Skip to main content
Neon Postgres Docs

Search documentation

Type to search this documentation.

Add JWKS URL

POST/projects/{project_id}/jwksAdd JWKS URL

Adds a JWKS URL to the specified project for verifying JWTs used as the authentication mechanism.

The URL must be a valid HTTPS URL that returns a JSON Web Key Set.

The provider_name field allows you to specify which authentication provider you're using (e.g., Clerk, Auth0, AWS Cognito).

The branch_id scopes the JWKS URL to specific branches; if not specified, it applies to all branches.

The role_names scopes the URL to specific roles; if not specified, default roles are used (authenticator, authenticated, anonymous).

The jwt_audience specifies which aud values are accepted in JWTs.

Parameters

project_idstringpathrequired

The Neon project ID

pattern ^[a-z0-9-]{1,60}$

Request body

required
application/json
objectAddProjectJWKSRequest

Add a new JWKS to a specific endpoint of a project

branch_idstring

The Neon branch ID. Returned as `id` from `GET /projects/{project_id}/branches`.

pattern ^[a-z0-9-]{1,60}$

jwks_urlstringrequired

URL of the provider's JWKS endpoint used to verify JWTs.

jwt_audiencestring

Expected `aud` claim in incoming JWTs. When set, tokens with a different audience are rejected; tokens with no audience are still accepted. Omit to skip audience validation.

provider_namestringrequired

The name of the authentication provider (e.g., Clerk, Stytch, Auth0)

role_namesarray of string

Deprecated. The roles the JWKS should be mapped to. By default, the JWKS is mapped to the `authenticator`, `authenticated`, and `anonymous` roles.

maxItems 10 · minItems 0

Show child attributes

maxItems 10 · minItems 0

skip_role_creationboolean

Deprecated. Only used with Neon RLS. If true, role creation is skipped.

default false

Example request
{
  "branch_id": "string",
  "jwks_url": "string",
  "jwt_audience": "string",
  "provider_name": "string",
  "role_names": [
    "string"
  ],
  "skip_role_creation": false
}

Responses

201The JWKS URL was added to the project's authentication connectionsapplication/json
valueJWKSCreationOperation
allOf · 2 options
Option 1objectJWKSResponse
jwksobjectrequired
Show child attributes
branch_idstring

The Neon branch ID. Returned as `id` from `GET /projects/{project_id}/branches`.

pattern ^[a-z0-9-]{1,60}$

created_atstring · date-timerequired

The date and time when the JWKS was created

idstringrequired

The JWKS configuration's ID.

jwks_urlstringrequired

URL of the provider's JWKS endpoint used to verify JWTs.

jwt_audiencestring

Expected JWT `aud` claim value configured for this JWKS.

project_idstringrequired

The Neon project ID. Returned as `id` from `GET /projects`.

pattern ^[a-z0-9-]{1,60}$

provider_namestringrequired

The name of the authentication provider (e.g., Clerk, Stytch, Auth0)

role_namesarray of string

Database role names that are permitted to authenticate using this JWKS configuration.

Show child attributes
updated_atstring · date-timerequired

The date and time when the JWKS was last modified

Option 2objectOperationsResponse
operationsarray of objectrequired
Show child attributes
Show array items

An asynchronous action Neon performs on your resources (for example, starting a compute or creating a branch). Fields such as `action`, `status`, and `total_duration_ms` describe the operation and its progress.

actionstringrequired

The action performed by the operation

one of "create_compute", "create_timeline", "start_compute", "suspend_compute", "apply_config", "check_availability", "delete_timeline", "create_branch", "import_data", "tenant_ignore", "tenant_attach", "tenant_detach", "tenant_detach_safekeepers", "tenant_attach_safekeepers", "tenant_reattach", "replace_safekeeper", "disable_maintenance", "apply_storage_config", "prepare_secondary_pageserver", "switch_pageserver", "detach_parent_branch", "timeline_archive", "timeline_unarchive", "start_reserved_compute", "sync_dbs_and_roles_from_compute", "apply_schema_from_branch", "timeline_mark_invisible", "timeline_update_protected_config", "prewarm_replica", "promote_replica", "set_storage_non_dirty", "swap_binding_id", "finalize_migration", "mark_migration_prepared", "update_catalog", "epc_sync"

branch_idstring

The ID of the branch this operation ran on.

pattern ^[a-z0-9-]{1,60}$

created_atstring · date-timerequired

A timestamp indicating when the operation was created

endpoint_idstring

The ID of the compute endpoint this operation ran on.

pattern ^[a-z0-9-]{1,60}$

errorstring

Human-readable message describing why the operation failed.

failures_countinteger · int32required

The number of times the operation failed

idstring · uuidrequired

The operation ID

project_idstringrequired

The ID of the project this operation ran on.

pattern ^[a-z0-9-]{1,60}$

retry_atstring · date-time

A timestamp indicating when the operation was last retried

statusstringrequired

Lifecycle state of the operation. `scheduling`: queued, not yet started. `running`: actively executing. `finished`: completed successfully. `failed`: ended with a failure. `error`: ended with a terminal error. `cancelling`: cancellation requested but not yet complete. `cancelled`: stopped before completion. `skipped`: bypassed without executing.

one of "scheduling", "running", "finished", "failed", "error", "cancelling", "cancelled", "skipped"

total_duration_msinteger · int32required

The total duration of the operation in milliseconds

updated_atstring · date-timerequired

A timestamp indicating when the operation status was last updated

Example response
{
  "jwks": {
    "branch_id": "string",
    "created_at": "2026-06-09T00:00:00Z",
    "id": "string",
    "jwks_url": "string",
    "jwt_audience": "string",
    "project_id": "string",
    "provider_name": "string",
    "role_names": [
      "string"
    ],
    "updated_at": "2026-06-09T00:00:00Z"
  },
  "operations": [
    {
      "action": "start_compute",
      "branch_id": "br-wispy-meadow-118737",
      "created_at": "2022-11-15T20:02:00Z",
      "endpoint_id": "ep-silent-smoke-806639",
      "failures_count": 0,
      "id": "d8ac46eb-a757-42b1-9907-f78322ee394e",
      "project_id": "spring-example-302709",
      "status": "finished",
      "total_duration_ms": 200,
      "updated_at": "2022-11-15T20:02:02Z"
    }
  ]
}
defaultGeneral Error. The request may or may not be safe to retry, depending on the HTTP method, response status code, and whether a response was received. - If no response is returned from the API, a network error or timeout likely occurred. - In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results. The following HTTP methods are considered non-idempotent: `POST`, `PATCH`, `DELETE`, and `PUT`. Retrying these methods is generally **not safe**. The following methods are considered idempotent: `GET`, `HEAD`, and `OPTIONS`. Retrying these methods is **safe** in the event of a network error or timeout. Any request that returns a `503 Service Unavailable` response is always safe to retry. Any request that returns a `423 Locked` response is safe to retry. `423 Locked` indicates that the resource is temporarily locked, for example, due to another operation in progress. application/json
objectGeneralError
codestringrequired

default ""

messagestringrequired

Error message

request_idstring

Unique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.

Example response
{
  "code": "",
  "message": "string",
  "request_id": "string"
}
Documentation menu