/projects/{project_id}/branches/{branch_id}/credentials/{token_id}/rotatebetaRotate a credential's secrets
Replaces the secret material on an existing scoped credential in
place. token_id is preserved — it is the AWS_ACCESS_KEY_ID for
S3-compatible clients, so the access key id your application already
holds keeps working and only the secret changes. This is the analog of
resetting a Postgres password, not of issuing a second credential.
The response carries the new api_token and s3_secret_access_key
exactly once. Rotation is not idempotent: retrying after an
ambiguous timeout mints another secret and supersedes the previous
replacement, so a retry does not recover a lost response — it only
invalidates the secret you did not receive. If you lose the response,
issue a replacement credential and revoke this one.
The old secret stops authenticating as soon as the rotation commits.
Where a region caches credentials on its data-plane verifiers, a
replica may briefly keep accepting the old secret — and rejecting the
new one — until its cache entry expires; where it does not, the
cutover is immediate apart from requests already in flight. Either way
the changeover is not atomic across replicas, so retry an unexpected
authentication failure right after rotating rather than treating the
new secret as bad. last_used_at continues to report the logical
credential's prior usage and says nothing about whether the new secret
has been used yet.
Only a live, unexpired, unrevoked customer-managed (user) credential
on a live project and live branch is eligible. Anything else —
including the platform-internal function and system credentials —
is reported as not found, indistinguishable from an unknown
token_id.
Note: This endpoint is currently in Beta.
Quick start
curl "https://console.neon.tech/api/v2/projects/$PROJECT_ID/branches/$BRANCH_ID/credentials/$TOKEN_ID/rotate" \
-X POST \
-H "Authorization: Bearer $NEON_API_KEY"Every field below is optional. An empty body works too.
import { createNeonClient, raw } from '@neon/sdk';
const neon = createNeonClient({ apiKey: process.env.NEON_API_KEY });
const { data } = await raw.rotateCredential({
client: neon.client,
path: {
project_id: process.env.PROJECT_ID,
branch_id: process.env.BRANCH_ID,
token_id: process.env.TOKEN_ID
}
});Parameters
project_idThe Neon project ID
branch_idThe Neon branch ID
token_idThe opaque credential id (e.g. nak_live_<32hex>).
Response
200Credential rotated — new secrets shown once.
Errors
General error
This endpoint can return the standard Neon API error response.
Response fields
messageRequired. Human-readable error message.codeRequired. Machine-readable error code.request_idOptional. Request identifier for debugging. You can provide one with theX-Request-IDheader.
Retry guidance
If no response is returned, the request may still have reached the server. This is why retry safety depends on the method and status code.
Idempotent methods (GET, HEAD, OPTIONS) are generally safe to retry after a network error or timeout. Non-idempotent methods (POST, PATCH, DELETE, PUT) can change state, so avoid automatic retries unless your workflow can tolerate duplicate effects.
Responses with 423 Locked or 503 Service Unavailable are safe to retry. 423 Locked means the resource is temporarily locked, usually because another operation is in progress.








