/projects/{project_id}/branches/{branch_id}/credentialsIssue a scoped credential on the branchIssues a new scoped service credential anchored to the specified branch. The response carries api_token and s3_secret_access_key exactly once — they are not stored server-side.
Note: This endpoint is currently in Beta.
Parameters
project_idstringpathrequiredThe Neon project ID
branch_idstringpathrequiredThe Neon branch ID
Request body
requiredapplication/json
namestringFree-form customer label for the credential.
principal_typestringrequiredPrincipal type for the credential. Only `user` is customer-managed and accepted here. `function` and `system` credentials are platform-internal (e.g. function-serve auto-mint, presign signer) and are never issued through the customer-facing API.
scopesarray of stringrequiredShow child attributes
{
"name": "string",
"principal_type": "user",
"scopes": [
"ai_gateway:invoke"
]
}Responses
api_tokenstringrequiredBearer token; returned exactly once.
branch_idstringrequiredcreated_atstring · date-timerequiredexpires_atstring · date-timeWhen the credential expires; absent means never expires.
namestringCustomer-supplied label, echoed back from the request. Absent when not provided.
s3_secret_access_keystringrequirednsk_live_<64 hex>; the AWS_SECRET_ACCESS_KEY, returned exactly once.
scopesarray of stringrequiredShow child attributes
token_idstringrequiredOpaque credential id (e.g. nak_live_<32hex>).
token_id_shortstringrequiredFirst 12 hex chars of token_id; safe to log.
{
"api_token": "",
"branch_id": "string",
"created_at": "2026-06-09T00:00:00Z",
"expires_at": "2026-06-09T00:00:00Z",
"name": "string",
"s3_secret_access_key": "string",
"scopes": [
"ai_gateway:invoke"
],
"token_id": "string",
"token_id_short": "string"
}codestringrequiredmessagestringrequiredError message
request_idstringUnique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.
{
"code": "",
"message": "string",
"request_id": "string"
}