We ran the same workload through 42 models via AI Gateway and compared costs
/APIs & SDKs/Credentials/Rotate a credential's secrets
POST/projects/{project_id}/branches/{branch_id}/credentials/{token_id}/rotatebeta

Rotate a credential's secrets

Replaces the secret material on an existing scoped credential in place. token_id is preserved — it is the AWS_ACCESS_KEY_ID for S3-compatible clients, so the access key id your application already holds keeps working and only the secret changes. This is the analog of resetting a Postgres password, not of issuing a second credential.

The response carries the new api_token and s3_secret_access_key exactly once. Rotation is not idempotent: retrying after an ambiguous timeout mints another secret and supersedes the previous replacement, so a retry does not recover a lost response — it only invalidates the secret you did not receive. If you lose the response, issue a replacement credential and revoke this one.

The old secret stops authenticating as soon as the rotation commits. Where a region caches credentials on its data-plane verifiers, a replica may briefly keep accepting the old secret — and rejecting the new one — until its cache entry expires; where it does not, the cutover is immediate apart from requests already in flight. Either way the changeover is not atomic across replicas, so retry an unexpected authentication failure right after rotating rather than treating the new secret as bad. last_used_at continues to report the logical credential's prior usage and says nothing about whether the new secret has been used yet.

Only a live, unexpired, unrevoked customer-managed (user) credential on a live project and live branch is eligible. Anything else — including the platform-internal function and system credentials — is reported as not found, indistinguishable from an unknown token_id.

Note: This endpoint is currently in Beta.

Markdown for AI context

Quick start

REST API - curl
curl "https://console.neon.tech/api/v2/projects/$PROJECT_ID/branches/$BRANCH_ID/credentials/$TOKEN_ID/rotate" \
  -X POST \
  -H "Authorization: Bearer $NEON_API_KEY"

Every field below is optional. An empty body works too.

Also available in
import { createNeonClient, raw } from '@neon/sdk';

const neon = createNeonClient({ apiKey: process.env.NEON_API_KEY });
const { data } = await raw.rotateCredential({
  client: neon.client,
  path: {
    project_id: process.env.PROJECT_ID,
    branch_id: process.env.BRANCH_ID,
    token_id: process.env.TOKEN_ID
  }
});

Parameters

Project ID
project_id
string

The Neon project ID

Branch ID
branch_id
string

The Neon branch ID

Token ID
token_id
string

The opaque credential id (e.g. nak_live_<32hex>).

Response

200

Credential rotated — new secrets shown once.

Depth
"token_id": (string),req
"token_id_short": (string),req
"api_token": (string),req
"s3_secret_access_key": (string),req
"scopes": (array),req
"branch_id": (string),req
"principal_type": (string),requser
"created_at": (string),reqdate-time
"name": (string),
"expires_at": (string),date-time

Errors

default

General error

This endpoint can return the standard Neon API error response.

Response fields

  • message Required. Human-readable error message.
  • code Required. Machine-readable error code.
  • request_id Optional. Request identifier for debugging. You can provide one with the X-Request-ID header.

Retry guidance

If no response is returned, the request may still have reached the server. This is why retry safety depends on the method and status code.

Idempotent methods (GET, HEAD, OPTIONS) are generally safe to retry after a network error or timeout. Non-idempotent methods (POST, PATCH, DELETE, PUT) can change state, so avoid automatic retries unless your workflow can tolerate duplicate effects.

Responses with 423 Locked or 503 Service Unavailable are safe to retry. 423 Locked means the resource is temporarily locked, usually because another operation is in progress.

Was this page helpful?

On this page

Copy neon init command