Skip to main content
Neon Postgres Docs

Search documentation

Type to search this documentation.

Issue a scoped credential on the branch

POST/projects/{project_id}/branches/{branch_id}/credentialsIssue a scoped credential on the branch

Issues a new scoped service credential anchored to the specified branch. The response carries api_token and s3_secret_access_key exactly once — they are not stored server-side.

Note: This endpoint is currently in Beta.

Parameters

project_idstringpathrequired

The Neon project ID

pattern ^[a-z0-9-]{1,60}$

branch_idstringpathrequired

The Neon branch ID

pattern ^[a-z0-9-]{1,60}$

Request body

required
application/json
objectCreateCredentialRequest
namestring

Free-form customer label for the credential.

maxLength 256

principal_typestringrequired

Principal type for the credential. Only `user` is customer-managed and accepted here. `function` and `system` credentials are platform-internal (e.g. function-serve auto-mint, presign signer) and are never issued through the customer-facing API.

one of "user"

scopesarray of stringrequired

maxItems 16 · minItems 1

Show child attributes

maxItems 16 · minItems 1

Example request
{
  "name": "string",
  "principal_type": "user",
  "scopes": [
    "ai_gateway:invoke"
  ]
}

Responses

201Credential issued — secrets shown once.application/json
objectCreateCredentialResponse
api_tokenstringrequired

Bearer token; returned exactly once.

branch_idstringrequired

pattern ^[a-z0-9-]{1,60}$

created_atstring · date-timerequired
expires_atstring · date-time

When the credential expires; absent means never expires.

namestring

Customer-supplied label, echoed back from the request. Absent when not provided.

s3_secret_access_keystringrequired

nsk_live_<64 hex>; the AWS_SECRET_ACCESS_KEY, returned exactly once.

scopesarray of stringrequired
Show child attributes
token_idstringrequired

Opaque credential id (e.g. nak_live_<32hex>).

token_id_shortstringrequired

First 12 hex chars of token_id; safe to log.

Example response
{
  "api_token": "",
  "branch_id": "string",
  "created_at": "2026-06-09T00:00:00Z",
  "expires_at": "2026-06-09T00:00:00Z",
  "name": "string",
  "s3_secret_access_key": "string",
  "scopes": [
    "ai_gateway:invoke"
  ],
  "token_id": "string",
  "token_id_short": "string"
}
defaultGeneral Error. The request may or may not be safe to retry, depending on the HTTP method, response status code, and whether a response was received. - If no response is returned from the API, a network error or timeout likely occurred. - In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results. The following HTTP methods are considered non-idempotent: `POST`, `PATCH`, `DELETE`, and `PUT`. Retrying these methods is generally **not safe**. The following methods are considered idempotent: `GET`, `HEAD`, and `OPTIONS`. Retrying these methods is **safe** in the event of a network error or timeout. Any request that returns a `503 Service Unavailable` response is always safe to retry. Any request that returns a `423 Locked` response is safe to retry. `423 Locked` indicates that the resource is temporarily locked, for example, due to another operation in progress. application/json
objectGeneralError
codestringrequired

default ""

messagestringrequired

Error message

request_idstring

Unique identifier for the request, useful for debugging. You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.

Example response
{
  "code": "",
  "message": "string",
  "request_id": "string"
}
Documentation menu