We ran the same workload through 42 models via AI Gateway and compared costs
/APIs & SDKs/Credentials/Reveal a credential's secrets
POST/projects/{project_id}/branches/{branch_id}/credentials/{token_id}/revealbeta

Reveal a credential's secrets

Returns the live api_token and s3_secret_access_key of an existing credential, so a credential whose issuance response was lost can be recovered without minting a new one.

This is a POST with an explicit /reveal verb so the secrets never ride a GET, where they would land in access logs, browser history and proxy caches. Revoked and expired credentials return 404, as does a token_id that does not belong to this project.

A credential issued before secret retrieval was supported has no recoverable secret and returns 409 — rotate it to obtain one.

Note: This endpoint is currently in Beta.

Markdown for AI context

Quick start

REST API - curl
curl "https://console.neon.tech/api/v2/projects/$PROJECT_ID/branches/$BRANCH_ID/credentials/$TOKEN_ID/reveal" \
  -X POST \
  -H "Authorization: Bearer $NEON_API_KEY"

Every field below is optional. An empty body works too.

Also available in
import { createNeonClient, raw } from '@neon/sdk';

const neon = createNeonClient({ apiKey: process.env.NEON_API_KEY });
const { data } = await raw.revealCredential({
  client: neon.client,
  path: {
    project_id: process.env.PROJECT_ID,
    branch_id: process.env.BRANCH_ID,
    token_id: process.env.TOKEN_ID
  }
});

Parameters

Project ID
project_id
string

The Neon project ID

Branch ID
branch_id
string

The Neon branch ID

Token ID
token_id
string

The opaque credential id (e.g. nak_live_<32hex>).

Response

200

The credential's live secrets.

Depth
"token_id": (string),req
"api_token": (string),req
"s3_secret_access_key": (string),req

Errors

404

Credential not found

409

The credential exists but has no recoverable secret because it was issued before secret retrieval was supported. Rotate the credential to obtain a recoverable secret.

default

General error

This endpoint can return the standard Neon API error response.

Response fields

  • message Required. Human-readable error message.
  • code Required. Machine-readable error code.
  • request_id Optional. Request identifier for debugging. You can provide one with the X-Request-ID header.

Retry guidance

If no response is returned, the request may still have reached the server. This is why retry safety depends on the method and status code.

Idempotent methods (GET, HEAD, OPTIONS) are generally safe to retry after a network error or timeout. Non-idempotent methods (POST, PATCH, DELETE, PUT) can change state, so avoid automatic retries unless your workflow can tolerate duplicate effects.

Responses with 423 Locked or 503 Service Unavailable are safe to retry. 423 Locked means the resource is temporarily locked, usually because another operation is in progress.

Was this page helpful?

On this page

Copy neon init command