/projects/{project_id}/jwksAdd JWKS URLAdds a JWKS URL to the specified project for verifying JWTs used as the authentication mechanism.
The URL must be a valid HTTPS URL that returns a JSON Web Key Set.
The provider_name field allows you to specify which authentication provider you're using (e.g., Clerk, Auth0, AWS Cognito).
The branch_id scopes the JWKS URL to specific branches; if not specified, it applies to all branches.
The role_names scopes the URL to specific roles; if not specified, default roles are used (authenticator, authenticated, anonymous).
The jwt_audience specifies which aud values are accepted in JWTs.
Parameters
project_idstringpathrequiredThe Neon project ID
Request body
requiredapplication/json
Add a new JWKS to a specific endpoint of a project
branch_idstringThe Neon branch ID. Returned as `id` from `GET /projects/{project_id}/branches`.
jwks_urlstringrequiredURL of the provider's JWKS endpoint used to verify JWTs.
jwt_audiencestringExpected `aud` claim in incoming JWTs. When set, tokens with a different audience are rejected; tokens with no audience are still accepted. Omit to skip audience validation.
provider_namestringrequiredThe name of the authentication provider (e.g., Clerk, Stytch, Auth0)
role_namesarray of stringDeprecated. The roles the JWKS should be mapped to. By default, the JWKS is mapped to the `authenticator`, `authenticated`, and `anonymous` roles.
Show child attributes
skip_role_creationbooleanDeprecated. Only used with Neon RLS. If true, role creation is skipped.
{
"branch_id": "string",
"jwks_url": "string",
"jwt_audience": "string",
"provider_name": "string",
"role_names": [
"string"
],
"skip_role_creation": false
}Responses
allOf · 2 options
jwksobjectrequiredShow child attributes
branch_idstringThe Neon branch ID. Returned as `id` from `GET /projects/{project_id}/branches`.
created_atstring · date-timerequiredThe date and time when the JWKS was created
idstringrequiredThe JWKS configuration's ID.
jwks_urlstringrequiredURL of the provider's JWKS endpoint used to verify JWTs.
jwt_audiencestringExpected JWT `aud` claim value configured for this JWKS.
project_idstringrequiredThe Neon project ID. Returned as `id` from `GET /projects`.
provider_namestringrequiredThe name of the authentication provider (e.g., Clerk, Stytch, Auth0)
role_namesarray of stringDatabase role names that are permitted to authenticate using this JWKS configuration.
Show child attributes
updated_atstring · date-timerequiredThe date and time when the JWKS was last modified
operationsarray of objectrequiredShow child attributes
Show array items
An asynchronous action Neon performs on your resources (for example, starting a compute or creating a branch). Fields such as `action`, `status`, and `total_duration_ms` describe the operation and its progress.
actionstringrequiredThe action performed by the operation
branch_idstringThe ID of the branch this operation ran on.
created_atstring · date-timerequiredA timestamp indicating when the operation was created
endpoint_idstringThe ID of the compute endpoint this operation ran on.
errorstringHuman-readable message describing why the operation failed.
failures_countinteger · int32requiredThe number of times the operation failed
idstring · uuidrequiredThe operation ID
project_idstringrequiredThe ID of the project this operation ran on.
retry_atstring · date-timeA timestamp indicating when the operation was last retried
statusstringrequiredLifecycle state of the operation. `scheduling`: queued, not yet started. `running`: actively executing. `finished`: completed successfully. `failed`: ended with a failure. `error`: ended with a terminal error. `cancelling`: cancellation requested but not yet complete. `cancelled`: stopped before completion. `skipped`: bypassed without executing.
total_duration_msinteger · int32requiredThe total duration of the operation in milliseconds
updated_atstring · date-timerequiredA timestamp indicating when the operation status was last updated
{
"jwks": {
"branch_id": "string",
"created_at": "2026-06-09T00:00:00Z",
"id": "string",
"jwks_url": "string",
"jwt_audience": "string",
"project_id": "string",
"provider_name": "string",
"role_names": [
"string"
],
"updated_at": "2026-06-09T00:00:00Z"
},
"operations": [
{
"action": "start_compute",
"branch_id": "br-wispy-meadow-118737",
"created_at": "2022-11-15T20:02:00Z",
"endpoint_id": "ep-silent-smoke-806639",
"failures_count": 0,
"id": "d8ac46eb-a757-42b1-9907-f78322ee394e",
"project_id": "spring-example-302709",
"status": "finished",
"total_duration_ms": 200,
"updated_at": "2022-11-15T20:02:02Z"
}
]
}codestringrequiredmessagestringrequiredError message
request_idstringUnique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.
{
"code": "",
"message": "string",
"request_id": "string"
}