}/branches/{branch_id}/credentialsbetaIssue a scoped credential on the branch
Issues a new scoped service credential anchored to the specified
branch. The response carries api_token and s3_secret_access_key
exactly once — they are not stored server-side.
Note: This endpoint is currently in Private Beta.
Quick start
curl "https://console.neon.tech/api/v2/projects/$PROJECT_ID/branches/$BRANCH_ID/credentials" \
-X POST \
-H "Authorization: Bearer $NEON_API_KEY"import { createNeonClient, raw } from '@neon/sdk';
const neon = createNeonClient({ apiKey: process.env.NEON_API_KEY });
const { data } = await raw.createCredential({
client: neon.client,
path: {
project_id: process.env.PROJECT_ID,
branch_id: process.env.BRANCH_ID
}
});Parameters
project_idThe Neon project ID
branch_idThe Neon branch ID
Request body
2 required Required: scopes, principal_type.
scopesprincipal_typePrincipal type for the credential. Only user is customer-managed
and accepted here. function and system credentials are
platform-internal (e.g. function-serve auto-mint, presign signer)
and are never issued through the customer-facing API.
nameFree-form customer label for the credential.
≤256 chars
Response
201Credential issued — secrets shown once.
Errors
General error
This endpoint can return the standard Neon API error response.
Response fields
messageRequired. Human-readable error message.codeRequired. Machine-readable error code.request_idOptional. Request identifier for debugging. You can provide one with theX-Request-IDheader.
Retry guidance
If no response is returned, the request may still have reached the server. This is why retry safety depends on the method and status code.
Idempotent methods (GET, HEAD, OPTIONS) are generally safe to retry after a network error or timeout. Non-idempotent methods (POST, PATCH, DELETE, PUT) can change state, so avoid automatic retries unless your workflow can tolerate duplicate effects.
Responses with 423 Locked or 503 Service Unavailable are safe to retry. 423 Locked means the resource is temporarily locked, usually because another operation is in progress.








