---
operationId: "revealCredential"
method: "POST"
path: "/projects/{project_id}/branches/{branch_id}/credentials/{token_id}/reveal"
tag: "credentials"
stability: "beta"
interfaces: ["api", "sdk"]
---
> API Reference / Credentials / Reveal a credential's secrets

## POST /projects/{project_id}/branches/{branch_id}/credentials/{token_id}/reveal

Returns the live `api_token` and `s3_secret_access_key` of an existing
credential, so a credential whose issuance response was lost can be
recovered without minting a new one.

This is a POST with an explicit `/reveal` verb so the secrets never ride
a GET, where they would land in access logs, browser history and proxy
caches. Revoked and expired credentials return 404, as does a
`token_id` that does not belong to this project.

A credential issued before secret retrieval was supported has no
recoverable secret and returns 409 — rotate it to obtain one.

**Note**: This endpoint is currently in Beta.


### Parameters

- `project_id` (string, path, required)
  The Neon project ID
- `branch_id` (string, path, required)
  The Neon branch ID
- `token_id` (string, path, required)
  The opaque credential id (e.g. nak_live_<32hex>).

### Response (200)

- `token_id` (string, optional)
  Opaque credential id (e.g. nak_live_<32hex>).
- `api_token` (string, optional)
  Bearer token.
- `s3_secret_access_key` (string, optional)
  nsk_live_<64 hex>; the AWS_SECRET_ACCESS_KEY.

### Code examples

```bash
curl "https://console.neon.tech/api/v2/projects/$PROJECT_ID/branches/$BRANCH_ID/credentials/$TOKEN_ID/reveal" \
  -X POST \
  -H "Authorization: Bearer $NEON_API_KEY"
```

```typescript
import { createNeonClient, raw } from '@neon/sdk';

const neon = createNeonClient({ apiKey: process.env.NEON_API_KEY });
const { data } = await raw.revealCredential({
  client: neon.client,
  path: {
    project_id: process.env.PROJECT_ID,
    branch_id: process.env.BRANCH_ID,
    token_id: process.env.TOKEN_ID
  }
});
```

### Errors

**404**
Credential not found
- `request_id` (string, optional)
  Unique identifier for the request, useful for debugging.
  You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.
  
- `code` (string, required)
  Machine-readable code classifying the error type. See `message` for a human-readable explanation.
  Default: ``
- `message` (string, required)
  Error message

**409**
The credential exists but has no recoverable secret because it was
issued before secret retrieval was supported. Rotate the credential
to obtain a recoverable secret.

- `request_id` (string, optional)
  Unique identifier for the request, useful for debugging.
  You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.
  
- `code` (string, required)
  Machine-readable code classifying the error type. See `message` for a human-readable explanation.
  Default: ``
- `message` (string, required)
  Error message

**default**
General Error.

The request may or may not be safe to retry, depending on the HTTP method, response status code,
and whether a response was received.

- If no response is returned from the API, a network error or timeout likely occurred.
- In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results.

The following HTTP methods are considered non-idempotent: `POST`, `PATCH`, `DELETE`, and `PUT`. Retrying these methods is generally **not safe**.
The following methods are considered idempotent: `GET`, `HEAD`, and `OPTIONS`. Retrying these methods is **safe** in the event of a network error or timeout.

Any request that returns a `503 Service Unavailable` response is always safe to retry.

Any request that returns a `423 Locked` response is safe to retry. `423 Locked` indicates that the resource is temporarily locked, for example, due to another operation in progress.

- `request_id` (string, optional)
  Unique identifier for the request, useful for debugging.
  You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.
  
- `code` (string, required)
  Machine-readable code classifying the error type. See `message` for a human-readable explanation.
  Default: ``
- `message` (string, required)
  Error message
